Skip to content

Evidence request lists

BSI IT-Grundschutz

Evidence request list. 55 controls, 55 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Applications

APP.1.1
Office Products

Office productivity applications shall be securely configured, kept up to date and integrated with malware protection and macro controls.

Artefacts an auditor will ask for
  • Office hardening baseline
  • Macro execution policy
  • Patch status reports
Where this commonly fails
  • Macros enabled by default
  • Legacy file formats allowed
APP.3.1
Web Applications

Web applications shall be designed, developed and operated according to OWASP-aligned secure practices and tested against application-layer threats.

Artefacts an auditor will ask for
  • Pen test reports
  • WAF rule sets
  • OWASP ASVS coverage
  • Secure SDLC evidence
Where this commonly fails
  • No annual pen test
  • WAF in detect-only

BSI IT-Grundschutz: Access Control & Identity

BSI-01
Account management and provisioning

Account management and provisioning. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BSI-02
Access enforcement and least privilege

Access enforcement and least privilege. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BSI-03
Multi-factor authentication requirements

Multi-factor authentication requirements. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BSI-04
Remote access controls

Remote access controls. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BSI-05
Wireless access restrictions

Wireless access restrictions. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BSI-06
Identity proofing and verification

Identity proofing and verification. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Access Control & Identity.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped

BSI IT-Grundschutz: Audit & Accountability

BSI-28
Audit event logging and storage

Audit event logging and storage. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Audit & Accountability.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs
BSI-29
Audit record review and analysis

Audit record review and analysis. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Audit & Accountability.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs
BSI-30
Time synchronization

Time synchronization. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Audit & Accountability.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs
BSI-31
Audit log protection and retention

Audit log protection and retention. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Audit & Accountability.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs
BSI-32
Accountability and non-repudiation

Accountability and non-repudiation. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Audit & Accountability.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs

BSI IT-Grundschutz: Configuration Management

BSI-23
Baseline configuration establishment

Baseline configuration establishment. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Configuration Management.

Artefacts an auditor will ask for
  • Secure configuration baselines per platform
  • Change advisory board minutes
  • CMDB extracts
  • Configuration drift reports
  • Software allow-list and usage records
Where this commonly fails
  • Baselines missing for newer platforms
  • Emergency changes bypassing CAB
  • CMDB out of sync with reality
  • No automated drift detection
BSI-24
Configuration change control

Configuration change control. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Configuration Management.

Artefacts an auditor will ask for
  • Secure configuration baselines per platform
  • Change advisory board minutes
  • CMDB extracts
  • Configuration drift reports
  • Software allow-list and usage records
Where this commonly fails
  • Baselines missing for newer platforms
  • Emergency changes bypassing CAB
  • CMDB out of sync with reality
  • No automated drift detection
BSI-25
Security impact analysis

Security impact analysis. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Configuration Management.

Artefacts an auditor will ask for
  • Secure configuration baselines per platform
  • Change advisory board minutes
  • CMDB extracts
  • Configuration drift reports
  • Software allow-list and usage records
Where this commonly fails
  • Baselines missing for newer platforms
  • Emergency changes bypassing CAB
  • CMDB out of sync with reality
  • No automated drift detection
BSI-26
System component inventory

System component inventory. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Configuration Management.

Artefacts an auditor will ask for
  • Secure configuration baselines per platform
  • Change advisory board minutes
  • CMDB extracts
  • Configuration drift reports
  • Software allow-list and usage records
Where this commonly fails
  • Baselines missing for newer platforms
  • Emergency changes bypassing CAB
  • CMDB out of sync with reality
  • No automated drift detection
BSI-27
Software usage restrictions

Software usage restrictions. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Configuration Management.

Artefacts an auditor will ask for
  • Secure configuration baselines per platform
  • Change advisory board minutes
  • CMDB extracts
  • Configuration drift reports
  • Software allow-list and usage records
Where this commonly fails
  • Baselines missing for newer platforms
  • Emergency changes bypassing CAB
  • CMDB out of sync with reality
  • No automated drift detection

BSI IT-Grundschutz: Incident Response

BSI-18
Incident response planning and testing

Incident response planning and testing. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Incident Response.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out
BSI-19
Incident handling and containment

Incident handling and containment. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Incident Response.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out
BSI-20
Incident reporting and notification

Incident reporting and notification. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Incident Response.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out
BSI-21
Forensic analysis capabilities

Forensic analysis capabilities. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Incident Response.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out
BSI-22
Lessons learned and improvement

Lessons learned and improvement. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Incident Response.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out

BSI IT-Grundschutz: Risk Assessment & Management

BSI-13
Risk assessment procedures

Risk assessment procedures. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Risk Assessment & Management.

