APP.1.1 | Office Products | 0 |
APP.3.1 | Web Applications | 0 |
BSI-01 | Account management and provisioning | 39 |
BSI-02 | Access enforcement and least privilege | 77 |
BSI-03 | Multi-factor authentication requirements | 155 |
BSI-04 | Remote access controls | 121 |
BSI-05 | Wireless access restrictions | 121 |
BSI-06 | Identity proofing and verification | 0 |
BSI-07 | Boundary protection and segmentation | 0 |
BSI-08 | Cryptographic protection of data | 133 |
BSI-09 | Denial-of-service protection | 0 |
BSI-10 | Transmission confidentiality and integrity | 0 |
BSI-11 | Session management controls | 0 |
BSI-12 | Network monitoring and defense | 0 |
BSI-13 | Risk assessment procedures | 153 |
BSI-14 | Vulnerability scanning and management | 61 |
BSI-15 | Security categorization | 177 |
BSI-16 | Threat intelligence integration | 14 |
BSI-17 | Continuous monitoring strategy | 164 |
BSI-18 | Incident response planning and testing | 137 |
BSI-19 | Incident handling and containment | 0 |
BSI-20 | Incident reporting and notification | 137 |
BSI-21 | Forensic analysis capabilities | 137 |
BSI-22 | Lessons learned and improvement | 0 |
BSI-23 | Baseline configuration establishment | 54 |
BSI-24 | Configuration change control | 68 |
BSI-25 | Security impact analysis | 0 |
BSI-26 | System component inventory | 54 |
BSI-27 | Software usage restrictions | 0 |
BSI-28 | Audit event logging and storage | 61 |
BSI-29 | Audit record review and analysis | 61 |
BSI-30 | Time synchronization | 0 |
BSI-31 | Audit log protection and retention | 61 |
BSI-32 | Accountability and non-repudiation | 1 |
CON.1 | Crypto Concept | 0 |
CON.2 | Data Protection | 0 |
CON.3 | Data Backup Concept | 0 |
CON.8 | Software Development | 0 |
DER.1 | Detection of Security-Relevant Events | 0 |
DER.2.1 | Security Incident Handling | 0 |
DER.4 | Business Continuity Management | 0 |
INF.1 | General Building | 0 |
ISMS.1 | Security Management | 0 |
NET.1.1 | Network Architecture and Design | 0 |
OPS.1.1.2 | Proper IT Administration | 0 |
OPS.1.1.3 | Patch and Change Management | 0 |
OPS.1.1.5 | Logging | 3 |
OPS.1.2.4 | Teleworking | 0 |
OPS.2.2 | Cloud Usage | 0 |
ORP.1 | Organisation | 0 |
ORP.2 | Personnel | 1 |
ORP.3 | Awareness and Training | 1 |
ORP.4 | Identity and Access Management | 0 |
SYS.1.1 | General Server | 0 |
SYS.2.1 | General Client | 0 |
APP | APP Anwendungen (Applications) | 0 |
APP.1.1 | APP.1.1 Office-Produkte (Office Products) | 0 |
APP.1.2 | APP.1.2 Webbrowser (Web Browsers) | 0 |
APP.1.4 | APP.1.4 Mobile Anwendungen (Apps) (Mobile Applications (Apps)) | 0 |
APP.2.1 | APP.2.1 Allgemeiner Verzeichnisdienst (General Directory Service) | 0 |
APP.2.2 | APP.2.2 Active Directory Domain Services (Active Directory Domain Services) | 0 |
APP.2.3 | APP.2.3 OpenLDAP (OpenLDAP) | 0 |
