Protection needs
Protection needs assessment: justify categories instead of documenting gut feeling
Protection needs arise from potential damage to processes and information. Inheritance and cumulation then carry them over to the technology.
10 minute read · Content as of 21.07.2026
What is the protection needs assessment under BSI Standard 200-2?
The protection needs assessment assigns each target object in the information domain one of three categories, normal, high or very high, separately for confidentiality, integrity and availability. The aim is to direct effort to where damage would actually hurt the organisation and to identify the target objects that need a risk analysis under BSI Standard 200-3.
BSI Standard 200-2 provides six damage scenarios against which the rating is justified. Business processes and applications are rated first; the protection needs are then carried over to IT systems, rooms and communication links.
- Violations of laws, regulations or contracts
- Impairment of the right to informational self-determination
- Impairment of personal integrity
- Impairment of task performance
- Negative internal or external effects
- Financial consequences
Assess processes and information first
The protection needs assessment considers confidentiality, integrity and availability in terms of potential damage. Understandable scenarios and organisation-specific thresholds make the classification traceable.
The maximum principle alone is not always enough
The protection needs of supporting applications and systems are derived from the objects that depend on them. Distribution effects can reduce the need, cumulation effects can increase it. Every deviation needs a documented justification.
- Define damage scenarios and thresholds up front
- Involve business owners in the assessment
- Document inheritance paths visibly
- Check cumulation and distribution explicitly
- Approve decisions under the four-eyes principle
Questions help more than abstract categories
The free protection needs starter translates the protection goals into concrete impact questions. That gives business units a traceable frame for the conversation instead of an empty selection box.
Sources used
- BSI Standard 200-2 · BSI · Version 1.0 · October 2017
- Grundschutz practice patterns · KaitoSec