Management Systems
Grundschutz
BSI IT-Grundschutz
The German federal information security methodology: a modular catalogue of building blocks, each with concrete threats and required safeguards, plus the BSI Standards that describe the management system around them.
Its distinguishing feature is prescriptiveness: where ISO/IEC 27001 says "assess your risk", IT-Grundschutz hands you a baseline of measures per component. Certification is available as ISO/IEC 27001 on the basis of IT-Grundschutz.
At a glance
- Category
- Management Systems
- Jurisdiction
- EU / Germany
- Governance
- BSI (Germany)
- Status
- BSI Standards 200-1, 200-2 and 200-3, with 200-4 for business continuity; Kompendium revised regularly
- First released
- 1994
Links
Related frameworks
Other entries under Management Systems.
- ISO/IEC 27001: Information Security Management Systems
- NIST CSF: Cybersecurity Framework 2.0
- NIST RMF: Risk Management Framework (SP 800-37)
See Grundschutz in context
Open the interactive Data Landscape for Regulation to compare Grundschutz against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.