LOGBOOK

HELP

Quiz Entry - updated: 2026.07.30

In which areas does the modernized IT-Grundschutz go beyond ISO 27001, and where do the two essentially coincide?

They coincide on the process/management side — ISO's controls reappear almost fully in the process Bausteine — but Grundschutz goes further on the system side, above all industrial IT (IND) and the security of individual applications (APP), where ISO 27001 gives no concrete requirements.

The ten Grundschutz Baustein families mapped onto ISO 27001 Annex A controls, with APP and IND marked as having no ISO counterpart.

* Grundschutz Baustein families laid over ISO 27001 Annex A — process blocks map almost fully; only APP and IND (green) have no ISO counterpart. *

Lay the ten Baustein families over ISO 27001's Annex A and most of them line up:

  • Process Bausteine ≈ ISO Annex A. ISMS↔A.5, ORP↔A.6–A.9/A.18, CON↔A.10/A.14.2, OPS↔A.12–A.15, DER↔A.16/A.12.7/A.17. ISO's Maßnahmenziele und Maßnahmen (control objectives and controls) show up almost completely in these blocks' requirements — the process-oriented ISO approach is clearly recognisable.
  • System Bausteine reach further. SYS↔A.8.3/A.12.5, NET↔A.13.1, INF↔A.11 still map — but APP (individual applications) and IND (industrial IT / SCADA) have no ISO counterpart. ISO 27001 makes no specific requirements for securing a concrete application or an industrial control environment.

So the modernised Grundschutz is roughly "ISO 27001 plus concrete, technology-specific depth", and that extra reach is concentrated in the system blocks — exactly where a generic management standard stops and hands-on baseline protection begins.

Tip: ISO tells you to manage security; Grundschutz additionally tells you how to secure the box — most of all for the two areas ISO ignores, industrial control systems and individual apps.

Go deeper:

From Quiz: ISM / IT-Grundschutz (BSI) | Updated: Jul 30, 2026