BSI IT-Grundschutz
Evidence request list. 55 controls, 55 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Applications
Office productivity applications shall be securely configured, kept up to date and integrated with malware protection and macro controls.
- Office hardening baseline
- Macro execution policy
- Patch status reports
- Macros enabled by default
- Legacy file formats allowed
Web applications shall be designed, developed and operated according to OWASP-aligned secure practices and tested against application-layer threats.
- Pen test reports
- WAF rule sets
- OWASP ASVS coverage
- Secure SDLC evidence
- No annual pen test
- WAF in detect-only
BSI IT-Grundschutz: Access Control & Identity
Account management and provisioning. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
Access enforcement and least privilege. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
Multi-factor authentication requirements. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
Remote access controls. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
Wireless access restrictions. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
Identity proofing and verification. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.
- Access control policy and standard
- Joiner/mover/leaver workflow records
- Role and entitlement matrix
- Quarterly access review attestations
- MFA enrolment and exception register
- Stale or dormant accounts not deprovisioned
- Shared or generic accounts retained
- MFA not enforced for privileged or remote access
- Access reviews skipped or rubber-stamped
BSI IT-Grundschutz: Audit & Accountability
Audit event logging and storage. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Audit & Accountability.
- Logging standard and event taxonomy
- SIEM coverage matrix
- Log retention policy and evidence
- Time synchronisation configuration
- Log integrity controls and hash records
- Critical systems not forwarding logs
- Retention shorter than regulatory minimum
- Time drift on legacy systems
- No tamper-evident protections on logs
Audit record review and analysis. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Audit & Accountability.
- Logging standard and event taxonomy
- SIEM coverage matrix
- Log retention policy and evidence
- Time synchronisation configuration
- Log integrity controls and hash records
- Critical systems not forwarding logs
- Retention shorter than regulatory minimum
- Time drift on legacy systems
- No tamper-evident protections on logs
Time synchronization. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Audit & Accountability.
- Logging standard and event taxonomy
- SIEM coverage matrix
- Log retention policy and evidence
- Time synchronisation configuration
- Log integrity controls and hash records
- Critical systems not forwarding logs
- Retention shorter than regulatory minimum
- Time drift on legacy systems
- No tamper-evident protections on logs
Audit log protection and retention. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Audit & Accountability.
- Logging standard and event taxonomy
- SIEM coverage matrix
- Log retention policy and evidence
- Time synchronisation configuration
- Log integrity controls and hash records
- Critical systems not forwarding logs
- Retention shorter than regulatory minimum
- Time drift on legacy systems
- No tamper-evident protections on logs
Accountability and non-repudiation. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Audit & Accountability.
- Logging standard and event taxonomy
- SIEM coverage matrix
- Log retention policy and evidence
- Time synchronisation configuration
- Log integrity controls and hash records
- Critical systems not forwarding logs
- Retention shorter than regulatory minimum
- Time drift on legacy systems
- No tamper-evident protections on logs
BSI IT-Grundschutz: Configuration Management
Baseline configuration establishment. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Configuration Management.
- Secure configuration baselines per platform
- Change advisory board minutes
- CMDB extracts
- Configuration drift reports
- Software allow-list and usage records
- Baselines missing for newer platforms
- Emergency changes bypassing CAB
- CMDB out of sync with reality
- No automated drift detection
Configuration change control. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Configuration Management.
- Secure configuration baselines per platform
- Change advisory board minutes
- CMDB extracts
- Configuration drift reports
- Software allow-list and usage records
- Baselines missing for newer platforms
- Emergency changes bypassing CAB
- CMDB out of sync with reality
- No automated drift detection
Security impact analysis. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Configuration Management.
- Secure configuration baselines per platform
- Change advisory board minutes
- CMDB extracts
- Configuration drift reports
- Software allow-list and usage records
- Baselines missing for newer platforms
- Emergency changes bypassing CAB
- CMDB out of sync with reality
- No automated drift detection
System component inventory. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Configuration Management.
