Skip to content

Difference between ISO27001 and BSI IT-Grundschutz

ISO 27001 vs. BSI IT-Grundschutz — When to use what (and how to combine them)

Section titled “ISO 27001 vs. BSI IT-Grundschutz — When to use what (and how to combine them)”

A practical, decision-oriented guide for ISO practitioners who want to look beyond their usual toolkit. Short, actionable, and built for momentum.


SituationPickWhyWhat you produce first
Global customers, mixed jurisdictions, fast proof neededISO 27001Internationally recognized, lighter docs, flexibleScope, risk method, Risk Register, SoA (Annex A), Objectives & KPIs
German public sector, KRITIS, tenders expect BSIIT-GrundschutzNative to DE, prescriptive measures, strong acceptanceStruct. analysis, Schutzbedarf (CIA), Baustein-Modellierung, GS-Check
Innovative/non-standard tech stackISO 27001 (+ selected BSI controls)Free to tailor controls to risksISO risk process + BSI hardening for the tricky parts
Small/mid org, lean team, quick winsISO 27001 (lean)Minimum viable ISMS possible90-day ISO starter (below)
Mature ISO ISMS, needs concrete hardeningISO + GrundschutzKeep ISO cert; adopt BSI depth where it mattersMap assets → pick BSI Bausteine for high-risk areas
You must show an actual “security level”GrundschutzCertification indicates achieved safeguarding levelGS-Check evidence + Maßnahmennachweise

  1. Is a German authority/KRITIS tender in scope?
    → Yes: Grundschutz or Hybrid → Go to Hybrid recipe.
    → No: continue.

  2. Do you need an internationally recognized certificate quickly?
    → Yes: ISO firstISO 90-day starter.
    → No/unclear: continue.

  3. Is your IT mostly standard (Windows, AD, LAN, office apps)?
    → Yes: Grundschutz fits well.
    → No (cloud-native, data platforms, OT/IoT mix): ISO core + selected BSI Bausteine.


How they differ (only what matters in practice)

Section titled “How they differ (only what matters in practice)”
  • ISO 27001 = management system + risk-based controls (Annex A). Certifies your system, not a fixed security level.
  • Grundschutz = catalogue of concrete measures (Bausteine) + model-driven coverage. Certification reflects a safeguarding level.

Use ISO when you need speed, flexibility, global recognition.
Use Grundschutz when you need prescriptive depth and German public acceptance.


Goal: Minimal viable ISMS that scales.
Deliverables (must-have): Scope (§4.3), Context & stakeholders, Risk method & criteria, Risk Register, SoA (Annex A:2022 93 controls), IS objectives + KPIs, Audit plan, Management review cadence.

Timeline:

  • Weeks 1–3: Scope, roles/RACI, risk method; inventory top-20 assets/processes; quick CIA.
  • Weeks 4–7: Risk assessment workshops; pick controls; draft SoA; treatment plan with owners/dates.
  • Weeks 8–10: Implement top 10 high-impact controls (IDM, backup, vuln mgmt, incident flow, logging).
  • Weeks 11–12: Internal audit (sample), KPI baseline, Mgmt review #1; close gaps.

Tip: Borrow BSI depth surgically: use Bausteine for Windows/AD, networks, and backup hardening while staying ISO-centric.


What changes from ISO thinking?

  • Start structure → protection needs → modelling before deep risk.
  • Controls come from Bausteine (with Basis/Standard/Hoch).
  • Do a GS-Check (Soll/Ist) to show safeguarding level.

Minimal path:

  1. Strukturanalyse: group assets into manageable TOGs (servers, clients, networks, apps, sites).
  2. Schutzbedarf (CIA): normal/high/very high; apply inheritance (process → app → system).
  3. Modellierung: assign Bausteine to TOGs; record deviations.
  4. GS-Check: close gaps; for “hoch” add ergänzende Risikoanalyse.
  5. Nachweise: measures implemented, responsibilities, evidence.

Tip: Reuse your ISO risk register; tag items that map to Bausteine to avoid double work.


  1. ISO as the frame: scope, governance, risk method, SoA, KPIs, audits.
  2. BSI for depth: assign Bausteine to high-impact TOGs (AD/Entra ID, servers, networks, backups, remote access).
  3. One register: keep a single Risk & Control Register; each control is tagged ISO-A.x and/or BSI-<Baustein-ID>.
  4. SoA + GS-Check: run both artefacts from the same data: SoA for ISO; GS-Check for BSI stakeholders.
  5. Certification path: certify ISO first for speed; add Grundschutz later where demanded.

  • Public administration / KRITIS: Grundschutz or Hybrid (expect BSI language, Bausteine evidence).
  • International group / suppliers abroad: ISO (auditor availability, recognition in supply chains).
  • Managed service providers (MSP/MSSP): ISO baseline; BSI depth for AD, backups, and remote admin.
  • Startups/scaleups: ISO lean; adopt BSI hardening checklists for quick wins.
  • OT/IoT environments: ISO risk engine + BSI OT-related Bausteine for prescriptive controls.

ISO first?

  • Build SoA with Annex A; mark not applicable with risk-based justifications.
  • Where your SoA is “thin”, import BSI measures (e.g., hardening checklists) to raise assurance.

Grundschutz first?

  • Use Baustein requirements as your default control set.
  • Where BSI is silent/too generic (e.g., SaaS multi-tenant specifics), add ISO-style, risk-derived controls.

Documentation you actually need (no fluff)

Section titled “Documentation you actually need (no fluff)”
AreaISO deliverableBSI deliverableHybrid shortcut
Scope & contextScope, stakeholder & issuesGeltungsbereich in StrukturmodellOne scope doc, two summaries
RiskMethod, criteria, register, planErgänzende Risikoanalyse (bei „hoch“)One risk process; extra BSI section
ControlsSoA (Annex A)Baustein-Umsetzung & GS-CheckUnified register with cross-refs
EvidenceKPIs, audits, mgmt reviewMaßnahmennachweise, GS-Check ProtokollShared evidence library

  • Pitfall: ISO “paper ISMS” without real controls.
    Fix: Tie every top risk to a tested control + evidence; baseline KPIs early.

  • Pitfall: Grundschutz over-documentation stalls delivery.
    Fix: Group TOGs aggressively; prioritize GS-Check gaps by risk; iterate.

  • Pitfall: Two parallel worlds (ISO vs. BSI).
    Fix: Single taxonomy for assets, risks, controls; tags map to ISO/BSI.

  • Pitfall: SoA/GS-Check not kept current.
    Fix: Update on every change window; calendar reminders; owner per control.


ISO → Grundschutz

  1. Map assets to TOGs; import ISO CIA → Schutzbedarf.
  2. Assign Bausteine; run GS-Check; record deviations.
  3. Keep ISO risk method; add BSI “hoch” analyses where needed.

Grundschutz → ISO

  1. Derive ISO scope from Geltungsbereich.
  2. Convert GS risks into a single risk register with ISO criteria.
  3. Build SoA from existing measures; justify N/A items; align KPIs & audits.

  • Patch SLA met (%), Backup success (%), Incident MTTR, Access review closure time, Phishing fail rate, Log coverage (% of critical systems), Recovery test success.

  • One inventory (assets/TOGs), one risk register, one control catalogue with tags:
    tags: ["ISO:A.5.15", "BSI:SYS.1.1.A5"]
  • Reports: ISO SoA view, BSI GS-Check view, shared evidence links.

  • If you need speed + global trustISO; sprinkle in BSI hardening where high risk.
  • If you need German public acceptance + prescriptive depthGrundschutz or Hybrid.
  • Always keep one register (risks & controls) and tag for ISO/BSI to avoid duplication.