Graham Miranda logo
Graham MirandaNetwork
BSI Grundschutz · Graham Miranda Network

BSI IT-Grundschutz preparation

Practical BSI IT-Grundschutz preparation for SMEs that need to demonstrate a recognized German security baseline — for public-sector contracts, larger customer due diligence, or general defensibility. We do the scoping, mapping and documentation work, not the formal certification itself.

BSI Grundschutz · BSI IT Grundschutz · Mittelstand BSI · security baseline Germany
BSI IT-Grundschutz preparation Graham Miranda service overview
概要

このページの内容

Practical BSI IT-Grundschutz preparation for SMEs that need to demonstrate a recognized German security baseline — scoping, mapping and documentation work.

  • Scoping: which information domain, which Grundschutz profile (Basis/Standard)
  • Mapping current state against BSI Grundschutz building blocks
  • Gap analysis with prioritised remediation plan
  • Documentation work: security guideline, risk analysis, evidence pack
  • Preparation for formal audit if certification is the goal
進め方

進め方

明確なマイルストーンを伴う透明な協働モデル。

01

Scoping workshop

Decide which Grundschutz profile (Basis or Standard), which information domain is in scope, which building blocks apply.

02

Map & analyse

Map current technical, organisational and procedural controls against Grundschutz building blocks. Written gap report with prioritised remediation.

03

Lift & document

Implement missing controls over 6–12 months; produce the documentation needed for self-assessment or external audit.

期待できる成果

期待できる成果

現実的で誠実な期待値 — 過剰な約束はしません。

Recognized baseline

A defensible posture against a German national standard.

Audit-ready documentation

Evidence pack structured for review.

Right-sized

Basis profile for SMEs; Standard for higher maturity.

Stays useful

The work produces operational hygiene, not paperwork.

FAQ

よくあるご質問

Graham Mirandaのサービスを比較する方への簡潔な回答です。

Do you certify us against Grundschutz?

No — formal certification requires an accredited auditor. We do the preparation work; we coordinate with auditors when certification is the goal.

Is Basis enough for our needs?

For most SMEs that need to demonstrate a serious baseline for public-sector tenders or larger-customer due diligence, Basis is typically appropriate. Standard for higher requirements.

How does this relate to ISO 27001?

Grundschutz building blocks largely map to ISO 27001 controls. Some SMEs prepare both. We coordinate scope to avoid duplication.

What about Grundschutz-Kompendium 2023 updates?

We work to the current edition. Updates to building blocks tracked as part of the engagement.

How long does preparation take?

Basis: typically 6–9 months for SMEs starting from a baseline. Standard: 9–18 months.

Can you provide ongoing audit support?

Yes — annual review and maintenance is a common follow-on engagement.

次のステップ

BSI IT-Grundschutz preparation

Practical BSI IT-Grundschutz preparation for SMEs that need to demonstrate a recognized German security baseline — scoping, mapping and documentation work.