BSI IT-Grundschutz Compendium
Comprehensive German cybersecurity methodology from the Federal Office for Information Security (BSI). Covers 111 modules across process, system, network, application, infrastructure, operations, and detection/response layers. Widely adopted across German government, critical infrastructure, and enterprise.
Clauses: 30
Avg Coverage: 86.0%
Publisher: Bundesamt fur Sicherheit in der Informationstechnik (BSI) Version: 2023 | Clause | Title | SP 800-53 Controls |
|---|---|---|
| APP.1.1 | Office Products | |
| APP.3.1 | Web Applications and Web Services | |
| CON.1 | Crypto Concept | |
| CON.2 | Privacy | |
| CON.3 | Data Backup | |
| CON.6 | Deletion and Destruction | |
| CON.7 | Information Security on Business Trips | |
| DER.1 | Detection of Security-Relevant Events | |
| DER.2.1 | Incident Management | |
| DER.4 | Business Continuity Management | |
| INF.1 | Building | |
| INF.2 | Data Centre | |
| ISMS.1 | Security Management | |
| NET.1.1 | Network Architecture and Design | |
| NET.1.2 | Network Management | |
| NET.3.1 | Router and Switches | |
| OPS.1.1.2 | Proper IT Administration | |
| OPS.1.1.3 | Patch and Change Management | |
| OPS.1.1.4 | Protection Against Malware | |
| OPS.1.1.5 | Logging | |
| OPS.1.1.6 | Software Testing | |
| OPS.1.2.4 | Telecommuting | |
| OPS.1.2.5 | Remote Maintenance | |
| ORP.1 | Organisation | |
| ORP.2 | Personnel | |
| ORP.3 | Awareness and Training | |
| ORP.4 | Identity and Access Management | |
| ORP.5 | Compliance Management | |
| SYS.1.1 | General Server | |
| SYS.2.1 | General Client |