BSI IT-Grundschutz and ISO/IEC 27001 at LamaPoll

The development and operation of LamaPoll are certified to ISO/IEC 27001:2022 by TÜV SÜD Management Service GmbH. LamaPoll itself does not hold an “ISO 27001 certification on the basis of IT-Grundschutz”. Our infrastructure, and therefore your data, is operated in parallel and redundantly across data centres run by several German providers. The data centres we use hold ISO/IEC 27001 certifications; some providers additionally hold certification on the basis of BSI IT-Grundschutz. ISO 27001 defines requirements for establishing, maintaining and continually improving an ISMS (information security management system) and follows a risk-based approach. BSI IT-Grundschutz combines the BSI 200-series standards with the IT-Grundschutz Compendium and uses a structured methodology of modules and specific requirements. It is compatible with ISO 27001; the BSI offers an “ISO 27001 certification on the basis of IT-Grundschutz” scheme. Below, we compare the main similarities and differences and explain what the two approaches mean for protecting your data.

a. BSI IT-Grundschutz vs ISO 27001: measures and controls

ISO 27001BSI IT-Grundschutz
ISO/IEC 27001 defines the requirements for an information security management system (ISMS). Annex A contains 93 information security controls; ISO/IEC 27002:2022 explains these controls and provides implementation guidance.IT-Grundschutz combines the BSI 200-series standards with the IT-Grundschutz Compendium. The Compendium contains modules with specific requirements for typical processes, applications, IT systems, networks and infrastructure.

b. ISO 27001 vs BSI IT-Grundschutz: risk-based approach

AspectISO 27001BSI IT-Grundschutz
BasisClause 6.1.2: information security risk assessment; Clause 6.1.3: information security risk treatment.BSI Standard 200-2 describes the IT-Grundschutz methodology; BSI Standard 200-3 covers risk analysis based on IT-Grundschutz.
ObjectiveSystematically identify, analyse, assess and treat information security risks.Achieve an appropriate level of security through structured modelling, determination of protection requirements, the IT-Grundschutz check and supplementary risk analysis.
Approach
  1. Define risk assessment and risk acceptance criteria.
  2. Identify and analyse risks.
  3. Assess and prioritise risks.
  4. Define risk treatment and select appropriate controls.
  5. Monitor effectiveness and continually improve the ISMS.
  1. Define the information domain and determine protection requirements.
  2. Model target objects using suitable IT-Grundschutz modules.
  3. Use the IT-Grundschutz check to determine the implementation status of requirements.
  4. Carry out a risk analysis in accordance with BSI Standard 200-3 for high or very high protection requirements, target objects not adequately covered, or additional threats.
  5. Implement, review and continually improve appropriate measures.
ComparisonMore strongly risk-based and open to organisation-specific measures, provided the standard's requirements are met and decisions are documented and justified.More methodically structured: modules and requirements provide a detailed framework for typical target objects, while supplementary risk analysis remains part of the methodology.

c. Objectives, advantages and limitations: ISO 27001 vs BSI IT-Grundschutz

ISO 27001BSI IT-Grundschutz
ObjectiveEstablish, operate, monitor and continually improve an effective ISMS. The standard is internationally applicable and written independently of any particular type of organisation.Establish and operate an ISMS using a methodology defined by the BSI and specific requirements from the IT-Grundschutz Compendium.
Advantages
  • High degree of flexibility in selecting and designing appropriate security measures.
  • International recognition and broad applicability.
  • A risk-based approach allows security to be aligned with the organisation's actual protection requirements.
  • Continual improvement is built into the management system.
  • Detailed, structured methodology with reusable modules and specific requirements.
  • Clear guidance for typical IT systems, applications, networks and organisational processes.
  • Determining protection requirements, modelling and the IT-Grundschutz check provide a traceable methodology.
  • The BSI offers ISO 27001 certification based on IT-Grundschutz.
Limitations
  • The standard deliberately allows flexibility. The organisation must therefore derive and document its risks, choice of controls and risk treatment on a sound basis.
  • ISO/IEC 27002 describes recognised controls but is not itself a certifiable standard.
  • Detailed modelling and assessment of requirements can involve greater documentation and implementation effort.
  • Existing modules do not fully cover every individual scenario; the methodology therefore provides for supplementary risk analyses.

