Fundamentals of Information Security
Information security is a complex discipline with a wide range of specific terms, methods, and standards. This knowledge page provides a central overview of key terminology from ISO 27001, BSI IT-Grundschutz, and ISMS management. It serves as a reference for consistent use of terms and as a quick orientation guide in daily security work.
Consistent terminology is essential for effective communication between business units, IT, and management, as well as for the successful implementation of security measures.
Core Concepts of Information Security
Section titled “Core Concepts of Information Security”The Three Core Values (Security Objectives)
Section titled “The Three Core Values (Security Objectives)”Information security is based on three fundamental objectives:
- Confidentiality: Protection against unauthorized access to information
- Integrity: Protection against unauthorized alteration of data and systems
- Availability: Ensuring that information and services are available as required
These core values form the CIA triangle and are central to all security standards.
ISMS (Information Security Management System)
Section titled “ISMS (Information Security Management System)”An ISMS is the entirety of policies, processes, and measures used to systematically manage information security. It follows the continuous PDCA cycle (Plan-Do-Check-Act) and ensures:
- A structured approach to security risks
- Continuous improvement of the security posture
- Demonstrable compliance with standards and requirements
- Systematic monitoring and adjustment of measures
IT-Grundschutz vs. ISO 27001
Section titled “IT-Grundschutz vs. ISO 27001”IT-Grundschutz is the approach developed by the German BSI to identify and implement appropriate security measures. It offers:
- Modular building blocks with concrete implementation recommendations
- Proven practice for typical IT environments
- A foundation for ISO 27001 certification “based on IT-Grundschutz”
ISO 27001 defines the international requirements for an ISMS and is:
- Risk-based and flexibly adaptable
- An internationally recognized certification standard
- A framework that can be complemented by concrete methodologies such as IT-Grundschutz
Determining Protection Needs and Risk Analysis
Section titled “Determining Protection Needs and Risk Analysis”Methodical Approach
Section titled “Methodical Approach”Determining protection needs is carried out systematically:
- Process Analysis: Identify business-critical processes
- Damage Scenarios: Assess potential impacts if security objectives are violated
- Categorization: Classify as “normal,” “high,” or “very high”
- Inheritance: Transfer protection requirements to dependent systems and components
Inheritance Principles
Section titled “Inheritance Principles”- Maximum Principle: The highest level of protection need determines the overall requirement
- Cumulative Effect: Protection needs increase due to combined damages in multiple processing steps
- Distribution Effect: Reduction of protection needs by distributing across multiple systems
Pro Tip: Document inheritance transparently and traceably. This greatly simplifies later audits and adjustments.
ISMS in Practice
Section titled “ISMS in Practice”Phases of ISMS Implementation
Section titled “Phases of ISMS Implementation”- Structural Analysis: Document the information network
- Determination of Protection Needs: Assess criticality
- Modeling: Map building blocks to target objects
- Baseline Security Check: Compare actual vs. required measures
- Risk Analysis: Assess additional risks
- Implementation of Measures: Apply required controls
Modeling and Building Blocks
Section titled “Modeling and Building Blocks”Modeling assigns IT-Grundschutz building blocks to identified target objects. Each block contains:
- Description: Purpose and scope
- Threat Landscape: Relevant threats
- Requirements: Concrete security measures
- Additional Information: Implementation guidance
Security Approaches
Section titled “Security Approaches”- Basic Security: Broad initial coverage across all processes as a starting point
- Core Security: Focus on particularly exposed processes and assets
- Standard Security: Classic, comprehensive BSI approach
Implementation Support and Best Practices
Section titled “Implementation Support and Best Practices”Consistent Terminology
Section titled “Consistent Terminology”- Use “information network” in IT-Grundschutz contexts
- Use “scope” in ISO/international contexts
- Distinguish clearly between “data protection” (personal data) and “data security” (technical protection)
Role Clarification
Section titled “Role Clarification”Define clear responsibilities:
- ISB/CISO: Strategic leadership of the ISMS
- Risk Owner: Responsibility for specific risks
- Asset Owner: Responsibility for protecting specific assets
- Governance Group: Strategic decisions and policies
Pro Tip: Use RACI matrices for clear role assignment (Responsible, Accountable, Consulted, Informed).
Documentation and Evidence
Section titled “Documentation and Evidence”- Keep all evidence documents version-controlled and immutable
- Document decisions and their rationale
- Ensure that audit trails are verifiable
Continuous Improvement
Section titled “Continuous Improvement”- Evaluate security concepts at least every 2 years
- Provide an updated ISMS version at least every 3 years
- Conduct regular internal audits
Pro Tip: Use the catalog features of the fuentis Suite for consistent application of IT-Grundschutz building blocks and automated compliance checks.
Key Takeaways at a Glance
Section titled “Key Takeaways at a Glance”- Consistent terminology is fundamental for successful information security and effective communication within the ISMS.
- The three core values – confidentiality, integrity, and availability – form the foundation of all security measures and standards.
- IT-Grundschutz and ISO 27001 complement each other: IT-Grundschutz provides proven practice, ISO 27001 offers the international certification framework.
- Structured phases from structural analysis to continuous improvement ensure systematic ISMS implementation and sustainable security.
- Clear roles, consistent documentation, and regular reviews are key success factors for effective information security in practice.