The BSI IT-Grundschutz Compendium defines mandatory requirements for protecting IT systems and processes in thematic modules. For data protection, module CON.3 (Data Backup Concept) is central.

CON.3 defines basic requirements (A), standard requirements (B) and requirements under heightened protection needs ©. Particularly relevant for ransomware protection: CON.3.A1 requires influencing factors to be identified and RTO/RPO to be documented per system. CON.3.A10 requires separate backup of particularly sensitive data with enhanced measures. CON.3.A11 requires regular recovery tests. CON.3.A14 requires, under heightened protection needs, physical separation of backup media from the network — this is the BSI requirement that directly points to a physical air gap.

Further relevant modules: OPS.1.2.2 (archiving) with requirements for protection against manipulation and unauthorized access to archived data. SYS.1.1 (general system hardening). For healthcare and KRITIS operators, there are additional sector-specific requirements.

The IT-Grundschutz is mandatory for German federal authorities and the central reference framework for KRITIS operators when demonstrating adequate security measures to the BSI.

Frequently asked questions

For German federal authorities, IT-Grundschutz is mandatory. For KRITIS operators, it is the central reference framework for demonstrating adequate security measures (§8a BSIG). For NIS2-affected organizations, it is a recognized method for implementing NIS2 requirements. For all other organizations, it is voluntary but recommended as a proven framework.
CON.3.A14 is the requirement for heightened protection needs: it requires physical separation of backup media from the network. This means: a network-bound backup system does not satisfy CON.3.A14. A physical air gap at hardware level — the system is physically non-addressable after the backup window — is the direct technical response to this requirement.