d. Example: network security and firewalls

AspectISO 27001 / ISO 27002BSI IT-Grundschutz
Current referenceISO/IEC 27001:2022 includes technological controls in Annex A. ISO/IEC 27002:2022 provides guidance on areas including network security, security of network services, network segregation, logging, monitoring and configuration management.IT-Grundschutz module NET.3.2 “Firewall” contains specific requirements for procuring, setting up, configuring and operating network-based firewalls.
ObjectiveProtect networks and network services so that confidentiality, integrity and availability are maintained in line with identified risks.Plan, configure, operate and monitor firewalls securely within the modelled network architecture.
Implementation
  • The organisation selects appropriate technical and organisational measures on the basis of its risks.
  • Network security, configuration management, logging and monitoring are addressed within the ISMS.
  • The specific technical architecture required follows from risk assessment and risk treatment.
  • NET.3.2 describes specific requirements for firewall rules, administration, documentation and secure operation.
  • The module is applied within IT-Grundschutz modelling where corresponding firewalls form part of the information domain.
  • Other network components are covered by additional modules, such as NET.3.1 for routers and switches.
LamaPoll statusThe relevant requirements of the ISO 27001 ISMS have been implemented and are monitored and continually improved. The ISMS is regularly audited internally and externally.At LamaPoll, network traffic is protected by firewalls; only required services and ports are enabled, rules are reviewed regularly and logs are monitored.
ComparisonISO 27001 defines the management and risk framework; ISO 27002 provides specific controls and implementation guidance without prescribing one particular network architecture in every case.For modelled target objects, IT-Grundschutz goes into greater technical detail and module NET.3.2 specifies concrete requirements for firewalls.
ConclusionThe difference is therefore not that ISO 27001 “does not require a firewall” while IT-Grundschutz always does. The key distinction is the methodology: ISO 27001 requires a traceable, risk-based selection of appropriate measures. IT-Grundschutz additionally uses specific modules and requirements for the target objects included in the model.

e. Conclusion

ISO 27001 and BSI IT-Grundschutz pursue the same fundamental objective: to manage information security systematically and improve it over time. ISO 27001 defines internationally recognised requirements for an ISMS and deliberately leaves room for risk-based implementation decisions. BSI IT-Grundschutz adds a structured methodology with detailed modules and requirements for typical target objects.

The certification routes also differ. ISO 27001 certification confirms that an ISMS conforms to ISO/IEC 27001. The BSI additionally offers “ISO 27001 certification based on IT-Grundschutz”, for which the IT-Grundschutz methodology and Compendium also form part of the assessment basis.

For LamaPoll, the risk-based ISO 27001 approach does not mean less concrete security. Our certified and regularly audited ISMS combines the standard's requirements with technical and organisational measures tailored to our systems, risks and protection requirements, and these measures are continually reviewed and improved.


Photo of Gunther Koschnick
5 / 5

Together with the Federal Office for Information Security (BSI), we conducted a security survey for the first time. The participating companies had high requirements for data protection, cybersecurity and anonymity. LamaPoll met them very well, both technically and organisationally. A contact person was also available whenever needed. We are extremely satisfied with the cooperation.

— Review for LamaPoll

Create a survey


Do you have questions for our team?

We are happy to answer any questions you may have about security at LamaPoll.

Please feel free to contact us.

Why LamaPoll?

  • GDPR-compliant
  • Certified servers
  • Hosting in Germany

Start for free

Create a free account – no commitment required

We’re happy to help!

Call us!

+49 30 120 88 512

Write to us!

support@lamapoll.com

Last updated on October 2, 2026


  • Allianz für Cybersicherheit participant logo
  • TÜV certificate

A clean website: no trackers, no cookies!

We REALLY respect your privacy: we set NO tracking, advertising or third-party cookies on this website.

And of course we do NOT track what you do on our site either!