
Why IT Baseline Protection is the Standard for Public Authorities
The BSI’s IT Baseline Protection (IT-Grundschutz) is more than a recommendation; it is the de facto standard for information security in German public administration. It offers concrete measures, field-tested building blocks, and a clear methodology, which makes it incredibly valuable.
An ISO 27001 certification is internationally recognised and demonstrates a functioning Information Security Management System (ISMS). Combining these two worlds is ideal: the specific guidelines of IT Baseline Protection fulfil the abstract requirements of ISO 27001.
The Synergy of IT Baseline Protection and ISO 27001
ISO 27001 requires an ISMS but does not specify how to implement it. IT Baseline Protection provides exactly that: a detailed guide. Those who implement IT Baseline Protection have already done most of the work for an ISO 27001 certification.
The advantages of this combination:
- Concrete and Field-Tested: IT Baseline Protection offers ready-made building blocks.
- BSI-Recognised: The methodology is well-established within the German public sector.
- Efficient: It avoids duplication of effort.
- Internationally Recognised: The ISO 27001 certification builds trust.

The Path to Certification
Step 1: Structural Analysis — Which information, processes, and IT systems need protection? The structural analysis defines the scope of the ISMS.
Step 2: Protection Needs Assessment — How critical is the data? Normal, high, or very high? The protection needs assessment evaluates the requirements for confidentiality, integrity, and availability.
Step 3: Modelling According to IT Baseline Protection — The identified systems are mapped to the building blocks of the IT-Grundschutz Compendium. The result is a list of relevant requirements.
Step 4: Basic Security Check — This is a gap analysis. Which requirements are already implemented? Where are the gaps? The basic security check identifies the need for action.
Step 5: Implementation and Audit — The gaps are closed. The ISMS is put into practice. An external auditor verifies conformity and issues the ISO 27001 certificate.
Quick Checklist: ISO 27001 Based on IT Baseline Protection
| Phase | Task | Status |
| 1. Preparation | Define Scope | ☐ |
| 2. Analysis | Conduct Structural Analysis | ☐ |
| 3. Assessment | Determine Protection Needs | ☐ |
| 4. Modelling | Map IT Baseline Protection Building Blocks | ☐ |
| 5. Gap Analysis | Perform Basic Security Check | ☐ |
| 6. Implementation | Execute Action Plan | ☐ |
| 7. Audit | Certification Audit | ☐ |
To-Do List for Project Managers
- Immediately: Secure management commitment.
- Week 1: Appoint an ISMS team.
- Week 2: Commission IT Baseline Protection consulting.
- Month 1: Start the structural analysis.
- Month 2: Complete the protection needs assessment.
- Quarter 2: Conduct the basic security check.
- Quarters 3-4: Implement measures.
- Next Year: Plan the certification audit.
IT Baseline Protection in the Cloud
The principles of IT Baseline Protection also apply in the cloud, but the implementation differs. Responsibility is shared. Cloud providers (Azure, AWS, GCP) deliver a secure foundation, while the authority is responsible for secure configuration and use (Shared Responsibility Model).
An ISO 27001 certification based on IT Baseline Protection for cloud workloads is possible. It requires a clear understanding of responsibilities, and BSI C5 requirements are integrated here. We map the building blocks to concrete cloud services in IT Baseline Protection in the Cloud: Shared Responsibility in Practice.
Insight42: Your Partner for IT Baseline Protection
We support ISO 27001 projects based on IT Baseline Protection for the public sector — from the initial analysis to successful certification and beyond, with managed services for continuous security and compliance.
Start on the secure path. See BSI C5 Beratung (German) or contact us.