- Secure configuration baselines per platform
- Change advisory board minutes
- CMDB extracts
- Configuration drift reports
- Software allow-list and usage records
- Baselines missing for newer platforms
- Emergency changes bypassing CAB
- CMDB out of sync with reality
- No automated drift detection
Software usage restrictions. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Configuration Management.
- Secure configuration baselines per platform
- Change advisory board minutes
- CMDB extracts
- Configuration drift reports
- Software allow-list and usage records
- Baselines missing for newer platforms
- Emergency changes bypassing CAB
- CMDB out of sync with reality
- No automated drift detection
BSI IT-Grundschutz: Incident Response
Incident response planning and testing. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Incident Response.
- Incident response plan and playbooks
- Tabletop exercise reports
- Incident ticket history with timelines
- Forensic toolkit and chain-of-custody log
- Post-incident review minutes
- Playbooks untested for major scenarios
- Unclear escalation thresholds
- Forensic readiness lacking outside core systems
- Lessons learned never closed out
Incident handling and containment. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Incident Response.
- Incident response plan and playbooks
- Tabletop exercise reports
- Incident ticket history with timelines
- Forensic toolkit and chain-of-custody log
- Post-incident review minutes
- Playbooks untested for major scenarios
- Unclear escalation thresholds
- Forensic readiness lacking outside core systems
- Lessons learned never closed out
Incident reporting and notification. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Incident Response.
- Incident response plan and playbooks
- Tabletop exercise reports
- Incident ticket history with timelines
- Forensic toolkit and chain-of-custody log
- Post-incident review minutes
- Playbooks untested for major scenarios
- Unclear escalation thresholds
- Forensic readiness lacking outside core systems
- Lessons learned never closed out
Forensic analysis capabilities. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Incident Response.
- Incident response plan and playbooks
- Tabletop exercise reports
- Incident ticket history with timelines
- Forensic toolkit and chain-of-custody log
- Post-incident review minutes
- Playbooks untested for major scenarios
- Unclear escalation thresholds
- Forensic readiness lacking outside core systems
- Lessons learned never closed out
Lessons learned and improvement. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Incident Response.
- Incident response plan and playbooks
- Tabletop exercise reports
- Incident ticket history with timelines
- Forensic toolkit and chain-of-custody log
- Post-incident review minutes
- Playbooks untested for major scenarios
- Unclear escalation thresholds
- Forensic readiness lacking outside core systems
- Lessons learned never closed out
BSI IT-Grundschutz: Risk Assessment & Management
Risk assessment procedures. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Risk Assessment & Management.
- Risk assessment methodology and register
- Vulnerability scan reports and remediation SLAs
- Threat intelligence feed inventory
- Continuous monitoring dashboard and KPI
- Risk acceptance approvals
- Risk register not refreshed at defined cadence
- Critical vulnerabilities exceeding SLA
- Threat intelligence not integrated into controls
- Continuous monitoring limited to a subset of systems
Vulnerability scanning and management. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Risk Assessment & Management.
- Risk assessment methodology and register
- Vulnerability scan reports and remediation SLAs
- Threat intelligence feed inventory
- Continuous monitoring dashboard and KPI
- Risk acceptance approvals
- Risk register not refreshed at defined cadence
- Critical vulnerabilities exceeding SLA
- Threat intelligence not integrated into controls
- Continuous monitoring limited to a subset of systems
Security categorization. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Risk Assessment & Management.
- Risk assessment methodology and register
- Vulnerability scan reports and remediation SLAs
- Threat intelligence feed inventory
- Continuous monitoring dashboard and KPI
- Risk acceptance approvals
- Risk register not refreshed at defined cadence
- Critical vulnerabilities exceeding SLA
- Threat intelligence not integrated into controls
- Continuous monitoring limited to a subset of systems
Threat intelligence integration. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Risk Assessment & Management.
