ISMS · IT-Grundschutz or ISO/IEC 27001

INFOSEC360

Two frameworks, one ISMS. You choose which.

Choose your framework when you set up, and INFOSEC360 takes you through it — step by step, down to the documents an auditor asks for. IT-Grundschutz works from the BSI's catalogue; ISO/IEC 27001 works from your risks. Different routes, same result.

AvailableBoth frameworks are ready to use: eleven modules for IT-Grundschutz, ten steps for ISO/IEC 27001. New organisations get access with a seat.

Registration · step 3 of 4

Which framework do you work to?

Your choice determines everything that follows — the steps, the catalogues and the documents. It applies to this scope.

The flow you chose

These are the screens you work in day to day.

You are seeing the flow for IT-Grundschutz — switchable at the top of the page.

IT-Grundschutz

The catalogue route

Eleven modules, in the order the standard sets out. Three of them:

Structure analysis

The information domain, in the order the BSI prescribes

You record what you have in five steps: processes, applications, network plan, IT systems, rooms. Always from the business down to the technology — because protection needs are inherited along that same line later on.

app.nis360.de

Target objects

Step 1 of 5
GP-01Order handling & invoicingProcess
INF-DAT-01Customer master dataInformation
APP-01ERP system (SAP S/4HANA)Application
SYS-01VMware virtualisation clusterIT system
RAUM-01Server room, head officeRoom

From the business purpose down to the technology — the direction is binding, because protection needs are later inherited downwards along it.

Protection needs assessment

Assessed once at the process, justified everywhere below it

Rate confidentiality, integrity and availability once, on the process. Everything beneath it inherits that rating automatically — and where a value differs, INFOSEC360 records why. That reason is what an auditor asks for.

app.nis360.de

Protection needs per target object

C · I · A
Target objectCIASource
GP-01 Order handlinghighhighhighset
INF-DAT-01 Customer datahighhighnormalset
APP-01 ERP systemhighhighvery highcumulative
SYS-01 Virtualisation clusterhighhighvery highinherited
RAUM-01 Server roomnormalnormalhighdistribution

If the ERP fails, order handling, purchasing and accounting stop at the same time — the summed damage crosses the threshold to “very high”. The deviation is justified, and it triggers the risk analysis.

Modelling & IT-Grundschutz check

Every requirement with an answer, every answer with its evidence

INFOSEC360 assigns the right modules to each object and walks you through their requirements. Four answers: yes, partially, no, dispensable. Two of them need a reason — which is what turns a checklist into evidence.

app.nis360.de

Implementation per module

142 requirements
ISMS.1 Security management100 %
ORP.4 Access rights82 %
CON.3 Backup concept61 %
SYS.1.1 General server74 %
RequirementStateJustification
CON.3.A5 Regular backupspartiallyrestore never tested
CON.3.A12 Off-site copyyessecond site, Augsburg
CON.3.A14 Offline copynoIT operations, 30 Nov
ORP.4.A21 Multi-factor authenticationdispensableno elevated need

“Partially” and “dispensable” demand a justification — that is the difference between a filled-in spreadsheet and a piece of evidence.

Two frameworks, the same destination — you work in one.

Both lead to the same place: an ISMS you can show is working — to an auditor, a regulator, or a customer who asks. IT-Grundschutz is the BSI's method, and the one German public bodies have to follow. ISO/IEC 27001 is the international standard, recognised abroad.

You choose per scope, not for the whole company, and the choice stays put once you have made it. Need both? Set up a second scope under the other framework — same organisation, same people, separate work.

IT-Grundschutz

From the catalogue to the requirement

BSI Standards 200-1/2/3, Compendium Edition 2023

ISO/IEC 27001

From the risk to the control

ISO/IEC 27001:2022

Where it starts
IT-GrundschutzCut the scope and settle the method: basic, core or standard protection.
ISO/IEC 27001Write down what the organisation does, who has a stake in its security — customers, authorities, insurers — and which part of it the ISMS covers.
What is to be protected
IT-GrundschutzStructure analysis: processes, applications, network plan, IT systems, rooms — recorded in that direction.
ISO/IEC 27001An inventory of assets — information, systems, suppliers — each with a named owner and rules for how it may be used.
How much protection is needed
IT-GrundschutzProtection needs in confidentiality, integrity and availability, inherited downwards — maximum, cumulative and distribution effects.
ISO/IEC 27001A risk assessment per asset: impact times likelihood, measured against an acceptance criterion fixed in advance.
Where the controls come from
IT-GrundschutzModelling: the Compendium's modules laid onto the target objects.
ISO/IEC 27001Annex A: 93 controls in four themes, selected out of the risk treatment.
How the state is evidenced
IT-GrundschutzAn IT-Grundschutz check per requirement: yes, partially, no, dispensable — with a justification and an owner.
ISO/IEC 27001A Statement of Applicability per control: applicable or not — with a justification that points at your own scope.
What happens at high risk
IT-GrundschutzA risk analysis to BSI Standard 200-3, along the 47 elementary threats.
ISO/IEC 27001A risk treatment plan, and the explicit sign-off of the residual risk by management.
What you hold at the end
IT-GrundschutzThe reference documents the BSI asks for — an attestation for basic protection, a certificate for core or standard.
ISO/IEC 27001The documents the standard requires — policy, scope, risk method, results — and the Statement of Applicability. That is exactly what a certification auditor asks to see.

Both hold you to the same standard: every answer needs a reason behind it. The only real risk is choosing by the more familiar name — so the difference is spelled out where you make the choice.

What is the same on both paths

Whichever framework you choose, these three come with it.

  • On both paths

    Catalogues in OSCAL

    The Compendium and Annex A sit in the same machine-readable format — importable, versionable and kept current without retyping.

  • On both paths

    Documents at the press of a button

    The BSI's reference documents on one side, the records the standard requires on the other — both generated from what is maintained anyway, rather than written out once a year.

  • On both paths

    Maintenance

    An ISMS goes stale between two audits, whichever standard it follows. INFOSEC360 records when each thing was last confirmed, and speaks up beforehand.

Who picks which

Usually the choice has already been made for you — by a regulator, a client, or a customer abroad. Here is how it tends to fall.

IT-Grundschutz

When the evidence is read in Germany

  • Public authorities and their suppliers, for whom IT-Grundschutz is not a choice.
  • Organisations working towards a BSI attestation or a certificate on the basis of IT-Grundschutz.
  • Anyone already tracking protection needs per process who wants the modules as a ready-made backlog.
ISO/IEC 27001

When the evidence is read internationally

  • Companies whose customers or parent group require an ISO certificate.
  • Anyone already working risk-based who needs the Statement of Applicability as the output.
  • Organisations with sites outside Germany, for whom the BSI catalogue is no common denominator.

NIS-2 requires neither one by name — you need an ISMS, and you choose the standard. Not sure whether NIS-2 applies to you? NIS360 answers that in four questions.

See what your scope looks like in it.

We will walk you through INFOSEC360 with your own sites, your processes and your framework. Hosted in German data centres, with each organisation's data kept separate.