IT-Grundschutz: the foundation first, the certificate after
The BSI methodology introduced pragmatically – guided by people who are certified to it themselves.
What IT-Grundschutz delivers
The BSI's IT-Grundschutz is a methodology, not a product. It answers the question that stands at the beginning of all security work: where do we start, and how do we know we have not missed anything essential? Instead of reasoning through every threat individually, you compare your environment against the modules of the IT-Grundschutz Kompendium – requirements reflecting the state of the art, organised by topic, for business processes, applications and IT systems.
That cuts the analytical effort considerably. “What could possibly happen” turns into a comparison: which requirements apply to us, which do we already meet, and where is the gap? What remains is an evidenced list of open points rather than a gut feeling.
Baseline protection: the pragmatic start
BSI Standard 200-2 offers three ways in. For organisations with little structure in place so far, baseline protection is the right one: broad basic protection across the whole organisation, initially with the basic requirements only. Effective quickly, without certification having to be the goal from day one.
- A first line of defence against the threats that actually occur – not the spectacular ones.
- A starting point that core or standard protection can build on later, all the way to the certificate.
- A protection requirements assessment: afterwards you know which information and systems are genuinely critical.
- A modular structure that adapts to your size instead of forcing you into a corporate straitjacket.
Running it in two stages – baseline protection across the board first, standard protection within a defined scope later – gets organisations furthest in practice.
The security process in three phases
IT-Grundschutz is not a documentation project but a process. And it does not begin in IT; it begins with management.
- 1
Initiation
Management sets the process in motion, steers it and carries it. The information security policy takes shape: scope, security objectives, the level you are aiming for. The information security officer plays the central role here – and if you do not have one, we provide one.
- 2
Organisation
A structure that matches the size of the institution. Who decides, who reports to whom, what the routes are between IT, business units and management. It sounds like bureaucracy but prevents exactly that, because responsibilities no longer have to be settled case by case.
- 3
Execution
Now the security concept takes shape: modelling with the modules of the Kompendium, comparison against what is already in place, identification of the gaps and derivation of the measures.
And afterwards? Maintain and improve. Process, organisational structure and measures are reviewed regularly for appropriateness, effectiveness and efficiency. A security level is not a state you reach and tick off.
What we take on, what you contribute
Ours
- Methodology and facilitation: structure analysis, protection requirements assessment, modelling, the IT-Grundschutz check.
- The documentation that makes it all evidenced – policy, guidelines, procedures, records.
- The judgement on which requirement genuinely applies to you and which you can meet with reasonable effort.
Yours
- A management team that carries the process. Without backing from the top, IT-Grundschutz fails reliably.
- Contacts from IT and the business units who can answer questions – we cannot know your processes from the outside.
- The decision on the scope. We advise on it, but it is yours to make.
We work remotely or on site, as agreed with you.
When baseline protection is enough – and when it is not
Baseline protection on its own cannot be certified. That is not a shortcoming but a question of purpose: if you want security, it is enough. If you need evidence for clients, a regulator or a tender, the route runs through standard protection to ISO 27001 on an IT-Grundschutz basis.
The two are not mutually exclusive. Baseline protection is the starting point you build on later – with the advantage that you are not unprotected in the meantime.
How the path to the certificate actually runs is described in detail here.
We have walked this road ourselves
Certified ourselves
SECURITYSQUAD is certified to ISO 27001 on an IT-Grundschutz basis, and to ISO 9001 as well. We are not guiding you through a procedure we know only from the standard.
From the auditor's side
Our consultants are trained ISO 27001 Lead Auditors and have completed the IT-Grundschutz practitioner qualification. We know what an audit actually looks at.
We also say no
If IT-Grundschutz is the wrong framework for you, you hear that in the first conversation, not after the third workshop.
Frequently asked questions about IT-Grundschutz
Is IT-Grundschutz only for public authorities?
No. The methodology comes from the BSI and is widespread in the public sector, but it is not limited to it. The modular structure is an advantage for smaller organisations in particular: you apply the modules that concern you and leave the rest aside.
Do we absolutely need certification?
No. You need certification when you have to provide evidence externally – to clients, in tenders or to a regulator. If what you care about is the security level itself, baseline protection without a certification goal is the more honest and cheaper route.
What is the difference from ISO 27001?
Native ISO 27001 says what a management system must achieve, but not how. IT-Grundschutz supplies the methodology and, with the Kompendium, concrete requirements. The BSI variant of ISO 27001 combines both: the same internationally recognised certificate, reached along the IT-Grundschutz route.
Who needs to be involved on our side?
Someone from management who owns the process, someone from IT with an overview of systems and networks, and — depending on the scope — contacts from the business units. The effort on your side is real but predictable, and it drops considerably when the scope is cleanly defined.
What drives the effort most?
The scope. It is the single biggest lever and the most common reason projects tip over. “The whole of IT” is not a boundary; a sensibly delimited information domain is. We make that decision together in the first conversation, before anyone writes a quote.
Where do you stand today?
Half an hour of conversation is enough to establish which approach fits you and how large the scope should sensibly be.
Arrange a first conversation