- Risk assessment methodology and register
- Vulnerability scan reports and remediation SLAs
- Threat intelligence feed inventory
- Continuous monitoring dashboard and KPI
- Risk acceptance approvals
- Risk register not refreshed at defined cadence
- Critical vulnerabilities exceeding SLA
- Threat intelligence not integrated into controls
- Continuous monitoring limited to a subset of systems
Continuous monitoring strategy. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Risk Assessment & Management.
- Risk assessment methodology and register
- Vulnerability scan reports and remediation SLAs
- Threat intelligence feed inventory
- Continuous monitoring dashboard and KPI
- Risk acceptance approvals
- Risk register not refreshed at defined cadence
- Critical vulnerabilities exceeding SLA
- Threat intelligence not integrated into controls
- Continuous monitoring limited to a subset of systems
BSI IT-Grundschutz: System & Communications Protection
Boundary protection and segmentation. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.
- Network architecture and segmentation diagram
- Firewall rule review evidence
- IDS/IPS tuning records
- Session timeout configuration
- DoS mitigation runbooks
- Flat networks with limited segmentation
- Stale firewall rules and any-any allows
- Session timeouts too long or inconsistent
- DoS protections untested
Cryptographic protection of data. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.
- Cryptographic standards and algorithm catalogue
- Key management policy and KMS configuration
- TLS configuration and inventory
- Encryption at rest evidence per system
- Key rotation and escrow records
- Use of deprecated ciphers or self-signed certificates
- Keys stored alongside encrypted data
- No documented rotation schedule
- Inconsistent encryption coverage across data stores
Denial-of-service protection. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.
- Network architecture and segmentation diagram
- Firewall rule review evidence
- IDS/IPS tuning records
- Session timeout configuration
- DoS mitigation runbooks
- Flat networks with limited segmentation
- Stale firewall rules and any-any allows
- Session timeouts too long or inconsistent
- DoS protections untested
Transmission confidentiality and integrity. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.
- Cryptographic standards and algorithm catalogue
- Key management policy and KMS configuration
- TLS configuration and inventory
- Encryption at rest evidence per system
- Key rotation and escrow records
- Use of deprecated ciphers or self-signed certificates
- Keys stored alongside encrypted data
- No documented rotation schedule
- Inconsistent encryption coverage across data stores
Session management controls. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.
- Network architecture and segmentation diagram
- Firewall rule review evidence
- IDS/IPS tuning records
- Session timeout configuration
- DoS mitigation runbooks
- Flat networks with limited segmentation
- Stale firewall rules and any-any allows
- Session timeouts too long or inconsistent
- DoS protections untested
Network monitoring and defense. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.
- Network architecture and segmentation diagram
- Firewall rule review evidence
- IDS/IPS tuning records
- Session timeout configuration
- DoS mitigation runbooks
- Flat networks with limited segmentation
- Stale firewall rules and any-any allows
- Session timeouts too long or inconsistent
- DoS protections untested
Concepts and Approaches
A cryptographic concept shall be drawn up that documents protection needs, selected procedures, key lifecycle and operational responsibilities.
- Crypto concept aligned to BSI TR-02102
- Key lifecycle procedure
- Algorithm migration plan
- Concept missing for OT systems
- No crypto agility planning
Personal data processing shall integrate the BSI standard data protection model (SDM) and align with GDPR and BDSG requirements.
- Record of processing activities
- DPIA outputs
- DPO appointment
- RoPA incomplete
- No DPIA for new high-risk processing
A backup concept covering protection needs, frequency, retention, encryption, offsite storage and restoration testing shall be implemented.
- Backup policy
- Schedule and retention matrix
- Restore test reports
- Immutability evidence
- No regular restore tests
- Backups not encrypted at rest
Software development shall follow a secure SDLC integrating threat modelling, secure coding, code review and security testing prior to release.
- SDLC standard
- SAST/DAST reports
- Threat models
- Code review records
- No threat modelling for high-risk apps
- SAST findings unresolved
Detection and Reaction
Detection capabilities shall be implemented to identify security-relevant events through monitoring, anomaly detection and threat intelligence.
