Knowledge Base → Privacy engineering → 🛡 SDM & BSI Grundschutz
🛡 SDM & BSI Grundschutz
German Standard Data Protection Model (SDM) and BSI IT-Grundschutz — the methodology that maps legal data-protection requirements to concrete technical & organisational measures. Central to inspection readiness in DE/EU.
Key resources (38)
- Martin Rost – Publizist & Datenschützer
- Prüfung & Zertifizierung nach BSI TR-03161
- BSI - FAQ zur TR-03161 — BSI TR 03161 FAQ
- BSI zu Zertifizierung nach TR 03161 (und Rezertifizierung) — BSI zu Zertifizierung nach TR 03161 (und Rezertifizierung)
- TR 03183 node — Das Bundesamt für Sicherheit in der Informationstechnik (BSI) hat die Technische Richtlinie TR-03183 Teil 1 „General Requirements" in der Version 1.0 veröffentlicht. Mit ihren IT-Sicherheitsempfehlungen für Produkte dient sie als Einstiegshilfe in den Cyber Resilience Act (CRA). Die BSI TR-03183-1: Cyber Resilience Requirements - Part 1: General requirements Version 1.0.0 besitzt keinen verpflichtenden oder verbindlichen Charakter. Zielgruppe sind insbesondere Hersteller, die noch keine ausgereiften IT-Sicherheitsprozesse im Rahmen ihrer Entwicklung und Schwachstellenbehandlung etabliert haben. Mit einem strukturierten Ansatz zur risikobasierten Auswahl von Cybersicherheitsmaßnahmen können die Anforderungen der TR-03183-1 als Orientierung für die Klasse der Standardprodukte des CRA dienen. Aufbauend auf ihrer Risikoanalyse können Hersteller identifizieren, welche Maßnahmen sie für ein angemessenes Cybersicherheitsniveau umsetzen sollten.
- BSI - AI Audit and Assurance Assessment Architecture (A5) — Bundesamt für Sicherheit in der Informationstechnik: Das BSI hat einen „Prüfkatalog vertrauenswürdige KI-Systeme“ (AI Audit and Assurance Assessment Architecture, A5) als Community Draft zur Kommentierung veröffentlicht. Der Katalog soll der Grundstein für eine modulare und erweiterbare Prüfarchitektur für KI-Systeme sein. Er richte sich an alle Akteure entlang der KI-Wertschöpfungskette, von Anbietern über Betreiber bis hin zu den mit Entwicklung, Betrieb und Aufsicht betrauten Personen. Anmerkungen und Anregungen können bis zum 31. August 2026 beim BSI eingereicht werden.
- BSI veröffentlicht Prüfkatalogsentwurf zur Vertrauenswürdigkeit von KI-Systemen — BSI veröffentlicht Prüfkatalogsentwurf zur Vertrauenswürdigkeit von KI-Systemen - heise online
- BSI - C3A - Criteria enabling Cloud Computing Autonomy
- C3A Cloud Computing Autonomy
- BSI - Presse - Praxisleitfaden für sichere Datenbanksysteme veröffentlicht — BSI: Praxisleitfaden für sichere Datenbanksysteme
- BSI: Praxisleitfaden für sichere Datenbanksysteme — BSI: Praxisleitfaden für sichere Datenbanksysteme
- Nicholas Carlini - Black-hat LLMs – unprompted 2026
- DLA Piper: Data Protection Laws of the World - 2026 — BSI veröffentlicht ersten Leitfaden für IT-Grundschutz++ | heise online
- Tr02102 node — 🏛️ BSI TR-02102 Kryptographische Verfahren: Empfehlungen und Schlüssellängen
- 260211 Ende klassischer Verschluesselungsverfahr — 🏛️PRESS RELEASE ▶️ In its annual update of cryptographic recommendations (TR-02102), the German Federal Office for Information Security (BSI) advocates for the first time an expiration date for classical asymmetric encryption methods. ▶️ According to the BSI, these methods should no longer be used in isolation by the end of 2031, or as early as the end of 2030 for highly sensitive applications. Instead, they should be combined in hybrid form with post-quantum cryptography. ▶️ For classical signature methods, the discontinuation of their sole use is planned for the end of 2035.
- BSI - Bundesamt für Sicherheit in der Informationstechnik - Leitfaden für den Einsatz von Cloud-Lösungen im VS-Kontext der Bundesv — Das vorliegende Dokument ist auf den Geheimhaltungsgrad VS - Nur für den Dienstgebrauch (VS-NfD) schwerpunktmäßig ausgerichtet.
- BSI veröffentlicht Leitfaden für Cloud-Lösungen im Geheimschutzkontext
- BSI: NIS-2-Starterpaket — BSI: NIS-2-Starterpaket
- BSI - Stand der Technik — State of the Art - BSI (Germany)
- GitHub - BSI-Bund/Stand-der-Technik-Bibliothek: Über die Stand-der-Technik-Bibliothek stellt das BSI seine Vorschriften und Richtl — State of the Art - BSI (Germany)
- BSI - Bundesamt für Sicherheit in der Informationstechnik - Design Principles for LLM-based Systems with Zero Trust — In this collaborative German-French publication titled “Design Principles for LLM-based Systems with Zero Trust”, central design principles are presented for the secure deployment of large language model (LLM) systems. Co-authored by the French Agence nationale de la sécurité des systèmes d’information (ANSSI) and Germany’s Federal Office for Information Security, the paper identifies typical risks associated with using LLM systems and proposes appropriate countermeasures. It recommends, among other strategies, limiting access rights for these systems as needed, making their decision-making processes transparent, and ensuring that critical decisions are made under human supervision. The aim of the publication is to raise awareness among IT professionals about the challenges involved in deploying LLM systems.
