IT-Grundschutz building blocks, continuously fulfilled.
Germany's BSI IT-Grundschutz methodology specifies concrete hardening requirements in its Kompendium building blocks. CISGuard evidences the system, operations, and network blocks through continuous CIS benchmark scans.
BSI IT-Grundschutz at a glance, for fast retrieval.
Atomic factual claims auditors and search engines can cite verbatim.
- Authority
- BSI (Bundesamt fuer Sicherheit in der Informationstechnik)
- Methodology
- BSI Standards 200-1 (ISMS), 200-2 (methodology), 200-3 (risk analysis)
- Protection approaches
- Basis, Standard, and Core protection (Basis-, Standard-, Kern-Absicherung)
- Control catalog
- IT-Grundschutz-Kompendium building blocks, updated in annual editions
- Certification path
- ISO 27001 certification on the basis of IT-Grundschutz, issued by BSI
- CISGuard coverage
- SYS, OPS, DER, and NET layer requirements evidenced via CIS benchmark scans
What is BSI IT-Grundschutz?
IT-Grundschutz is the information security methodology of Germany's Federal Office for Information Security (BSI). The BSI Standards 200-1, 200-2, and 200-3 define the ISMS requirements, the IT-Grundschutz methodology with its Basis, Standard, and Core protection approaches, and the risk analysis method. The companion IT-Grundschutz-Kompendium, updated in annual editions, contains the building blocks (Bausteine): modular requirement sets organized in layers covering ISMS, organization, operations (OPS), detection (DER), applications (APP), systems (SYS), networks (NET), and infrastructure. Organizations can pursue ISO 27001 certification on the basis of IT-Grundschutz, a BSI-issued certificate that combines the international standard with IT-Grundschutz's far more prescriptive technical depth. That prescriptiveness is precisely what makes automation valuable: SYS building blocks for servers and clients, OPS blocks for patching and logging, and NET blocks for network architecture state concrete configuration requirements that map naturally onto CIS Benchmarks. CISGuard verifies those requirements continuously and documents fulfillment per system.
Kompendium building blocks CISGuard automates.
Each CIS control is tagged with its corresponding framework reference. A single scan produces per-framework coverage reports.
- Server hardening (SYS layer)
- Controls
- SYS.1.1 General Server, SYS.1.3 Linux and Unix Servers
- Mapped by
- CIS server benchmarks (Windows Server, Linux distributions)
- Client hardening (SYS layer)
- Controls
- SYS.2.1 General Client + OS-specific client blocks
- Mapped by
- CIS desktop OS benchmarks
- Patch and change management (OPS layer)
- Controls
- OPS.1.1.3 Patch and Change Management
- Mapped by
- CIS update benchmarks + drift detection between baselines
- Logging (OPS layer)
- Controls
- OPS.1.1.5 Logging
- Mapped by
- CIS Audit Policy benchmarks (Windows + Linux)
- Detection (DER layer)
- Controls
- DER.1 Detection of Security-Relevant Events
- Mapped by
- Continuous scan alerts + drift detection events
- Network security (NET layer)
- Controls
- NET.1.1 Network Architecture and Design requirements at host level
- Mapped by
- CIS Network configuration benchmarks
How CISGuard automates BSI IT-Grundschutz evidence.
IT-Grundschutz's strength is prescriptiveness: a SYS building block does not say "harden the server", it enumerates specific requirements for accounts, services, logging, and updates. Auditors for ISO 27001 certification on the basis of IT-Grundschutz check fulfillment requirement by requirement, per target object. CISGuard industrializes that verification for the technical layers. Each Windows and Linux system is scanned continuously against its CIS Benchmark, and the results evidence the corresponding SYS block requirements: hardened services, restricted accounts, secure authentication, and logging configuration. OPS.1.1.3 patch management is evidenced by update state checks, OPS.1.1.5 by audit policy verification, and DER.1 detection duties are supported by drift alerts that flag security-relevant configuration changes as they happen. The Framework Coverage Report presents fulfillment status per mapped building block with timestamps and underlying scan data, giving the IT-Grundschutz-Check a maintained factual basis instead of an annual interview exercise. German public sector and KRITIS operators can deploy CISGuard fully on-premises or air-gapped, keeping all evidence within German infrastructure. Certification decisions remain with BSI and its licensed auditors.
