Modelling
IT-Grundschutz modelling: mapping modules cleanly onto target objects
The modelling decides which requirements apply to which target objects. Mistakes here multiply across the entire IT-Grundschutz-Check.
8 minute read · Content as of 21.07.2026
Modules follow the layers of the information domain
Process and organisation modules cover overarching requirements. Further modules are assigned to match applications, systems, networks, infrastructure and, where present, industrial components.
Every assignment needs a concrete target object
A bare list of relevant modules is not enough. The modelling becomes auditable through the connection of module, target object or target object group, version and justified adaptations.
- Fix the current Compendium edition
- Reference target objects and groups unambiguously
- Justify requirements that are not relevant
- Document substitute measures traceably
- Feed changes to the domain back into the modelling
The modelling map prevents blind spots
The free template connects layer, module, target object, owner and review status. That makes gaps visible before the actual check begins.
Sources used
- BSI Standard 200-2 · BSI · Version 1.0 · October 2017
- IT-Grundschutz Compendium · BSI · Edition 2022
- Grundschutz practice patterns · KaitoSec