INTRA/DEGermany
What the record establishes for Germany, measure by measure, and what each source requires of the measure it governs.
| Control | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|
| 14Mandatory | |||
| DP007/DEData loss prevention deploymentMandatory | Betriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026 | Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance. | The works council has to agree before the loss prevention capability is introduced at all. |
| DP008/DEData loss prevention policy and tuningMandatory | Betriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026 | Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance. | The agreement is owed twice: once on introducing the capability and again on the manner in which it is used, so a change to the rules it enforces reopens it. |
| DP015/DELive data in non-production environmentsMandatory | Urteil 8 AZR 209/21Bundesarbeitsgericht, Eighth Senate · read 16 Aug 2026 | That legitimate interests can carry a test on live employee data, and that the national employment provision fails the article 88 conditions. | Live personal data may be used for a test where depersonalized data would not answer the question, and the legitimate interests ground carries it. |
| GV007/DELawful basis registerMandatory | Urteil 8 AZR 209/21Bundesarbeitsgericht, Eighth Senate · read 16 Aug 2026 | That legitimate interests can carry a test on live employee data, and that the national employment provision fails the article 88 conditions. | The national employment provision cannot carry the register on its own: the ground recorded has to be one that stands under article 6 itself, the employer’s legitimate interests among them. |
| GV010/DEWorker representative engagementMandatory | Betriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026 | Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance. | The body brought in is the works council, and its role is co-determination rather than consultation: the employer cannot proceed over its objection. |
| MD004/DEEndpoint activity monitoringMandatory | Betriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026 | Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance. | The works council has to agree before introducing the endpoint agent, and again on the manner in which it is used. |
| MD005/DENetwork and egress monitoringMandatory | Betriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026Beschluss 1 ABR 16/23Bundesarbeitsgericht, First Senate · read 16 Aug 2026 | Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance. | The works council has to agree before introducing the traffic inspection, and again on the manner in which it is used. What brings a device under that agreement is what it is capable of: a system that let supervisors hear conversations between employees was caught by it although nothing was recorded or kept. |
| MD006/DEElectronic mail and collaboration monitoringMandatory | Betriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026 | Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance. | The works council has to agree before introducing the recording of the messaging platform, and again on the manner in which it is used. |
| MD011/DEPrivileged session recordingMandatory | Betriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026 | Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance. | The works council has to agree before introducing the session recorder, and again on the manner in which it is used. |
| MD012/DEUser and entity behavior analyticsMandatory | Betriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026 | Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance. | The works council has to agree before introducing the analytics engine, and again on the manner in which it is used. |
| MD013/DEPhysical access monitoringMandatory | Betriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026 | Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance. | The works council has to agree before introducing the access-control recording, and again on the manner in which it is used. |
| MD014/DEVideo surveillance of the workplaceMandatory | Betriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026 | Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance. | The works council has to agree before introducing the cameras, and again on the manner in which it is used. |
| MD015/DEGeolocation of vehicles and devicesMandatory | Betriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026 | Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance. | The works council has to agree before introducing the tracking device, and again on the manner in which it is used. |
| MD016/DEMeasurement of pace and performanceMandatory | Betriebsverfassungsgesetz, section 87(1)(6)Bundestag · read 16 Aug 2026 | Co-determination by the works council over the introduction and the use of technical devices intended to monitor conduct or performance. | The works council has to agree before introducing the measurement, and again on the manner in which it is used. |
| 27Recommended | |||
| AW003Role-specific trainingwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | Where the protection need is raised, particular people should be given the task of watching the logging data, it should be the greater part of what they do, and they should be given specialized further training and qualification. A group should be named that is responsible for the evaluation of logging data and for nothing else. |
| DP004Access control and least privilegewhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | An identifier or an entitlement may be granted only on actual need and on what the task requires, and what is no longer needed is removed when the person changes. Anything beyond the standard is granted only after a further justification and a check of it. Every entitlement is set up through separate administrative roles, and the duties the organization has declared incompatible are held apart by the entitlement system itself. |
| DP005Privileged access managementwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | An administrative activity should be one that two people have to carry out together. Where multi-factor authentication is used the factors are split between the two of them, and where a password is used it is divided in two and each of them holds a half. This sits at the grade the compendium keeps for a raised protection need. |
