Demo Instance User Guide
In 3 Steps to the Demo Instance:
- Select a Role → Choose from 7 preconfigured ISMS roles
- Test a Demo Company → Use realistic sample data from 11 organizations
- Gain Hands-On Experience → Walk through typical ISMS and BCMS processes
Overview
Section titled “Overview”Our demo instance provides a fully configured ISMS environment with realistic roles, permissions, and sample organizations. You can experience different compliance approaches in practice, based on BSI IT-Grundschutz and ISO 27001.
What to Expect:
Section titled “What to Expect:”- 7 preconfigured ISMS roles with specific permissions
- 11 demo organizations from different industries
- Realistic scenarios for public administration and private sector
- Complete workflows from risk analysis to certification
ISMS Roles and Permissions
Section titled “ISMS Roles and Permissions”1. Information Security Officer (ISO) / ISMS Owner
Section titled “1. Information Security Officer (ISO) / ISMS Owner”Responsibility: Full ISMS management and strategic leadership
Full access to:
- Authorization and rights management
- Organizational unit and user account management
- ISMS structural and protection needs analysis
- Modeling and risk analysis
- Asset management and reporting
- BCMS (Business Continuity Management)
Best Practice: Use this role for strategic decisions and compliance oversight.
2. Risk Manager
Section titled “2. Risk Manager”Responsibility: Risk management and assessment
Permissions:
- Structural analysis (read, edit, create, delete, link)
- Protection needs analysis (read, edit, recommend, distribute)
- Risk analysis (full access incl. risk matrix management)
- Controls management (read, edit, delete, assign)
- Risk treatment plan reports (create)
Why important: Risk management is at the heart of every ISMS – here you’ll learn practical application.
3. External Service Provider (Consultant ISMS)
Section titled “3. External Service Provider (Consultant ISMS)”Responsibility: External consulting and audit support
Permissions (read-only):
- Structural analysis
- Protection needs analysis
- Risk analysis
- Modeling
- Reporting
Use case: Ideal for consultants or external auditors with restricted access.
4. IT and Technical Staff (Admin)
Section titled “4. IT and Technical Staff (Admin)”Responsibility: Technical implementation and system maintenance
Permissions:
- Organizational unit management (full access)
- User and role management
- Structural analysis (read)
- Modeling (read, export, import)
- BSI A1–A5 reports (read)
Pro Tip: Use import/export functions for efficient model management.
5. ISMS Project Manager / ISMS Lead
Section titled “5. ISMS Project Manager / ISMS Lead”Responsibility: Project coordination and operational ISMS leadership
Full access to:
- Structural analysis
- Protection needs analysis
- Modeling and risk analysis
- Asset management
- Reporting
- Rights management (read, create, edit, assign users)
Recommendation: Perfect role for operational ISMS implementation.
6. Internal Auditor
Section titled “6. Internal Auditor”Responsibility: Internal auditing and compliance review
Permissions (read-only):
- Structural analysis
- Protection needs analysis
- Risk analysis and modeling
- BSI and ISO standard reports
Audit focus: Use extensive reporting for audit evidence.
7. BCMS Manager
Section titled “7. BCMS Manager”Responsibility: Business Continuity Management
Full access to:
- BCMS scopes
- Initiation and business processes
- Analysis/BIA (Business Impact Analysis)
- BCMS reporting
Integration: BCMS complements ISMS for holistic risk management.
Demo Organizations
Section titled “Demo Organizations”BSI IT-Grundschutz Organizations
Section titled “BSI IT-Grundschutz Organizations”City Administration Musterstadt
Section titled “City Administration Musterstadt”Scenario: Medium-sized municipality with digital citizen services
Challenges:
- Integrating legacy IT systems
- Aiming for BSI IT-Grundschutz certification
- Evolving WiBA basic requirements into a full ISMS
- Secure handling of citizen data
Demo Users:
- Anna Schuster (IT Manager): a.schuster
- Max Hoffmann (ISO): m.hoffmann
- Lisa Weber (ISMS Consultant): l.weber
- Daniel König (IT Admin): d.koenig
Learning: Public sector, e-government, legacy integration
University Hospital MediCare
Section titled “University Hospital MediCare”Scenario: Large hospital with research and critical infrastructure
Special Features:
- KRITIS compliance
- Patient data (GDPR-compliant)
- High availability of medical IT systems
- NIS2 implementation
- ISMS + BCMS + DSMS integration
Demo Users:
- Dr. Julia Wagner (ISO): j.wagner
- Thomas Becker (Risk Manager): t.becker
- Lisa Weber (ISMS Consultant): l.weber
- Daniel König (IT Admin): d.koenig
Learning: Critical infrastructure, healthcare, multi-domain compliance
Note: The remaining demo organizations are currently described in the German version of this page only.
Practical Application
Section titled “Practical Application”Step 1: Select Role and Login
Section titled “Step 1: Select Role and Login”- Choose one of the 7 ISMS roles based on your interest
- Log in with the provided demo credentials
- Explore available menu options
Step 2: Explore Demo Organizations
Section titled “Step 2: Explore Demo Organizations”- Switch between different demo organizations
- Compare BSI and ISO approaches
- Analyze industry-specific requirements
Step 3: Run ISMS Processes
Section titled “Step 3: Run ISMS Processes”- Structural analysis: Capture organizational structures
- Protection needs analysis: Assess information assets
- Modeling: Build IT-Grundschutz models
- Risk analysis: Identify and evaluate risks
- Reporting: Generate compliance reports
Compliance Standards Compared
Section titled “Compliance Standards Compared”BSI IT-Grundschutz vs. ISO 27001
Section titled “BSI IT-Grundschutz vs. ISO 27001”| Aspect | BSI IT-Grundschutz | ISO 27001 |
|---|---|---|
| Target group | German authorities, critical infrastructure | International, all industries |
| Approach | Module-based, prescriptive | Risk-based, flexible |
| Certification | BSI certification | Accredited certifiers |
| Controls | Predefined modules | Risk-adapted controls |
| Documentation | Extensive, structured | Leaner, process-oriented |
Key Notes
Section titled “Key Notes”Demo environment: All data is fictional and for demonstration only. Do not use real company or personal data.
Data reset: The demo instance is reset regularly. Save your insights externally.
Support: For technical issues, please contact our support team.
Next Steps
Section titled “Next Steps”Start Now:
Section titled “Start Now:”- Choose a role among the 7 ISMS positions
- Test 2–3 demo organizations to compare approaches
- Run a complete ISMS cycle from analysis to reporting
Deep Dive:
Section titled “Deep Dive:”- Compare BSI and ISO standards directly
- Test role-specific workflows
- Explore reporting for different audiences
For Your Organization:
Section titled “For Your Organization:”- Document best practices from the demo
- Identify relevant compliance requirements
- Plan your ISMS implementation based on demo experience
Start your ISMS demo experience now and discover how effective information security management works in practice!