Article

ISO 27001 and IT-Grundschutz: which approach fits your ISMS?

ISO/IEC 27001 defines requirements for an information security management system. IT-Grundschutz adds a concrete methodology and building blocks. Begin with scope and the evidence you need.

T-NEX GmbHFirst version: Updated: Editorial policy
In daily work

Establish the shared objective

Both approaches support systematic information security management. The organisation assigns responsibility, assesses risks, implements measures and checks their effectiveness. Define the information domain: business processes, information, applications, technology, people and providers. A certificate covering a narrow area says little about a service operated outside that scope.

Overview

Compare the standard with the methodology

ISO/IEC 27001:2022 is an ISMS requirements standard. Its publicly documented edition includes a 2024 amendment. IT-Grundschutz provides a structured implementation approach through BSI standards and the compendium. The approaches can be combined: BSI offers ISO 27001 certification on the basis of IT-Grundschutz.

AspectISO/IEC 27001BSI IT-Grundschutz
Starting pointManagement-system requirementsMethodology, modelling and building blocks
Choosing measuresOwn risk assessment and treatmentRelevant modules, protection needs and additional risk analysis
DocumentationScope, risks, reasons for measures and effectivenessInformation domain, module mapping, implementation and risks
EvidenceISMS conformity within the certified scopeImplementation evidence or certification, depending on approach
Selection questionHow will an appropriate risk process be run?How does the information domain fit the methodology?
Overview

Choose the appropriate Grundschutz approach

BSI Standard 200-2 distinguishes basic, core and standard protection. Basic protection provides an entry point. Core protection initially concentrates on particularly important assets and processes. Standard protection develops a comprehensive security process for the selected information domain. Starting with basic protection is not equivalent to full ISO 27001 certification based on IT-Grundschutz.

Overview

Compare using the same example

Working example: a bank evaluates a document-processing service. Under either approach, define the relevant data, people, applications, infrastructure and external dependencies. Then assess risks, protection needs and measures that operate effectively. A small exercise using this same information domain can reveal which approach fits the existing organisation and evidence practices.

Overview

Read a certificate precisely

Check the standard version, named legal entity, scope, issuer and validity. For a provider, establish whether the purchased service and relevant operational components are included. A certificate does not establish that every control works in every customer deployment. Request additional evidence in relation to the actual service.

Overview

Map DORA requirements separately

An ISMS can support the organisation of risks and controls. DORA adds specific obligations for entities in scope, including incident reporting, testing and ICT third parties. Map each DORA requirement to an existing process and evidence. A certificate does not establish that all DORA obligations are met. Revisit the mapping when standards or the Grundschutz methodology change.

FAQ

Frequently asked questions

Are ISO 27001 and IT-Grundschutz competing certificates?

That does not fully describe the relationship. ISO 27001 is an ISMS requirements standard. IT-Grundschutz is a methodology with implementation guidance and its own route to ISO 27001 certification.

Which approach is automatically cheaper?

It depends on the existing ISMS, scope, protection needs and required evidence. Use the same example to compare additional effort.

Does a certificate establish full DORA compliance?

No. Check the scope and map the relevant DORA obligations individually.

Related options

You may also be interested in these.

Which task would you like to solve next?

Bring a concrete task. Together, we will define what the application needs to do.

Discuss your project