Practical IT-Grundschutz
Why the starting point determines auditability
Many IT-Grundschutz projects begin with a long list of requirements. That looks thorough, but it quickly produces scattered spreadsheets, inconsistent ownership, and evidence that has to be gathered just before an audit.
A better starting point is a clean scope. Which organizational units, processes, applications, IT systems, networks, and service providers genuinely belong in the security concept? This decision determines which modules are relevant and which evidence will later need to withstand an audit.
- Define the scope in writing and name responsible owners
- Record target assets with unambiguous names, categories, and owners
- Make relationships among processes, data, applications, and infrastructure visible
Modeling is a working model, not a form
Modeling connects real target assets to suitable IT-Grundschutz modules. Its value does not come from the assignment alone, but from whether the information domain's structure is represented coherently.
If a critical process depends on an application, a network segment, and an external provider, that dependency must be visible in the security concept. Only then can protection needs, implementation status, and residual risks be explained convincingly.
- Explain each module assignment for its target asset
- Document dependencies before assessing safeguards
- Mark exceptions and special cases as open points early
A sensible minimum scope for the first pass
For the first defensible pass, a clear and compact scope is often more useful than a broad but vague one. Start with a representative information domain whose processes, applications, and infrastructure are well understood.
The method can then be repeated: add target assets, extend module assignments, propagate protection needs, prioritize open safeguards, and group evidence by ownership.
- Build the first security concept with clear depth rather than maximum breadth
- Prioritize open safeguards by risk, audit relevance, and feasibility
- Link evidence where the corresponding requirement is assessed
Build auditable compliance workflows
Secani connects scopes, evidence, tasks, and AI agents in one shared workspace.
Related posts
All postsWith the Stand-der-Technik-Bibliothek, IT-Grundschutz leaves the PDF behind: IT-Grundschutz++ ships as an OSCAL catalog – changing how ISMS work is organized.
Only about a third of affected companies registered with the BSI on time. Until the end of July 2026 this can be fixed – after that, it gets expensive.
Trust should not be maximized. It should be earned, evidenced, and continuously calibrated to actual trustworthiness.