Skip to content

Implementation as work products

Implementation path under BSI Standard 200-2

7 chapters put decisions, responsibilities and evidence in a defensible order.

Back to BSI IT-Grundschutz

  1. 01

    Initiation

    Initiate the security process

    Define the mandate, policy, roles, resources and approach.

    Expected work products

    • Management resolution
    • Security policy
    • Role model
    • Method decision

    Based on: BSI, BSI, KaitoSec

  2. 02

    Structure

    Structure the information domain

    Capture services and all supporting objects in connected form.

    Expected work products

    • Domain delimitation
    • Process inventory
    • Object inventory
    • Dependency map

    Based on: BSI, KaitoSec

  3. 03

    Protection needs

    Determine protection needs

    Assess damage and inherit protection needs traceably.

    Expected work products

    • Assessment criteria
    • Business assessments
    • Inheritance logic
    • Approvals

    Based on: BSI, KaitoSec

  4. 04

    Modelling

    Model IT-Grundschutz

    Map the current edition's modules onto target objects and groups.

    Expected work products

    • Module mapping
    • Target object reference
    • Adaptation justifications
    • Version status

    Based on: BSI, BSI, KaitoSec

  5. 05

    Check

    Carry out the IT-Grundschutz-Check

    Assess implementation with interviews, spot checks and evidence.

    Expected work products

    • Check plan
    • Status assessment
    • Evidence register
    • Implementation plan

    Based on: BSI, BSI, KaitoSec

  6. 06

    Risk

    Treat additional risks

    Identify particular threats and decide on supplementary measures.

    Expected work products

    • Risk triggers
    • Risk overview
    • Measure decisions
    • Residual risk approvals

    Based on: BSI, KaitoSec

  7. 07

    Operation

    Maintain and improve

    Permanently interlock changes, audits, BCM and improvement.

    Expected work products

    • Review calendar
    • Audit programme
    • BCM interface
    • Improvement backlog

    Based on: BSI, BSI, KaitoSec