Skip to content

Fundamentals of Information Security

Information security is a complex discipline with a wide range of specific terms, methods, and standards. This knowledge page provides a central overview of key terminology from ISO 27001, BSI IT-Grundschutz, and ISMS management. It serves as a reference for consistent use of terms and as a quick orientation guide in daily security work.

Consistent terminology is essential for effective communication between business units, IT, and management, as well as for the successful implementation of security measures.

The Three Core Values (Security Objectives)

Section titled “The Three Core Values (Security Objectives)”

Information security is based on three fundamental objectives:

  • Confidentiality: Protection against unauthorized access to information
  • Integrity: Protection against unauthorized alteration of data and systems
  • Availability: Ensuring that information and services are available as required

These core values form the CIA triangle and are central to all security standards.

ISMS (Information Security Management System)

Section titled “ISMS (Information Security Management System)”

An ISMS is the entirety of policies, processes, and measures used to systematically manage information security. It follows the continuous PDCA cycle (Plan-Do-Check-Act) and ensures:

  • A structured approach to security risks
  • Continuous improvement of the security posture
  • Demonstrable compliance with standards and requirements
  • Systematic monitoring and adjustment of measures

IT-Grundschutz is the approach developed by the German BSI to identify and implement appropriate security measures. It offers:

  • Modular building blocks with concrete implementation recommendations
  • Proven practice for typical IT environments
  • A foundation for ISO 27001 certification “based on IT-Grundschutz”

ISO 27001 defines the international requirements for an ISMS and is:

  • Risk-based and flexibly adaptable
  • An internationally recognized certification standard
  • A framework that can be complemented by concrete methodologies such as IT-Grundschutz

Determining Protection Needs and Risk Analysis

Section titled “Determining Protection Needs and Risk Analysis”

Determining protection needs is carried out systematically:

  1. Process Analysis: Identify business-critical processes
  2. Damage Scenarios: Assess potential impacts if security objectives are violated
  3. Categorization: Classify as “normal,” “high,” or “very high”
  4. Inheritance: Transfer protection requirements to dependent systems and components
  • Maximum Principle: The highest level of protection need determines the overall requirement
  • Cumulative Effect: Protection needs increase due to combined damages in multiple processing steps
  • Distribution Effect: Reduction of protection needs by distributing across multiple systems

Pro Tip: Document inheritance transparently and traceably. This greatly simplifies later audits and adjustments.

  1. Structural Analysis: Document the information network
  2. Determination of Protection Needs: Assess criticality
  3. Modeling: Map building blocks to target objects
  4. Baseline Security Check: Compare actual vs. required measures
  5. Risk Analysis: Assess additional risks
  6. Implementation of Measures: Apply required controls

Modeling assigns IT-Grundschutz building blocks to identified target objects. Each block contains:

  • Description: Purpose and scope
  • Threat Landscape: Relevant threats
  • Requirements: Concrete security measures
  • Additional Information: Implementation guidance
  • Basic Security: Broad initial coverage across all processes as a starting point
  • Core Security: Focus on particularly exposed processes and assets
  • Standard Security: Classic, comprehensive BSI approach
  • Use “information network” in IT-Grundschutz contexts
  • Use “scope” in ISO/international contexts
  • Distinguish clearly between “data protection” (personal data) and “data security” (technical protection)

Define clear responsibilities:

  • ISB/CISO: Strategic leadership of the ISMS
  • Risk Owner: Responsibility for specific risks
  • Asset Owner: Responsibility for protecting specific assets
  • Governance Group: Strategic decisions and policies

Pro Tip: Use RACI matrices for clear role assignment (Responsible, Accountable, Consulted, Informed).

  • Keep all evidence documents version-controlled and immutable
  • Document decisions and their rationale
  • Ensure that audit trails are verifiable
  • Evaluate security concepts at least every 2 years
  • Provide an updated ISMS version at least every 3 years
  • Conduct regular internal audits

Pro Tip: Use the catalog features of the fuentis Suite for consistent application of IT-Grundschutz building blocks and automated compliance checks.

  1. Consistent terminology is fundamental for successful information security and effective communication within the ISMS.
  2. The three core values – confidentiality, integrity, and availability – form the foundation of all security measures and standards.
  3. IT-Grundschutz and ISO 27001 complement each other: IT-Grundschutz provides proven practice, ISO 27001 offers the international certification framework.
  4. Structured phases from structural analysis to continuous improvement ensure systematic ISMS implementation and sustainable security.
  5. Clear roles, consistent documentation, and regular reviews are key success factors for effective information security in practice.