Zum Inhalt springen
Beta

Public sector

Zuletzt aktualisiert am

For workloads run by or for German public bodies: federal, state and municipal administration, and the operators who build for them. The mountain is the same as for everyone; this page maps what the public-sector route demands of it, and adds nothing.

What binds here, and what each regime asks of an architecture.

BSI IT-Grundschutz. The BSI’s methodology for information security, and the frame public bodies in Germany are assessed in. Its protection needs assessment is a data classification by another name, which is why SEC 3 stops being optional here, and it makes SEC 1.1, deriving the baseline from the frameworks you are assessed against, a statement with a known answer.

BSI C5. The cloud attestation public procurement asks a cloud provider for. STACKIT holds C5 Type 2 , which covers the provider’s side; the attestation explicitly leaves a customer side, and SOV 8.3, the responsibility split per control, is where an assessment establishes that yours is covered.

OZG. The Onlinezugangsgesetz obliges federal and state government to offer administrative services electronically. For an architecture this means the availability of a citizen-facing service is a statutory matter rather than a commercial one, which changes who sets the reliability targets in REL 1 and what an outage costs.

Citizen data. Administrative data routinely includes special categories of personal data: health, social, tax. That is the profile the Advisory Framework’s Tier 1 criteria describe.

Classified information. Anything carrying a classification, VS-NfD upward, follows the Geheimschutz regime and the BSI’s approval process for the products that handle it. That regime is outside this page.

Procurement. The requirements above arrive in contracts through the EVB-IT terms, the German public sector’s standard contract conditions for IT procurement, whose cloud terms carry the security attestation and the exit obligations into the agreement. The current edition comes from your procurement office rather than from a stable public link. The Deutsche Verwaltungscloud-Strategie points the same direction from the strategy side: administration clouds are expected to be sovereign and portable, which is SOV 10 and SOV 11 said by a buyer.

Tier 1, sovereignty-mandatory. The Advisory Framework decides the tier per workload; this default is what a deviation is recorded against, not a substitute for that decision. It is the default because the Tier 1 criteria read like a description of administrative data: special categories of personal data as a matter of routine, and severe consequences if a foreign authority could compel access to it.

Two qualifications. The tier is established per data set rather than per workload, SOV 1.3, and parts of a public estate legitimately sit lower: an open-data portal or a public website carries none of the data the criteria describe. And deviating from the default is not a finding; an undocumented deviation is. SOV 1.2 is where the reasoning lands.

Four pillars shift; each shift traces to the map.

Sovereignty & Compliance leads. At Tier 1 nearly every question in the pillar binds as mandatory, per the tier table in the pillar overview, and the evidence duties, SOV 7 and SOV 8, are what an audit against C5 and IT-Grundschutz actually consumes.

Security is elevated, and externally framed. The baseline is not yours to choose: IT-Grundschutz supplies the frame, which turns SEC 1 from a design question into a conformance question and makes the protection needs assessment the input to SEC 3.

Reliability is elevated for citizen-facing services. The OZG makes availability a statutory duty, so REL 1 targets derive from a service mandate rather than from revenue, and the deadline-day peak, the day a filing period ends, is the load REL 7 sizes for.

Operational Excellence is elevated as the evidence machine. Infrastructure as code with reviewed changes, OPS 3, is the change record an auditor reads, and SOV 7.4’s evidence-as-by-product is only reachable through it.

Performance Efficiency, Cost Optimization and Sustainability do not shift. A walkthrough covers them as it covers any workload; public money makes cost attribution no less interesting, it simply does not reweight the route.

What an assessment of a public-sector workload accounts for regardless of where the conversation went: each of these ends evidenced or in the risk register. At Tier 1 the sovereignty pillar’s own tier table already binds most of its questions; the core names the statements a review has to reach an answer on.

Classified information. VS-NfD and above is its own regime with its own approvals, decided case by case with the body’s security officer. Nothing on this page makes a workload fit for classified material.

The parts of an estate below the default. Open-data portals, public websites and other workloads carrying none of the data the Tier 1 criteria describe sit at a lower tier with the reasoning recorded, and the sovereignty pillar’s tier table then releases what does not bind. The core above shrinks accordingly; the recording duty, SOV 1.2, is the one thing that never does.