Browser-local readiness check
IT-Grundschutz starter check
20 evidence-backed questions from the security process through to maintenance. The evaluation stays local in your browser.
- 01
Initiation
Has management commissioned the information security process?
Expected evidence: Management resolution
- 02
Initiation
Are the information security officer, responsibilities and reporting lines defined?
Expected evidence: Role and committee model
- 03
Initiation
Is a security policy approved and communicated?
Expected evidence: Policy and communication
- 04
Scope
Is the information domain clearly delimited?
Expected evidence: Scoping document
- 05
Scope
Is the chosen protection approach justified and formally decided?
Expected evidence: Method decision
- 06
Structural analysis
Are business processes and information recorded?
Expected evidence: Process and information inventory
- 07
Structural analysis
Are applications, systems, connections and rooms assigned?
Expected evidence: Structural analysis
- 08
Structural analysis
Are grouping and object ownership traceable?
Expected evidence: Grouping rules
- 09
Protection needs
Are damage scenarios and categories defined specifically for the organisation?
Expected evidence: Protection needs methodology
- 10
Protection needs
Are the protection needs for processes and information justified?
Expected evidence: Approved assessments
- 11
Protection needs
Are inheritance, cumulation and distribution documented?
Expected evidence: Inheritance record
- 12
Modelling
Is a valid Compendium edition defined?
Expected evidence: Method and version status
- 13
Modelling
Are relevant modules linked to target objects?
Expected evidence: Modelling table
- 14
Modelling
Are adaptations and non-relevant requirements justified?
Expected evidence: Deviation justifications
- 15
Check
Is the implementation status checked against current evidence?
Expected evidence: IT-Grundschutz-Check
- 16
Check
Are deviations linked to measures, owners and due dates?
Expected evidence: Implementation plan
- 17
Risk
Are triggers for additional risk analyses defined?
Expected evidence: Risk criteria
- 18
Risk
Are particular risks and supplementary measures documented?
Expected evidence: Risk analyses
- 19
Maintenance
Are the domain, protection needs and modelling updated when changes occur?
Expected evidence: Review and change records
- 20
Maintenance
Are effectiveness, audits and improvements managed regularly?
Expected evidence: Audit and management reports