Graham Miranda logo
Graham MirandaNetwork
BSI Grundschutz · Graham Miranda Network

BSI IT-Grundschutz preparation

Practical BSI IT-Grundschutz preparation for SMEs that need to demonstrate a recognized German security baseline — for public-sector contracts, larger customer due diligence, or general defensibility. We do the scoping, mapping and documentation work, not the formal certification itself.

BSI Grundschutz · BSI IT Grundschutz · Mittelstand BSI · security baseline Germany
BSI IT-Grundschutz preparation Graham Miranda service overview
개요

이 페이지에서 다루는 내용

Practical BSI IT-Grundschutz preparation for SMEs that need to demonstrate a recognized German security baseline — scoping, mapping and documentation work.

  • Scoping: which information domain, which Grundschutz profile (Basis/Standard)
  • Mapping current state against BSI Grundschutz building blocks
  • Gap analysis with prioritised remediation plan
  • Documentation work: security guideline, risk analysis, evidence pack
  • Preparation for formal audit if certification is the goal
진행 방식

진행 방식

명확한 마일스톤을 갖춘 투명한 협업 모델.

01

Scoping workshop

Decide which Grundschutz profile (Basis or Standard), which information domain is in scope, which building blocks apply.

02

Map & analyse

Map current technical, organisational and procedural controls against Grundschutz building blocks. Written gap report with prioritised remediation.

03

Lift & document

Implement missing controls over 6–12 months; produce the documentation needed for self-assessment or external audit.

기대되는 결과

기대되는 결과

과장 없는 현실적이고 정직한 기대치.

Recognized baseline

A defensible posture against a German national standard.

Audit-ready documentation

Evidence pack structured for review.

Right-sized

Basis profile for SMEs; Standard for higher maturity.

Stays useful

The work produces operational hygiene, not paperwork.

FAQ

자주 묻는 질문

Graham Miranda 서비스 영역을 비교하는 방문자를 위한 간결한 답변.

Do you certify us against Grundschutz?

No — formal certification requires an accredited auditor. We do the preparation work; we coordinate with auditors when certification is the goal.

Is Basis enough for our needs?

For most SMEs that need to demonstrate a serious baseline for public-sector tenders or larger-customer due diligence, Basis is typically appropriate. Standard for higher requirements.

How does this relate to ISO 27001?

Grundschutz building blocks largely map to ISO 27001 controls. Some SMEs prepare both. We coordinate scope to avoid duplication.

What about Grundschutz-Kompendium 2023 updates?

We work to the current edition. Updates to building blocks tracked as part of the engagement.

How long does preparation take?

Basis: typically 6–9 months for SMEs starting from a baseline. Standard: 9–18 months.

Can you provide ongoing audit support?

Yes — annual review and maintenance is a common follow-on engagement.

다음 단계

BSI IT-Grundschutz preparation

Practical BSI IT-Grundschutz preparation for SMEs that need to demonstrate a recognized German security baseline — scoping, mapping and documentation work.