Compliance

BSI IT-Grundschutz

BSI IT-Grundschutz is the German BSI's methodology for information security, mainly serving as a reference in Switzerland.

IT-Grundschutz is a standard from the German Federal Office for Information Security (BSI). It describes how organisations build and implement an information security management system using established measures.

How it works

IT-Grundschutz consists of BSI Standards 200-1 to 200-4 and the IT-Grundschutz Compendium. The standards describe the management system, the methodology, risk analysis, and business continuity management. The compendium contains modules for typical topics like servers, clients, cloud, or personnel.

Each module lists threats and the associated requirements. Organisations model their environment using the relevant modules. They then check which requirements have already been met.

A practical example

A Swiss municipality wants to structure its information security. It uses selected compendium modules as a checklist for servers, workstations, and backups. This quickly reveals that no recovery tests are performed for the backups. The municipality then introduces them.

What to look out for

  • IT-Grundschutz is very comprehensive. Select the modules that fit your organisation's environment.
  • Basic protection is suitable as a starting point, and standard protection is the approach recommended by the BSI.
  • Use the compendium as a knowledge resource, even without pursuing certification.
  • Be mindful of the documentation effort, which can be considerable.

When it is relevant for Swiss companies

IT-Grundschutz is a German standard and not mandatory in Switzerland. It primarily serves as a reference and a collection of concrete measures. It becomes relevant if required by German customers or authorities. For certifications, Swiss organisations generally use ISO 27001.

Switzerland and regulation

The Swiss government has its own ICT Minimum Standard for critical infrastructure operators. This is based on the NIST Cybersecurity Framework. IT-Grundschutz can be used as a supplement for specific measures.

How it differs from ISO 27001

Certification to ISO 27001 on the basis of IT-Grundschutz is possible. It is awarded by the BSI and is mainly prevalent in Germany.

Relevance for the SOC

Several modules concern logging, detection, and the handling of security incidents. A SOC provides the implementation and evidence for these activities.

How we implement it

Our SOC services provide evidence for logging and detection. Integrating this evidence into your management system remains your responsibility.

How ANOMAL implements this