Skip to content

Protection needs

Protection needs assessment: justify categories instead of documenting gut feeling

Protection needs arise from potential damage to processes and information. Inheritance and cumulation then carry them over to the technology.

Back to BSI IT-Grundschutz

10 minute read · Content as of 21.07.2026

What is the protection needs assessment under BSI Standard 200-2?

The protection needs assessment assigns each target object in the information domain one of three categories, normal, high or very high, separately for confidentiality, integrity and availability. The aim is to direct effort to where damage would actually hurt the organisation and to identify the target objects that need a risk analysis under BSI Standard 200-3.

BSI Standard 200-2 provides six damage scenarios against which the rating is justified. Business processes and applications are rated first; the protection needs are then carried over to IT systems, rooms and communication links.

  • Violations of laws, regulations or contracts
  • Impairment of the right to informational self-determination
  • Impairment of personal integrity
  • Impairment of task performance
  • Negative internal or external effects
  • Financial consequences

Assess processes and information first

The protection needs assessment considers confidentiality, integrity and availability in terms of potential damage. Understandable scenarios and organisation-specific thresholds make the classification traceable.

The maximum principle alone is not always enough

The protection needs of supporting applications and systems are derived from the objects that depend on them. Distribution effects can reduce the need, cumulation effects can increase it. Every deviation needs a documented justification.

  • Define damage scenarios and thresholds up front
  • Involve business owners in the assessment
  • Document inheritance paths visibly
  • Check cumulation and distribution explicitly
  • Approve decisions under the four-eyes principle

Questions help more than abstract categories

The free protection needs starter translates the protection goals into concrete impact questions. That gives business units a traceable frame for the conversation instead of an empty selection box.

Sources used

  • BSI Standard 200-2 · BSI · Version 1.0 · October 2017
  • Grundschutz practice patterns · KaitoSec

Back to BSI IT-Grundschutz