Skip to content

Browser-local readiness check

IT-Grundschutz starter check

20 evidence-backed questions from the security process through to maintenance. The evaluation stays local in your browser.

Back to BSI IT-Grundschutz

  1. 01

    Initiation

    Has management commissioned the information security process?

    Expected evidence: Management resolution

  2. 02

    Initiation

    Are the information security officer, responsibilities and reporting lines defined?

    Expected evidence: Role and committee model

  3. 03

    Initiation

    Is a security policy approved and communicated?

    Expected evidence: Policy and communication

  4. 04

    Scope

    Is the information domain clearly delimited?

    Expected evidence: Scoping document

  5. 05

    Scope

    Is the chosen protection approach justified and formally decided?

    Expected evidence: Method decision

  6. 06

    Structural analysis

    Are business processes and information recorded?

    Expected evidence: Process and information inventory

  7. 07

    Structural analysis

    Are applications, systems, connections and rooms assigned?

    Expected evidence: Structural analysis

  8. 08

    Structural analysis

    Are grouping and object ownership traceable?

    Expected evidence: Grouping rules

  9. 09

    Protection needs

    Are damage scenarios and categories defined specifically for the organisation?

    Expected evidence: Protection needs methodology

  10. 10

    Protection needs

    Are the protection needs for processes and information justified?

    Expected evidence: Approved assessments

  11. 11

    Protection needs

    Are inheritance, cumulation and distribution documented?

    Expected evidence: Inheritance record

  12. 12

    Modelling

    Is a valid Compendium edition defined?

    Expected evidence: Method and version status

  13. 13

    Modelling

    Are relevant modules linked to target objects?

    Expected evidence: Modelling table

  14. 14

    Modelling

    Are adaptations and non-relevant requirements justified?

    Expected evidence: Deviation justifications

  15. 15

    Check

    Is the implementation status checked against current evidence?

    Expected evidence: IT-Grundschutz-Check

  16. 16

    Check

    Are deviations linked to measures, owners and due dates?

    Expected evidence: Implementation plan

  17. 17

    Risk

    Are triggers for additional risk analyses defined?

    Expected evidence: Risk criteria

  18. 18

    Risk

    Are particular risks and supplementary measures documented?

    Expected evidence: Risk analyses

  19. 19

    Maintenance

    Are the domain, protection needs and modelling updated when changes occur?

    Expected evidence: Review and change records

  20. 20

    Maintenance

    Are effectiveness, audits and improvements managed regularly?

    Expected evidence: Audit and management reports