A transparent quick check, not an audit
The check follows BSI IT-Grundschutz and BSI Standards 200-1, 200-2 and 200-3. Module questions refer to the IT-Grundschutz Compendium. Scoring is explicit: Yes = 3, Partly = 2, Unknown = 1, No = 0. The result provides orientation and is neither an audit, an ISO 27001 certificate on the basis of IT-Grundschutz, nor legal advice. English BSI publications are drafts; the German versions remain authoritative for certification. For orientation under NIS 2, see the NIS 2 Check.
Result
Prioritised action areas
From quick check to robust IT administration
cube one will review the ISMS, modelling and operations with you in the actual infrastructure context, from authorisations to emergency preparedness. A starting point is our IT Administration.
Discuss IT securityRegulatory context and target groups
Regulatory basis
The questions provide orientation. The binding publications are those of the BSI on IT-Grundschutz, including BSI Standards 200-1 to 200-3.
For IT operations
IT owners in pharma and life science gain an initial view of the ISMS, authorisations, logging and emergency preparedness: independently of GxP CSV.
For information security officers
The check helps prioritise gaps in modelling, risk analysis and the supply chain before a certification or audit calendar tightens.