usd AG BSI KRITIS

KRITIS Audits: BSI Specifies Maturity Levels for Verification Assessment

30. January 2025

In January, the German Federal Office for Information Security (BSI) published the document „Reife- und Umsetzungsgradbewertung im Rahmen der Nachweisprüfung (RUN)“ (Maturity and implementation level assessment as part of the verification audit). This document defines how maturity and implementation levels are assessed in the context of the § 8a BSIG assessment. The new criteria are intended to ensure greater transparency and standardize the provision of evidence to the BSI for operators and auditing bodies. The new requirements apply to assessments that are completed after April 1, 2025.

The current KRITIS verifications already include an assessment of the maturity levels of the information security management systems (ISMS) and business continuity management systems (BCMS) as well as the degree of implementation of the systems used to detect attacks, which is carried out by the auditing body in each case.

In connection with the newly presented method for determining the degree of maturity and implementation, the following subject areas will be added, for which the respective degree of implementation will also be determined in future as part of the regular verifications to be provided:

• Organizational measures (OrgM)
• Personal measures (PerM)
• Physical measures (PhyM)
• Technical measures (TecM)

Specific measures have been assigned to the new subject areas, leaving room for individual or sector-specific adjustments.

I welcome the development of the BSI now introducing maturity assessments for all subject areas. Audits are often not black or white - especially in complex organizations and environments. However, I have a feeling that this change will de-facto push operators to use the KdA (“Specification of the requirements for the measures to be implemented in accordance with Section 8a (1) and (1a) BSIG”) and individual audit bases will increasingly take a back seat as further mappings to the RUN become necessary to report the maturity level accordingly. Whether this will have unintended consequences at the end of the day remains to be seen.


Jan Kemper, Head of Security Audits

With the introduction of the RUN, the BSI is pursuing the goal of providing operators and auditing bodies with a standardized basis for assessment and highlighting the need for action.

I like the fact that the BSI wants to further standardize the KRITIS audit and is taking a step in this direction with the RUN. The maturity levels themselves are very deterministic and are based on the measures defined by the BSI. The specific mapping makes them a de facto standard. Other standards may still be used, but these in turn must have a mapping to the BSI requirements so that the maturity levels can be calculated. From our point of view as auditors, this de facto standard is a positive thing, as there is now a mandatory and therefore uniform audit basis that can be expanded to include industry-specific controls.


Vinzent Ratermann, expert for the IT security of critical infrastructures


If you need support or advice on your KRITIS auditcontact us. We will be happy to help you.

Also interesting:

Andrea Tubach is the new CEO of usd AG

Andrea Tubach is the new CEO of usd AG

Yesterday, at usd's Annual General Meeting and the subsequent meeting of the new Supervisory Board, long-prepared personnel changes were unanimously approved and then celebrated with an atmosphere of deep friendship: Andrea Tubach takes over as CEO. The founder and...

Security Advisories on Vtiger

Security Advisories on Vtiger

The pentest professionals at usd HeroLab examined Vtiger Open Source Edition 8.2.0 during the execution of their pentests. Our analysts discovered two vulnerabilities in the Vtiger software that allow low-privileged authorized users to upload files and execute...

NIS-2 Draft Bill under Examination: Everything You Need to Know

NIS-2 Draft Bill under Examination: Everything You Need to Know

A few days ago, the AG KRITIS published the latest draft bill on the NIS-2 Implementation Law (NIS2UmsuCG) on its website. Which requirements could become relevant for you if the law is passed in this version? Our experts have analyzed the draft for you and summarized...

Categories

Categories