Orientation in eight questions

BSI IT-Grundschutz Check for information security

In a few minutes, assess how robustly the ISMS, protection needs, modelling, risk analysis, emergency preparedness, authorisations, logging and the supply chain are organised. The evaluation identifies initial priorities without collecting personal data.

A transparent quick check, not an audit

The check follows BSI IT-Grundschutz and BSI Standards 200-1, 200-2 and 200-3. Module questions refer to the IT-Grundschutz Compendium. Scoring is explicit: Yes = 3, Partly = 2, Unknown = 1, No = 0. The result provides orientation and is neither an audit, an ISO 27001 certificate on the basis of IT-Grundschutz, nor legal advice. English BSI publications are drafts; the German versions remain authoritative for certification. For orientation under NIS 2, see the NIS 2 Check.

Evidence Review · 8 questions
Step 1 of 2
Step 1: ISMS and methodology
01 · ISMSIs an information security management system in place, with a security policy, defined roles (including an information security officer) and clear management responsibility?

Requirement from BSI Standard 200-1: Information Security Management Systems (ISMS).

02 · Protection needsHas a protection-needs assessment been performed for the business processes, information and IT systems of the information domain?

Requirement from BSI Standard 200-2: IT-Grundschutz Methodology (protection-needs assessment).

03 · Modules and modellingIs the information domain modelled with the applicable modules of the IT-Grundschutz Compendium, and has an approach (Basic, Standard or Core Protection) been selected?

Requirement from BSI Standard 200-2 and the IT-Grundschutz Compendium.

04 · Risk analysisIs a risk analysis according to BSI Standard 200-3 performed for high protection needs or for risks that remain after the relevant Grundschutz requirements have been implemented?

Requirement from BSI Standard 200-3: Risk management.

Step 2: Operations and supply chain
05 · Emergency managementIs emergency management with preparedness and recovery established for the information domain: corresponding to Compendium module DER.4?

Requirement from the IT-Grundschutz Compendium, module DER.4: Emergency Management; methodically supplemented by BSI Standard 200-4 (Business Continuity Management).

06 · AuthorisationsAre identities assigned uniquely, are access rights granted according to the need-to-know principle, and are they reviewed regularly?

Requirement from the IT-Grundschutz Compendium, module ORP.4: Identity and Rights Management.

07 · LoggingAre security-relevant events detected and logged, and are the logs protected against unauthorised modification?

Requirement from the IT-Grundschutz Compendium, module DER.1: Detection of Security-Relevant Events.

08 · Supply chainAre external service providers, outsourcing and cloud use included in the information domain, and are security requirements agreed and their implementation monitored?

Requirement from BSI Standard 200-2 (modelling) and Compendium modules OPS.2.1 Outsourcing for Customers and OPS.2.2 Cloud Usage.

Regulatory context and target groups

For IT operations

IT owners in pharma and life science gain an initial view of the ISMS, authorisations, logging and emergency preparedness: independently of GxP CSV.

For information security officers

The check helps prioritise gaps in modelling, risk analysis and the supply chain before a certification or audit calendar tightens.

Develop IT-Grundschutz with robust evidence

Discuss the ISMS, modelling or secure IT operations with our advisory team.

Contact us