LOGBOOK

HELP

Quiz Entry - updated: 2026.07.30

By which three structural changes did the modernized IT-Grundschutz converge methodologically with ISO 27001?

Splitting each block into requirements + separate implementation notes, grouping blocks into process vs system families, and the function-oriented layer model — together they reshaped Grundschutz to mirror ISO 27001's structure.

The modernization (BSI 100-2 → 200-2) was deliberately an evolution toward ISO 27001, driven by three changes:

  1. Requirements split from implementation notes — blocks now state Anforderungen (what to achieve), while the concrete Umsetzungshinweise (how) live in separate, non-binding documents — mirroring ISO 27001 (requirements) vs ISO 27002 (guidance).
  2. Process- vs system-Bausteine — overarching/organizational concerns are separated from concrete technology, bundling responsibilities the way ISO's control groups do.
  3. Function-oriented Schichtenmodell — the old system-oriented catalog became a function-oriented layer model, structurally much closer to ISO 27001.

Two important caveats: the requirement-orientation should reduce implementation effort (you choose measures instead of following prescribed ones), and it is "no revolution" — the advantages of both approaches are preserved, so moving closer to ISO doesn't cost Grundschutz its concreteness.

Tip: Three levers — what/how split, process/system split, function-oriented layers — all pointing the same way: from a standalone measure catalog toward an ISO-27001-shaped requirements framework.

Go deeper:

From Quiz: ISM / IT-Grundschutz (BSI) | Updated: Jul 30, 2026