Skip to main content
Back to Glossary
Documents

IT Security Concept

Document required in IT tenders describing the technical and organizational measures to ensure information security.

What is an IT Security Concept?

An IT Security Concept is a key document in public IT tenders. It describes the technical and organizational measures (TOMs) a bidder implements to ensure the confidentiality, integrity, and availability of data and IT systems. In public procurement, the IT security concept is often a mandatory suitability or award criterion.

Legal Framework

Legal basisRelevance
BSI IT-GrundschutzGerman standard security methodology
ISO 27001International ISMS standard
GDPR Art. 32Technical and organizational measures
IT Security Act 2.0Requirements for critical infrastructure operators
EVB-IT Cloud TermsIT security requirements for cloud services

Contents of an IT Security Concept

Organizational security: ISMS, security organization, employee training, incident response, business continuity management.

Technical security: Network security, encryption, authentication and access control, patch management, backup and recovery.

Physical security: Data center security, location and geo-redundancy, environmental monitoring.

Data protection: Personal data processing, data processing agreement, data location (EU/EEA requirement), deletion concept.

Requirement Levels in Tenders

LevelRequirementTypical Tender
BasicBSI baseline protectionSimple IT services
StandardBSI standard protectionGovernment IT
EnhancedBSI core protection + ISO 27001Critical infrastructure
Very highBSI C5 / ISO 27017 / SOC 2Cloud services for authorities

Common Mistakes in Bids

  1. Too generic security descriptions without reference to the specific contract
  2. Missing certificates (ISO 27001 or BSI Grundschutz)
  3. Unclear data location statements
  4. No incident response description
  5. Forgetting subcontractor security requirements

Patterno Helps

With Patterno-HIT, you can specifically find IT tenders with specific security requirements. Our AI recognizes requirements like "BSI Grundschutz," "ISO 27001," "C5 attestation," or "critical infrastructure" and filters tenders matching your security profile.

Find Matching Tenders

With Patterno you automatically find relevant tenders - based on your profile.

Start for free