ISM Logs
BSI 200-2 (IT-Grundschutz Methodology) provides practical guidance for building and operating an ISMS, including creating a security concept and selecting appropriate security measures.
BSI 200-2 concretizes BSI 200-1 by describing:
IT security management tasks — Roles and respo...
Q What changed between the old BSI 100-x series and the new BSI 200-x series?
The BSI 200-x series modernized the structure: 200-1 expanded from 4 to 6 phases, and 200-2 reorganized from 5 technical layers to process-oriented and system-oriented building block layers.
BSI 100-1 vs 200-1 (ISMS):
BSI 100-1 (old)
BSI 200-1 (new)
1. Initiate security pr...
Q What are the Cyber Kill Chain and MITRE ATT&CK, and how do they differ as ways of describing an atta...
The Cyber Kill Chain is a short, linear 7-stage model of an intrusion; MITRE ATT&CK is a large, detailed catalogue of attacker tactics organized into stages but not strictly sequential.
* The Cyber Kill Chain — seven sequential intrusion stages, Reconnaissance through Actions on...
Q The threat-modelling exercise begins with "identify your industry." Why is industry the very first s...
Because the industry you operate in shapes which assets are valuable, which threat actors target you, and which attack types and regulations apply — it sets the context for everything that follows.
Examples of industries on the list include automotive, healthcare, manufacturing,...
Q In the worked healthcare ransomware scenario, why is the likelihood rated "very likely," and what fa...
It is rated very likely because ransomware is highly effective against hospitals — contributing factors include that hospitals pay often, are heavily targeted, have staff poorly trained to spot phishing, and struggle to find "patient zero" and the root cause.
Hospitals make attra...
Q What is BSI Standard 200-3 and when is a supplementary risk analysis required?
BSI 200-3 covers risk analysis based on IT-Grundschutz. It's needed when the standard Grundschutz measures aren't sufficient — for assets with high security requirements or unusual scenarios.
* The BSI 200-3 process; a supplementary risk analysis kicks in only where standard Gru...
Q What are the three pillars of information security, and why does relying on just one fail?
Information security stands on three pillars — technology, processes, and people — and it is only as strong as the weakest of them; a firewall means nothing if the process is undefined or an employee clicks the phishing link.
* Information security rests on three complementary p...
Q In a "Value at Risk" view of cyber risk, which three high-level factors combine to determine the ris...
Vulnerability, Assets, and Profile of Attacker — together they answer who/why, what/how, and where/when an attack happens.
* Value at Risk — three factors combine: Vulnerability (where/when), Assets (what/how), Attacker Profile (who/why). *
Value at Risk decomposes cyber risk in...
Q In the second modelling step you "identify your high-value asset." What kinds of things count as hig...
High-value assets are the systems and processes that produce value or money — e.g. a customer database, web portal, payment process, reconciliation, a SWIFT gateway, the production/operational-technology (OT) process, an ERP or HR system, or logistic planning.
The point is to fin...
Q In step 6 you "determine current and desired-state measures." How does referencing MITRE mitigation...
Listing concrete, catalogued mitigations — like network segmentation (M1030) or multi-factor authentication (M1032) — turns vague intentions into specific, traceable controls mapped to the threats they counter.
Example improvements from the worked exercise include segmenting the...