Difference between ISO27001 and BSI IT-Grundschutz
ISO 27001 vs. BSI IT-Grundschutz — When to use what (and how to combine them)
Section titled “ISO 27001 vs. BSI IT-Grundschutz — When to use what (and how to combine them)”A practical, decision-oriented guide for ISO practitioners who want to look beyond their usual toolkit. Short, actionable, and built for momentum.
TL;DR – Quick selector
Section titled “TL;DR – Quick selector”| Situation | Pick | Why | What you produce first |
|---|---|---|---|
| Global customers, mixed jurisdictions, fast proof needed | ISO 27001 | Internationally recognized, lighter docs, flexible | Scope, risk method, Risk Register, SoA (Annex A), Objectives & KPIs |
| German public sector, KRITIS, tenders expect BSI | IT-Grundschutz | Native to DE, prescriptive measures, strong acceptance | Struct. analysis, Schutzbedarf (CIA), Baustein-Modellierung, GS-Check |
| Innovative/non-standard tech stack | ISO 27001 (+ selected BSI controls) | Free to tailor controls to risks | ISO risk process + BSI hardening for the tricky parts |
| Small/mid org, lean team, quick wins | ISO 27001 (lean) | Minimum viable ISMS possible | 90-day ISO starter (below) |
| Mature ISO ISMS, needs concrete hardening | ISO + Grundschutz | Keep ISO cert; adopt BSI depth where it matters | Map assets → pick BSI Bausteine for high-risk areas |
| You must show an actual “security level” | Grundschutz | Certification indicates achieved safeguarding level | GS-Check evidence + Maßnahmennachweise |
Decision tree (fast)
Section titled “Decision tree (fast)”-
Is a German authority/KRITIS tender in scope?
→ Yes: Grundschutz or Hybrid → Go to Hybrid recipe.
→ No: continue. -
Do you need an internationally recognized certificate quickly?
→ Yes: ISO first → ISO 90-day starter.
→ No/unclear: continue. -
Is your IT mostly standard (Windows, AD, LAN, office apps)?
→ Yes: Grundschutz fits well.
→ No (cloud-native, data platforms, OT/IoT mix): ISO core + selected BSI Bausteine.
How they differ (only what matters in practice)
Section titled “How they differ (only what matters in practice)”- ISO 27001 = management system + risk-based controls (Annex A). Certifies your system, not a fixed security level.
- Grundschutz = catalogue of concrete measures (Bausteine) + model-driven coverage. Certification reflects a safeguarding level.
Use ISO when you need speed, flexibility, global recognition.
Use Grundschutz when you need prescriptive depth and German public acceptance.
ISO 90-day starter (lean but cert-ready)
Section titled “ISO 90-day starter (lean but cert-ready)”Goal: Minimal viable ISMS that scales.
Deliverables (must-have): Scope (§4.3), Context & stakeholders, Risk method & criteria, Risk Register, SoA (Annex A:2022 93 controls), IS objectives + KPIs, Audit plan, Management review cadence.
Timeline:
- Weeks 1–3: Scope, roles/RACI, risk method; inventory top-20 assets/processes; quick CIA.
- Weeks 4–7: Risk assessment workshops; pick controls; draft SoA; treatment plan with owners/dates.
- Weeks 8–10: Implement top 10 high-impact controls (IDM, backup, vuln mgmt, incident flow, logging).
- Weeks 11–12: Internal audit (sample), KPI baseline, Mgmt review #1; close gaps.
Tip: Borrow BSI depth surgically: use Bausteine for Windows/AD, networks, and backup hardening while staying ISO-centric.
Grundschutz fast-track (for ISO folks)
Section titled “Grundschutz fast-track (for ISO folks)”What changes from ISO thinking?
- Start structure → protection needs → modelling before deep risk.
- Controls come from Bausteine (with Basis/Standard/Hoch).
- Do a GS-Check (Soll/Ist) to show safeguarding level.
Minimal path:
- Strukturanalyse: group assets into manageable TOGs (servers, clients, networks, apps, sites).
- Schutzbedarf (CIA): normal/high/very high; apply inheritance (process → app → system).
- Modellierung: assign Bausteine to TOGs; record deviations.
- GS-Check: close gaps; for “hoch” add ergänzende Risikoanalyse.
- Nachweise: measures implemented, responsibilities, evidence.
