By which three structural changes did the modernized IT-Grundschutz converge methodologically with ISO 27001?
Splitting each block into requirements + separate implementation notes, grouping blocks into process vs system families, and the function-oriented layer model — together they reshaped Grundschutz to mirror ISO 27001's structure.
The modernization (BSI 100-2 → 200-2) was deliberately an evolution toward ISO 27001, driven by three changes:
- Requirements split from implementation notes — blocks now state Anforderungen (what to achieve), while the concrete Umsetzungshinweise (how) live in separate, non-binding documents — mirroring ISO 27001 (requirements) vs ISO 27002 (guidance).
- Process- vs system-Bausteine — overarching/organizational concerns are separated from concrete technology, bundling responsibilities the way ISO's control groups do.
- Function-oriented Schichtenmodell — the old system-oriented catalog became a function-oriented layer model, structurally much closer to ISO 27001.
Two important caveats: the requirement-orientation should reduce implementation effort (you choose measures instead of following prescribed ones), and it is "no revolution" — the advantages of both approaches are preserved, so moving closer to ISO doesn't cost Grundschutz its concreteness.
Tip: Three levers — what/how split, process/system split, function-oriented layers — all pointing the same way: from a standalone measure catalog toward an ISO-27001-shaped requirements framework.
Go deeper:
BSI-Standard 200-2: IT-Grundschutz-Methodik — Die modernisierte Vorgehensweise, die Grundschutz an die ISO-27001-Struktur annähert.