Skip to content

Risk Management

LEGAL BASIS

§30(2) No. 1 BSIG – Concepts relating to risk analysis and to information technology security

Information Security Policy

BAUER GROUP operates an Information Security Management System (ISMS) covering the protection goals of confidentiality, integrity, availability and authenticity. The information security policy is reviewed and approved annually by management.

Systematic Risk Analysis

The risk analysis follows a standardized process:

StepDescriptionInterval
Asset identificationRecording of all critical systems, data and processesOngoing
Threat analysisIdentification of relevant threat scenariosAnnually
Vulnerability assessmentTechnical and organizational vulnerabilitiesAnnually + event-driven
Risk assessmentLikelihood × impactAnnually
Risk treatmentAvoid, mitigate, transfer, acceptAfter assessment

Risk Treatment Options

OptionDescriptionApplication
AvoidEliminate the risk sourceWhen economically justifiable
MitigateTechnical/organizational measuresStandard approach
TransferInsurance, outsourcing to qualified providerFor residual risks
AcceptConscious acceptance with documentationOnly for low residual risk, management approval

Asset Inventory

All IT systems, components and processes are recorded in a central inventory:

  • Server systems – Physical and virtual servers with location, purpose and owner
  • Network components – Firewalls, switches, routers with firmware versions
  • Applications – Custom and third-party software with license and support status
  • Data assets – Classification by protection need (normal, high, very high)
  • Cloud services – External services with provider, location and contract status

Standards and Requirements

Implementation is based on:

  • ISO/IEC 27001:2022 – Information security management systems
  • BSI IT-Grundschutz – Methodological framework for risk analysis
  • Implementing Regulation (EU) 2024/2690 – binding for BAUER GROUP as a DNS service provider and managed service provider; its technical and methodological requirements take precedence (§30(3) BSIG)

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT