Your situation

BSI IT-Grundschutz consulting for a workable ISMS

You want to introduce IT-Grundschutz or further develop your existing security management. Together with you, we develop the methodology and documents for your information domain. The BSI standards set the framework; your processes and responsibilities shape the implementation.

Free of charge and without obligation.

  • BSI-certified IT-Grundschutz Consultants on the team
  • BSI-certified for IS consulting and IS audit
  • BSI audit team leaders for ISO 27001 on the basis of IT-Grundschutz
Four members of the secuvera team planning a project at a map with navigation instruments
BSI IT-Grundschutz that holds up in everyday work, together with your team.

Your situation

You need to introduce or demonstrate an ISMS based on BSI IT-Grundschutz?

A supervisory authority, a client or your own management requires information security management based on IT-Grundschutz. Sometimes it is about an attestation for Basic Protection, sometimes about an ISO 27001 certification on the basis of IT-Grundschutz, sometimes about an existing IT-Grundschutz ISMS that no longer fits the information domain.

At the start, there is often a wish for ready-made templates. However, adopted documents rarely describe your actual processes – and end up back in the drawer after the audit. What remains open is which evidence goal you really need and how much IT-Grundschutz it takes.

This is where we come in: we clarify the evidence goal with you and build the ISMS so that it is formally correct and works in everyday operations. We develop an existing IT-Grundschutz ISMS further; the information domain must reflect your current processes. A proven starting point is Basic Protection. It is lean, can be expanded at any time and can already be demonstrated by an attestation following the BSI audit scheme (in German).

We have been working with ISMS since the days of the BSI IT Security Manual. In the BSI directory (in German), secuvera is listed under the ID BSI-APS-9002 as a certified IT security service provider for IS audit (IS-Revision) and IS consulting. When the audit itself is due, our auditors carry it out as part of IT-Grundschutz certification or IS audit – but not for an organisation we have previously advised. For projects under the IT-Grundschutz of the German Armed Forces (Bundeswehr) or involving classified information, we prepare audit-ready security concepts.

Services & results

From evidence goal to an IT-Grundschutz ISMS your people run themselves

You get an IT-Grundschutz ISMS (information security management system) based on the BSI standards, newly introduced or further developed, with Basic Protection as a lean, expandable starting point if you wish. At the end, you have the evidence you need: an attestation for Basic Protection, an ISO 27001 certification on the basis of IT-Grundschutz or an IS audit (IS-Revision), supported by BSI-certified IT-Grundschutz Consultants.

We do not apply the BSI standards slavishly but adapt them sensibly to your organisation. The goal is a state that is workable in practice and formally correct at the same time – and an ISMS that your responsible staff continue without us.

Clarify evidence goal and information domain

First, we clarify which evidence is required: an attestation for Basic Protection, an ISO 27001 certification on the basis of IT-Grundschutz, or an IS audit without a certificate. We then define the boundaries of the information domain – sites, processes, systems and service providers.

For an initial review, a one- to two-day workshop with your subject-matter contacts is often enough.

Your evidence goal

A clearly bounded information domain and a defined evidence goal as the basis for effort and project plan.

Start with Basic Protection

A proven approach is to build the IT-Grundschutz ISMS along Basic Protection. The approach is lean and can be expanded at any time if your evidence goal later requires more.

Basic Protection alone already enables an official BSI attestation, issued by the auditor.

Develop methodology and documents together

We do not rely on off-the-shelf documents: we bring proven content from many projects, but adapt every document to your actual processes together with your responsible staff. We include existing security concepts and documents.

The result is documentation that is used – and does not disappear back into the drawer after the audit.

Methodologically, we work according to the IT-Grundschutz methodology of BSI Standard 200-2. Depending on the protection approach, this includes:

  • Structure analysis of the information domain
  • Protection requirements determination
  • Modelling with the modules of the IT-Grundschutz Compendium
  • IT-Grundschutz Check
  • Risk analysis according to BSI Standard 200-3

Your ISMS documentation

Reference documents and processes that describe your actual organisation and can be maintained by your responsible staff.

Prepare for attestation or certification

Our BSI-certified IT-Grundschutz Consultants prepare you for the agreed evidence. Because BSI-certified audit team leaders for ISO 27001 on the basis of IT-Grundschutz also work on our team, the perspective of audit practice feeds into the preparation.

The audit itself is carried out by an independent body: under the certification scheme, consulting and the certification audit cannot be combined for the same organisation.

Handover: your ISMS runs without us

An ISMS has to be maintained by your own responsible staff and employees. Our goal is achieved when your organisation no longer needs our support and the ISMS works as implemented.

If you would nevertheless like ongoing support, secuvera's CISO as a service can take on this role.

Our expertise

We have been working with information security management systems since the days of the BSI IT Security Manual – a Computerwoche article from 1993 documents this. secuvera has offered IT security consulting since 1988 and has been a BSI-certified IT security service provider since December 2011.

Our team includes BSI-certified IT-Grundschutz Consultants and BSI-certified audit team leaders for ISO 27001 on the basis of IT-Grundschutz. Many of the organisations we have supported are certified today – mostly because they prepared well with our support, in some cases after an audit by our auditors.

Getting started

Define information domain and evidence goal

Basic Protection or a full IT-Grundschutz ISMS?

Describe the information domain, existing security concepts and the evidence goal you are aiming for. For Basic Protection, the fundamental requirements come first. If an existing IT-Grundschutz ISMS is to be further developed or a certification prepared, we include modelling, risk analysis and existing audit findings.

Clarify your IT-Grundschutz starting point
Dividers and compass on a historical world map
Information domain clearly bounded, effort realistically planned.

Plan for maintaining the information domain

Basic Protection, an attestation for it and an ISO 27001 certification on the basis of IT-Grundschutz are different goals. At the start, we clarify which scope your requirements call for.

Questions about implementing IT-Grundschutz

Is Basic Protection a suitable entry into IT-Grundschutz?

It can allow a limited build-up of the ISMS that can be expanded later. What matters is which security and evidence goal you are pursuing. Preparing for an attestation for Basic Protection differs from preparing for an ISO 27001 certification on the basis of IT-Grundschutz.

Do we receive ready-made IT-Grundschutz documents?

We bring experience and proven approaches, but adapt the documents to your information domain. A document adopted unchanged rarely describes your actual processes. Developing them together is meant to enable your employees to maintain the documents themselves later.

Is an attestation for Basic Protection the same as a certification?

No. The attestation demonstrates the audited implementation of Basic Protection. An ISO 27001 certification on the basis of IT-Grundschutz follows a different procedure. We clarify the required evidence goal before the preparation begins.

Can secuvera advise us and later also certify us?

Not both for the same organisation. Under the certification scheme, consulting or coaching and the certification audit cannot be combined. You decide whether we prepare you for the audit or carry out the audit.

Does an existing ISO 27001 certificate help when switching to IT-Grundschutz?

It makes preparation easier, but it is not sufficient. The ISMS documents have to be prepared differently for IT-Grundschutz. How quickly this succeeds depends on your existing ISMS; we clarify this in the initial consultation.

Articles on this topic (in German)

All 32 articles on the topic (in German)

Older articles reflect the legal situation at the time of publication. The sections above summarise the current situation.

How can we support you with IT-Grundschutz?