What is…
BSI IT-Grundschutz
The BSI IT-Grundschutz Compendium defines mandatory requirements for protecting IT systems and processes in thematic modules. For data protection, module CON.3 (Data Backup Concept) is central.
CON.3 defines basic requirements (A), standard requirements (B) and requirements under heightened protection needs ©. Particularly relevant for ransomware protection: CON.3.A1 requires influencing factors to be identified and RTO/RPO to be documented per system. CON.3.A10 requires separate backup of particularly sensitive data with enhanced measures. CON.3.A11 requires regular recovery tests. CON.3.A14 requires, under heightened protection needs, physical separation of backup media from the network — this is the BSI requirement that directly points to a physical air gap.
Further relevant modules: OPS.1.2.2 (archiving) with requirements for protection against manipulation and unauthorized access to archived data. SYS.1.1 (general system hardening). For healthcare and KRITIS operators, there are additional sector-specific requirements.
The IT-Grundschutz is mandatory for German federal authorities and the central reference framework for KRITIS operators when demonstrating adequate security measures to the BSI.