Here is the honest situation. BSI IT-Grundschutz is the German Federal Office for Information Security's methodology for building an information security management system, structured through the BSI 200 standards and the IT-Grundschutz Compendium. It works in clear steps: define your information domain, analyse the structure, assess protection needs, model against the Compendium, run the IT-Grundschutz Check, add risk analysis where protection needs are high, and consolidate a security concept. It is methodical and thorough, which is exactly why organizations stall partway. An organization with a structure analysis but no protection needs, or requirements modeled but no Grundschutz Check, is exactly where organizations fall short.
This Kit removes the guesswork. It is the IT-Grundschutz methodology written as adopt-ready controls you personalize in a weekend, with the evidence an assessor examines.
What you get, the moment you buy
Grounded in the BSI IT-Grundschutz methodology and the BSI 200-1, 200-2 and 200-3 standards, with the ISMS, structure analysis, protection needs assessment, modeling against the Compendium, the IT-Grundschutz Check, risk analysis and the security concept called out. Editable Word and Excel files.
What one control looks like
This is establishing the ISMS and management commitment, where IT-Grundschutz begins. All 18 are built to this depth.
Why this is not another template pack
- The evidence is the point. A step you cannot evidence leaves a hole in the security concept. This tells you what an assessor examines and where organizations fall short, for every step.
- The full methodology built in. The ISMS, structure analysis, protection needs, modeling, the Grundschutz Check, risk analysis and the security concept are written into the controls, the substance the methodology requires.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. IT-Grundschutz maps to ISO 27001, so this work feeds your wider ISMS and certification readiness.
Who buys this
Organizations adopting BSI IT-Grundschutz, and the information security officers, ISMS and IT leads who own it, in Germany and beyond. Whether it is a first pass or a push to complete the security concept, you save weeks and walk in with the structure, protection needs, modeling and concept structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Is this legal or certification advice? No. It is an implementation toolkit grounded in the methodology. For a specific matter consult your assessor or counsel; this gets your controls and evidence in order fast.
Does it cover protection needs assessment? Yes. Assessing protection needs as normal, high or very high and applying inheritance are built as controls.
Does it cover the IT-Grundschutz Check? Yes. Modeling against the Compendium and performing the Grundschutz Check are built as controls.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com