SiKoSH
A framework of standard, policies and templates maintained by the IT association of Schleswig-Holstein (ITV.SH) that municipal administrations use to build an ISMS on the basis of the BSI IT-Grundschutz profile "Basis-Absicherung Kommunalverwaltung".
SiKoSH stands for "Sicherheit für Kommunen in Schleswig-Holstein" (Security for Municipalities in Schleswig-Holstein) and denotes a framework that supports municipal administrations in building and operating an information security management system (ISMS). It has been run since 2019 as a project of the IT association of Schleswig-Holstein (ITV.SH AöR, formerly KomFIT) and is developed jointly with the State Chancellery of Schleswig-Holstein, the Independent State Centre for Data Protection (ULD), the State Audit Office of Schleswig-Holstein and practitioners from municipal administrations.
In substance, SiKoSH builds on the IT-Grundschutz profile "Basis-Absicherung Kommunalverwaltung", which the working group on municipal basic protection (AG koBA) of the German municipal umbrella associations produced on the basis of the IT-Grundschutz methodology set out in BSI Standard 200-2. Its centrepiece is the SiKoSH Standard as the guiding document, complemented by policies, toolkits of templates, and QuickChecks for assessing how far ISMS implementation has progressed. The roadmap is structured into seven phases and nine steps that an administration works through in sequence and then maintains over time.
SiKoSH is not a certification standard: the framework itself leads to neither a certificate nor an attestation. Its value lies in reaching an appropriate and demonstrable level of security without extensive preparatory work of its own or external consultants. The documentation produced can later feed into a more comprehensive IT-Grundschutz approach – for example an attestation under BSI IT-Grundschutz or certification under ISO 27001. It primarily addresses municipal administrations in Schleswig-Holstein; beyond that, the approach also suits smaller public institutions and small and mid-sized enterprises.
Legal Basis
BSI Standard 200-2 (IT-Grundschutz methodology), IT-Grundschutz profile "Basis-Absicherung Kommunalverwaltung" (AG koBA), NIS2 Directive – where extended to municipalities by state law
Practical Example
A municipal administration in Schleswig-Holstein with 120 employees is required to establish an ISMS, but has neither a dedicated information security role nor a budget for external consultants. It works through the SiKoSH Standard phase by phase: a QuickCheck first establishes the starting position, then the security policy, guidelines and role descriptions are adapted from the templates to the organization itself. The administration then records its processes – citizen registration, financial software, building authority – and assigns the profile's measures to named owners with deadlines. This allows the state of information security to be evidenced to the administration's management and to municipal supervision at any time.