ISMS · IT-Grundschutz or ISO/IEC 27001
INFOSEC360
Two frameworks, one ISMS. You choose which.
Choose your framework when you set up, and INFOSEC360 takes you through it — step by step, down to the documents an auditor asks for. IT-Grundschutz works from the BSI's catalogue; ISO/IEC 27001 works from your risks. Different routes, same result.
Both frameworks are ready to use: eleven modules for IT-Grundschutz, ten steps for ISO/IEC 27001. New organisations get access with a seat.
Registration · step 3 of 4
Which framework do you work to?
Your choice determines everything that follows — the steps, the catalogues and the documents. It applies to this scope.
The flow you chose
These are the screens you work in day to day.
You are seeing the flow for IT-Grundschutz — switchable at the top of the page.
The catalogue route
Eleven modules, in the order the standard sets out. Three of them:
Structure analysis
The information domain, in the order the BSI prescribes
You record what you have in five steps: processes, applications, network plan, IT systems, rooms. Always from the business down to the technology — because protection needs are inherited along that same line later on.
Target objects
Step 1 of 5From the business purpose down to the technology — the direction is binding, because protection needs are later inherited downwards along it.
Protection needs assessment
Assessed once at the process, justified everywhere below it
Rate confidentiality, integrity and availability once, on the process. Everything beneath it inherits that rating automatically — and where a value differs, INFOSEC360 records why. That reason is what an auditor asks for.
Protection needs per target object
C · I · AIf the ERP fails, order handling, purchasing and accounting stop at the same time — the summed damage crosses the threshold to “very high”. The deviation is justified, and it triggers the risk analysis.
Modelling & IT-Grundschutz check
Every requirement with an answer, every answer with its evidence
INFOSEC360 assigns the right modules to each object and walks you through their requirements. Four answers: yes, partially, no, dispensable. Two of them need a reason — which is what turns a checklist into evidence.
Implementation per module
142 requirements“Partially” and “dispensable” demand a justification — that is the difference between a filled-in spreadsheet and a piece of evidence.
The risk route
Ten steps, from context to certificate. Three of them:
Context & scope
Who wants something from your security — and what follows from it
You note who has a stake in your security and what they expect. Where something is binding, INFOSEC360 asks where it lands — as a risk, a control or an objective. This is where auditors most often find that nothing followed.
Interested parties
Step 1 of 10A binding requirement that leads nowhere is an entry with no effect — and the commonest finding at this step.
Assets & risks
Not how much protection is needed, but what can go wrong
Rate each risk by impact and likelihood, against a threshold you set in advance. Anything above it needs a decision — and a name against it.
Risk register
Acceptance criterion 8Two risks above the threshold — both need a treatment option and an explicit sign-off of the residual risk.
Statement of Applicability
At the end there is one sentence per control — and it has to hold up
For each of the 93 Annex A controls: does it apply, and why? INFOSEC360 flags reasons that will not hold up — “best practice”, or simply repeating the control's own title. Those are exactly what an auditor picks up on.
Statement of Applicability
93 controlsJustifications that merely restate the control's title are flagged as boilerplate — they are the standard finding in a Statement of Applicability.
Two frameworks, the same destination — you work in one.
Both lead to the same place: an ISMS you can show is working — to an auditor, a regulator, or a customer who asks. IT-Grundschutz is the BSI's method, and the one German public bodies have to follow. ISO/IEC 27001 is the international standard, recognised abroad.
You choose per scope, not for the whole company, and the choice stays put once you have made it. Need both? Set up a second scope under the other framework — same organisation, same people, separate work.
From the catalogue to the requirement
BSI Standards 200-1/2/3, Compendium Edition 2023
From the risk to the control
ISO/IEC 27001:2022
Both hold you to the same standard: every answer needs a reason behind it. The only real risk is choosing by the more familiar name — so the difference is spelled out where you make the choice.
What is the same on both paths
Whichever framework you choose, these three come with it.
On both paths
Catalogues in OSCAL
The Compendium and Annex A sit in the same machine-readable format — importable, versionable and kept current without retyping.
On both paths
Documents at the press of a button
The BSI's reference documents on one side, the records the standard requires on the other — both generated from what is maintained anyway, rather than written out once a year.
On both paths
Maintenance
An ISMS goes stale between two audits, whichever standard it follows. INFOSEC360 records when each thing was last confirmed, and speaks up beforehand.
Who picks which
Usually the choice has already been made for you — by a regulator, a client, or a customer abroad. Here is how it tends to fall.
When the evidence is read in Germany
- Public authorities and their suppliers, for whom IT-Grundschutz is not a choice.
- Organisations working towards a BSI attestation or a certificate on the basis of IT-Grundschutz.
- Anyone already tracking protection needs per process who wants the modules as a ready-made backlog.
When the evidence is read internationally
- Companies whose customers or parent group require an ISO certificate.
- Anyone already working risk-based who needs the Statement of Applicability as the output.
- Organisations with sites outside Germany, for whom the BSI catalogue is no common denominator.
NIS-2 requires neither one by name — you need an ISMS, and you choose the standard. Not sure whether NIS-2 applies to you? NIS360 answers that in four questions.
See what your scope looks like in it.
We will walk you through INFOSEC360 with your own sites, your processes and your framework. Hosted in German data centres, with each organisation's data kept separate.