Germany (used across the German-speaking countries and by German public bodies under the UP Bund)

BSI IT-Grundschutz

180 controls. 293 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

180 controls 293 frameworks share controls with it Germany (used across the German-speaking countries and by German public bodies under the UP Bund) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

BSI IT-Grundschutz Evidence & Implementation Kit

180 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
APP.1.1Office Products0
APP.3.1Web Applications0
BSI-01Account management and provisioning39
BSI-02Access enforcement and least privilege77
BSI-03Multi-factor authentication requirements155
BSI-04Remote access controls121
BSI-05Wireless access restrictions121
BSI-06Identity proofing and verification0
BSI-07Boundary protection and segmentation0
BSI-08Cryptographic protection of data133
BSI-09Denial-of-service protection0
BSI-10Transmission confidentiality and integrity0
BSI-11Session management controls0
BSI-12Network monitoring and defense0
BSI-13Risk assessment procedures153
BSI-14Vulnerability scanning and management61
BSI-15Security categorization177
BSI-16Threat intelligence integration14
BSI-17Continuous monitoring strategy164
BSI-18Incident response planning and testing137
BSI-19Incident handling and containment0
BSI-20Incident reporting and notification137
BSI-21Forensic analysis capabilities137
BSI-22Lessons learned and improvement0
BSI-23Baseline configuration establishment54
BSI-24Configuration change control68
BSI-25Security impact analysis0
BSI-26System component inventory54
BSI-27Software usage restrictions0
BSI-28Audit event logging and storage61
BSI-29Audit record review and analysis61
BSI-30Time synchronization0
BSI-31Audit log protection and retention61
BSI-32Accountability and non-repudiation1
CON.1Crypto Concept0
CON.2Data Protection0
CON.3Data Backup Concept0
CON.8Software Development0
DER.1Detection of Security-Relevant Events0
DER.2.1Security Incident Handling0
DER.4Business Continuity Management0
INF.1General Building0
ISMS.1Security Management0
NET.1.1Network Architecture and Design0
OPS.1.1.2Proper IT Administration0
OPS.1.1.3Patch and Change Management0
OPS.1.1.5Logging3
OPS.1.2.4Teleworking0
OPS.2.2Cloud Usage0
ORP.1Organisation0
ORP.2Personnel1
ORP.3Awareness and Training1
ORP.4Identity and Access Management0
SYS.1.1General Server0
SYS.2.1General Client0
APPAPP Anwendungen (Applications)0
APP.1.1APP.1.1 Office-Produkte (Office Products)0
APP.1.2APP.1.2 Webbrowser (Web Browsers)0
APP.1.4APP.1.4 Mobile Anwendungen (Apps) (Mobile Applications (Apps))0
APP.2.1APP.2.1 Allgemeiner Verzeichnisdienst (General Directory Service)0
APP.2.2APP.2.2 Active Directory Domain Services (Active Directory Domain Services)0
APP.2.3APP.2.3 OpenLDAP (OpenLDAP)0
APP.3.1APP.3.1 Webanwendungen und Webservices (Web Applications and Web Services)0
APP.3.2APP.3.2 Webserver (Web Servers)0
APP.3.3APP.3.3 Fileserver (File Servers)0
APP.3.4APP.3.4 Samba (Samba)0
APP.3.6APP.3.6 DNS-Server (DNS Servers)0
APP.4.2APP.4.2 SAP-ERP-System (SAP ERP Systems)0
APP.4.3APP.4.3 Relationale Datenbanken (Relational Database Systems)0
APP.4.4APP.4.4 Kubernetes (Kubernetes)0
APP.4.6APP.4.6 SAP ABAP-Programmierung (SAP ABAP Programming)0
APP.5.2APP.5.2 Microsoft Exchange und Outlook (Microsoft Exchange and Outlook)0
APP.5.3APP.5.3 Allgemeiner E-Mail-Client und -Server (General Email Clients and Servers)0
APP.5.4APP.5.4 Unified Communications und Collaboration (UCC) (Unified Communications and Collaboration (UCC))0
APP.6APP.6 Allgemeine Software (General Software)0