Artefacts an auditor will ask for
  • Risk assessment methodology and register
  • Vulnerability scan reports and remediation SLAs
  • Threat intelligence feed inventory
  • Continuous monitoring dashboard and KPI
  • Risk acceptance approvals
Where this commonly fails
  • Risk register not refreshed at defined cadence
  • Critical vulnerabilities exceeding SLA
  • Threat intelligence not integrated into controls
  • Continuous monitoring limited to a subset of systems
BSI-14
Vulnerability scanning and management

Vulnerability scanning and management. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Risk Assessment & Management.

Artefacts an auditor will ask for
  • Risk assessment methodology and register
  • Vulnerability scan reports and remediation SLAs
  • Threat intelligence feed inventory
  • Continuous monitoring dashboard and KPI
  • Risk acceptance approvals
Where this commonly fails
  • Risk register not refreshed at defined cadence
  • Critical vulnerabilities exceeding SLA
  • Threat intelligence not integrated into controls
  • Continuous monitoring limited to a subset of systems
BSI-15
Security categorization

Security categorization. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Risk Assessment & Management.

Artefacts an auditor will ask for
  • Risk assessment methodology and register
  • Vulnerability scan reports and remediation SLAs
  • Threat intelligence feed inventory
  • Continuous monitoring dashboard and KPI
  • Risk acceptance approvals
Where this commonly fails
  • Risk register not refreshed at defined cadence
  • Critical vulnerabilities exceeding SLA
  • Threat intelligence not integrated into controls
  • Continuous monitoring limited to a subset of systems
BSI-16
Threat intelligence integration

Threat intelligence integration. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Risk Assessment & Management.

Artefacts an auditor will ask for
  • Risk assessment methodology and register
  • Vulnerability scan reports and remediation SLAs
  • Threat intelligence feed inventory
  • Continuous monitoring dashboard and KPI
  • Risk acceptance approvals
Where this commonly fails
  • Risk register not refreshed at defined cadence
  • Critical vulnerabilities exceeding SLA
  • Threat intelligence not integrated into controls
  • Continuous monitoring limited to a subset of systems
BSI-17
Continuous monitoring strategy

Continuous monitoring strategy. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Risk Assessment & Management.

Artefacts an auditor will ask for
  • Risk assessment methodology and register
  • Vulnerability scan reports and remediation SLAs
  • Threat intelligence feed inventory
  • Continuous monitoring dashboard and KPI
  • Risk acceptance approvals
Where this commonly fails
  • Risk register not refreshed at defined cadence
  • Critical vulnerabilities exceeding SLA
  • Threat intelligence not integrated into controls
  • Continuous monitoring limited to a subset of systems

BSI IT-Grundschutz: System & Communications Protection

BSI-07
Boundary protection and segmentation

Boundary protection and segmentation. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.

Artefacts an auditor will ask for
  • Network architecture and segmentation diagram
  • Firewall rule review evidence
  • IDS/IPS tuning records
  • Session timeout configuration
  • DoS mitigation runbooks
Where this commonly fails
  • Flat networks with limited segmentation
  • Stale firewall rules and any-any allows
  • Session timeouts too long or inconsistent
  • DoS protections untested
BSI-08
Cryptographic protection of data

Cryptographic protection of data. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.

Artefacts an auditor will ask for
  • Cryptographic standards and algorithm catalogue
  • Key management policy and KMS configuration
  • TLS configuration and inventory
  • Encryption at rest evidence per system
  • Key rotation and escrow records
Where this commonly fails
  • Use of deprecated ciphers or self-signed certificates
  • Keys stored alongside encrypted data
  • No documented rotation schedule
  • Inconsistent encryption coverage across data stores
BSI-09
Denial-of-service protection

Denial-of-service protection. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.

Artefacts an auditor will ask for
  • Network architecture and segmentation diagram
  • Firewall rule review evidence
  • IDS/IPS tuning records
  • Session timeout configuration
  • DoS mitigation runbooks
Where this commonly fails
  • Flat networks with limited segmentation
  • Stale firewall rules and any-any allows
  • Session timeouts too long or inconsistent
  • DoS protections untested
BSI-10
Transmission confidentiality and integrity

Transmission confidentiality and integrity. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.

