FAQ
What does IT-Grundschutz mean?
Approach by the German Federal Office for Information Security (BSI) to identify and implement technical, organizational, personnel, and infrastructural security measures to achieve an appropriate level of protection.
Evidence of a systematic approach can be demonstrated through an ISO/IEC 27001 certificate based on IT-Grundschutz.
What is information?
Data used in value-creating processes – both digital and analog (e.g., spoken, paper).
An ISMS protects both forms.
Why a dedicated authority (BSI)?
Digitalization creates new threats. The BSI provides standards (including IT-Grundschutz), situation reports, and practical guidance.
What are the protection objectives?
- Confidentiality (only authorized access)
- Availability (accessible, functional)
- Integrity (unchanged/correct)
What is protection needs determination?
Assigning protection requirements (C, I, A, and possibly Authenticity) to processes/information/objects based on damage scenarios (normal/high/very high).
→ Inheritance to dependent objects (maximum principle, accumulation, distribution effect).
What is a Grundschutz Check?
Comparison of target vs. actual state against BSI requirements per modeled module.
→ Snapshot in the ISMS implementation process; completed once all partial requirements are met or justified as “not needed.”
How often to review?
Evaluate security concepts at least every 2 years; provide an updated ISMS version no later than every 3 years.
ISO 27001 certification based on IT-Grundschutz?
An external auditor reviews the ISMS (incl. on-site audit) and recommends certification. The certification body makes the decision.
Role of the auditor?
Checks completeness/effectiveness; issues recommendations (does not certify). Comments on implementation status must always be professionally justified.
What happens during structural analysis/modeling?
- Structural analysis: Recording infrastructures, rooms, networks, servers, systems, applications, processes within scope (grouping allowed → sample testing).
- Modeling: Assignment of elementary threats and modules, forming the basis for the Grundschutz Check.
Elementary threats?
The BSI compendium (currently 47) assigns threats to modules (e.g., fire, espionage, malware).
What happens during risk assessment?
Evaluation = damage × likelihood → expected risk per module/object.
What is an ISMS?
A set of rules and methods to ensure information security; continuous (PDCA cycle).
ISO 27001 defines requirements; IT-Grundschutz specifies and extends them.
What exactly is the “Statement of Applicability” (SoA)?
Documents which Annex A controls (with justification for inclusion/exclusion) apply to the ISMS.
It must also include additional controls outside Annex A if used for risk treatment (ISO 27001, 6.1.3 d).
How did Annex A change with ISO/IEC 27001:2022?
Annex A now references 93 controls from ISO/IEC 27002:2022, grouped into:
- 37 organizational
- 8 people-related
- 14 physical
- 34 technological controls
ISO 27001 vs. ISO 27002 – what’s the difference?
- ISO 27001: Requirements (certifiable).
- ISO 27002: Guidelines/implementation advice for controls (not certifiable).
Annex A of 27001 references 27002.
How does the certification cycle work (surveillance/recertification)?
Certificates are valid for 3 years.
→ Annual surveillance audits required, recertification after 3 years.
(Applies also to ISO 27001 based on IT-Grundschutz.)
What is the current transition to ISO/IEC 27001:2022?
IAF MD 26:2023 governs the transition.
→ Deadline for full transition: October 31, 2025.
(Practice: complete transition audits by July 2025 to allow certification body decisions in time.)
Multi-site ISMS: Any special rules?
Yes. For multi-site certifications, IAF rules apply, incl. sampling quotas for surveillance audits (typically 30% of sites, rounded up; details in MD 1).
Which mandatory documents does an auditor expect?
ISO 27001 requires “documented information” for:
- Scope
- ISMS policy/objectives
- Risk methodology
- SoA
- Risk treatment/plan
- Performance indicators
- Internal audit
- Management review
(Clauses 4–10; SoA explicitly in 6.1.3 d).
Internal audits vs. management review – what’s the purpose?
- Internal audits (9.2): check effectiveness/conformity.
- Management review (9.3): strategic evaluation of the ISMS (performance, risks/opportunities, resources, improvements).
How does Business Continuity (BCMS) fit with ISO 27001?
An ISMS addresses information security; ISO 22301 complements it for business continuity (RTO/RPO, etc.).
Both systems should be integrated. ISO 22301 was updated in 2019 and in 2024 with Amd 1: Climate action.
Cloud security & privacy – relevant standards?
- ISO/IEC 27017: Cloud-specific security controls (current Ed. 1 confirmed; DIS 27017 successor in progress).
- ISO/IEC 27018:2025: Protection of personal data (PII) in public cloud as processor.
ISMS vs. NIS2?
NIS2 requires risk management measures (policies, incident handling, BCM, supply chain security).
A mature ISO 27001 ISMS covers many of these but does not replace legal compliance.
→ See ENISA guidance and EU Implementing Regulation (EU) 2024/2690.
Suppliers & cloud providers: Must they be in ISMS scope?
Yes. Risk-based supply chain management is part of ISMS (Annex A: supplier relationships, cloud guidance via 27017/27018).
Contractual/data protection obligations (e.g., GDPR Art. 28 data processing agreements) must also be met.
What does an IT-Grundschutz audit check additionally?
For ISO 27001 based on IT-Grundschutz: structural analysis, modeling, module requirements, elementary threats, and implementation levels (standard/core/basic protection) are audited using a formal schema.
How is audit time planned?
IAF documents (e.g., ID 14, MD 5) define calculation/adjustment of audit times for surveillance and recertification – depending on size, complexity, and risk.
Do additional controls (outside Annex A) need to be documented?
Yes – if used for risk treatment, they must appear in the SoA (ISO 27001 6.1.3 d).