APP.7APP.7 Entwicklung von Individualsoftware (Development of Individual Software)0
CHANGESEdition 2023 changes against Edition 2022, and the errata as at 26 March 20260
CONCON Konzepte und Vorgehensweisen (Concepts and Approaches)0
CON.1CON.1 Kryptokonzept (Crypto Concept)0
CON.10CON.10 Entwicklung von Webanwendungen (Development of Web Applications)0
CON.11.1CON.11.1 Geheimschutz VS-NUR FÜR DEN DIENSTGEBRAUCH (Protection of Classified Information VS-NUR FÜR DEN DIENSTGEBRAUCH)0
CON.2CON.2 Datenschutz (Data Protection)0
CON.3CON.3 Datensicherungskonzept (Backup Concept)0
CON.6CON.6 Löschen und Vernichten (Deletion and Destruction)0
CON.7CON.7 Informationssicherheit auf Auslandsreisen (Information Security on Trips Abroad)0
CON.8CON.8 Software-Entwicklung (Software Development)0
CON.9CON.9 Informationsaustausch (Information Exchange)0
DERDER Detektion und Reaktion (Detection and Reaction)0
DER.1DER.1 Detektion von sicherheitsrelevanten Ereignissen (Detection of Security-Relevant Events)0
DER.2.1DER.2.1 Behandlung von Sicherheitsvorfällen (Security Incident Handling)0
DER.2.2DER.2.2 Vorsorge für die IT-Forensik (Provisions for IT Forensics)0
DER.2.3DER.2.3 Bereinigung weitreichender Sicherheitsvorfälle (Clean-up of Extensive Security Incidents)0
DER.3.1DER.3.1 Audits und Revisionen (Audits and Reviews)0
DER.3.2DER.3.2 Revisionen auf Basis des Leitfadens IS-Revision (Reviews Based on the IS Audit Guideline)0
DER.4DER.4 Notfallmanagement (Business Continuity Management)0
INDIND Industrielle IT (Industrial IT)0
IND.1IND.1 Prozessleit- und Automatisierungstechnik (Process Control and Automation Technology)0
IND.2.1IND.2.1 Allgemeine ICS-Komponente (General ICS Components)0
IND.2.2IND.2.2 Speicherprogrammierbare Steuerung (SPS) (Programmable Logic Controllers (PLC))0
IND.2.3IND.2.3 Sensoren und Aktoren (Sensors and Actuators)0
IND.2.4IND.2.4 Maschine (Machines)0
IND.2.7IND.2.7 Safety Instrumented Systems (Safety Instrumented Systems)0
IND.3.2IND.3.2 Fernwartung im industriellen Umfeld (Remote Maintenance in the Industrial Environment)0
INFINF Infrastruktur (Infrastructure)0
INF.1INF.1 Allgemeines Gebäude (General Buildings)0
INF.10INF.10 Besprechungs-, Veranstaltungs- und Schulungsräume (Meeting, Event and Training Rooms)0
INF.11INF.11 Allgemeines Fahrzeug (General Vehicles)0
INF.12INF.12 Verkabelung (Cabling)0
INF.13INF.13 Technisches Gebäudemanagement (Technical Building Management)0
INF.14INF.14 Gebäudeautomation (Building Automation)0
INF.2INF.2 Rechenzentrum sowie Serverraum (Data Centres and Server Rooms)0
INF.5INF.5 Raum sowie Schrank für technische Infrastruktur (Rooms and Cabinets for Technical Infrastructure)0
INF.6INF.6 Datenträgerarchiv (Storage Media Archives)0
INF.7INF.7 Büroarbeitsplatz (Office Workplaces)0
INF.8INF.8 Häuslicher Arbeitsplatz (Home Workplaces)0
INF.9INF.9 Mobiler Arbeitsplatz (Mobile Workplaces)0
ISMSISMS Sicherheitsmanagement (Security Management)0
ISMS.1ISMS.1 Sicherheitsmanagement (Security Management)0
ISOMAPMapping table: ISO/IEC 27001:2022 to IT-Grundschutz (Zuordnungstabelle, Edition 2023)0
KOMPThe IT-Grundschutz-Kompendium, its editions, its status and what is held0
METHODThe IT-Grundschutz method: BSI Standards 200-1 to 200-4, requirement levels B, S and H, and the modelling order R1 to R30
NETNET Netze und Kommunikation (Networks and Communication)0
NET.1.1NET.1.1 Netzarchitektur und -design (Network Architecture and Design)0
NET.1.2NET.1.2 Netzmanagement (Network Management)0
NET.2.1NET.2.1 WLAN-Betrieb (WLAN Operation)0
NET.2.2NET.2.2 WLAN-Nutzung (WLAN Usage)0
NET.3.1NET.3.1 Router und Switches (Routers and Switches)0
