Menu

We are your ServiceNow partner for strategic consulting

BSI IT Baseline Protection

Picture of Sebastian Leinhos
Sebastian Leinhos

Managing Director

BSI-Grundschutz provides organizations with a clear framework for building information security in a planned manner and to prove permanently. The focus is on methodology, standards, certification, and how requirements can be practically implemented in ongoing IT operations.

Table of Content
BSI-Basic Protection – Key Takeaways
The BSI IT-Grundschutz is a structured security approach that organizations use to protect IT systems, data, and processes against cyberattacks, data loss, and other threats.
With IT-Grundschutz, a robust foundation for IT security, compliance, and a Information Security Management System, especially with sensitive data and business-critical processes.

Healthcare, financial institutions, public administration, critical infrastructure operators, and companies with sensitive data are ideal users.

Certification is carried out through document review and on-site audits, is generally valid for three years, and is accompanied by annual surveillance audits.

What is BSI Grundschutz?

The BSI IT-Grundschutz is a practical framework for information security. It shows companies and authorities which measures are necessary to systematically secure IT systems, data, and processes.

IT baseline protection was developed by the Federal Office for Information Security (BSI). The approach consciously goes beyond pure technology. Organization, rooms, employees, processes, and documentation are also included. This makes baseline protection more practical than many purely technical security concepts.

The practical basis is the IT Baseline Protection Compendium. It includes 113 building blocks in 10 topic areas and describes suitable requirements, hazards, and security measures for securing IT systems. This makes the basic protection a reliable basis for IT security, compliance, IT transformation and an information security management system (Information Security Management System).

Successfully shaping IT transformation!

Modernize your IT landscape, digitize processes and create the technological foundation for sustainable growth and innovation.
IT transformation

Who is IT-Grundschutz relevant for in IT security?

IT baseline protection is relevant for companies that need to establish or prove information security in a structured manner. It becomes particularly important when failures, data loss, or security incidents have direct consequences for operations, customers, or legal obligations.

IT Grundschutz is used by:

  • Authorities and Public Administration You need clear standards, comprehensible measures, and reliable documentation for legal compliance.

  • CRITICAL operator: Companies in energy, water, healthcare, transport, finance, or IT must effectively secure their systems against threats. However, healthcare and financial institutions also benefit as primary target groups from clear IT basic protection measures.

  • Companies in the NIS2 environment: The basic protection helps to clearly organize responsibilities, requirements, and IT security measures.

  • Suppliers and B2B service providers: Many customers today expect reliable evidence of information security. Third-party risk management fits in well with this.

  • Organizations with ISO 27001 goals: Anyone aiming for ISO 27001 certification can use IT baseline protection as a methodological basis.

IT-Grundschutz Methodology: How does BSI-Grundschutz work in practice?

The IT baseline protection methodology turns BSI's IT baseline protection into a concrete procedure. Companies first assess their protection needs, then derive suitable measures from the IT Baseline Protection Compendium, and check their implementation during ongoing operations.

The methodical basis is provided by BSI Standard 200-2. He describes how an organization analyzes its information network, categorizes IT systems, and systematically implements security requirements.

Determine need for protection

It begins with an inventory. Companies need to know which IT systems, applications, data, and processes are truly critical for operations.

The protection requirements are assessed along the three fundamental values of IT security:

  • Confidentiality Sensitive information should only be visible to authorized persons.

  • Integrity Data and systems must remain correct, complete, and unaltered.

  • Availability: Important applications and processes must function reliably.

This evaluation results in a classification into Normal, high or very high. This very classification determines how extensive the subsequent security measures must be.

Derive security measures from the IT Baseline Protection Compendium

After the protection needs come the modeling. There are suitable IT baseline protection building blocks for servers, networks, applications, rooms, or organizational processes. They describe typical threats, requirements, and measures.

For normal protection needs, standard security measures are often sufficient. For high or very high protection needs, it requires additionally a risk analysis. Then it is checked which special risks exist and which measures are necessary beyond the basic protection.

Plan, review, and improve implementation

A security concept is only effective if it is implemented and tested in everyday practice.

Typical steps are

  • Perform IT Security Baseline Check: The target-actual comparison shows which requirements have already been met and where gaps still exist.

  • Prioritize measures Critical issues are addressed first so that available resources can be deployed where the risk is greatest.

  • Establish responsibilities: Every measure requires clear responsibility, a deadline, documentation, and close coordination between IT teams and stakeholders.

  • Check effectiveness Audits, checks, and continuous IT Monitoring check if the safety measures in the company are effective.

  • Trace findings Security incidents from the Incident Management become part of the continuous improvement in the information security management system.

BSI Standards: An Overview of 200-1, 200-2, and 200-3

BSI Standards 200-1, 200-2, and 200-3 provide the IT baseline protection with its methodical structure. They clarify how information security is organized, how the implementation of IT baseline protection proceeds, and when an additional risk analysis is necessary.

BSI Standard 200-1: Information Security Management Systems

The BSI Standard 200-1 describes, how a Information Security Management System should be built. At its core, it's about clear responsibility, binding security goals, and a management level that actively supports information security. On the organizational side, companies define who decides, who implements, and how requirements are documented. The standard is compatible with ISO 27001, thereby also facilitating the path to later certification.