Evidence artifacts CISGuard generates.
Auditor-grade outputs in PDF/CSV. No spreadsheets, no screenshots, no manual cross-referencing.
- Per-system CIS benchmark reports mapped to SYS building block requirements
- Framework Coverage Report showing fulfillment status per mapped Baustein
- Patch and update posture reports evidencing OPS.1.1.3
- Audit logging configuration state evidencing OPS.1.1.5
- Drift detection event history supporting DER.1 detection requirements
- Posture trends per protection approach scope for recertification audits
BSI IT-Grundschutz questions, answered directly.
What is BSI IT-Grundschutz?
IT-Grundschutz is the information security methodology published by Germany's Federal Office for Information Security (BSI). BSI Standards 200-1, 200-2, and 200-3 define the ISMS, the methodology, and risk analysis, while the annually updated IT-Grundschutz-Kompendium supplies modular building blocks with concrete security requirements per system type. It is significantly more prescriptive than ISO 27001 alone, which makes automated verification especially valuable.
What is ISO 27001 certification on the basis of IT-Grundschutz?
A certification issued by BSI that demonstrates ISO 27001 conformity implemented through the IT-Grundschutz methodology. Audits verify fulfillment of the applicable Kompendium building block requirements for each target object, requirement by requirement. CISGuard evidences the technical SYS, OPS, DER, and NET requirements through continuous CIS benchmark scans; the certificate itself is issued by BSI on the basis of a licensed auditor's report.
Which Kompendium building blocks does CISGuard evidence?
The technical layers: SYS blocks for servers and clients (such as SYS.1.1 General Server and SYS.2.1 General Client), OPS.1.1.3 Patch and Change Management, OPS.1.1.5 Logging, DER.1 detection requirements, and host-level NET requirements. Organizational and personnel blocks (ISMS, ORP layers) are process controls outside automated configuration scanning. Mapping is exposed in the Framework Coverage Report per building block.
What are the Basis, Standard, and Core protection approaches?
BSI Standard 200-2 defines three entry paths: Basis protection (Basis-Absicherung) implements the most essential requirements first, Core protection (Kern-Absicherung) concentrates on the most critical assets, and Standard protection (Standard-Absicherung) is the full methodology and the path to certification. CISGuard supports all three by scoping which systems are scanned and reporting fulfillment against the requirements applicable to the chosen approach.
Can German agencies run CISGuard without cloud dependencies?
Yes. CISGuard deploys fully on-premises and supports air-gapped operation, so scan data, evidence, and reports remain entirely within your own German infrastructure. That fits public sector data sovereignty expectations and KRITIS operator constraints. Continuous CIS benchmark scanning, drift detection, and Framework Coverage Reports all function identically without any outbound connection.
Continue exploring CISGuard coverage.
ISO 27001
CISGuard maps 36 ISO/IEC 27001:2022 Annex A controls to CIS benchmark scans, automating the technical evidence that certification audits demand and continuous-monitoring requirements imply.
Read more →ISO 27002
ISO/IEC 27002:2022 tells you how to implement the 93 controls behind ISO 27001 Annex A. CISGuard proves the technological ones are actually in place, with continuous CIS benchmark scans as the implementation evidence.
Read more →NIS2
CISGuard automates the cybersecurity risk-management measures NIS2 Article 21 requires of EU Essential and Important Entities, with continuous evidence the national supervisory authorities expect.
Read more →TISAX
CISGuard automates the technical Annex A controls that TISAX assessors validate, generating the continuous evidence VDA ISA requires for AL2 and AL3 certification.
Read more →Ready for BSI IT-Grundschutz readiness?
Our compliance engineers have helped organizations achieve regulatory readiness in as little as one business day.