- BSI: Design Principles for LLM-based Systems with Zero Trust — BSI: Design Principles for LLM-based Systems with Zero Trust
- Whitepaper Bias KI 250724 — BSI veröffentlicht Whitepaper zu Bias in der künstlichen Intelligenz
- GitHub - BSI-Bund/QUAIDAL · GitHub — BSI page for AI
- GitHub - BSI-Bund/QUAIDAL-SRC · GitHub — The German BSI has published quality criteria for AI training data in the AI lifecylce.Ten criteria supported by 143 metrics and methods.
- CNIL issues guidance on mobile apps (citation — link removed)
- Datenqualität: BSI legt Latte zum Training von KI-Systemen hoch — The German BSI has published quality criteria for AI training data in the AI lifecylce.Ten criteria supported by 143 metrics and methods.
- BSI - Bundesamt für Sicherheit in der Informationstechnik - Sektorspezifische Fragen und Antworten zu NIS-2 — Hessel: Artikel zu NIS2 - Umsetzung der NIS-2-Richtlinie in Deutschland – Mehr Cybersicherheit für Unternehmen
- BSI Grundschutz con2
- BSI page for AI — Article in German
- BSI, Pressemitteilung vom 30.9.2025, — BSI, Pressemitteilung vom 30.9.2025,
- Federal Office for Information Security: “AI Security Concerns in a Nutshell” ( 2023. — NCSC: “Guidelines for secure AI system development” ( 2023.
- German SDM - official English translation — SDM v31a english
- I just threw this JSON here into this tool here.. — OSCAL - BSI state of the art
- SDM 3.0
- SDM v31a english — SDM v31a english [[sdm:bsi_con2|BSI Grundschutz con2] [[sdm:sdm_30| SDM 3.0] - [[sdm:sdm_30_english_inofficial|local inofficial English translation] German SDM - official English translation [[germany:stiftung_datenschutz_anonymization|Anonymization - Stiftung Datenschutz] EU AI Act has - Regulation 20241689 Martin Rost, SDM 2.Auflage
- several documents, requirements especially in and — Germany. BSI published - an AI audit catalog “Assurance Assessment Architecture” A5 - Community draft for comments
- Webinar vom 07.01.2026 → — Webinar vom 07.01.2026 → Prozesszertifizierung zum Nachweis sicherer Release-Zyklen in 2 Stages 1. Stage Dokumentenprüfung 2. Stage Prozessprüfung Zertifikate 3 Jahre Gültigkeit mit jährlichen Überwachungsauditskeine separaten Prüfstellen. BSI Grundschutzauditoren werden dafür qualifiziert (im ersten Schritt sind ca. 30 Auditoren geplant. BSI wird Liste veröffentlichen) Zertifizierungsprozess soll noch im Januar starten Prozesszertifizierung nach TR-3185 ist prinzipiell freiwillig, angesichts der Ausgangssituation aber quasi alternativlos. Liegt eine Zertifizierung nach der TR-3185 vor, entfallen Re-Zertifizierungen und Maintenance-Verfahren nach der TR-3161 sowie die üblichen Änderungsmitteilungen bei UpdatesPatches. Start des Verfahrens noch für den Januar 2026 geplant. Laufzeit der Zertifikate nach der TR-3185: 3 Jahre mit jährlichen Überwachungs-Audits (Managementsystemzertifizierung). Für die Auditierung wird auf BSI-Grundschutz-Auditoren zurückgegriffen, eine Liste der möglichen Auditoren wird zeitnah vom BSI bereitgestellt.
See also: security-regulation (NIS2 / CRA / DORA / ISO 27001) is collected in Security & Resilience.
🆕 Recent additions (auto)
- 2026-09-07 Hungary: Sanction against online shop due to insufficient information about third-country transfer — Hungary’s data protection authority imposed a fine of approximately 41,500 euros on the operator of an online shop because they failed to provide their customers with transparent and understandable information about the purposes, legal basis, and duration of data processing, as well as about data transfers to third countries. This resulted in violations of Article 5 para (Datenzirkus (BvD))
- 2026-09-07 BSI: Between Memes and Manipulation – Fake News in the Everyday Life of Young People — In this BSI podcast episode (duration approximately 40 minutes), it discusses what happens when young people are daily confronted with a flood of contradictory information, influencer opinions, and algorithmically curated content. It also addresses what role parents, schools, and society play in promoting media literacy (Datenzirkus (BvD))
- 2026-09-07 BSI: Information Package for Secure Use of Generative AI — The BSI’s information package for secure use of generative AI includes, among other things, three sub-areas: Security through AI: How can AI models contribute to improving IT security? Threats through AI: What measures can be taken to protect against AI-assisted attacks? (Datenzirkus (BvD))
- 2026-09-07 BSI: TR03174 – Secure Applications in the Financial Sector — The BSI published guidance for manufacturers of financial sector applications for mobile devices, guidance for manufacturers of web applications in the financial sector, and guidance for manufacturers of financial sector applications for back-end systems; these can also be considered as guidelines for back-end systems that process or store sensitive data. 1.34 ENISA: Cybersecurity Assessment Market 2021–2025 (Datenzirkus (BvD))
Curated from the personal reference library. Add items directly on this page.