Tip: Reuse your ISO risk register; tag items that map to Bausteine to avoid double work.
Hybrid recipe (best of both)
Section titled “Hybrid recipe (best of both)”- ISO as the frame: scope, governance, risk method, SoA, KPIs, audits.
- BSI for depth: assign Bausteine to high-impact TOGs (AD/Entra ID, servers, networks, backups, remote access).
- One register: keep a single Risk & Control Register; each control is tagged
ISO-A.xand/orBSI-<Baustein-ID>. - SoA + GS-Check: run both artefacts from the same data: SoA for ISO; GS-Check for BSI stakeholders.
- Certification path: certify ISO first for speed; add Grundschutz later where demanded.
“When to use what” — by scenario
Section titled ““When to use what” — by scenario”- Public administration / KRITIS: Grundschutz or Hybrid (expect BSI language, Bausteine evidence).
- International group / suppliers abroad: ISO (auditor availability, recognition in supply chains).
- Managed service providers (MSP/MSSP): ISO baseline; BSI depth for AD, backups, and remote admin.
- Startups/scaleups: ISO lean; adopt BSI hardening checklists for quick wins.
- OT/IoT environments: ISO risk engine + BSI OT-related Bausteine for prescriptive controls.
Picking controls pragmatically
Section titled “Picking controls pragmatically”ISO first?
- Build SoA with Annex A; mark not applicable with risk-based justifications.
- Where your SoA is “thin”, import BSI measures (e.g., hardening checklists) to raise assurance.
Grundschutz first?
- Use Baustein requirements as your default control set.
- Where BSI is silent/too generic (e.g., SaaS multi-tenant specifics), add ISO-style, risk-derived controls.
Documentation you actually need (no fluff)
Section titled “Documentation you actually need (no fluff)”| Area | ISO deliverable | BSI deliverable | Hybrid shortcut |
|---|---|---|---|
| Scope & context | Scope, stakeholder & issues | Geltungsbereich in Strukturmodell | One scope doc, two summaries |
| Risk | Method, criteria, register, plan | Ergänzende Risikoanalyse (bei „hoch“) | One risk process; extra BSI section |
| Controls | SoA (Annex A) | Baustein-Umsetzung & GS-Check | Unified register with cross-refs |
| Evidence | KPIs, audits, mgmt review | Maßnahmennachweise, GS-Check Protokoll | Shared evidence library |
Common pitfalls (and fixes)
Section titled “Common pitfalls (and fixes)”-
Pitfall: ISO “paper ISMS” without real controls.
Fix: Tie every top risk to a tested control + evidence; baseline KPIs early. -
Pitfall: Grundschutz over-documentation stalls delivery.
Fix: Group TOGs aggressively; prioritize GS-Check gaps by risk; iterate. -
Pitfall: Two parallel worlds (ISO vs. BSI).
Fix: Single taxonomy for assets, risks, controls; tags map to ISO/BSI. -
Pitfall: SoA/GS-Check not kept current.
Fix: Update on every change window; calendar reminders; owner per control.
Migration playbooks
Section titled “Migration playbooks”ISO → Grundschutz
- Map assets to TOGs; import ISO CIA → Schutzbedarf.
- Assign Bausteine; run GS-Check; record deviations.
- Keep ISO risk method; add BSI “hoch” analyses where needed.
Grundschutz → ISO
- Derive ISO scope from Geltungsbereich.
- Convert GS risks into a single risk register with ISO criteria.
- Build SoA from existing measures; justify N/A items; align KPIs & audits.
KPIs that prove it works (both worlds)
Section titled “KPIs that prove it works (both worlds)”- Patch SLA met (%), Backup success (%), Incident MTTR, Access review closure time, Phishing fail rate, Log coverage (% of critical systems), Recovery test success.
Tooling pattern (example)
Section titled “Tooling pattern (example)”- One inventory (assets/TOGs), one risk register, one control catalogue with tags:
tags: ["ISO:A.5.15", "BSI:SYS.1.1.A5"] - Reports: ISO SoA view, BSI GS-Check view, shared evidence links.
One-page recommendations
Section titled “One-page recommendations”- If you need speed + global trust → ISO; sprinkle in BSI hardening where high risk.
- If you need German public acceptance + prescriptive depth → Grundschutz or Hybrid.
- Always keep one register (risks & controls) and tag for ISO/BSI to avoid duplication.