Skip to main content
Image coming soon

BSI IT-Grundschutz Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
BSI IT-Grundschutz · Information Security Methodology · Evidence & Implementation Kit
Work the BSI IT-Grundschutz methodology, without decoding the BSI standards yourself.
Every step handed to you as an adopt-ready control, from the ISMS and structure analysis through protection needs, modeling and the IT-Grundschutz Check to risk analysis, the security concept and continual improvement, with the evidence an assessor examines.
Grundschutz-ready in a weekend, not a quarter.

Here is the honest situation. BSI IT-Grundschutz is the German Federal Office for Information Security's methodology for building an information security management system, structured through the BSI 200 standards and the IT-Grundschutz Compendium. It works in clear steps: define your information domain, analyse the structure, assess protection needs, model against the Compendium, run the IT-Grundschutz Check, add risk analysis where protection needs are high, and consolidate a security concept. It is methodical and thorough, which is exactly why organizations stall partway. An organization with a structure analysis but no protection needs, or requirements modeled but no Grundschutz Check, is exactly where organizations fall short.

This Kit removes the guesswork. It is the IT-Grundschutz methodology written as adopt-ready controls you personalize in a weekend, with the evidence an assessor examines.

What you get, the moment you buy

18
Methodology steps as adopt-ready controls. Every step, from the ISMS and structure analysis through protection needs, modeling, the Grundschutz Check, risk analysis and the security concept, written so you personalize and apply it.
18
Evidence-they-examine checklists. For each control, exactly what an assessor examines, plus where organizations fall short, so you close the gap first.
1
IT-Grundschutz Control Matrix, pre-built. Every step in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each step and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the BSI IT-Grundschutz methodology and the BSI 200-1, 200-2 and 200-3 standards, with the ISMS, structure analysis, protection needs assessment, modeling against the Compendium, the IT-Grundschutz Check, risk analysis and the security concept called out. Editable Word and Excel files.

The methodology is thorough, which is why organizations stall partway
IT-Grundschutz works in disciplined steps, and each depends on the last. Organizations complete a structure analysis, then run out of momentum before protection needs, modeling or the Grundschutz Check, and end up with documentation but no security concept. This Kit builds every step as a control with the evidence an assessor asks for, so you get all the way through.

What one control looks like

This is establishing the ISMS and management commitment, where IT-Grundschutz begins. All 18 are built to this depth.

BSI-1 Establish the ISMS and management commitment ISMS
Put this control in place

Establish an information security management system at [your organization name] in line with the BSI 200-1 standard, with management commitment, a security policy, defined responsibilities and resources, so that information security is managed systematically, and document it, so that the ISMS exists and the organization can evidence its management commitment as IT-Grundschutz requires.

Methodology note.

BSI Standard 200-1 defines the information security management system underpinning IT-Grundschutz.

Evidence an assessor examines
  • The information security policy
  • Management commitment records
  • Defined security responsibilities and resources
Common finding they raise: Security is handled ad hoc with no ISMS or management mandate.

Why this is not another template pack

  • The evidence is the point. A step you cannot evidence leaves a hole in the security concept. This tells you what an assessor examines and where organizations fall short, for every step.
  • The full methodology built in. The ISMS, structure analysis, protection needs, modeling, the Grundschutz Check, risk analysis and the security concept are written into the controls, the substance the methodology requires.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. IT-Grundschutz maps to ISO 27001, so this work feeds your wider ISMS and certification readiness.

Who buys this

Organizations adopting BSI IT-Grundschutz, and the information security officers, ISMS and IT leads who own it, in Germany and beyond. Whether it is a first pass or a push to complete the security concept, you save weeks and walk in with the structure, protection needs, modeling and concept structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 18 methodology steps
✓  A completed IT-Grundschutz control matrix
✓  The evidence an assessor examines
✓  Your structure analysis and protection needs in place
✓  A readiness percentage and a fix list
✓  The modeling and security concept gaps closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is this legal or certification advice? No. It is an implementation toolkit grounded in the methodology. For a specific matter consult your assessor or counsel; this gets your controls and evidence in order fast.

Does it cover protection needs assessment? Yes. Assessing protection needs as normal, high or very high and applying inheritance are built as controls.

Does it cover the IT-Grundschutz Check? Yes. Modeling against the Compendium and performing the Grundschutz Check are built as controls.

What if it is not for me? A 30-day money-back guarantee.

Do not stall halfway through the methodology.
Every IT-Grundschutz step is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be Grundschutz-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com