Skip to main content
Informationssicherheit / NIS2

BSI Standards 200-1 to 200-4

BSI Standards 200-1 to 200-4 are the methodological core documents of German IT-Grundschutz: they cover building an ISMS (200-1), the IT-Grundschutz methodology (200-2), risk analysis (200-3) and business continuity management (200-4).

IT-Grundschutz, issued by the German Federal Office for Information Security (BSI), rests on two pillars: the 200 series of BSI Standards, which provide the method, and the annually updated IT-Grundschutz Compendium, which contains the concrete requirements and implementation guidance for each module. BSI Standard 200-1 sets out the general requirements for an information security management system (ISMS) and is deliberately aligned with ISO/IEC 27001: management responsibility, a security policy, roles such as the information security officer, resources, documentation and continual improvement following the PDCA cycle. Working to 200-1 therefore does not create a German special case; it builds an ISMS structure that maps onto internationally recognised standards while being considerably more prescriptive.

BSI Standard 200-2 describes the IT-Grundschutz methodology itself and offers three routes: basic protection (Basis-Absicherung) as a fast, broad entry level, core protection (Kern-Absicherung) focused on the organisation's most critical assets, and standard protection (Standard-Absicherung) as the full, certifiable approach. The sequence is always the same: define the information domain, carry out a structure analysis, determine protection needs against the objectives of confidentiality, integrity and availability, model the domain using the compendium modules, run the IT-Grundschutz check as a target-actual comparison, and then plan and implement the missing measures. BSI Standard 200-3 takes over wherever the standard requirements are not sufficient: for target objects with high or very high protection needs, for cases with no suitable module and for atypical deployment scenarios, a risk analysis based on the elementary threats is performed, assessed and translated into risk treatment – avoid, reduce, transfer, or accept the residual risk by formal management decision.

BSI Standard 200-4 replaced the earlier Standard 100-4 and describes how to build a business continuity management system (BCMS). It is staged: a reactive BCMS creates a rapid incident-response capability, the build-up stage adds a business impact analysis and continuity plans, and the standard BCMS reaches a level comparable to ISO 22301. For companies the series matters for two reasons. First, an ISO 27001 certificate can be obtained on the basis of IT-Grundschutz. Second, customers and supervisory authorities accept IT-Grundschutz as a recognised state of the art. The 200 series also provides a defensible, auditable structure for the risk management and continuity duties arising from the German BSIG as shaped by the NIS2 implementation act; the precise national implementation and evidence deadlines remain in flux and should be verified for each specific case.

Legal Basis

BSI Standards 200-1, 200-2, 200-3 and 200-4 together with the BSI IT-Grundschutz Compendium; German Act on the Federal Office for Information Security (BSIG); ISO/IEC 27001 (certification on the basis of IT-Grundschutz); ISO 22301 (reference for BSI Standard 200-4)

Practical Example

A mid-sized automotive supplier with 400 employees is required by a major customer to demonstrate a working ISMS. The information security officer opts for IT-Grundschutz. Following BSI Standard 200-1, the policy, roles and reporting lines to the management board are established. With no time for full standard protection, the team starts with core protection under 200-2 and scopes the information domain to design data, the PLM system and production control; the structure analysis, protection needs assessment and IT-Grundschutz check reveal 62 open requirements. Production control has very high availability needs, so a risk analysis under 200-3 follows, leading to redundant lines and a hardened remote maintenance access; the remaining residual risk is accepted by management in documented form. In parallel the company builds a reactive BCMS under 200-4 with an alerting plan and a recovery sequence, extending it the following year with a business impact analysis – after 18 months the information domain is ready for ISO 27001 certification on the basis of IT-Grundschutz.

FAQ

200-1 sets out the general requirements for an ISMS and closely follows ISO/IEC 27001. 200-2 provides the operational IT-Grundschutz methodology with basic, core and standard protection. 200-3 governs the supplementary risk analysis for target objects with high protection needs or without a suitable module. 200-4 describes the staged build-up of a business continuity management system.
No – it is a route towards it. An ISO 27001 certificate can be issued on the basis of IT-Grundschutz, confirming that the modules of the compendium have been implemented, as verified by an auditor certified by the BSI. The difference lies in depth: IT-Grundschutz prescribes concrete requirements, whereas ISO/IEC 27001 largely leaves the selection of controls to the organisation's risk-based judgement.
Those without an established ISMS that need a broad baseline quickly. Basic protection implements only the basic requirements of the modules and skips a full protection needs assessment. It cannot be certified, but it is a solid first step that can later be upgraded to core or standard protection.

How preeco supports you

Learn how our software supports you with this topic.

Learn more