Skip to main content
← All frameworks
BSI IT-Grundschutz Automation

IT-Grundschutz building blocks, continuously fulfilled.

Germany's BSI IT-Grundschutz methodology specifies concrete hardening requirements in its Kompendium building blocks. CISGuard evidences the system, operations, and network blocks through continuous CIS benchmark scans.

GermanyGovernment, Critical Infrastructure (KRITIS), All industries
Quick Facts

BSI IT-Grundschutz at a glance, for fast retrieval.

Atomic factual claims auditors and search engines can cite verbatim.

Authority
BSI (Bundesamt fuer Sicherheit in der Informationstechnik)
Methodology
BSI Standards 200-1 (ISMS), 200-2 (methodology), 200-3 (risk analysis)
Protection approaches
Basis, Standard, and Core protection (Basis-, Standard-, Kern-Absicherung)
Control catalog
IT-Grundschutz-Kompendium building blocks, updated in annual editions
Certification path
ISO 27001 certification on the basis of IT-Grundschutz, issued by BSI
CISGuard coverage
SYS, OPS, DER, and NET layer requirements evidenced via CIS benchmark scans
Overview

What is BSI IT-Grundschutz?

IT-Grundschutz is the information security methodology of Germany's Federal Office for Information Security (BSI). The BSI Standards 200-1, 200-2, and 200-3 define the ISMS requirements, the IT-Grundschutz methodology with its Basis, Standard, and Core protection approaches, and the risk analysis method. The companion IT-Grundschutz-Kompendium, updated in annual editions, contains the building blocks (Bausteine): modular requirement sets organized in layers covering ISMS, organization, operations (OPS), detection (DER), applications (APP), systems (SYS), networks (NET), and infrastructure. Organizations can pursue ISO 27001 certification on the basis of IT-Grundschutz, a BSI-issued certificate that combines the international standard with IT-Grundschutz's far more prescriptive technical depth. That prescriptiveness is precisely what makes automation valuable: SYS building blocks for servers and clients, OPS blocks for patching and logging, and NET blocks for network architecture state concrete configuration requirements that map naturally onto CIS Benchmarks. CISGuard verifies those requirements continuously and documents fulfillment per system.

Control Mapping

Kompendium building blocks CISGuard automates.

Each CIS control is tagged with its corresponding framework reference. A single scan produces per-framework coverage reports.

  • Server hardening (SYS layer)
    Controls
    SYS.1.1 General Server, SYS.1.3 Linux and Unix Servers
    Mapped by
    CIS server benchmarks (Windows Server, Linux distributions)
  • Client hardening (SYS layer)
    Controls
    SYS.2.1 General Client + OS-specific client blocks
    Mapped by
    CIS desktop OS benchmarks
  • Patch and change management (OPS layer)
    Controls
    OPS.1.1.3 Patch and Change Management
    Mapped by
    CIS update benchmarks + drift detection between baselines
  • Logging (OPS layer)
    Controls
    OPS.1.1.5 Logging
    Mapped by
    CIS Audit Policy benchmarks (Windows + Linux)
  • Detection (DER layer)
    Controls
    DER.1 Detection of Security-Relevant Events
    Mapped by
    Continuous scan alerts + drift detection events
  • Network security (NET layer)
    Controls
    NET.1.1 Network Architecture and Design requirements at host level
    Mapped by
    CIS Network configuration benchmarks
How It Works

How CISGuard automates BSI IT-Grundschutz evidence.

IT-Grundschutz's strength is prescriptiveness: a SYS building block does not say "harden the server", it enumerates specific requirements for accounts, services, logging, and updates. Auditors for ISO 27001 certification on the basis of IT-Grundschutz check fulfillment requirement by requirement, per target object. CISGuard industrializes that verification for the technical layers. Each Windows and Linux system is scanned continuously against its CIS Benchmark, and the results evidence the corresponding SYS block requirements: hardened services, restricted accounts, secure authentication, and logging configuration. OPS.1.1.3 patch management is evidenced by update state checks, OPS.1.1.5 by audit policy verification, and DER.1 detection duties are supported by drift alerts that flag security-relevant configuration changes as they happen. The Framework Coverage Report presents fulfillment status per mapped building block with timestamps and underlying scan data, giving the IT-Grundschutz-Check a maintained factual basis instead of an annual interview exercise. German public sector and KRITIS operators can deploy CISGuard fully on-premises or air-gapped, keeping all evidence within German infrastructure. Certification decisions remain with BSI and its licensed auditors.

Auditor Evidence

Evidence artifacts CISGuard generates.

Auditor-grade outputs in PDF/CSV. No spreadsheets, no screenshots, no manual cross-referencing.

  • Per-system CIS benchmark reports mapped to SYS building block requirements
  • Framework Coverage Report showing fulfillment status per mapped Baustein
  • Patch and update posture reports evidencing OPS.1.1.3
  • Audit logging configuration state evidencing OPS.1.1.5
  • Drift detection event history supporting DER.1 detection requirements
  • Posture trends per protection approach scope for recertification audits
Frequently Asked

BSI IT-Grundschutz questions, answered directly.

What is BSI IT-Grundschutz?

IT-Grundschutz is the information security methodology published by Germany's Federal Office for Information Security (BSI). BSI Standards 200-1, 200-2, and 200-3 define the ISMS, the methodology, and risk analysis, while the annually updated IT-Grundschutz-Kompendium supplies modular building blocks with concrete security requirements per system type. It is significantly more prescriptive than ISO 27001 alone, which makes automated verification especially valuable.

What is ISO 27001 certification on the basis of IT-Grundschutz?

A certification issued by BSI that demonstrates ISO 27001 conformity implemented through the IT-Grundschutz methodology. Audits verify fulfillment of the applicable Kompendium building block requirements for each target object, requirement by requirement. CISGuard evidences the technical SYS, OPS, DER, and NET requirements through continuous CIS benchmark scans; the certificate itself is issued by BSI on the basis of a licensed auditor's report.

Which Kompendium building blocks does CISGuard evidence?

The technical layers: SYS blocks for servers and clients (such as SYS.1.1 General Server and SYS.2.1 General Client), OPS.1.1.3 Patch and Change Management, OPS.1.1.5 Logging, DER.1 detection requirements, and host-level NET requirements. Organizational and personnel blocks (ISMS, ORP layers) are process controls outside automated configuration scanning. Mapping is exposed in the Framework Coverage Report per building block.

What are the Basis, Standard, and Core protection approaches?

BSI Standard 200-2 defines three entry paths: Basis protection (Basis-Absicherung) implements the most essential requirements first, Core protection (Kern-Absicherung) concentrates on the most critical assets, and Standard protection (Standard-Absicherung) is the full methodology and the path to certification. CISGuard supports all three by scoping which systems are scanned and reporting fulfillment against the requirements applicable to the chosen approach.

Can German agencies run CISGuard without cloud dependencies?

Yes. CISGuard deploys fully on-premises and supports air-gapped operation, so scan data, evidence, and reports remain entirely within your own German infrastructure. That fits public sector data sovereignty expectations and KRITIS operator constraints. Continuous CIS benchmark scanning, drift detection, and Framework Coverage Reports all function identically without any outbound connection.

Ready for BSI IT-Grundschutz readiness?

Our compliance engineers have helped organizations achieve regulatory readiness in as little as one business day.