ISO 27001:2022 → BSI IT-Grundschutz Mapping

Cross-reference mapping between ISO/IEC 27001:2022 Annex A controls and BSI IT-Grundschutz building blocks.

This page maps ISO/IEC 27001:2022 Annex A controls to BSI IT-Grundschutz building blocks. ISO 27001 is the international standard for information security management systems (ISMS), with 93 controls organized into four themes.

A.5.12 Classification of information
A.5.13 Labelling of information
A.5.17 Authentication information
A.5.2 Information security roles and responsibilities
A.5.21 Managing information security in the ICT supply chain
A.5.24 Information security incident management planning and preparation
A.5.3 Segregation of duties
A.5.8 Information security in project management
A.5.9 Inventory of information and other associated assets
A.6.1 Screening
A.6.2 Terms and conditions of employment
A.6.3 Information security awareness, education and training
A.6.4 Disciplinary process
A.6.5 Responsibilities after termination or change of employment
A.6.6 Confidentiality or non-disclosure agreements
A.7.10 Storage media
A.7.4 Physical security monitoring
A.7.6 Working in secure areas
A.8.10 Deletion of information
A.8.30 Outsourced development

These mappings are provided for reference and do not replace a professional compliance assessment.