IT security

IT security is the protection of IT systems, applications and networks and the information processed in them against loss of confidentiality, integrity and availability. Germany's BSI Act calls it “security in information technology” (§ 2 no. 39 BSIG). According to BSI Standard 200-1, it is a subset of information security.

ISMSLast reviewed:

Key takeaways

  • IT security protects information technology systems, components and processes and the information processed electronically in them.
  • The German BSI Act calls it “security in information technology” and defines it in § 2 no. 39 BSIG through availability, integrity and confidentiality.
  • According to BSI Standard 200-1, IT security is a subset of information security, which also covers paper and people's knowledge.
  • Since December 6, 2025, § 30(2), second sentence, BSIG has listed ten minimum measures for essential and important entities.
  • IT security is not only technology: the law also requires policies, training, personnel security and an all-hazards approach.

What is IT security?

IT security is the protection of information technology and the information it processes against loss of confidentiality, integrity and availability. BSI Standard 200-1 describes it as the subset of information security that focuses on protecting electronically stored information and its processing.

In German law, IT security is called “security in information technology”. § 2 no. 39 BSIG defines it as compliance with specific security standards that concern the availability, integrity or confidentiality of information, through safeguards in information technology systems, components or processes or in their use (our paraphrase).

The broader term is information security, which also covers paper and people's knowledge.

The 9 areas of IT security at a glance

IT security covers every layer on which information is processed electronically, from the network through endpoints and applications to cloud services and industrial systems. The breakdown is not standardized.

AreaProtectsTypical measures
Network securityNetworks, gateways, remote accessNetwork segmentation, firewalls, encrypted connections
Endpoint securityWorkstations, servers, mobile devicesHardening, patch management, malware protection, mobile device management
Identity and access managementAccounts, rights, sign-inLeast privilege, multi-factor authentication, privileged access management
Application securityIn-house and third-party softwareSecure development, vulnerability management, penetration testing
Cloud securityCloud services and their configurationClarify shared responsibility, configuration review, access control
Email and communication securityMessages and collaborationSender verification, encryption, phishing protection
Backup and recoveryAvailability of data and systemsBackup strategy, separate storage, restore tests
Detection and responseOngoing operationsLogging and monitoring, SIEM, incident handling
OT and industrial securityControl and production systemsSeparating office and production networks, coordinated maintenance windows

Who gets which access rights, and how they are reviewed, is set out in the access control concept.

What IT security measures does the law require?

The law requires IT security measures from two directions: § 30 BSIG for essential and important entities and Article 32 GDPR for anyone processing personal data.

§ 30 BSIG: duties of essential and important entities

For essential and important entities in Germany, § 30 BSIG has required appropriate, proportionate and effective technical and organizational measures since the NIS2 Implementation Act took effect on December 6, 2025. The measures are meant to prevent disruptions to the availability, integrity and confidentiality of the IT systems, components and processes the entity uses to provide its services (§ 30(1), first sentence); entities must document their compliance (§ 30(1), third sentence). The measures must be based on an all-hazards approach (§ 30(2), first sentence). So the scope is every event that can disrupt these systems, such as fire, power failure or operator error, not only attacks.

§ 30(2), second sentence, BSIG lists ten minimum measures, from policies on risk analysis through incident handling and supply chain security to multi-factor authentication. Training (no. 7) and personnel security (no. 9) alone show that the law means more by IT security than technology. The full list is explained in the glossary entry on NIS2 risk management measures under § 30 BSIG, and what implementation involves in practice in the article on NIS2 requirements.

Article 32 GDPR: a duty for anyone processing personal data

Separately from the BSIG, Article 32 GDPR requires anyone processing personal data to implement technical and organizational measures that ensure a level of security appropriate to the risk. Article 32(1) names, among others, pseudonymization and encryption, the ongoing confidentiality, integrity, availability and resilience of systems, and a process for regularly testing the effectiveness of the measures.

How do companies build IT security in 7 steps?

IT security develops in seven steps that build on each other: first know what to protect, then close the basics, then be able to detect and respond.

  1. Inventory your IT. Record systems, applications, cloud services, accounts and service providers, each with an owner.
  2. Determine protection needs. Assess which systems are critical for which business processes and what damage failure, tampering or data loss would cause.
  3. Close the basics. Updates and hardening, multi-factor authentication, least privilege, separate and tested backups, staff training.
  4. Detect and respond. Logging, monitoring and a rehearsed process for security incidents, including reporting channels.
  5. Plan recovery. Define and rehearse emergency plans and recovery times for critical systems.
  6. Check effectiveness. Vulnerability scans, penetration tests and internal audits show whether the measures actually work.
  7. Embed it in a management system. Policy, roles, risk assessment and regular review, for example in an ISMS under ISO/IEC 27001 or BSI IT-Grundschutz.

The written basis for this is the IT security concept; the guide on creating an IT security concept explains how to build it. Steering these steps through objectives, roles, risk assessment and effectiveness reviews is called IT security management. How to set up the management system for it is covered in the guide to implementing an ISMS.

IT security as part of information security

IT security is narrower than information security because it does not cover paper, rooms or people's knowledge. According to BSI Standard 200-1, cybersecurity extends the field of classic IT security to all of cyberspace, meaning all information technology connected to the internet and comparable networks.

The side-by-side table, including data security, is in the comparison information security vs IT security. How data security differs from data protection is shown in data protection vs data security.

Where Rizzqo sits next to IT security tools

Rizzqo models the layer above IT security tools: which requirement applies to which system, who it is assigned to and whether it is demonstrably met.

Systems, applications, cloud services and service providers are assets, linked to the information and processes they support. A system's asset category and subcategory determine which ISO/IEC 27001 and ISO/IEC 27002 requirements appear on it. From the primary assets, the system takes over only the confidentiality rating and the personal-data flag; integrity and availability are rated on the system itself. Each requirement can be assigned to an owner and only counts as met once it is finalized with a name and timestamp. Risk assessments compute likelihood in percent and impact in euros, and measures run as tasks that can sync with Jira in both directions.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework