Skip to content

Municipalities, cities and districts

From WIBA to Grundschutz++ without entering anything twice.

KaitoSec brings the WIBA questionnaire, the municipal IT-Grundschutz profile and the Grundschutz compendium together in one data model. What you answer for WIBA feeds Basic Protection (Basis-Absicherung); what you implement there carries through to Grundschutz++.

IT-Grundschutz check audit plan: per target object the protection need, contact, progress of the checked module requirements and follow-up.
Check complete
Follow-up current
  • TeleTrusT trust seal, IT Security made in Germany
  • Member of BITMi, Bundesverband IT-Mittelstand e. V.
  • OMR Reviews5.0 out of 5
  • HOSTING INGERMANY
  • GDPR-COMPLIANT
  • GRUNDSCHUTZ++ READY

Four stages on the same data.

  1. WIBA: the road into Basic Protection

    The complete BSI WIBA questionnaire lives in the tool. Every answer is mapped to the matching requirements of the Grundschutz compendium and creates the data base for everything that follows.

    The control Patch and change management with status, owner, due date and effectiveness, above the four ISO 27001 requirements it meets.
    The requirements the control meets: A.8.8, A.8.32, A.8.9 and A.8.19.
  2. Municipal IT-Grundschutz profile

    The Grundschutz profile for municipal administrations serves as the template for your information domain: adopt the module scope, adapt it to your own specialised procedures, derive the audit plan.

    Protection rating of an ERP database: confidentiality high, integrity very high, availability high, giving an elevated protection level, with rationale.
  3. Basic and Standard Protection

    Modelling, the IT-Grundschutz check, risk analysis under BSI standard 200-3, treatment planning and reports run in the same tool, without a consulting project alongside.

    Risk matrix of likelihood and impact on five levels each, every cell shaded by its risk level.Inherent riskResidual risk
  4. Grundschutz++ ready

    Catalogues and evidence are OSCAL-based and machine-readable. When the machine-readable Grundschutz arrives, you carry your data forward instead of re-entering it.

    Requirement A.8.8 with status, owner and due date, above its context chain: one control, two risks, one finding, one improvement, two assets.
The control Patch and change management with status, owner, due date and effectiveness, above the four ISO 27001 requirements it meets.
The requirements the control meets: A.8.8, A.8.32, A.8.9 and A.8.19.

Implement standards despite tight budgets.

Security across the country rarely fails for lack of will. It fails on procurement procedures, operating costs and missing exchange. The municipal offer addresses these three points.

  1. Procurement without a tender

    Every tier stays below the value limits for a direct award. You procure without a tender procedure and receive the full product, not a reduced municipal edition.

  2. On-premise without a project budget

    Running KaitoSec in your own or a municipal data centre is standard, not a surcharge. The installation is deliberately kept simple, because we know from experience that operations otherwise break the budget.

  3. Advisory circle and municipal network

    At regular intervals, a cyber security consultant from the pool works with you on the state of your implementation. In the same circle, municipalities connect with each other, so knowledge spreads across the country.

Target objects and network come from the systems you already use.

100+ integrations

All integrations
  • i-doit
  • Docusnap 365
  • Matrix42
  • PRTG
  • macmon NAC
  • SharePoint Online
  • Microsoft Entra ID
  • Microsoft Intune
  • Microsoft Defender
  • i-doit
  • Docusnap 365
  • Matrix42
  • PRTG
  • macmon NAC
  • SharePoint Online
  • Microsoft Entra ID
  • Microsoft Intune
  • Microsoft Defender
  • Personio
  • AWS
  • Microsoft Azure
  • Google Cloud
  • Confluence
  • Jira
  • Microsoft Teams
  • Excel & CSV
  • Personio
  • AWS
  • Microsoft Azure
  • Google Cloud
  • Confluence
  • Jira
  • Microsoft Teams
  • Excel & CSV

Frequent questions.

Does KaitoSec cover the WIBA questionnaire completely?

Yes. The WIBA catalogue (road into Basic Protection) lives in the tool in full, and every question is mapped to the requirements of the Grundschutz compendium. Your answers persist when you move on to Basic Protection.

Can we use the municipal IT-Grundschutz profile?

Yes. The profile serves as the template for modelling your information domain. You adapt the module scope to your specialised procedures; the audit plan derives from it.

What does Grundschutz++ ready mean?

Catalogues, requirements and evidence are stored OSCAL-based and machine-readable. Your body of data is prepared for the coming machine-readable Grundschutz, without re-entry.

How does procurement work without a tender?

Every tier stays below the procurement thresholds, so a direct award is possible. Your procurement office checks the value limits that apply in your state; we provide the required documents.

What does the on-premise installation need?

A server in your own or a municipal data centre. The installation is designed for operation without a dedicated project team; we clarify the technical prerequisites in a short call beforehand.

How does the advisory session work?

At regular intervals, a cyber security consultant from our pool walks through status, open items and next steps with you. The session spans municipalities: you hear how other administrations solve the same requirements, and connect directly.

Does KaitoSec support the B3S for waste management?

Yes. Municipal waste utilities work with the sector-specific security standard in the same tool. Overlaps with Grundschutz prove themselves through the mapping.

Bring calm to your working week.

A personal demo in 30 minutes: we go through where you stand, from WIBA to Standard-Absicherung, and show how procurement by direct award works.