<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Iso-27001 on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/iso-27001/</link><description>Recent content in Iso-27001 on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/iso-27001/index.xml" rel="self" type="application/rss+xml"/><item><title>BSI IT-Grundschutz</title><link>https://lesitedefrancois.be/en/compliance/bsi-it-grundschutz/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/bsi-it-grundschutz/</guid><description>&lt;p&gt;&lt;strong&gt;BSI IT-Grundschutz&lt;/strong&gt; is Germany&amp;rsquo;s national framework for establishing, implementing, and certifying an Information Security Management System (ISMS). It is developed and maintained by the BSI (Bundesamt für Sicherheit in der Informationstechnik) and stands out from generic standards like ISO/IEC 27001 by its extreme level of prescriptive detail — the IT-Grundschutz Compendium contains hundreds of specific security building blocks (&amp;ldquo;Bausteine&amp;rdquo;) covering technical, organizational, infrastructure, and personnel aspects. The framework is defined across four BSI Standards: &lt;strong&gt;200-1&lt;/strong&gt; (ISMS requirements), &lt;strong&gt;200-2&lt;/strong&gt; (methodology with three approaches: Basis-Absicherung, Standard-Absicherung, Kern-Absicherung), &lt;strong&gt;200-3&lt;/strong&gt; (risk analysis), and &lt;strong&gt;200-4&lt;/strong&gt; (business continuity management). Organizations can pursue &lt;strong&gt;ISO 27001 certification based on IT-Grundschutz&lt;/strong&gt;, which is recognized as equivalent to standalone ISO 27001 but with the added rigor of the BSI&amp;rsquo;s detailed control catalog. Compliance is &lt;strong&gt;mandatory&lt;/strong&gt; for German federal agencies (Bundesbehörden) under the UP Bund framework and is strongly recommended — often contractually required — for KRITIS operators and public-sector contractors. A major modernization is underway: &lt;strong&gt;Grundschutz++&lt;/strong&gt;, introduced in 2025–2026, replaces the traditional PDF-based building blocks with OSCAL/JSON machine-readable catalogs, aligning with the NIS2 implementation requirement for a BSI-defined &amp;ldquo;state of the art.&amp;rdquo; The classic IT-Grundschutz remains valid for audits until end of 2028.&lt;/p&gt;</description></item></channel></rss>