Skip to content

Demo Instance User Guide

In 3 Steps to the Demo Instance:

  1. Select a Role → Choose from 7 preconfigured ISMS roles
  2. Test a Demo Company → Use realistic sample data from 11 organizations
  3. Gain Hands-On Experience → Walk through typical ISMS and BCMS processes

Our demo instance provides a fully configured ISMS environment with realistic roles, permissions, and sample organizations. You can experience different compliance approaches in practice, based on BSI IT-Grundschutz and ISO 27001.

  • 7 preconfigured ISMS roles with specific permissions
  • 11 demo organizations from different industries
  • Realistic scenarios for public administration and private sector
  • Complete workflows from risk analysis to certification

1. Information Security Officer (ISO) / ISMS Owner

Section titled “1. Information Security Officer (ISO) / ISMS Owner”

Responsibility: Full ISMS management and strategic leadership

Full access to:

  • Authorization and rights management
  • Organizational unit and user account management
  • ISMS structural and protection needs analysis
  • Modeling and risk analysis
  • Asset management and reporting
  • BCMS (Business Continuity Management)

Best Practice: Use this role for strategic decisions and compliance oversight.


Responsibility: Risk management and assessment

Permissions:

  • Structural analysis (read, edit, create, delete, link)
  • Protection needs analysis (read, edit, recommend, distribute)
  • Risk analysis (full access incl. risk matrix management)
  • Controls management (read, edit, delete, assign)
  • Risk treatment plan reports (create)

Why important: Risk management is at the heart of every ISMS – here you’ll learn practical application.


3. External Service Provider (Consultant ISMS)

Section titled “3. External Service Provider (Consultant ISMS)”

Responsibility: External consulting and audit support

Permissions (read-only):

  • Structural analysis
  • Protection needs analysis
  • Risk analysis
  • Modeling
  • Reporting

Use case: Ideal for consultants or external auditors with restricted access.


Responsibility: Technical implementation and system maintenance

Permissions:

  • Organizational unit management (full access)
  • User and role management
  • Structural analysis (read)
  • Modeling (read, export, import)
  • BSI A1–A5 reports (read)

Pro Tip: Use import/export functions for efficient model management.


Responsibility: Project coordination and operational ISMS leadership

Full access to:

  • Structural analysis
  • Protection needs analysis
  • Modeling and risk analysis
  • Asset management
  • Reporting
  • Rights management (read, create, edit, assign users)

Recommendation: Perfect role for operational ISMS implementation.


Responsibility: Internal auditing and compliance review

Permissions (read-only):

  • Structural analysis
  • Protection needs analysis
  • Risk analysis and modeling
  • BSI and ISO standard reports

Audit focus: Use extensive reporting for audit evidence.


Responsibility: Business Continuity Management

Full access to:

  • BCMS scopes
  • Initiation and business processes
  • Analysis/BIA (Business Impact Analysis)
  • BCMS reporting

Integration: BCMS complements ISMS for holistic risk management.


Scenario: Medium-sized municipality with digital citizen services

Challenges:

  • Integrating legacy IT systems
  • Aiming for BSI IT-Grundschutz certification
  • Evolving WiBA basic requirements into a full ISMS
  • Secure handling of citizen data

Demo Users:

  • Anna Schuster (IT Manager): a.schuster
  • Max Hoffmann (ISO): m.hoffmann
  • Lisa Weber (ISMS Consultant): l.weber
  • Daniel König (IT Admin): d.koenig

Learning: Public sector, e-government, legacy integration


Scenario: Large hospital with research and critical infrastructure

Special Features:

  • KRITIS compliance
  • Patient data (GDPR-compliant)
  • High availability of medical IT systems
  • NIS2 implementation
  • ISMS + BCMS + DSMS integration

Demo Users:

  • Dr. Julia Wagner (ISO): j.wagner
  • Thomas Becker (Risk Manager): t.becker
  • Lisa Weber (ISMS Consultant): l.weber
  • Daniel König (IT Admin): d.koenig

Learning: Critical infrastructure, healthcare, multi-domain compliance


Note: The remaining demo organizations are currently described in the German version of this page only.


  1. Choose one of the 7 ISMS roles based on your interest
  2. Log in with the provided demo credentials
  3. Explore available menu options
  1. Switch between different demo organizations
  2. Compare BSI and ISO approaches
  3. Analyze industry-specific requirements
  1. Structural analysis: Capture organizational structures
  2. Protection needs analysis: Assess information assets
  3. Modeling: Build IT-Grundschutz models
  4. Risk analysis: Identify and evaluate risks
  5. Reporting: Generate compliance reports

AspectBSI IT-GrundschutzISO 27001
Target groupGerman authorities, critical infrastructureInternational, all industries
ApproachModule-based, prescriptiveRisk-based, flexible
CertificationBSI certificationAccredited certifiers
ControlsPredefined modulesRisk-adapted controls
DocumentationExtensive, structuredLeaner, process-oriented

Demo environment: All data is fictional and for demonstration only. Do not use real company or personal data.

Data reset: The demo instance is reset regularly. Save your insights externally.

Support: For technical issues, please contact our support team.


  1. Choose a role among the 7 ISMS positions
  2. Test 2–3 demo organizations to compare approaches
  3. Run a complete ISMS cycle from analysis to reporting
  • Compare BSI and ISO standards directly
  • Test role-specific workflows
  • Explore reporting for different audiences
  • Document best practices from the demo
  • Identify relevant compliance requirements
  • Plan your ISMS implementation based on demo experience

Start your ISMS demo experience now and discover how effective information security management works in practice!