BSI.html
* created: 2026-06-19T17:52
* modified: 2026-06-21T00:17
title
Title
description
Description
The Bundesamt for Sicherheit in the Informationstechnik
The BSI is an organization that focuses on providing frameworks to ensure theoretical security. These frameworks are a bit fuzzy on purpose to allow for a wide range of valid implementations, while fulfilling measurable guidelines.
These guidelines have the aim to prevent security vulnerabilities, but can't eliminate them entirely.
Getting a BSI certification is quite cumbersome and only shows that you are doing "something" to prevent potential threats.
Adhering to the foundational framework requires you to implement a security process as outlined:
- Determine responsibilities on a management level
- Concept and planning
- Creating IT-Security handbook
- Maintaining IT-Security department
- Making resources accessible
- Incorporating employees
This is an iterative process with the core loop containing the following 3 steps:
- Create a security concept
- Execute the security concept
- Maintain and refine, i.e., go back to step 1
Modelling IT-Systems
Planning a system includes the following steps:
- System composition
- Structural analysis
- Need for protection
- Modelling
- Planned system
- Production system
A system built using building blocks categorized as follows:
- B1: Overarching aspects
- B2: Infrastructure
- B3: IT-Systems
- B4: Networks
- B5: Applications
The following dangers are specified for each building block:
- G0: Elemental Dangers
- G1: Higher Powers
- G2: Structural Issues
- G3: Human Errors
- G4: Technical Failure
- G5: Targeted Attacks
These dangers can be mitigated/prevented by implementing these categories of preventive measures:
- M1: Infrastructure
- M2: Organization
- M3: Employees
- M4: Hardware and Software
- M5: Communication
- M6: Emergency Preparedness