Artefacts an auditor will ask for
  • Cryptographic standards and algorithm catalogue
  • Key management policy and KMS configuration
  • TLS configuration and inventory
  • Encryption at rest evidence per system
  • Key rotation and escrow records
Where this commonly fails
  • Use of deprecated ciphers or self-signed certificates
  • Keys stored alongside encrypted data
  • No documented rotation schedule
  • Inconsistent encryption coverage across data stores
BSI-11
Session management controls

Session management controls. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.

Artefacts an auditor will ask for
  • Network architecture and segmentation diagram
  • Firewall rule review evidence
  • IDS/IPS tuning records
  • Session timeout configuration
  • DoS mitigation runbooks
Where this commonly fails
  • Flat networks with limited segmentation
  • Stale firewall rules and any-any allows
  • Session timeouts too long or inconsistent
  • DoS protections untested
BSI-12
Network monitoring and defense

Network monitoring and defense. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: System & Communications Protection.

Artefacts an auditor will ask for
  • Network architecture and segmentation diagram
  • Firewall rule review evidence
  • IDS/IPS tuning records
  • Session timeout configuration
  • DoS mitigation runbooks
Where this commonly fails
  • Flat networks with limited segmentation
  • Stale firewall rules and any-any allows
  • Session timeouts too long or inconsistent
  • DoS protections untested

Concepts and Approaches

CON.1
Crypto Concept

A cryptographic concept shall be drawn up that documents protection needs, selected procedures, key lifecycle and operational responsibilities.

Artefacts an auditor will ask for
  • Crypto concept aligned to BSI TR-02102
  • Key lifecycle procedure
  • Algorithm migration plan
Where this commonly fails
  • Concept missing for OT systems
  • No crypto agility planning
CON.2
Data Protection

Personal data processing shall integrate the BSI standard data protection model (SDM) and align with GDPR and BDSG requirements.

Artefacts an auditor will ask for
  • Record of processing activities
  • DPIA outputs
  • DPO appointment
Where this commonly fails
  • RoPA incomplete
  • No DPIA for new high-risk processing
CON.3
Data Backup Concept

A backup concept covering protection needs, frequency, retention, encryption, offsite storage and restoration testing shall be implemented.

Artefacts an auditor will ask for
  • Backup policy
  • Schedule and retention matrix
  • Restore test reports
  • Immutability evidence
Where this commonly fails
  • No regular restore tests
  • Backups not encrypted at rest
CON.8
Software Development

Software development shall follow a secure SDLC integrating threat modelling, secure coding, code review and security testing prior to release.

Artefacts an auditor will ask for
  • SDLC standard
  • SAST/DAST reports
  • Threat models
  • Code review records
Where this commonly fails
  • No threat modelling for high-risk apps
  • SAST findings unresolved

Detection and Reaction

DER.1
Detection of Security-Relevant Events

Detection capabilities shall be implemented to identify security-relevant events through monitoring, anomaly detection and threat intelligence.

Artefacts an auditor will ask for
  • SOC operating model
  • Detection rule catalogue
  • TI feed list
  • Coverage map vs MITRE ATT&CK
Where this commonly fails
  • Detection gaps for cloud
  • TI not actioned
DER.2.1
Security Incident Handling

Security incidents shall be handled through a defined process covering identification, containment, eradication, recovery and lessons learned.

Artefacts an auditor will ask for
  • Incident response plan
  • Playbooks
  • Sample incident records
  • Post-incident reviews
Where this commonly fails
  • No PIR step
  • Playbooks not tested
DER.4
Business Continuity Management

Business continuity management shall be implemented to maintain critical business processes during and after disruptive events using BSI Standard 200-4.

Artefacts an auditor will ask for
  • BCM framework
  • BIA results
  • BCP and DR plans
  • Exercise reports
Where this commonly fails
  • Plans not exercised
  • RTO/RPO not validated

ISMS Layer

ISMS.1
Security Management

Management shall establish an information security management system, define the scope, set the security strategy and provide adequate resources to implement IT-Grundschutz methodology.

Artefacts an auditor will ask for
  • Information security policy
  • Scope and security domain definition
  • CISO appointment
  • Annual security report to management
Where this commonly fails
  • Strategy not endorsed at board level
  • Scope omits OT/IoT components

Infrastructure

INF.1
General Building

Buildings shall be protected by physical security measures appropriate to the protection needs of housed IT systems and information.

