The essentials at a glance:
The IT-Grundschutz Compendium has replaced the IT-Grundschutz Catalogues and provides a modular guide to IT security. It enables companies to systematically secure their IT infrastructure and efficiently meet legal requirements.
Complete and regularly updated IT documentation is essential for minimizing security risks. Companies benefit from clearly defined processes, faster troubleshooting, and optimized audit preparation.
With Docusnap, companies can automate their IT security measures, analyze permissions, and identify vulnerabilities. The software simplifies the implementation of the IT-Grundschutz Compendium and helps meet compliance requirements efficiently.

That IT-Grundschutz Compendium from the Federal Office for Information Security (BSI) is a central tool that helps organizations to systematically strengthen their information security (see BSI IT-Grundschutz Compendium). It has the earlier IT-Grundschutz catalogues replaced and offers a modernized, modular structure that is better adapted to current IT security requirements. While the catalogues consisted of extensive collections of documents that were regularly revised, the IT-Grundschutz Compendium offers a more compact and flexible alternative. It contains standardized components that can be individually adapted to the respective IT environment, which enables companies to implement security measures in a more targeted manner.
The IT-Grundschutz Compendium provides specific recommendations for action to identify and secure critical business processes. The aim is to minimize risks, meet legal requirements and ensure reliable IT operation. Well-structured IT documentation is the basis for implementing the BSI requirements and ensuring a high level of security quality.
In addition, the compendium contains a detailed description of the building blocks for various IT areas, including network security, system hardening, and risk management. It is continuously updated to take account of new security risks and technological developments. This ensures that companies are always up to date with the latest IT security standards and can secure their systems against current threats.
IT-Grundschutz Compendium: Basics and Objectives of IT Documentation
The IT documentation according to IT-Grundschutz Compendium is much more than just an inventory. It forms the basis for effective IT management, helps with risk analysis, supports emergency measures and facilitates communication within the company. Organizations are required to maintain complete and always up-to-date documentation that includes all relevant IT components and security measures.
Why is complete IT documentation so important?
Complete IT documentation ensures transparency. It provides information about which systems and applications are being used, how they are linked together and where potential security gaps could exist. In this way, responsibilities can be clearly defined and changes in the IT environment can be tracked at any time.
Good documentation also helps to identify weak points at an early stage. For example, a complete overview of systems in use can reveal outdated software versions that pose a security risk. During audits, the documentation provides the required proof that all IT security requirements are met. It also speeds up the recovery of systems in the event of an emergency, as those responsible immediately know what measures to take.
For companies, this means that they not only meet compliance requirements through structured IT documentation, but also increase operational efficiency. A well-thought-out documentation strategy reduces sources of error, accelerates response times and makes it easier to train new employees in IT processes.
Structure and content of IT documentation in accordance with the IT-Grundschutz Compendium
that IT-Grundschutz Compendium recommends comprehensive documentation that covers various aspects of the IT landscape. This should be updated regularly in order to always comply with current conditions.
IT structure and system overview
The first step is to create a detailed inventory of all IT components. These include:
- hardware: servers, workstations, mobile devices, and peripherals
- software: operating systems, applications, and databases
- network infrastructure: routers, switches, firewalls, and VPN connections
- Cloud services and external service providers: platforms used and their security measures
Documenting these components enables companies to manage their IT resources optimally and identify potential security risks at an early stage. Continuous updates ensure that new IT components are seamlessly integrated and outdated systems are replaced in a timely manner.
Security guidelines and operating instructions
Security guidelines define the safe use of IT. This includes regulations regarding passwords, email usage, mobile devices, and conduct in the event of security incidents. Operating instructions supplement these guidelines with specific recommendations for action.
With clearly defined security policies and documented procedures, companies can ensure that their employees know how to act in the event of an IT security incident. A consistent approach reduces the risk of human error and improves the company's overall IT security posture.
How Docusnap supports the implementation of the IT-Grundschutz Compendium
Docusnap offers a comprehensive solution for IT documentation, which enables the seamless implementation of the IT-Grundschutz Compendium. Through automated IT inventory , Docusnap collects all hardware, software, and networks, providing companies with a complete and always up-to-date overview of their IT landscape. The collected data is presented in detailed and visually appealing diagrams, which allow for in-depth analysis.
In addition, Docusnap makes it easier to identify and manage IT security risks by making critical dependencies between systems visible.
The Docusnap software enables continuous updates to IT documentation, providing companies with a complete and up-to-date overview of their IT infrastructure at all times. Automatically generated reports help identify potential security gaps early and initiate necessary measures. This not only increases overall IT security but also significantly simplifies preparation for IT audits.
With the Permission analysis Docusnap provides a detailed overview of user access to IT resources. This makes it possible to quickly identify and correct unauthorized or excessive permissions. This is how Docusnap helps ensure that “Need-to-know” principle is consistently implemented. In addition, Docusnap can automatically analyze permission inheritance or origin and present it clearly. On this basis, companies can take preventive measures and continuously optimize their IT security policies.
Practical examples: How Docusnap supports the implementation of the IT-Grundschutz Compendium
An automotive company uses Docusnap to gain a complete overview of its IT systems. Through automated inventory, all relevant systems, networks, and permissions are continuously recorded. This enables IT managers to efficiently demonstrate compliance and optimally prepare for audits. Furthermore, Docusnap ensures that sensitive production data can only be viewed by authorized personnel by identifying unauthorized permissions and proposing adjustments where necessary.
A logistics company uses Docusnap to specifically optimize its IT security measures and identify vulnerabilities at an early stage. Especially in a company with numerous warehouse locations and complex supply chains, Docusnap helps make potential security gaps visible. Detailed network and infrastructure documentation makes it possible to identify critical interfaces between IT and logistics systems, minimize attack vectors, and implement targeted measures to secure the systems. Additionally, emergency plans can be created for system failures, ensuring that operational processes can be quickly restored in the event of security incidents.
A healthcare company uses Docusnap to secure its IT systems in accordance with the IT-Grundschutz Compendium and to create audit-proof documentation. A detailed analysis of permission structures ensures that patient data can only be viewed by authorized personnel. At the same time, the solution enables audit-proof documentation of all IT processes, making it easier for medical institutions to protect themselves against external audit bodies.
Docusnap successfully supports companies in implementing the requirements of the IT-Grundschutz Compendium through precise IT documentation, detailed permission analyses, and automated reporting.
IT-Grundschutz Compendium: A final conclusion
Implementing the IT-Grundschutz Compendium is essential for companies to minimize IT security risks and comply with legal requirements. Comprehensive and structured IT documentation makes it easier to identify vulnerabilities, improves IT security, and ensures greater transparency. Companies that consistently implement the IT-Grundschutz Compendium benefit in the long term from more stable IT processes and greater reliability.
Our Docusnap software helps companies efficiently implement the requirements of the IT-Grundschutz Compendium by providing automated IT documentation, permission analyses, and emergency management functions.