- SOC operating model
- Detection rule catalogue
- TI feed list
- Coverage map vs MITRE ATT&CK
- Detection gaps for cloud
- TI not actioned
Security incidents shall be handled through a defined process covering identification, containment, eradication, recovery and lessons learned.
- Incident response plan
- Playbooks
- Sample incident records
- Post-incident reviews
- No PIR step
- Playbooks not tested
Business continuity management shall be implemented to maintain critical business processes during and after disruptive events using BSI Standard 200-4.
- BCM framework
- BIA results
- BCP and DR plans
- Exercise reports
- Plans not exercised
- RTO/RPO not validated
ISMS Layer
Management shall establish an information security management system, define the scope, set the security strategy and provide adequate resources to implement IT-Grundschutz methodology.
- Information security policy
- Scope and security domain definition
- CISO appointment
- Annual security report to management
- Strategy not endorsed at board level
- Scope omits OT/IoT components
Infrastructure
Buildings shall be protected by physical security measures appropriate to the protection needs of housed IT systems and information.
- Site security plan
- Access control logs
- CCTV inventory
- No tailgating controls
- CCTV retention too short
Networks
Network architecture shall be planned with zones of differing trust, segmentation, redundancy and documented in current diagrams.
- Network diagrams
- Zone concept
- Firewall rule base
- Segmentation tests
- Diagrams outdated
- Flat networks for OT
Operations
Administration of IT systems shall follow documented procedures, use dedicated admin workstations and apply the principle of least privilege.
- Admin handbook
- PAW configuration baseline
- Jump host architecture
- Admins browse internet from PAWs
- No session recording
Patches and changes shall be planned, tested, approved and implemented through a defined process with documented rollback options.
- Patch policy with SLAs
- Vulnerability scan reports
- CAB minutes
- Emergency change records
- Critical patches over 30 days
- Emergency changes not back-reviewed
Security-relevant events shall be logged, protected against tampering, retained appropriately and reviewed for indicators of compromise.
- Logging concept
- SIEM use case catalogue
- Log retention policy
- Sample alerts
- Logs not centralised
- Retention shorter than legal requirement
Teleworking shall be enabled through secure remote access, hardened endpoints and clear rules on handling information outside the office.
- VPN/ZTNA config
- Teleworking policy
- Endpoint compliance dashboard
- Split-tunnel without DLP
- Personal devices used unmanaged
Use of external cloud services shall follow a cloud strategy, with risk assessment, contracts, exit plan and operational monitoring.
- Cloud usage policy
- Risk assessments per service
- Exit and reversibility plan
- No exit plan
- Sub-processor visibility missing
Organisation and Personnel
Roles, responsibilities and tasks for information security shall be defined and assigned across the organisation including reporting lines and interfaces.
- Org chart
- Role descriptions for ISO and security officers
- Communication matrix
- Deputy roles undefined
- Interfaces with data protection unclear
Personnel processes for hiring, onboarding, role changes and termination shall integrate security requirements such as confidentiality, training and asset return.
- Onboarding checklist
- Confidentiality agreements
- Termination procedure
- Asset return not enforced
- External staff omitted
All personnel shall receive sensitisation and training appropriate to their role and the security objectives of the organisation.
- Training plan
- Attendance records
- Phishing campaign results
- No refresher cycle
- Specialist training not provided
User identities, access rights and authentication mechanisms shall be managed in a structured, documented and verifiable manner.
- IAM concept document
- Periodic access review reports
- Privileged account inventory
- No periodic recertification
- Shared accounts in use
Systems
Servers shall be hardened, patched, monitored and operated according to a documented baseline aligned to BSI hardening guidance.
- Hardening baselines
- Configuration scans
- EDR coverage report
- Baselines not enforced via config mgmt
- EDR not on legacy servers
Client devices shall be hardened, encrypted, endpoint-protected and managed via a centralised management platform.
- MDM/UEM console reports
- BitLocker/FileVault evidence
- EDR coverage
- BYOD without containerisation
- Encryption not enforced
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the BSI IT-Grundschutz framework page.