The development and operation of LamaPoll are certified to ISO/IEC 27001:2022 by TÜV SÜD Management Service GmbH. LamaPoll itself does not hold an “ISO 27001 certification on the basis of IT-Grundschutz”. Our infrastructure, and therefore your data, is operated in parallel and redundantly across data centres run by several German providers. The data centres we use hold ISO/IEC 27001 certifications; some providers additionally hold certification on the basis of BSI IT-Grundschutz. ISO 27001 defines requirements for establishing, maintaining and continually improving an ISMS (information security management system) and follows a risk-based approach. BSI IT-Grundschutz combines the BSI 200-series standards with the IT-Grundschutz Compendium and uses a structured methodology of modules and specific requirements. It is compatible with ISO 27001; the BSI offers an “ISO 27001 certification on the basis of IT-Grundschutz” scheme. Below, we compare the main similarities and differences and explain what the two approaches mean for protecting your data.
Table of Contents
a. BSI IT-Grundschutz vs ISO 27001: measures and controls
| ISO 27001 | BSI IT-Grundschutz |
|---|---|
| ISO/IEC 27001 defines the requirements for an information security management system (ISMS). Annex A contains 93 information security controls; ISO/IEC 27002:2022 explains these controls and provides implementation guidance. | IT-Grundschutz combines the BSI 200-series standards with the IT-Grundschutz Compendium. The Compendium contains modules with specific requirements for typical processes, applications, IT systems, networks and infrastructure. |
b. ISO 27001 vs BSI IT-Grundschutz: risk-based approach
| Aspect | ISO 27001 | BSI IT-Grundschutz |
|---|---|---|
| Basis | Clause 6.1.2: information security risk assessment; Clause 6.1.3: information security risk treatment. | BSI Standard 200-2 describes the IT-Grundschutz methodology; BSI Standard 200-3 covers risk analysis based on IT-Grundschutz. |
| Objective | Systematically identify, analyse, assess and treat information security risks. | Achieve an appropriate level of security through structured modelling, determination of protection requirements, the IT-Grundschutz check and supplementary risk analysis. |
| Approach |
|
|
| Comparison | More strongly risk-based and open to organisation-specific measures, provided the standard's requirements are met and decisions are documented and justified. | More methodically structured: modules and requirements provide a detailed framework for typical target objects, while supplementary risk analysis remains part of the methodology. |
c. Objectives, advantages and limitations: ISO 27001 vs BSI IT-Grundschutz
| ISO 27001 | BSI IT-Grundschutz | |
|---|---|---|
| Objective | Establish, operate, monitor and continually improve an effective ISMS. The standard is internationally applicable and written independently of any particular type of organisation. | Establish and operate an ISMS using a methodology defined by the BSI and specific requirements from the IT-Grundschutz Compendium. |
| Advantages |
|
|
| Limitations |
|
|
d. Example: network security and firewalls
| Aspect | ISO 27001 / ISO 27002 | BSI IT-Grundschutz |
|---|---|---|
| Current reference | ISO/IEC 27001:2022 includes technological controls in Annex A. ISO/IEC 27002:2022 provides guidance on areas including network security, security of network services, network segregation, logging, monitoring and configuration management. | IT-Grundschutz module NET.3.2 “Firewall” contains specific requirements for procuring, setting up, configuring and operating network-based firewalls. |
| Objective | Protect networks and network services so that confidentiality, integrity and availability are maintained in line with identified risks. | Plan, configure, operate and monitor firewalls securely within the modelled network architecture. |
| Implementation |
|
|
| LamaPoll status | The relevant requirements of the ISO 27001 ISMS have been implemented and are monitored and continually improved. The ISMS is regularly audited internally and externally. | At LamaPoll, network traffic is protected by firewalls; only required services and ports are enabled, rules are reviewed regularly and logs are monitored. |
| Comparison | ISO 27001 defines the management and risk framework; ISO 27002 provides specific controls and implementation guidance without prescribing one particular network architecture in every case. | For modelled target objects, IT-Grundschutz goes into greater technical detail and module NET.3.2 specifies concrete requirements for firewalls. |
| Conclusion | The difference is therefore not that ISO 27001 “does not require a firewall” while IT-Grundschutz always does. The key distinction is the methodology: ISO 27001 requires a traceable, risk-based selection of appropriate measures. IT-Grundschutz additionally uses specific modules and requirements for the target objects included in the model. | |
e. Conclusion
ISO 27001 and BSI IT-Grundschutz pursue the same fundamental objective: to manage information security systematically and improve it over time. ISO 27001 defines internationally recognised requirements for an ISMS and deliberately leaves room for risk-based implementation decisions. BSI IT-Grundschutz adds a structured methodology with detailed modules and requirements for typical target objects.
The certification routes also differ. ISO 27001 certification confirms that an ISMS conforms to ISO/IEC 27001. The BSI additionally offers “ISO 27001 certification based on IT-Grundschutz”, for which the IT-Grundschutz methodology and Compendium also form part of the assessment basis.
For LamaPoll, the risk-based ISO 27001 approach does not mean less concrete security. Our certified and regularly audited ISMS combines the standard's requirements with technical and organisational measures tailored to our systems, risks and protection requirements, and these measures are continually reviewed and improved.
Together with the Federal Office for Information Security (BSI), we conducted a security survey for the first time. The participating companies had high requirements for data protection, cybersecurity and anonymity. LamaPoll met them very well, both technically and organisationally. A contact person was also available whenever needed. We are extremely satisfied with the cooperation.
Do you have questions for our team?
We are happy to answer any questions you may have about security at LamaPoll.
Please feel free to contact us.