Artefacts an auditor will ask for
  • Site security plan
  • Access control logs
  • CCTV inventory
Where this commonly fails
  • No tailgating controls
  • CCTV retention too short

Networks

NET.1.1
Network Architecture and Design

Network architecture shall be planned with zones of differing trust, segmentation, redundancy and documented in current diagrams.

Artefacts an auditor will ask for
  • Network diagrams
  • Zone concept
  • Firewall rule base
  • Segmentation tests
Where this commonly fails
  • Diagrams outdated
  • Flat networks for OT

Operations

OPS.1.1.2
Proper IT Administration

Administration of IT systems shall follow documented procedures, use dedicated admin workstations and apply the principle of least privilege.

Artefacts an auditor will ask for
  • Admin handbook
  • PAW configuration baseline
  • Jump host architecture
Where this commonly fails
  • Admins browse internet from PAWs
  • No session recording
OPS.1.1.3
Patch and Change Management

Patches and changes shall be planned, tested, approved and implemented through a defined process with documented rollback options.

Artefacts an auditor will ask for
  • Patch policy with SLAs
  • Vulnerability scan reports
  • CAB minutes
  • Emergency change records
Where this commonly fails
  • Critical patches over 30 days
  • Emergency changes not back-reviewed
OPS.1.1.5
Logging

Security-relevant events shall be logged, protected against tampering, retained appropriately and reviewed for indicators of compromise.

Artefacts an auditor will ask for
  • Logging concept
  • SIEM use case catalogue
  • Log retention policy
  • Sample alerts
Where this commonly fails
  • Logs not centralised
  • Retention shorter than legal requirement
OPS.1.2.4
Teleworking

Teleworking shall be enabled through secure remote access, hardened endpoints and clear rules on handling information outside the office.

Artefacts an auditor will ask for
  • VPN/ZTNA config
  • Teleworking policy
  • Endpoint compliance dashboard
Where this commonly fails
  • Split-tunnel without DLP
  • Personal devices used unmanaged
OPS.2.2
Cloud Usage

Use of external cloud services shall follow a cloud strategy, with risk assessment, contracts, exit plan and operational monitoring.

Artefacts an auditor will ask for
  • Cloud usage policy
  • Risk assessments per service
  • Exit and reversibility plan
Where this commonly fails
  • No exit plan
  • Sub-processor visibility missing

Organisation and Personnel

ORP.1
Organisation

Roles, responsibilities and tasks for information security shall be defined and assigned across the organisation including reporting lines and interfaces.

Artefacts an auditor will ask for
  • Org chart
  • Role descriptions for ISO and security officers
  • Communication matrix
Where this commonly fails
  • Deputy roles undefined
  • Interfaces with data protection unclear
ORP.2
Personnel

Personnel processes for hiring, onboarding, role changes and termination shall integrate security requirements such as confidentiality, training and asset return.

Artefacts an auditor will ask for
  • Onboarding checklist
  • Confidentiality agreements
  • Termination procedure
Where this commonly fails
  • Asset return not enforced
  • External staff omitted
ORP.3
Awareness and Training

All personnel shall receive sensitisation and training appropriate to their role and the security objectives of the organisation.

Artefacts an auditor will ask for
  • Training plan
  • Attendance records
  • Phishing campaign results
Where this commonly fails
  • No refresher cycle
  • Specialist training not provided
ORP.4
Identity and Access Management

User identities, access rights and authentication mechanisms shall be managed in a structured, documented and verifiable manner.

Artefacts an auditor will ask for
  • IAM concept document
  • Periodic access review reports
  • Privileged account inventory
Where this commonly fails
  • No periodic recertification
  • Shared accounts in use

Systems

SYS.1.1
General Server

Servers shall be hardened, patched, monitored and operated according to a documented baseline aligned to BSI hardening guidance.

Artefacts an auditor will ask for
  • Hardening baselines
  • Configuration scans
  • EDR coverage report
Where this commonly fails
  • Baselines not enforced via config mgmt
  • EDR not on legacy servers
SYS.2.1
General Client

Client devices shall be hardened, encrypted, endpoint-protected and managed via a centralised management platform.

Artefacts an auditor will ask for
  • MDM/UEM console reports
  • BitLocker/FileVault evidence
  • EDR coverage
Where this commonly fails
  • BYOD without containerisation
  • Encryption not enforced
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the BSI IT-Grundschutz framework page.