BSI Standards 200-1 to 200-4
BSI Standards 200-1 to 200-4 are the methodological core documents of German IT-Grundschutz: they cover building an ISMS (200-1), the IT-Grundschutz methodology (200-2), risk analysis (200-3) and business continuity management (200-4).
IT-Grundschutz, issued by the German Federal Office for Information Security (BSI), rests on two pillars: the 200 series of BSI Standards, which provide the method, and the annually updated IT-Grundschutz Compendium, which contains the concrete requirements and implementation guidance for each module. BSI Standard 200-1 sets out the general requirements for an information security management system (ISMS) and is deliberately aligned with ISO/IEC 27001: management responsibility, a security policy, roles such as the information security officer, resources, documentation and continual improvement following the PDCA cycle. Working to 200-1 therefore does not create a German special case; it builds an ISMS structure that maps onto internationally recognised standards while being considerably more prescriptive.
BSI Standard 200-2 describes the IT-Grundschutz methodology itself and offers three routes: basic protection (Basis-Absicherung) as a fast, broad entry level, core protection (Kern-Absicherung) focused on the organisation's most critical assets, and standard protection (Standard-Absicherung) as the full, certifiable approach. The sequence is always the same: define the information domain, carry out a structure analysis, determine protection needs against the objectives of confidentiality, integrity and availability, model the domain using the compendium modules, run the IT-Grundschutz check as a target-actual comparison, and then plan and implement the missing measures. BSI Standard 200-3 takes over wherever the standard requirements are not sufficient: for target objects with high or very high protection needs, for cases with no suitable module and for atypical deployment scenarios, a risk analysis based on the elementary threats is performed, assessed and translated into risk treatment – avoid, reduce, transfer, or accept the residual risk by formal management decision.
BSI Standard 200-4 replaced the earlier Standard 100-4 and describes how to build a business continuity management system (BCMS). It is staged: a reactive BCMS creates a rapid incident-response capability, the build-up stage adds a business impact analysis and continuity plans, and the standard BCMS reaches a level comparable to ISO 22301. For companies the series matters for two reasons. First, an ISO 27001 certificate can be obtained on the basis of IT-Grundschutz. Second, customers and supervisory authorities accept IT-Grundschutz as a recognised state of the art. The 200 series also provides a defensible, auditable structure for the risk management and continuity duties arising from the German BSIG as shaped by the NIS2 implementation act; the precise national implementation and evidence deadlines remain in flux and should be verified for each specific case.
Legal Basis
BSI Standards 200-1, 200-2, 200-3 and 200-4 together with the BSI IT-Grundschutz Compendium; German Act on the Federal Office for Information Security (BSIG); ISO/IEC 27001 (certification on the basis of IT-Grundschutz); ISO 22301 (reference for BSI Standard 200-4)
Practical Example
A mid-sized automotive supplier with 400 employees is required by a major customer to demonstrate a working ISMS. The information security officer opts for IT-Grundschutz. Following BSI Standard 200-1, the policy, roles and reporting lines to the management board are established. With no time for full standard protection, the team starts with core protection under 200-2 and scopes the information domain to design data, the PLM system and production control; the structure analysis, protection needs assessment and IT-Grundschutz check reveal 62 open requirements. Production control has very high availability needs, so a risk analysis under 200-3 follows, leading to redundant lines and a hardened remote maintenance access; the remaining residual risk is accepted by management in documented form. In parallel the company builds a reactive BCMS under 200-4 with an alerting plan and a recovery sequence, extending it the following year with a business impact analysis – after 18 months the information domain is ready for ISO 27001 certification on the basis of IT-Grundschutz.