| DP006Access recertificationwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | Which identifiers, groups, and rights profiles have been permitted and created is documented, and the documentation is checked at intervals against the state the entitlements are actually in, and against whether what has been granted still answers to the security requirements and to what the users now do. The documentation itself is protected from unauthorized access. |
| DP013Separation of program datawhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | The collected security relevant data are to be held centrally, as a log server assembly placed in a network segment set up for the purpose, and the administrators who operate it should hold no entitlement to alter or delete what it has recorded. The separation is of the store from the estate it observes and from the people who run that estate. |
| GV005Shared definitions and severity scalewhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | What counts as a security incident has to be defined clearly and marked off, as far as it can be, from the disruptions of ordinary operation. Everyone involved in handling one has to know the definition, and the definition and the thresholds at which it is met should follow the protection the affected processes, systems, and applications need. A single procedure for classifying incidents and disruptions should be settled, and agreed between security management and the function that handles ordinary faults. |
| GV006Escalation triggers and ownerswhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | An escalation strategy is formulated beyond the communication and contact strategy and agreed between the people who handle ordinary faults and information security management. It should say unambiguously who is to be brought in, by what route, and when, for each kind of detected or suspected disturbance, what measures an escalation leads to, and how the response is to run. The contact strategy under it settles who must be informed and who may be, by whom, in what order, and in what depth, and who may pass information about an incident outside. It is reviewed at intervals and the paths are practiced in exercises. |
| IR001Insider incident playbookswhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | A policy on handling security incidents has to be drawn up, stating its purpose and its aim and settling every aspect of the handling, with rules of conduct described for the different kinds of incident and instructions that are addressed to their audience and can actually be applied. It has to be known to everyone, agreed with the IT function, adopted by the leadership of the organization, and checked and updated at intervals. |
| IR005Coordination with security operationswhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | The interfaces between ordinary fault handling, emergency management, and security management are to be analyzed, and the resources they might share identified. The staff who handle ordinary faults are to be made aware of what handling a security incident involves, and security management should have read access to the incident management tools in use. |
| IR008Escalation to crisis managementwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | The handling of a security incident is to be settled with emergency management, and where the organization keeps a separate role for ordinary fault handling that role is brought in too. The interfaces to crisis and emergency management are defined and documented, which staff answer for which task is settled, how they are to be communicated with is settled, and the contact people are to be reachable at all times. |
| IR009Post-incident reviewwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | An incident should be worked through afterwards to a standard form, examining how quickly it was detected and remedied, whether the reporting routes worked, whether there was enough information to assess it, and whether the detection measures were effective. What is learned is used to write instructions for comparable incidents, made known to the groups they concern, and updated as more is learned. The leadership of the organization is told about the incidents once a year, and at once where something has to be done immediately. |
| IV001Internal reporting channelwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | Reporting routes suited to each kind of incident should be built, so that an employee can report quickly and simply over channels that are reliable and can be trusted, and where a central point is set up for it that is communicated to everyone. A communication and contact strategy should state who must be informed and who may be, by whom, in what order, and in what depth, and who passes information about an incident outside. That nobody unauthorized passes it on is to be ensured. |
| IV004Investigation plan and scopewhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | A forensic examination should begin by defining its objectives, or the work it has been asked to do, as concretely as they can be put, and only then identifying the data sources it needs. A written guide should set out how evidence is to be secured, naming the procedures, the technical tools, the legal conditions, and what has to be documented. |
| IV005Forensic acquisitionwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | The order in which data are secured follows how volatile they are: what is quickly lost is taken first, then what is not, the contents of fixed storage, and last of all the backups. A storage medium should be duplicated forensically in full, and where that cannot be done, on memory or on a storage network partition, the method chosen is the one that alters least. Originals are kept sealed, written cryptographic checksums are made of them and held separately in several copies and secured against alteration, and for the result to be usable in court a witness should confirm how it was done and attest the checksums. Only trained staff or a forensic service provider should carry out the securing. |
| IV006Chain of custodywhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | Every step taken in securing evidence should be documented, and the documentation should show without a gap how the original evidence was handled, which methods were used, and why the people responsible chose them. The originals should be stored so that only the staff conducting the examination, known by name, can reach them. |
