Security concepts for defence and processing classified information
You need an audit-ready information security concept for a German Armed Forces (Bundeswehr) project or for handling classified information? We support you in preparing, reviewing and updating your concepts.
BSI-certified IT-Grundschutz Consultants on the team
Security concepts for defence and classified information, clearly scoped.
Your situation
You need an audit-ready information security concept for a Bundeswehr project or for processing classified information?
You develop or operate a solution in the Bundeswehr context and have to submit a project information security concept (InfoSichhKProj) in line with ZDv A-960/1 and the IT-Grundschutz of the Bundeswehr (IT-GSBw) – mapped in the ISMS tool SAVe™ 6 and coordinated with the German Military Security Accreditation Authority (DEUmilSAA). Or you process classified information such as VS-NfD (classified information – RESTRICTED) and must demonstrate that your environment meets the requirements of the Classified Information Directive (Verschlusssachenanweisung, VSA) and the VS-NfD leaflet (VS-NfD-Merkblatt).
Typical questions are then: How can the requirements be implemented in a structured way? How does this result in an audit-ready concept? How do you manage the high documentation and coordination effort in the project – and will the concept be ready on time? The difficulty usually lies not in individual measures but in interpreting the requirements correctly and translating them into an audit-ready structure.
This is where we come in: as a BSI-certified IT security service provider, we have supported projects in the Bundeswehr and classified information environment for many years. We work through the IT-Grundschutz check with you in guided sessions and take care of the documentation. If products also need to be evaluated for use with classified information, our BSI evaluation facility supports you with product approval for classified information.
Services & results
Two routes to an audit-ready concept: InfoSichhKProj and processing classified information
Your information security concept is prepared, reviewed or updated – for example a project information security concept (InfoSichhKProj) in line with ZDv A-960/1 and the Bundeswehr's IT-Grundschutz, or concepts for processing classified information in line with the VSA and the VS-NfD leaflet. You work through the IT-Grundschutz check with us in guided sessions while we take care of the documentation; for higher classification levels we work on site.
Our approach is designed to reduce coordination effort and to ensure that your security concept is audit-ready from the start. For an InfoSichhKProj we work in line with IT-GSBw (steps 1 to 4), for processing classified information in line with the VSA and the VS-NfD leaflet (steps 5 and 6).
01
InfoSichhKProj: clarify framework and structure
We describe the scope, take into account assumptions about operational and general conditions, and map the subject under consideration in a structured way (structure analysis).
We then agree on protection requirements and modelling together with you – supported by workshops in which we put existing requirements into context.
02
InfoSichhKProj: IT-Grundschutz check in guided sessions
We work through the IT-GSBw requirements efficiently in guided online sessions. We take care of the documentation. For higher classification levels, the sessions take place on site.
03
InfoSichhKProj: risk analysis
We identify and assess the specific risks of your environment and map the analysis, modelling and risk analysis in the ISMS tool SAVe™ 6.
04
InfoSichhKProj: finalise and coordinate the concept
The concept undergoes technical and editorial quality assurance. We prepare all further components and coordinate with the DEUmilSAA and all parties involved in the project.
Contingency planning
Patch management
Auditing concept
Your audit-ready InfoSichhKProj
An information security concept with all required annexes in line with Bundeswehr and DEUmilSAA requirements, mapped in SAVe™ 6.
05
Processing classified information: assess the starting point, build policies and evidence
We analyse your IT structures and the VS-compliant products in use and compare them with existing security measures and ISMS components.
From this, we determine missing ISMS and security concept components and prepare policies and documentation in line with VS-NfD requirements – including a plan for fully meeting the evidence requirements.
Evidence for processing classified information
Policies and documentation in line with the VS-NfD leaflet and the VSA, plus a plan for the evidence requirements still outstanding.
06
Processing classified information: support implementation
We support you with open points in line with your objectives and coordinate the products in use – if necessary including clarifying specific solution requirements with the BSI. We clearly divide the tasks between your team and us.
Our expertise
Information security concepts in the defence or classified information environment do not follow the logic of conventional ISMS projects. In addition to framework standards, binding requirements apply, such as ZDv A-960/1 with its working aids, IT-GSBw, the VSA and the VS-NfD leaflet. From many years of project work on InfoSichhKProj and processing classified information, we know the typical requirements, procedures and pitfalls.
We have long been active in the Bundeswehr environment: as early as 2013, after the amendment of ZDV 54/100, we offered Bundeswehr IT security officers qualified consultants for aligning with BSI IT-Grundschutz. Our staff can also be deployed in highly sensitive projects.
At secuvera, consulting and Product Security work under one roof. If VS-compliant products are needed, we clarify specific solution requirements with the BSI where necessary and support manufacturers on the way to BSI approval for classified information (VS approval).
Getting started
Clarify the project and permissible information exchange
Clarify scope and classification
For the initial consultation, an unclassified description of the project, the relevant requirements and your timeframe are sufficient. We agree separately on how sensitive documents are exchanged.
Divide tasks in the project
We divide the tasks between your team and us and agree on how to handle open points and the products in use. If necessary, we clarify specific solution requirements with the BSI.
Project and permissible information exchange clarified early.
Observe classification and exchange channel
The relevant regulations, the classification and the permissible information exchange are agreed for each project. The competent authorities decide on any approvals required.
Questions about InfoSichhKProj and security concepts for classified information
Which information security concepts does secuvera support?
We support the preparation and updating of InfoSichhKProj for Bundeswehr projects as well as security concepts for processing classified information. The relevant regulations and required annexes depend on the project and its requirements.
Can you extend an existing VS concept?
Existing measures, documents and evidence are taken into account. We check which parts still reflect the current scope and operating conditions. Missing or outdated content is addressed specifically.
May we send classified documents for the first discussion?
For the preliminary discussion, use an unclassified description. Before sensitive information is exchanged, we agree on the classification and the permissible transmission channel. Depending on the requirements, the work takes place in suitable online sessions or on site.
Does the security concept replace the approval of the products used?
No. The concept and any required product approvals are separate pieces of evidence. We can coordinate specific solution requirements and open questions with the parties involved; the competent authorities make any required approval decisions.
Which regulations apply to an InfoSichhKProj, and which to processing classified information?
In the Bundeswehr context, these are primarily ZDv A-960/1 with binding requirements in working aids, the IT-Grundschutz for the Bundeswehr (IT-GSBw) with the ISMS tool SAVe™ 6, and the coordination processes as part of accreditation, for example by the DEUmilSAA. For processing classified information, the Classified Information Directive (VSA), the VS-NfD leaflet and additional authority-specific and project-specific requirements apply. BSI IT-Grundschutz can provide methodological support.