APP.3.1 | APP.3.1 Webanwendungen und Webservices (Web Applications and Web Services) | 0 |
APP.3.2 | APP.3.2 Webserver (Web Servers) | 0 |
APP.3.3 | APP.3.3 Fileserver (File Servers) | 0 |
APP.3.4 | APP.3.4 Samba (Samba) | 0 |
APP.3.6 | APP.3.6 DNS-Server (DNS Servers) | 0 |
APP.4.2 | APP.4.2 SAP-ERP-System (SAP ERP Systems) | 0 |
APP.4.3 | APP.4.3 Relationale Datenbanken (Relational Database Systems) | 0 |
APP.4.4 | APP.4.4 Kubernetes (Kubernetes) | 0 |
APP.4.6 | APP.4.6 SAP ABAP-Programmierung (SAP ABAP Programming) | 0 |
APP.5.2 | APP.5.2 Microsoft Exchange und Outlook (Microsoft Exchange and Outlook) | 0 |
APP.5.3 | APP.5.3 Allgemeiner E-Mail-Client und -Server (General Email Clients and Servers) | 0 |
APP.5.4 | APP.5.4 Unified Communications und Collaboration (UCC) (Unified Communications and Collaboration (UCC)) | 0 |
APP.6 | APP.6 Allgemeine Software (General Software) | 0 |
APP.7 | APP.7 Entwicklung von Individualsoftware (Development of Individual Software) | 0 |
CHANGES | Edition 2023 changes against Edition 2022, and the errata as at 26 March 2026 | 0 |
CON | CON Konzepte und Vorgehensweisen (Concepts and Approaches) | 0 |
CON.1 | CON.1 Kryptokonzept (Crypto Concept) | 0 |
CON.10 | CON.10 Entwicklung von Webanwendungen (Development of Web Applications) | 0 |
CON.11.1 | CON.11.1 Geheimschutz VS-NUR FÜR DEN DIENSTGEBRAUCH (Protection of Classified Information VS-NUR FÜR DEN DIENSTGEBRAUCH) | 0 |
CON.2 | CON.2 Datenschutz (Data Protection) | 0 |
CON.3 | CON.3 Datensicherungskonzept (Backup Concept) | 0 |
CON.6 | CON.6 Löschen und Vernichten (Deletion and Destruction) | 0 |
CON.7 | CON.7 Informationssicherheit auf Auslandsreisen (Information Security on Trips Abroad) | 0 |
CON.8 | CON.8 Software-Entwicklung (Software Development) | 0 |
CON.9 | CON.9 Informationsaustausch (Information Exchange) | 0 |
DER | DER Detektion und Reaktion (Detection and Reaction) | 0 |
DER.1 | DER.1 Detektion von sicherheitsrelevanten Ereignissen (Detection of Security-Relevant Events) | 0 |
DER.2.1 | DER.2.1 Behandlung von Sicherheitsvorfällen (Security Incident Handling) | 0 |
DER.2.2 | DER.2.2 Vorsorge für die IT-Forensik (Provisions for IT Forensics) | 0 |
DER.2.3 | DER.2.3 Bereinigung weitreichender Sicherheitsvorfälle (Clean-up of Extensive Security Incidents) | 0 |
DER.3.1 | DER.3.1 Audits und Revisionen (Audits and Reviews) | 0 |
DER.3.2 | DER.3.2 Revisionen auf Basis des Leitfadens IS-Revision (Reviews Based on the IS Audit Guideline) | 0 |
DER.4 | DER.4 Notfallmanagement (Business Continuity Management) | 0 |
IND | IND Industrielle IT (Industrial IT) | 0 |
IND.1 | IND.1 Prozessleit- und Automatisierungstechnik (Process Control and Automation Technology) | 0 |
IND.2.1 | IND.2.1 Allgemeine ICS-Komponente (General ICS Components) | 0 |
IND.2.2 | IND.2.2 Speicherprogrammierbare Steuerung (SPS) (Programmable Logic Controllers (PLC)) | 0 |