| IV007Legal hold and preservationwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | It should be settled in advance which secondary data, log data and traffic captures among them, are held against a possible securing of evidence, in what way, and for how long within what the law allows. |
| IV011Engagement of external investigatorswhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | An organization without a forensic team of its own has to identify possible service providers in the preparation phase, before there is anything to examine, and to document which of them come into question. Call-off agreements or framework contracts with them should be concluded so that an incident can be examined sooner. |
| IV012Case closure and dispositionwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | A period is fixed for how long secured originals and evidence are kept, and when it has run out it is examined whether they still have to be. After it, evidence should be securely deleted or destroyed and the original media returned. |
| IV013Investigator competencewhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | Everyone who is responsible for it should know how to secure traces correctly and how to use the forensic tools, and suitable training should be given for that. |
| MD002Log collection and centralizationwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | A logging policy of its own is drawn up, saying how, where, and what is logged, with the kind and the extent of it following the protection the information needs. All security relevant events on systems and applications are logged, the clocks of everything that logs are kept synchronized and the date and time format made uniform, and it is checked at defined intervals that the logging still works. Data protection law and the co-determination rights of the workforce representation are to be kept to, logging data are deleted on a defined process, and their uncontrolled deletion or alteration is prevented technically. The data should be held centrally, on a log server assembly in a network segment set up for it, and filtered, normalized, aggregated, and correlated for evaluation while a copy is kept in unaltered original form. The administrators who run it should have no entitlement to change or delete what has been recorded. |
| MD005Network and egress monitoringwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | Proxies that break the encrypted connection should be placed at the boundary to external networks so that what passes can be examined, they are themselves protected from unauthorized access, and security relevant events on them are detected automatically. An organizational rule is to be drawn up stating the data protection conditions under which the log data may be evaluated by hand. |
| MD021Detection coverage assessmentwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | The detection systems in place and the measures taken should be examined in regular audits for whether they are still current and still effective. The metrics that arise when a security relevant event is taken in, reported, and escalated are evaluated, the results of the audit are documented so that they can be followed, and they are compared against the state the systems are supposed to be in. A departure from it is pursued. |
| PS001Pre-employment screeningwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | A new employee should be checked for trustworthiness before being hired, and everyone taking part in the selection should check whether what the candidate says bearing on that is credible. The curriculum vitae is examined for correctness, plausibility, and completeness, and whatever looks conspicuous in it is followed up. Separately, the qualifications a post requires are to be formulated exactly, and a post filled only by someone who has them. |
| PS002Risk-tiered screening standardswhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | Depth follows the area and not the person. In a high security area a further check is carried out on top of the basic check of trustworthiness, and where the work touches classified material the person goes through the statutory security clearance. This sits at the grade the compendium keeps for a raised protection need, which is itself settled by an individual risk analysis. |
| PS005Contractor and third-party personnel standardswhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | External personnel are bound to the same laws, rules, and internal regulations as employees. Those brought in briefly or once are to be supervised in security relevant areas, and those there longer are inducted as employees are and given a deputizing arrangement of their own. A written confidentiality agreement is concluded before an external person is given access to confidential information, and on leaving they hand over their work and give back whatever access they were issued. |
| PS006Onboarding security briefingwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | At the start of the employment the person is informed of the rules, the instructions, and the procedures that exist, and a checklist and a named contact should be set up to carry it. Every employee is obliged to keep to the law and to the internal rules, has to know the legal frame of their own work, and has their tasks and responsibilities documented. They are told that what they receive at work is for internal use only, and made aware that they protect the organization’s information security outside working hours and away from its premises as well. |
| PS008Leaver processwhere writtenRecommended | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | The successor is briefed in time, by the person leaving where that can be done, and where it cannot the person leaving writes the documentation instead. Every document, key, device, badge, and access right received in the course of the work is collected back. The obligations of confidentiality are put to the person once more before they go, and to keep conflicts of interest from arising a non-competition clause and a waiting period should be agreed. Contingency and other plans are updated, and every part of the organization affected is told, the security staff and the IT function among them. |
