Your situation

Security concepts for defence and processing classified information

You need an audit-ready information security concept for a German Armed Forces (Bundeswehr) project or for handling classified information? We support you in preparing, reviewing and updating your concepts.

Free of charge and without obligation.

  • BSI-certified for IS consulting and IS audit
  • BSI-certified IT-Grundschutz Consultants on the team
Dividers and compass on a historical world map
Security concepts for defence and classified information, clearly scoped.

Your situation

You need an audit-ready information security concept for a Bundeswehr project or for processing classified information?

You develop or operate a solution in the Bundeswehr context and have to submit a project information security concept (InfoSichhKProj) in line with ZDv A-960/1 and the IT-Grundschutz of the Bundeswehr (IT-GSBw) – mapped in the ISMS tool SAVe™ 6 and coordinated with the German Military Security Accreditation Authority (DEUmilSAA). Or you process classified information such as VS-NfD (classified information – RESTRICTED) and must demonstrate that your environment meets the requirements of the Classified Information Directive (Verschlusssachenanweisung, VSA) and the VS-NfD leaflet (VS-NfD-Merkblatt).

Typical questions are then: How can the requirements be implemented in a structured way? How does this result in an audit-ready concept? How do you manage the high documentation and coordination effort in the project – and will the concept be ready on time? The difficulty usually lies not in individual measures but in interpreting the requirements correctly and translating them into an audit-ready structure.

This is where we come in: as a BSI-certified IT security service provider, we have supported projects in the Bundeswehr and classified information environment for many years. We work through the IT-Grundschutz check with you in guided sessions and take care of the documentation. If products also need to be evaluated for use with classified information, our BSI evaluation facility supports you with product approval for classified information.

Services & results

Two routes to an audit-ready concept: InfoSichhKProj and processing classified information

Your information security concept is prepared, reviewed or updated – for example a project information security concept (InfoSichhKProj) in line with ZDv A-960/1 and the Bundeswehr's IT-Grundschutz, or concepts for processing classified information in line with the VSA and the VS-NfD leaflet. You work through the IT-Grundschutz check with us in guided sessions while we take care of the documentation; for higher classification levels we work on site.

Our approach is designed to reduce coordination effort and to ensure that your security concept is audit-ready from the start. For an InfoSichhKProj we work in line with IT-GSBw (steps 1 to 4), for processing classified information in line with the VSA and the VS-NfD leaflet (steps 5 and 6).

InfoSichhKProj: clarify framework and structure

We describe the scope, take into account assumptions about operational and general conditions, and map the subject under consideration in a structured way (structure analysis).

We then agree on protection requirements and modelling together with you – supported by workshops in which we put existing requirements into context.

InfoSichhKProj: IT-Grundschutz check in guided sessions

We work through the IT-GSBw requirements efficiently in guided online sessions. We take care of the documentation. For higher classification levels, the sessions take place on site.

InfoSichhKProj: risk analysis

We identify and assess the specific risks of your environment and map the analysis, modelling and risk analysis in the ISMS tool SAVe™ 6.

InfoSichhKProj: finalise and coordinate the concept

The concept undergoes technical and editorial quality assurance. We prepare all further components and coordinate with the DEUmilSAA and all parties involved in the project.

  • Contingency planning
  • Patch management
  • Auditing concept

Your audit-ready InfoSichhKProj

An information security concept with all required annexes in line with Bundeswehr and DEUmilSAA requirements, mapped in SAVe™ 6.

Processing classified information: assess the starting point, build policies and evidence

We analyse your IT structures and the VS-compliant products in use and compare them with existing security measures and ISMS components.

From this, we determine missing ISMS and security concept components and prepare policies and documentation in line with VS-NfD requirements – including a plan for fully meeting the evidence requirements.

Evidence for processing classified information

Policies and documentation in line with the VS-NfD leaflet and the VSA, plus a plan for the evidence requirements still outstanding.

Processing classified information: support implementation

We support you with open points in line with your objectives and coordinate the products in use – if necessary including clarifying specific solution requirements with the BSI. We clearly divide the tasks between your team and us.

Our expertise

Information security concepts in the defence or classified information environment do not follow the logic of conventional ISMS projects. In addition to framework standards, binding requirements apply, such as ZDv A-960/1 with its working aids, IT-GSBw, the VSA and the VS-NfD leaflet. From many years of project work on InfoSichhKProj and processing classified information, we know the typical requirements, procedures and pitfalls.

We have long been active in the Bundeswehr environment: as early as 2013, after the amendment of ZDV 54/100, we offered Bundeswehr IT security officers qualified consultants for aligning with BSI IT-Grundschutz. Our staff can also be deployed in highly sensitive projects.

At secuvera, consulting and Product Security work under one roof. If VS-compliant products are needed, we clarify specific solution requirements with the BSI where necessary and support manufacturers on the way to BSI approval for classified information (VS approval).

Getting started

Clarify the project and permissible information exchange

Clarify scope and classification

For the initial consultation, an unclassified description of the project, the relevant requirements and your timeframe are sufficient. We agree separately on how sensitive documents are exchanged.

Divide tasks in the project

We divide the tasks between your team and us and agree on how to handle open points and the products in use. If necessary, we clarify specific solution requirements with the BSI.

Agree on a security concept
Hands writing notes next to a compass and navigation instruments on a map
Project and permissible information exchange clarified early.

Observe classification and exchange channel

The relevant regulations, the classification and the permissible information exchange are agreed for each project. The competent authorities decide on any approvals required.

Questions about InfoSichhKProj and security concepts for classified information

Which information security concepts does secuvera support?

We support the preparation and updating of InfoSichhKProj for Bundeswehr projects as well as security concepts for processing classified information. The relevant regulations and required annexes depend on the project and its requirements.

Can you extend an existing VS concept?

Existing measures, documents and evidence are taken into account. We check which parts still reflect the current scope and operating conditions. Missing or outdated content is addressed specifically.

May we send classified documents for the first discussion?

For the preliminary discussion, use an unclassified description. Before sensitive information is exchanged, we agree on the classification and the permissible transmission channel. Depending on the requirements, the work takes place in suitable online sessions or on site.

Does the security concept replace the approval of the products used?

No. The concept and any required product approvals are separate pieces of evidence. We can coordinate specific solution requirements and open questions with the parties involved; the competent authorities make any required approval decisions.

Which regulations apply to an InfoSichhKProj, and which to processing classified information?

In the Bundeswehr context, these are primarily ZDv A-960/1 with binding requirements in working aids, the IT-Grundschutz for the Bundeswehr (IT-GSBw) with the ISMS tool SAVe™ 6, and the coordination processes as part of accreditation, for example by the DEUmilSAA. For processing classified information, the Classified Information Directive (VSA), the VS-NfD leaflet and additional authority-specific and project-specific requirements apply. BSI IT-Grundschutz can provide methodological support.

How can we support you with security concepts for classified information?