SCRM Supplier Compliance & Risk Management

Explainer · information security

ISO 27001 or IT-Grundschutz – what is the difference?

Both build an information security management system. One route starts from your risks, the other from a catalogue of measures. That produces very different effort – and different recognition in the market.

ISO/IEC 27001 is an international standard with around a hundred controls in Annex A. Which of them you need is decided by your own risk assessment. The standard says you must assess – not what the outcome should be.

The German IT-Grundschutz from the Federal Office for Information Security works the other way round. It supplies a compendium of modules for typical objects – servers, networks, applications, buildings, outsourcing – each with concrete requirements. You map your environment onto those modules and work through them. Your own risk analysis becomes necessary only where protection needs exceed the usual.

For a company with little experience the baseline approach is therefore pleasantly concrete and simultaneously extensive. ISO 27001 is more tersely written and demands more thinking of your own – but lets you cut the scope precisely to your business.

The differences at a glance

AspectISO/IEC 27001IT-Grundschutz
Starting pointYour risk assessmentA module catalogue with prescribed requirements
ScopeYou define it and justify exclusionsFollows from structure analysis and protection needs
GranularityAround a hundred controls, tersely writtenSeveral hundred concrete requirements depending on modelling
Own risk analysisAlways and for everythingOnly for elevated protection needs or missing modules
CertificateISO 27001 certificate from an accredited bodyISO 27001 certificate on the basis of IT-Grundschutz
RecognitionInternational, asked for in tenders worldwideStrong in German public sector and critical infrastructure
Effort profileFewer prescriptions, more design workMore prescriptions, more working through

How the baseline approach works

The method is set out in the BSI 200 series of standards and runs in fixed steps.

  1. Structure analysisWhat objects exist at all – applications, systems, networks, rooms, people and outsourced services.
  2. Protection needsHow high are the needs for confidentiality, integrity and availability, from normal to very high.
  3. ModellingEach object is mapped to the matching modules of the compendium.
  4. Baseline checkFor every requirement, whether it is implemented – yes, partly, no, not applicable.
  5. Risk analysisOnly where protection needs are high or very high, or no suitable module exists.

What it means for suppliers

Both routes require governance of providers – only worded differently.

ISO 27001
Controls A.5.19 to A.5.23 require risk assessment, contractual requirements, consideration of the ICT supply chain, continuous monitoring and separate rules for cloud services. How deeply you assess follows from your risk assessment.
IT-Grundschutz
Dedicated modules for outsourcing and cloud use spell the requirements out – from defining requirements through contracting to orderly termination. Less room for interpretation, but a clear checklist.
In common
Both need the same underlying data: a complete register of providers with criticality, data category, contractual position and evidence. The difference lies in the justification, not the record.

Which route fits

  • You supply German public authorities or critical infrastructure operators: the baseline approach is often required or expected.
  • Your customers are international, Swiss or industrial: ISO 27001 is the currency they ask for.
  • You have little experience with information security and need guidance: the baseline approach makes many decisions for you.
  • Your business is narrow, say a single SaaS product: ISO 27001 permits a precise scope with considerably less effort.
  • You need both: the baseline route leads to an ISO 27001 certificate, though one recognisable as the Grundschutz variant.

The question is rarely “which is better” but “what do the customers I want to win ask for”. That answer sits in tenders and supplier questionnaires, not in the standard.

Where SCRM fits either route

Both require a maintained register of your providers with criticality, evidence and deadlines. That is exactly what SCRM covers – whichever of the two routes you take.

Request a consultation Go to ISO 27001 ISO 27001 or SOC 2?