NET.3.2NET.3.2 Firewall (Firewalls)0
NET.3.3NET.3.3 VPN (VPN)0
NET.3.4NET.3.4 Network Access Control (Network Access Control)0
NET.4.1NET.4.1 TK-Anlagen (PBX Systems)0
NET.4.2NET.4.2 VoIP (VoIP)0
NET.4.3NET.4.3 Faxgeräte und Faxserver (Fax Machines and Fax Servers)0
OPSOPS Betrieb (Operations)0
OPS.1.1.1OPS.1.1.1 Allgemeiner IT-Betrieb (General IT Operation)0
OPS.1.1.2OPS.1.1.2 Ordnungsgemäße IT-Administration (Proper IT Administration)0
OPS.1.1.3OPS.1.1.3 Patch- und Änderungsmanagement (Patch and Change Management)0
OPS.1.1.4OPS.1.1.4 Schutz vor Schadprogrammen (Protection Against Malware)0
OPS.1.1.5OPS.1.1.5 Protokollierung (Logging)0
OPS.1.1.6OPS.1.1.6 Software-Tests und -Freigaben (Software Tests and Approvals)0
OPS.1.1.7OPS.1.1.7 Systemmanagement (System Management)0
OPS.1.2.2OPS.1.2.2 Archivierung (Archiving)0
OPS.1.2.4OPS.1.2.4 Telearbeit (Teleworking)0
OPS.1.2.5OPS.1.2.5 Fernwartung (Remote Maintenance)0
OPS.1.2.6OPS.1.2.6 NTP-Zeitsynchronisation (NTP Time Synchronisation)0
OPS.2.2OPS.2.2 Cloud-Nutzung (Cloud Usage)0
OPS.2.3OPS.2.3 Nutzung von Outsourcing (Use of Outsourcing)0
OPS.3.2OPS.3.2 Anbieten von Outsourcing (Provision of Outsourcing)0
ORPORP Organisation und Personal (Organisation and Personnel)0
ORP.1ORP.1 Organisation (Organisation)0
ORP.2ORP.2 Personal (Personnel)0
ORP.3ORP.3 Sensibilisierung und Schulung zur Informationssicherheit (Awareness and Training in Information Security)0
ORP.4ORP.4 Identitäts- und Berechtigungsmanagement (Identity and Access Management)0
ORP.5ORP.5 Compliance Management (Anforderungsmanagement) (Compliance Management (Requirements Management))0
SYSSYS IT-Systeme (IT Systems)0
SYS.1.1SYS.1.1 Allgemeiner Server (General Server)0
SYS.1.2.2SYS.1.2.2 Windows Server 2012 (Windows Server 2012)0
SYS.1.2.3SYS.1.2.3 Windows Server (Windows Server)0
SYS.1.3SYS.1.3 Server unter Linux und Unix (Servers under Linux and Unix)0
SYS.1.5SYS.1.5 Virtualisierung (Virtualisation)0
SYS.1.6SYS.1.6 Containerisierung (Containerisation)0
SYS.1.7SYS.1.7 IBM Z (IBM Z)0
SYS.1.8SYS.1.8 Speicherlösungen (Storage Solutions)0
SYS.1.9SYS.1.9 Terminalserver (Terminal Servers)0
SYS.2.1SYS.2.1 Allgemeiner Client (General Client)0
SYS.2.2.3SYS.2.2.3 Clients unter Windows (Clients under Windows)0
SYS.2.3SYS.2.3 Clients unter Linux und Unix (Clients under Linux and Unix)0
SYS.2.4SYS.2.4 Clients unter macOS (Clients under macOS)0
SYS.2.5SYS.2.5 Client-Virtualisierung (Client Virtualisation)0
SYS.2.6SYS.2.6 Virtual Desktop Infrastructure (Virtual Desktop Infrastructure)0
SYS.3.1SYS.3.1 Laptops (Laptops)0
SYS.3.2.1SYS.3.2.1 Allgemeine Smartphones und Tablets (General Smartphones and Tablets)0
SYS.3.2.2SYS.3.2.2 Mobile Device Management (MDM) (Mobile Device Management (MDM))0
SYS.3.2.3SYS.3.2.3 iOS (for Enterprise) (iOS (for Enterprise))0
SYS.3.2.4SYS.3.2.4 Android (Android)0
SYS.3.3SYS.3.3 Mobiltelefon (Mobile Phones)0
SYS.4.1SYS.4.1 Drucker, Kopierer und Multifunktionsgeräte (Printers, Copiers and Multifunction Devices)0
SYS.4.3SYS.4.3 Eingebettete Systeme (Embedded Systems)0
SYS.4.4SYS.4.4 Allgemeines IoT-Gerät (General IoT Devices)0
SYS.4.5SYS.4.5 Wechseldatenträger (Removable Media)0

Tell me when BSI IT-Grundschutz files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • ROPA per processing operation
  • DPIA reports for high-risk
  • Privacy by Design embedded in SDLC
  • Annual training records + role-based
  • Encarregado designation records + ANPD Resolution CD/ANPD 2/2022 compliance
  • RIPD (Brazilian DPIA) reports
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for BSI IT-Grundschutz, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition