Graham Miranda logo
Graham MirandaNetwork
BSI Grundschutz · Graham Miranda Network

BSI IT-Grundschutz preparation

Practical BSI IT-Grundschutz preparation for SMEs that need to demonstrate a recognized German security baseline — for public-sector contracts, larger customer due diligence, or general defensibility. We do the scoping, mapping and documentation work, not the formal certification itself.

BSI Grundschutz · BSI IT Grundschutz · Mittelstand BSI · security baseline Germany
BSI IT-Grundschutz preparation Graham Miranda service overview
概览

本页涵盖的内容

Practical BSI IT-Grundschutz preparation for SMEs that need to demonstrate a recognized German security baseline — scoping, mapping and documentation work.

  • Scoping: which information domain, which Grundschutz profile (Basis/Standard)
  • Mapping current state against BSI Grundschutz building blocks
  • Gap analysis with prioritised remediation plan
  • Documentation work: security guideline, risk analysis, evidence pack
  • Preparation for formal audit if certification is the goal
我们如何工作

我们如何工作

透明的合作模式,里程碑清晰。

01

Scoping workshop

Decide which Grundschutz profile (Basis or Standard), which information domain is in scope, which building blocks apply.

02

Map & analyse

Map current technical, organisational and procedural controls against Grundschutz building blocks. Written gap report with prioritised remediation.

03

Lift & document

Implement missing controls over 6–12 months; produce the documentation needed for self-assessment or external audit.

可期待的成果

可期待的成果

务实、诚实的预期 — 无夸大承诺。

Recognized baseline

A defensible posture against a German national standard.

Audit-ready documentation

Evidence pack structured for review.

Right-sized

Basis profile for SMEs; Standard for higher maturity.

Stays useful

The work produces operational hygiene, not paperwork.

FAQ

常见问题

为比较 Graham Miranda 服务的访客提供简明回答。

Do you certify us against Grundschutz?

No — formal certification requires an accredited auditor. We do the preparation work; we coordinate with auditors when certification is the goal.

Is Basis enough for our needs?

For most SMEs that need to demonstrate a serious baseline for public-sector tenders or larger-customer due diligence, Basis is typically appropriate. Standard for higher requirements.

How does this relate to ISO 27001?

Grundschutz building blocks largely map to ISO 27001 controls. Some SMEs prepare both. We coordinate scope to avoid duplication.

What about Grundschutz-Kompendium 2023 updates?

We work to the current edition. Updates to building blocks tracked as part of the engagement.

How long does preparation take?

Basis: typically 6–9 months for SMEs starting from a baseline. Standard: 9–18 months.

Can you provide ongoing audit support?

Yes — annual review and maintenance is a common follow-on engagement.

下一步

BSI IT-Grundschutz preparation

Practical BSI IT-Grundschutz preparation for SMEs that need to demonstrate a recognized German security baseline — scoping, mapping and documentation work.