IND.2.3 | IND.2.3 Sensoren und Aktoren (Sensors and Actuators) | 0 |
IND.2.4 | IND.2.4 Maschine (Machines) | 0 |
IND.2.7 | IND.2.7 Safety Instrumented Systems (Safety Instrumented Systems) | 0 |
IND.3.2 | IND.3.2 Fernwartung im industriellen Umfeld (Remote Maintenance in the Industrial Environment) | 0 |
INF | INF Infrastruktur (Infrastructure) | 0 |
INF.1 | INF.1 Allgemeines Gebäude (General Buildings) | 0 |
INF.10 | INF.10 Besprechungs-, Veranstaltungs- und Schulungsräume (Meeting, Event and Training Rooms) | 0 |
INF.11 | INF.11 Allgemeines Fahrzeug (General Vehicles) | 0 |
INF.12 | INF.12 Verkabelung (Cabling) | 0 |
INF.13 | INF.13 Technisches Gebäudemanagement (Technical Building Management) | 0 |
INF.14 | INF.14 Gebäudeautomation (Building Automation) | 0 |
INF.2 | INF.2 Rechenzentrum sowie Serverraum (Data Centres and Server Rooms) | 0 |
INF.5 | INF.5 Raum sowie Schrank für technische Infrastruktur (Rooms and Cabinets for Technical Infrastructure) | 0 |
INF.6 | INF.6 Datenträgerarchiv (Storage Media Archives) | 0 |
INF.7 | INF.7 Büroarbeitsplatz (Office Workplaces) | 0 |
INF.8 | INF.8 Häuslicher Arbeitsplatz (Home Workplaces) | 0 |
INF.9 | INF.9 Mobiler Arbeitsplatz (Mobile Workplaces) | 0 |
ISMS | ISMS Sicherheitsmanagement (Security Management) | 0 |
ISMS.1 | ISMS.1 Sicherheitsmanagement (Security Management) | 0 |
ISOMAP | Mapping table: ISO/IEC 27001:2022 to IT-Grundschutz (Zuordnungstabelle, Edition 2023) | 0 |
KOMP | The IT-Grundschutz-Kompendium, its editions, its status and what is held | 0 |
METHOD | The IT-Grundschutz method: BSI Standards 200-1 to 200-4, requirement levels B, S and H, and the modelling order R1 to R3 | 0 |
NET | NET Netze und Kommunikation (Networks and Communication) | 0 |
NET.1.1 | NET.1.1 Netzarchitektur und -design (Network Architecture and Design) | 0 |
NET.1.2 | NET.1.2 Netzmanagement (Network Management) | 0 |
NET.2.1 | NET.2.1 WLAN-Betrieb (WLAN Operation) | 0 |
NET.2.2 | NET.2.2 WLAN-Nutzung (WLAN Usage) | 0 |
NET.3.1 | NET.3.1 Router und Switches (Routers and Switches) | 0 |
NET.3.2 | NET.3.2 Firewall (Firewalls) | 0 |
NET.3.3 | NET.3.3 VPN (VPN) | 0 |
NET.3.4 | NET.3.4 Network Access Control (Network Access Control) | 0 |
NET.4.1 | NET.4.1 TK-Anlagen (PBX Systems) | 0 |
NET.4.2 | NET.4.2 VoIP (VoIP) | 0 |
NET.4.3 | NET.4.3 Faxgeräte und Faxserver (Fax Machines and Fax Servers) | 0 |
OPS | OPS Betrieb (Operations) | 0 |
OPS.1.1.1 | OPS.1.1.1 Allgemeiner IT-Betrieb (General IT Operation) | 0 |
OPS.1.1.2 | OPS.1.1.2 Ordnungsgemäße IT-Administration (Proper IT Administration) | 0 |
OPS.1.1.3 | OPS.1.1.3 Patch- und Änderungsmanagement (Patch and Change Management) | 0 |
OPS.1.1.4 | OPS.1.1.4 Schutz vor Schadprogrammen (Protection Against Malware) | 0 |
OPS.1.1.5 | OPS.1.1.5 Protokollierung (Logging) | 0 |
