Skip to content

Modelling

IT-Grundschutz modelling: mapping modules cleanly onto target objects

The modelling decides which requirements apply to which target objects. Mistakes here multiply across the entire IT-Grundschutz-Check.

Back to BSI IT-Grundschutz

8 minute read · Content as of 21.07.2026

Modules follow the layers of the information domain

Process and organisation modules cover overarching requirements. Further modules are assigned to match applications, systems, networks, infrastructure and, where present, industrial components.

Every assignment needs a concrete target object

A bare list of relevant modules is not enough. The modelling becomes auditable through the connection of module, target object or target object group, version and justified adaptations.

  • Fix the current Compendium edition
  • Reference target objects and groups unambiguously
  • Justify requirements that are not relevant
  • Document substitute measures traceably
  • Feed changes to the domain back into the modelling

The modelling map prevents blind spots

The free template connects layer, module, target object, owner and review status. That makes gaps visible before the actual check begins.

Sources used

Back to BSI IT-Grundschutz