BSI IT-Consultation
Your contacts for BSI basic protection advice
Your contacts for BSI basic protection advice
YOUR CONTACT FOR BSI BASIC PROTECTION ADVICE
You can rely on established standards developed by the German Federal Office for Information Security (BSI) to secure your company’s IT. This BSI IT baseline protection analyzes the potential for hazards and damage and defines appropriate protection levels and security measures. You can prove your basic IT protection with a certification.
BSI STANDARDS REQUIRED FOR THE SECURITY CONCEPT
In order to guarantee the prescribed IT baseline protection, the BSI prescribes four standards for the security concept, which are presented in more detail below. The BSI’s IT baseline protection catalog includes a large number of documents for analyzing and modeling security risks and protection requirements. The focus here is on protecting the most important areas of information security: Integrity, confidentiality and availability.
The specifications are fully compatible with those of the internationally recognized ISO 22301, but also include detailed instructions and tools for practical implementation.
Implementation of BSI IT-Grundschutz
Information security in companies is a process that must be constantly monitored and optimized. The BSI IT baseline protection standards offer a practical guide to establishing your own information security management system, especially for less experienced users in small and medium-sized companies with an independent IT department.
A distinction is made between eight phases or steps. The first step is to define which components and areas in the company are eligible for an ISMS. This is followed by a structural analysis of all security-critical company assets and their dependencies. Once the protection requirements have been determined, the minimum requirements specified by the BSI baseline protection as building blocks are modeled and then compared with the current status in the IT baseline protection check. A risk analysis is necessary for all company values that do not match any of the modules.
An action implementation plan summarizes all the safety measures that will ultimately be implemented in order to achieve the desired safety level. This is divided into 3 levels (basic, core and standard) so that the security concept can be implemented and tested in line with the requirements of your own company.