BSI Standard 200-2: IT Baseline Protection Methodology

The BSI Standard 200-2 is the practical guide for getting started and implementation. He describes how companies apply IT baseline protection and which security level suits their own goals.

Three paths are particularly important:

  • Base hedging Quick start for elemental protection.

  • Core security Focus on business-critical processes and systems.

  • Standard Protection complete implementation as a basis for a higher level of security and possible certification. The standard security provides comprehensive protection for information systems.

A company can start small, secure important areas first, and then gradually increase the level of security. The basic security can only be confirmed by a certificate from the BSI.

BSI Standard 200-3: IT Baseline Security Risk Analysis

The BSI Standard 200-3 applies, if the normal requirements from the IT Basic Protection Compendium are not sufficient. This is particularly relevant for systems with high or very high security requirements. In such cases, a general catalog of measures is no longer sufficient.

The organization must more precisely examine what threats exist, how likely they are, and what damages could result. Based on this, additional measures for the specific case will be derived. The risk analysis combines standard requirements with the real risk in operations and can be well integrated with Integrated Risk Management (IRMlink.

BSI-Grundschutz, ISO 27001, and ISO 27001 Certificate

BSI-Grundschutz and ISO 27001 pursue the same goal: information security should be verifiably organized, audited, and improved. The difference lies in the path to get there. ISO 27001 works more risk-based and internationally, the BSI IT-Grundschutz provides more detailed specifications for concrete security measures.

Criterion

ISO 27001

BSI IT Baseline Protection

Security approach

Risk-based top-down approach with high implementation flexibility

Action-oriented bottom-up approach with concrete requirements

Practical relevance

Companies define many methods and procedures themselves

The BSI provides detailed recommendations, building blocks, and standard requirements.

Relevance

Internationally recognized security standard for global customers, supply chains, and audits

Especially relevant in the DACH region, for authorities, critical infrastructure, and regulated institutions

Effort

More freedom in design, but stronger own risk work

More structure and concrete specifications, requiring more effort in documentation and testing

Certification

An ISO 27001 certificate confirms a functioning Information Security Management System

A certificate based on IT Baseline Protection additionally confirms the implementation of specific technical and organizational measures.

In practice, the two approaches are not mutually exclusive. Many organizations use BSI IT-Grundschutz as a foundation to build security measures cleanly and document the protection of their IT in a traceable manner. The ISO 27001 standard additionally helps to Information Security Management System to make it internationally compatible.

The biggest challenges in implementation

Manual Documentation: Many organizations still maintain building blocks, measures, and evidence in Excel. This costs time, creates media breaks, and increases the error rate.

Dynamic IT Infrastructures Cloud, agile changes, and ongoing digitalization often change systems faster than documents can be updated.

Unclear data basis: For a robust IT baseline protection analysis, assets, dependencies, protection needs, and technical evidence must align.

Resource shortage in the company: Administrators and security officers cannot permanently maintain manual audit reports, controls, and evidence alongside their daily business operations.

Distributed Proofs: Audit content is often scattered across different tools, emails, tickets, or log files. At the latest during the audit, this costs time, nerves, and often rework.

Making ServiceNow operationally controllable with BSI IT-Grundschutz

ServiceNow helps to provide static proof of BSI-Grundschutz to integrate into an ongoing process. Requirements, risks, measures, and evidence will be more closely linked to operational IT operations. When selecting a platform, interfaces, CMDB, workflows, and verifiable security requirements should be considered. already in the Request for Information (Radio Frequency Interference) and Request for Proposal (Request for Proposal) can be queried.

About the Configuration Management Database and IT Operations ManagementITOM) a current view of systems, services, and dependencies is created. Integrated Risk Management supports risk assessment, control assignment, and traceable action tracking.

Technical evidence can also be integrated more easily. Vulnerability Management, Patch Management and Incident Management provide operative data relevant for checks and audits. This way the Implementation of BSI IT-Grundschutz more transparent, automatable, and controllable.

The benefit lies primarily in automation. ServiceNow does not replace BSI IT-Grundschutz, but makes its implementation more controllable. Individual checks, tables, and evidence transform into an ongoing process that better integrates auditability, IT security, and operations.

Frequently asked questions and answers

Is BSI-Grundschutz mandatory?

For federal agencies, BSI Basic Protection is mandatory. Operators of critical infrastructures often use it as recognized proof of the required state of the art. For many other companies, structured security management is becoming an important prerequisite due to NIS2. Base protection offers a recognized and practical way to implement this.

The Federal Office for Information Security is the central cybersecurity authority in Germany. The BSI develops standards such as the IT-Grundschutz Compendium, warns of security vulnerabilities and supports organizations in activities related to protection, prevention, and certification.

ISO 27001 is an international standard that describes, What an information security management system must achieve. IT baseline protection is stronger practice-oriented and concretized with building blocks, requirements, and measures the implementation of technical, organizational, and personnel aspects.

 

Do you have any questions?

We are happy to help you! Contact us and find out how you can drive your IT transformation forward efficiently.