In which areas does the modernized IT-Grundschutz go beyond ISO 27001, and where do the two essentially coincide?
They coincide on the process/management side — ISO's controls reappear almost fully in the process Bausteine — but Grundschutz goes further on the system side, above all industrial IT (IND) and the security of individual applications (APP), where ISO 27001 gives no concrete requirements.
* Grundschutz Baustein families laid over ISO 27001 Annex A — process blocks map almost fully; only APP and IND (green) have no ISO counterpart. *
Lay the ten Baustein families over ISO 27001's Annex A and most of them line up:
- Process Bausteine ≈ ISO Annex A. ISMS↔A.5, ORP↔A.6–A.9/A.18, CON↔A.10/A.14.2, OPS↔A.12–A.15, DER↔A.16/A.12.7/A.17. ISO's Maßnahmenziele und Maßnahmen (control objectives and controls) show up almost completely in these blocks' requirements — the process-oriented ISO approach is clearly recognisable.
- System Bausteine reach further. SYS↔A.8.3/A.12.5, NET↔A.13.1, INF↔A.11 still map — but APP (individual applications) and IND (industrial IT / SCADA) have no ISO counterpart. ISO 27001 makes no specific requirements for securing a concrete application or an industrial control environment.
So the modernised Grundschutz is roughly "ISO 27001 plus concrete, technology-specific depth", and that extra reach is concentrated in the system blocks — exactly where a generic management standard stops and hands-on baseline protection begins.
Tip: ISO tells you to manage security; Grundschutz additionally tells you how to secure the box — most of all for the two areas ISO ignores, industrial control systems and individual apps.
Go deeper:
ISO/IEC 27001 (Wikipedia DE) — Die Annex-A-Struktur, gegen die sich die Grundschutz-Schichten abbilden lassen.
BSI-Standard 200-2: IT-Grundschutz-Methodik — Das Schichtenmodell mit Prozess- und System-Bausteinen, inkl. IND und APP.