MRIS.bd.1 "Mythos-Resistant Hardening of the ISMS" operationalises the Mythos-Hardening Controls as a module with 14 requirements, implementation guidance, a machine-readable edition and a cross-reference table – applied once to the entire information domain.
Since mid-2026, agentic frontier AI models of the "Mythos class" have been broadly available across providers: they find vulnerabilities autonomously, develop exploits within hours and demonstrably execute 80 to 90 percent of tactical attack steps on their own. The IT-Grundschutz Compendium is deliberately technology-neutral and does not yet reflect this new capability class in its modules – many effectiveness assumptions still implicitly rely on the limited patience, speed and capacity of human attackers. The following five shifts name exactly this gap; MRIS.bd.1 addresses it with 14 targeted requirements.
Hours instead of days between a patch and a working exploit – staggered patch cycles break.
Attacks progress faster than human decision chains can react.
Individually inconspicuous steps – the risk only materialises in aggregation.
Nation-state capability becomes available to actors without specialist capacity of their own.
Privileged agents without inventory, identity or audit trail – a new attack surface existing catalogues do not capture.
In the MRIS work comparison (13 security works, four-quadrant methodology), BSI IT-Grundschutz positions at high implementation readiness (8.4) but limited Gen-AI coverage (3.0) – implementation-strong, with a Gen-AI gap (golden ring). MRIS.bd.1 transfers the 13 MHC into exactly this format and closes the gap where IT-Grundschutz practitioners work: in the module.
Qualitative expert scoring (0–10 scale), methodology and rubric fully disclosed in the work. Assessment status: July 2026. Full data, error bars and reading: market comparison on the ISO page →
Each requirement follows the BSI requirement format (MUST/SHOULD), names its level and responsibility and can be adopted individually into the security concept – or, where an ISO/IEC 27001 ISMS is additionally operated, into its Statement of Applicability. Expanding shows the core statement, MHC origin, Annex A reference and the corresponding safeguard in the implementation guidance.
Reassess the effectiveness and probability assumptions of all implemented safeguards against the AI threat landscape; identify friction-based safeguards and feed the results into the risk analysis and the SoA.
FIDO2/WebAuthn (passkeys or hardware tokens) mandatory for privileged, externally reachable and particularly sensitive access; SMS and simple push excluded for new access, legacy with a dated phase-out plan.
At least one immutable or air-gapped copy per business-critical data set, dedicated backup access paths, quarterly documented restore tests.
Detection via behavioural patterns and event correlation aligned with MITRE ATT&CK, with measured and regularly reviewed technique coverage; threat hunting or an MDR service.
Cryptographically verifiable, short-lived identities for privileged workloads; authorisation never based on network location alone; no long-lived plain-text secrets on critical paths.
Complete cryptographic inventory; for long-lived confidential data a documented migration strategy towards quantum-safe mechanisms, hybrid during the transition.
Inventory of all production AI agents; treated as privileged systems with their own technical identity, complete person-attributable logging, named shutdown responsibility, approval for irreversible actions and an allow list for components.
Automatic SBOMs per build including transitive dependencies; exposure to new vulnerabilities determinable within 24 hours; build provenance for critical artefacts.
SAST, DAST and SCA automated on every change; severe findings block the merge; AI-generated code as a distinct risk category; KEV patches for exposed systems under 24 hours.
Predefined playbooks contain unambiguous incidents within minutes; human approval for large blast radius; the automation layer itself is hardened.
Continuously and automatically verify the safeguards listed in the security concept or Statement of Applicability against target states (policy as code); deviations trigger a defined response, the verified share is measured and increased.
Production containers exclusively from signed, verified images of controlled registries, technically enforced; confidential computing with remote attestation for particularly high protection needs.
Data, networks and compute resources separated per tenant, tenant-specific keys; effectiveness demonstrated through regular, preferably automated separation tests.
TLPT with AI scenarios – fragmented chains, parallel multi-vector attacks, AI phishing including deepfake voice; purple teaming between cycles, dated remediation of critical findings.
In IT-Grundschutz, adoption takes place via the modelling and the security concept of the information domain – the methodology has no SoA. If the organisation additionally operates an ISMS under ISO/IEC 27001, every requirement can be adopted directly into its Statement of Applicability; requirements that do not apply are excluded there with justification.
Reassessment (A1) before investment · detection (A4) before response automation (A10) · SBOMs (A8) before pipeline testing (A9) · validation (A14) after the basic implementation.
The Implementation Guide describes a cumulative three-level path per safeguard (Initial, Defined, Managed) with stage gates and key figures for management reporting.
A8/A9 for organisations without in-house development (the principle works through procurement), A13 without multi-tenant operation. NIS2/DORA reporting duties run via incident handling.
License: CC BY-NC 4.0 · © 2026 Richard Peddi · Use within IT security concepts based on IT-Grundschutz is expressly permitted.
MRIS.bd.1 is a user-defined module within the meaning of the IT-Grundschutz methodology (BSI Standard 200-2), which explicitly provides for custom modules covering topics not yet addressed – an independent, privately produced work (CC BY-NC 4.0, © 2026 Richard Peddi). The module has not been reviewed, approved or certified by the BSI, is not part of the IT-Grundschutz Compendium and does not replace any certification. "IT-Grundschutz" and "BSI" designate standards and institutions of the German Federal Office for Information Security; MRIS has no affiliation with the BSI. No legal or certification advice; use at your own responsibility.