Public sector
Zuletzt aktualisiert am
For workloads run by or for German public bodies: federal, state and municipal administration, and the operators who build for them. The mountain is the same as for everyone; this page maps what the public-sector route demands of it, and adds nothing.
The regulatory map
Section titled “The regulatory map”What binds here, and what each regime asks of an architecture.
BSI IT-Grundschutz. The
BSI’s methodology
for information security, and the frame public bodies in Germany are assessed in. Its protection
needs assessment is a data classification by another name, which is why SEC 3 stops being
optional here, and it makes SEC 1.1, deriving the baseline from the frameworks you are
assessed against, a statement with a known answer.
BSI C5. The
cloud attestation
public procurement asks a cloud provider for. STACKIT holds
C5 Type 2 , which covers the
provider’s side; the attestation explicitly leaves a customer side, and SOV 8.3, the
responsibility split per control, is where an assessment establishes that yours is covered.
OZG. The Onlinezugangsgesetz obliges federal and
state government to offer administrative services electronically. For an architecture this means
the availability of a citizen-facing service is a statutory matter rather than a commercial one,
which changes who sets the reliability targets in REL 1 and what an outage costs.
Citizen data. Administrative data routinely includes special categories of personal data: health, social, tax. That is the profile the Advisory Framework’s Tier 1 criteria describe.
Classified information. Anything carrying a classification, VS-NfD upward, follows the Geheimschutz regime and the BSI’s approval process for the products that handle it. That regime is outside this page.
Procurement. The requirements above arrive in contracts through the EVB-IT terms, the German
public sector’s standard contract conditions for IT procurement, whose cloud terms carry the
security attestation and the exit obligations into the agreement. The current edition comes from
your procurement office rather than from a stable public link. The Deutsche
Verwaltungscloud-Strategie points the same direction from the strategy side: administration
clouds are expected to be sovereign and portable, which is SOV 10 and SOV 11 said by a
buyer.
The tier default
Section titled “The tier default”Tier 1, sovereignty-mandatory. The Advisory Framework decides the tier per workload; this default is what a deviation is recorded against, not a substitute for that decision. It is the default because the Tier 1 criteria read like a description of administrative data: special categories of personal data as a matter of routine, and severe consequences if a foreign authority could compel access to it.
Two qualifications. The tier is established per data set rather
than per workload, SOV 1.3, and parts of a public estate legitimately sit lower: an open-data
portal or a public website carries none of the data the criteria describe. And deviating from the
default is not a finding; an undocumented deviation is. SOV 1.2 is where the reasoning lands.
The pillar weighting
Section titled “The pillar weighting”Four pillars shift; each shift traces to the map.
Sovereignty & Compliance leads. At Tier 1 nearly every question in the pillar binds as
mandatory, per the tier table in the pillar overview, and the evidence
duties, SOV 7 and SOV 8, are what an audit against C5 and IT-Grundschutz actually consumes.
Security is elevated, and externally framed. The baseline is not yours to choose:
IT-Grundschutz supplies the frame, which turns SEC 1 from a design question into a conformance
question and makes the protection needs assessment the input to SEC 3.
Reliability is elevated for citizen-facing services. The OZG makes availability a statutory
duty, so REL 1 targets derive from a service mandate rather than from revenue, and the
deadline-day peak, the day a filing period ends, is the load REL 7 sizes for.
Operational Excellence is elevated as the evidence machine. Infrastructure as code with
reviewed changes, OPS 3, is the change record an auditor reads, and SOV 7.4’s
evidence-as-by-product is only reachable through it.
Performance Efficiency, Cost Optimization and Sustainability do not shift. A walkthrough covers them as it covers any workload; public money makes cost attribution no less interesting, it simply does not reweight the route.
The statement core
Section titled “The statement core”What an assessment of a public-sector workload accounts for regardless of where the conversation went: each of these ends evidenced or in the risk register. At Tier 1 the sovereignty pillar’s own tier table already binds most of its questions; the core names the statements a review has to reach an answer on.
Sovereignty & Compliance
Section titled “Sovereignty & Compliance”| Statement | What makes it mandatory here |
|---|---|
SOV 1.1 | The tier decision is the hinge of the whole route, and it must be Advisory’s, recorded |
SOV 1.2 | Deviations from the Tier 1 default are legitimate only as recorded reasoning |
SOV 2.1 | Placement against the tier is what sovereign procurement bought |
SOV 2.2 | The dependency nobody traced is where residency fails first |
SOV 3.1 | Telemetry carries citizen data the moment a log does |
SOV 3.3 | Backups and exports leave the boundary more quietly than workloads do |
SOV 4.1 | Who can technically decrypt is the question a foreign-access scenario turns on |
SOV 4.2 | Tier 1 is where customer-held keys stop being optional |
SOV 5.1 | Provider reach must be established, not assumed, for the liability the tier names |
SOV 5.2 | Data in use is the gap the strictest criteria ask about |
SOV 6.1 | The processing inventory is what a supervisory question is answered from |
SOV 6.2 | Jurisdiction, not location, is what compelled access follows |
SOV 7.1 | The audit trail is what IT-Grundschutz and C5 audits consume |
SOV 7.2 | Records alterable by the recorded party are not evidence |
SOV 7.3 | Retention here follows the obligation, not the storage bill |
SOV 8.1 | Which frameworks apply is the first thing an assessor establishes |
SOV 8.3 | C5 leaves a customer side; unowned controls are uncovered controls |
SOV 9.1 | The identity control plane decides who can reach everything else |
SOV 11.2 | The exit obligations in the contract are only real if rehearsed |
Security
Section titled “Security”| Statement | What makes it mandatory here |
|---|---|
SEC 1.1 | The baseline is externally given: IT-Grundschutz, and whatever the body adds |
SEC 1.2 | A conformance frame with yearly audits still needs continuous measurement between them |
SEC 3.1 | The protection needs assessment is a classification; unclassified data sets are unfinished work |
SEC 3.3 | Copies of citizen data inherit every obligation of the original |
SEC 4.1 | Administrative access rests on federated identity with strong authentication |
SEC 5.4 | Entitlement review is a standing audit expectation, not a hygiene habit |
SEC 7.2 | Encryption at rest, including every copy, is table stakes for the data profile |
SEC 7.3 | Who is technically able to decrypt is the sovereignty question inside security |
SEC 11.1 | Security records must survive the person they record |
SEC 11.3 | An incident touching citizen data has reporting duties; the response cannot be improvised |
Operational Excellence
Section titled “Operational Excellence”Reliability
Section titled “Reliability”| Statement | What makes it mandatory here |
|---|---|
REL 1.2 | Availability targets follow the service mandate, per flow, not the workload average |
REL 1.4 | A statutory duty needs a named owner for the target that implements it |
REL 8.3 | A restore that has not been rehearsed is a continuity claim, not a capability |
REL 9.3 | The recovery duty is only met if the rehearsal fits the time the mandate allows |
Outside this page
Section titled “Outside this page”Classified information. VS-NfD and above is its own regime with its own approvals, decided case by case with the body’s security officer. Nothing on this page makes a workload fit for classified material.
The parts of an estate below the default. Open-data portals, public websites and other
workloads carrying none of the data the Tier 1 criteria describe sit at a lower tier with the
reasoning recorded, and the sovereignty pillar’s tier table then releases what does not bind.
The core above shrinks accordingly; the recording duty, SOV 1.2, is the one thing that never
does.
Related
Section titled “Related”- Sovereignty & Compliance: the pillar the route leans on most
- Security: the pillar the external frame lands on