OPS.1.1.6 | OPS.1.1.6 Software-Tests und -Freigaben (Software Tests and Approvals) | 0 |
OPS.1.1.7 | OPS.1.1.7 Systemmanagement (System Management) | 0 |
OPS.1.2.2 | OPS.1.2.2 Archivierung (Archiving) | 0 |
OPS.1.2.4 | OPS.1.2.4 Telearbeit (Teleworking) | 0 |
OPS.1.2.5 | OPS.1.2.5 Fernwartung (Remote Maintenance) | 0 |
OPS.1.2.6 | OPS.1.2.6 NTP-Zeitsynchronisation (NTP Time Synchronisation) | 0 |
OPS.2.2 | OPS.2.2 Cloud-Nutzung (Cloud Usage) | 0 |
OPS.2.3 | OPS.2.3 Nutzung von Outsourcing (Use of Outsourcing) | 0 |
OPS.3.2 | OPS.3.2 Anbieten von Outsourcing (Provision of Outsourcing) | 0 |
ORP | ORP Organisation und Personal (Organisation and Personnel) | 0 |
ORP.1 | ORP.1 Organisation (Organisation) | 0 |
ORP.2 | ORP.2 Personal (Personnel) | 0 |
ORP.3 | ORP.3 Sensibilisierung und Schulung zur Informationssicherheit (Awareness and Training in Information Security) | 0 |
ORP.4 | ORP.4 Identitäts- und Berechtigungsmanagement (Identity and Access Management) | 0 |
ORP.5 | ORP.5 Compliance Management (Anforderungsmanagement) (Compliance Management (Requirements Management)) | 0 |
SYS | SYS IT-Systeme (IT Systems) | 0 |
SYS.1.1 | SYS.1.1 Allgemeiner Server (General Server) | 0 |
SYS.1.2.2 | SYS.1.2.2 Windows Server 2012 (Windows Server 2012) | 0 |
SYS.1.2.3 | SYS.1.2.3 Windows Server (Windows Server) | 0 |
SYS.1.3 | SYS.1.3 Server unter Linux und Unix (Servers under Linux and Unix) | 0 |
SYS.1.5 | SYS.1.5 Virtualisierung (Virtualisation) | 0 |
SYS.1.6 | SYS.1.6 Containerisierung (Containerisation) | 0 |
SYS.1.7 | SYS.1.7 IBM Z (IBM Z) | 0 |
SYS.1.8 | SYS.1.8 Speicherlösungen (Storage Solutions) | 0 |
SYS.1.9 | SYS.1.9 Terminalserver (Terminal Servers) | 0 |
SYS.2.1 | SYS.2.1 Allgemeiner Client (General Client) | 0 |
SYS.2.2.3 | SYS.2.2.3 Clients unter Windows (Clients under Windows) | 0 |
SYS.2.3 | SYS.2.3 Clients unter Linux und Unix (Clients under Linux and Unix) | 0 |
SYS.2.4 | SYS.2.4 Clients unter macOS (Clients under macOS) | 0 |
SYS.2.5 | SYS.2.5 Client-Virtualisierung (Client Virtualisation) | 0 |
SYS.2.6 | SYS.2.6 Virtual Desktop Infrastructure (Virtual Desktop Infrastructure) | 0 |
SYS.3.1 | SYS.3.1 Laptops (Laptops) | 0 |
SYS.3.2.1 | SYS.3.2.1 Allgemeine Smartphones und Tablets (General Smartphones and Tablets) | 0 |
SYS.3.2.2 | SYS.3.2.2 Mobile Device Management (MDM) (Mobile Device Management (MDM)) | 0 |
SYS.3.2.3 | SYS.3.2.3 iOS (for Enterprise) (iOS (for Enterprise)) | 0 |
SYS.3.2.4 | SYS.3.2.4 Android (Android) | 0 |
SYS.3.3 | SYS.3.3 Mobiltelefon (Mobile Phones) | 0 |
SYS.4.1 | SYS.4.1 Drucker, Kopierer und Multifunktionsgeräte (Printers, Copiers and Multifunction Devices) | 0 |
SYS.4.3 | SYS.4.3 Eingebettete Systeme (Embedded Systems) | 0 |
SYS.4.4 | SYS.4.4 Allgemeines IoT-Gerät (General IoT Devices) | 0 |
SYS.4.5 | SYS.4.5 Wechseldatenträger (Removable Media) | 0 |