← Frameworks / Security Framework

BSI IT-Grundschutz Compendium

Comprehensive German cybersecurity methodology from the Federal Office for Information Security (BSI). Covers 111 modules across process, system, network, application, infrastructure, operations, and detection/response layers. Widely adopted across German government, critical infrastructure, and enterprise.

Clause Title SP 800-53 Controls
APP.1.1 Office Products
APP.3.1 Web Applications and Web Services
CON.1 Crypto Concept
CON.2 Privacy
CON.3 Data Backup
CON.6 Deletion and Destruction
CON.7 Information Security on Business Trips
DER.1 Detection of Security-Relevant Events
DER.2.1 Incident Management
DER.4 Business Continuity Management
INF.1 Building
INF.2 Data Centre
ISMS.1 Security Management
NET.1.1 Network Architecture and Design
NET.1.2 Network Management
NET.3.1 Router and Switches
OPS.1.1.2 Proper IT Administration
OPS.1.1.3 Patch and Change Management
OPS.1.1.4 Protection Against Malware
OPS.1.1.5 Logging
OPS.1.1.6 Software Testing
OPS.1.2.4 Telecommuting
OPS.1.2.5 Remote Maintenance
ORP.1 Organisation
ORP.2 Personnel
ORP.3 Awareness and Training
ORP.4 Identity and Access Management
ORP.5 Compliance Management
SYS.1.1 General Server
SYS.2.1 General Client