Secani
Secani
  • Company
  • Roadmap
Request demo

Summarize with AI

Open in ChatGPTOpen in ClaudeOpen in PerplexityOpen in MistralOpen in Grok
SIBB Startups
Berlin
Co-funded by the European Union
Secani

Jonathan Bezdek

Wörther Straße 9

10435 Berlin


hello@secani.com

Product

  • Roadmap
  • Documentation
  • OSCAL
  • NIS2 applicability check

Legal

  • Privacy Policy
  • Terms
  • Cookie settings
  • Legal Notice

Company

  • Company
  • Contact
  • Blog

Support

  • Help

Practical IT-Grundschutz

Jonathan BezdekCTO
8 min read
May 28, 2026

On this page

Why the starting point determines auditabilityModeling is a working model, not a formA sensible minimum scope for the first pass

Why the starting point determines auditability

Many IT-Grundschutz projects begin with a long list of requirements. That looks thorough, but it quickly produces scattered spreadsheets, inconsistent ownership, and evidence that has to be gathered just before an audit.

A better starting point is a clean scope. Which organizational units, processes, applications, IT systems, networks, and service providers genuinely belong in the security concept? This decision determines which modules are relevant and which evidence will later need to withstand an audit.

  • Define the scope in writing and name responsible owners
  • Record target assets with unambiguous names, categories, and owners
  • Make relationships among processes, data, applications, and infrastructure visible

Modeling is a working model, not a form

Modeling connects real target assets to suitable IT-Grundschutz modules. Its value does not come from the assignment alone, but from whether the information domain's structure is represented coherently.

If a critical process depends on an application, a network segment, and an external provider, that dependency must be visible in the security concept. Only then can protection needs, implementation status, and residual risks be explained convincingly.

  • Explain each module assignment for its target asset
  • Document dependencies before assessing safeguards
  • Mark exceptions and special cases as open points early

Auditable documentation is created while work happens

A strong security concept continuously captures decisions, rationales, and evidence. Looking for proof only at the end builds an archive. Linking it continuously builds audit readiness.

A sensible minimum scope for the first pass

For the first defensible pass, a clear and compact scope is often more useful than a broad but vague one. Start with a representative information domain whose processes, applications, and infrastructure are well understood.

The method can then be repeated: add target assets, extend module assignments, propagate protection needs, prioritize open safeguards, and group evidence by ownership.

  • Build the first security concept with clear depth rather than maximum breadth
  • Prioritize open safeguards by risk, audit relevance, and feasibility
  • Link evidence where the corresponding requirement is assessed

Build auditable compliance workflows

Secani connects scopes, evidence, tasks, and AI agents in one shared workspace.

Request demo

Related posts

All posts
IT baseline protection
IT-Grundschutz++ meets OSCAL

With the Stand-der-Technik-Bibliothek, IT-Grundschutz leaves the PDF behind: IT-Grundschutz++ ships as an OSCAL catalog – changing how ISMS work is organized.

Read
Regulatory
NIS2: Germany's grace period is ending

Only about a third of affected companies registered with the BSI on time. Until the end of July 2026 this can be fixed – after that, it gets expensive.

Read
Digital Trust
Trust, Trustworthiness, and Zero Trust: Why the Future of Trust Must Be Verifiable

Trust should not be maximized. It should be earned, evidenced, and continuously calibrated to actual trustworthiness.

Read