Governance, Risk & Compliance
Evolution of Information Security: Will Grundschutz++ be the New Gold Standard?
For nearly three decades, the BSI IT-Grundschutz has been the bedrock of information security in Germany, providing a holistic and practical methodology for institutions of all sizes. Find out more about the new gold standard in this article.
For nearly three decades, the BSI IT-Grundschutz has been the bedrock of information security in Germany, providing a holistic and practical methodology for institutions of all sizes. However, as the digital landscape shifts toward higher complexity and faster innovation cycles, the traditional BSI Standards 200-1, 200-2, and 200-3 have reached a turning point. Enter Grundschutz++ (GS++), an evolutionary step designed to transition from static documentation to agile, machine-readable, and automated security management.
In this article, we will dive into the basics of the BSI's new guide, the full PDF version of which can be viewed or downloaded here. Below we provide an initial insight into the methodology that is outlined below.
The Context: Moving Beyond the 200-x Series
To understand GS++, we must look at the foundation it builds upon:
- BSI Standard 200-1 defined the general requirements for an Information Security Management System (ISMS), ensuring full compatibility with ISO/IEC 27001.
- BSI Standard 200-2 provided the classic methodology, offering three entry levels: Basic, Standard, and Core Protection.
- BSI Standard 200-3 simplified risk management by basing it on the "elementary threats" described in the Compendium.
- The IT-Grundschutz Compendium served as the modular library of building blocks (Bausteine) for modeling a security concept.
While effective, these standards often required significant manual effort in documentation and modeling. Grundschutz++ addresses these challenges by enabling a more flexible and scalable approach.
The 5-Step Process: A New Lifecycle
Unlike the traditional methodology that focused heavily on selecting building blocks, GS++ structures the ISMS into five clear process steps, mapped to the classic PDCA cycle (Plan-Do-Check-Act):
- Collection & Planning (Plan): Establishing the context, defining the scope, and anchoring the ISMS in the institution’s strategy.
- Requirement Analysis (Plan): Defining the "Information Verbund" and generating a tailored requirement package.
- Realization (Do): Systematic implementation and documentation of security requirements.
- Monitoring (Check): Evaluating implementation status and the effectiveness of measures through audits and monitoring tools.
- Continuous Improvement (Act): Using insights from monitoring to optimize the ISMS and address non-conformities.
The Core Innovation: Target Object Categories & Inheritance
One of the most significant shifts in GS++ is the move from manual "Modellierung" (modeling) to Asset Modeling via Target Object Categories (Zielobjektkategorien).
In the traditional 200-2 approach, CISOs manually assigned building blocks to groups of systems. In GS++, assets are mapped to standardized categories that follow a hierarchical inheritance structure. Requirements are defined once for a high-level category and automatically pass down to all subordinate categories and associated assets. This drastically reduces redundancy and ensures that cross-cutting requirements are consistently applied across complex IT landscapes.
Automation and Machine-Readability (OSCAL)
For modern security leaders, the highlight of GS++ is its focus on automation. By utilizing the OSCAL (Open Security Controls Assessment Language) standard, the requirement catalogs become machine-readable. This allows institutions — especially large ones with complex environments — to:
- Integrate the ISMS seamlessly with existing management and monitoring systems.
- Move away from "static text documents" toward a digital twin of their security posture.
- Utilize blueprints (via the "Technical Layer") to standardize and speed up the deployment of requirement packages.
Integrated Risk Management
In the traditional approach (200-3), a formal risk analysis was often a secondary step performed only for high-protection needs or assets not covered by building blocks. GS++ integrates risk assessment more deeply into the cycle. A risk analysis is now explicitly required whenever the security level is adjusted or when "requirement-less" assets are identified, ensuring that every implemented requirement is directly linked to a mitigated risk.
Conclusion: The BSI's new methodology enables increased efficiency for organizations
Grundschutz++ is not merely a new version of the compendium; it represents a shift in methodology. We are eager to see what specific guidelines and standards will be published in the coming months.
For you, this means: Increased efficiency through inheritance, better scalability for large organizations, and the ability to finally automate compliance audits. The methodology is also designed to allow existing IT security concepts to be migrated into this new, agile framework. We would be happy to assist you with this.