← Back to news 13.09.2026

Core is not the middle

Basic terms, part 3: basic, core and standard safeguarding are drawn as a staircase in almost every presentation. BSI Standard 200-2 describes something else: three approaches for three situations, on two axes. Anyone who takes core safeguarding for the middle step underestimates it.

In talks on IT-Grundschutz there is a picture that appears almost every time: three steps, basic at the bottom, core in the middle, standard at the top. A staircase you climb from the bottom up.

BSI Standard 200-2 does not draw that staircase. It describes three approaches, and in its first sentence on them it says what they are for:

"IT-Grundschutz offers different approaches that address different user groups and pursue different goals: basic, standard and core safeguarding."

Different user groups, different goals. Not one goal in three maturity levels.

Basic: broad and shallow

Basic safeguarding aims, in the standard's words, to achieve "initially a broad, fundamental first safeguarding across all relevant business processes or specialised procedures of an institution". Broad is the key word: it covers everything, but only to a certain depth.

That depth is precisely defined. The compendium divides its requirements into three categories, and basic safeguarding takes only the first:

"Basic requirements must be fulfilled as a priority, because with these recommendations the greatest possible benefit can be achieved with (relatively) little effort. They are unconditional requirements."

The procedure is correspondingly lean. Chapter 6 knows four fields of action: define the scope, select and prioritise modules, run the IT-Grundschutz check against the basic requirements, implement. What is missing is striking: no protection needs assessment, no risk analysis. Basic safeguarding needs neither, because it brings a precondition the standard states explicitly: "The targeted security level is normal." And: "Minor security incidents can be tolerated."

Core: narrow and deep

Core safeguarding goes the opposite way. It "concentrates on the protection of particularly valuable assets, the so-called 'crown jewels'". A small part of the information domain, but the part the institution depends on.

And here stands the sentence that topples the staircase:

"Since core safeguarding concentrates on the particularly valuable assets, an increased protection need is generally to be assumed. Therefore the basic and standard requirements listed in the relevant modules of the IT-Grundschutz compendium must be implemented in full."

Per target object, core safeguarding therefore demands more than standard safeguarding: all basic and all standard requirements, plus a risk analysis under BSI Standard 200-3, because increased protection needs are assumed. Chapter 7 accordingly lists the full procedure, structure analysis, protection needs assessment, modelling, check, risk analysis, just for a few objects.

Core safeguarding is not the middle between basic and standard. It lies on a different axis.

Standard: broad and deep

Standard safeguarding is "the third approach and the one preferred by the BSI" and corresponds to classic IT-Grundschutz: the whole domain, each object as deep as its protection needs demand. The standard leaves no doubt where the journey leads:

"Basic and core safeguarding are each methods for identifying and implementing the most important security recommendations for the selected area of application in a timely manner. The goal must be to produce a complete security concept in accordance with standard safeguarding in the medium term."

So there is a direction. But there are two entry points, and they are alternatives, not steps.

Two axes, one deciding question

Place the three on two axes, breadth and depth, and you see what the standard means: basic is broad and shallow. Core is narrow and deep. Standard is broad and deep. The field "narrow and shallow" does not exist, and neither does the staircase.

Which entry point is right is decided by a question that appears in both criteria lists of chapter 3.3, once negated and once affirmed: are there assets "whose theft, destruction or compromise would mean damage threatening the institution's existence"? Basic safeguarding presupposes that there are none. Core safeguarding presupposes that there are, and that they can be clearly named.

If you have crown jewels, start with them. If you have none, start in breadth. If you have crown jewels and still begin with basic safeguarding, you protect everything a little and the decisive part not enough.

What the choice decides about certification

The staircase suggests each step brings you closer to the certificate. That is not true either. Chapter 11 says:

"Such a certification is intended for standard safeguarding and is in principle possible for core safeguarding. With basic safeguarding alone, the security measures implemented are not sufficient for certification, but can serve as an entry point for one of the other two approaches."

Core leads to a certificate for the delimited domain, basic does not. That too shows that core is not the step below standard.

Sources

BSI Standard 200-2 (IT-Grundschutz methodology), chapter 3.3 "Deciding on an approach", chapter 6 "Creating a security concept using the basic safeguarding approach", chapter 7.1 "The core safeguarding method", chapter 8.3 on the requirement categories and chapter 11 "ISO 27001 certification based on IT-Grundschutz". Published by the German Federal Office for Information Security: BSI Standard 200-2. Quotations translated from the German original.

Next time: target object, asset, information domain. What IT-Grundschutz models and what it does not.

The previous part: How bad is not how fast.

Matching solution isidaten for BSI IT-Grundschutz

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.