Implementation as work products
Implementation path under BSI Standard 200-2
7 chapters put decisions, responsibilities and evidence in a defensible order.
- 01
Initiation
Initiate the security process
Define the mandate, policy, roles, resources and approach.
Expected work products
- Management resolution
- Security policy
- Role model
- Method decision
Based on: BSI, BSI, KaitoSec
- 02
Structure
Structure the information domain
Capture services and all supporting objects in connected form.
Expected work products
- Domain delimitation
- Process inventory
- Object inventory
- Dependency map
Based on: BSI, KaitoSec
- 03
Protection needs
Determine protection needs
Assess damage and inherit protection needs traceably.
Expected work products
- Assessment criteria
- Business assessments
- Inheritance logic
- Approvals
Based on: BSI, KaitoSec
- 04
Modelling
Model IT-Grundschutz
Map the current edition's modules onto target objects and groups.
Expected work products
- Module mapping
- Target object reference
- Adaptation justifications
- Version status
Based on: BSI, BSI, KaitoSec
- 05
Check
Carry out the IT-Grundschutz-Check
Assess implementation with interviews, spot checks and evidence.
Expected work products
- Check plan
- Status assessment
- Evidence register
- Implementation plan
Based on: BSI, BSI, KaitoSec
- 06
Risk
Treat additional risks
Identify particular threats and decide on supplementary measures.
Expected work products
- Risk triggers
- Risk overview
- Measure decisions
- Residual risk approvals
Based on: BSI, KaitoSec
- 07
Operation
Maintain and improve
Permanently interlock changes, audits, BCM and improvement.
Expected work products
- Review calendar
- Audit programme
- BCM interface
- Improvement backlog
Based on: BSI, BSI, KaitoSec