MRIS.bd.1 · User-Defined Module for IT-Grundschutz

The 13 MHC in IT-Grundschutz format

MRIS.bd.1 "Mythos-Resistant Hardening of the ISMS" operationalises the Mythos-Hardening Controls as a module with 14 requirements, implementation guidance, a machine-readable edition and a cross-reference table – applied once to the entire information domain.

Free · CC BY-NC 4.0 · No registration · For CISOs and IT-Grundschutz practitioners

Threat landscape

Five threats the Compendium does not capture with regard to GenAI-accelerated attacks

Since mid-2026, agentic frontier AI models of the "Mythos class" have been broadly available across providers: they find vulnerabilities autonomously, develop exploits within hours and demonstrably execute 80 to 90 percent of tactical attack steps on their own. The IT-Grundschutz Compendium is deliberately technology-neutral and does not yet reflect this new capability class in its modules – many effectiveness assumptions still implicitly rely on the limited patience, speed and capacity of human attackers. The following five shifts name exactly this gap; MRIS.bd.1 addresses it with 14 targeted requirements.

G1

Patch-exploit collapse

Hours instead of days between a patch and a working exploit – staggered patch cycles break.

G2

Time compression

Attacks progress faster than human decision chains can react.

G3

Micro-step fragmentation

Individually inconspicuous steps – the risk only materialises in aggregation.

G4

Capability decoupling

Nation-state capability becomes available to actors without specialist capacity of their own.

G5

Unregulated AI agents

Privileged agents without inventory, identity or audit trail – a new attack surface existing catalogues do not capture.

Market comparison

Where IT-Grundschutz stands today – and what MRIS.bd.1 changes

In the MRIS work comparison (13 security works, four-quadrant methodology), BSI IT-Grundschutz positions at high implementation readiness (8.4) but limited Gen-AI coverage (3.0) – implementation-strong, with a Gen-AI gap (golden ring). MRIS.bd.1 transfers the 13 MHC into exactly this format and closes the gap where IT-Grundschutz practitioners work: in the module.

implementation-strong · Gen-AI gapcomprehensively stronglimited positiontopic-strong · execution open00224466881010Mythos / Gen-AI coverage →Implementation readiness & auditability →ISO/IEC 27002:2022BSI IT-GrundschutzCSA CCM v4BSI C5:2026ISO/IEC 42001:2023CIS Controls v8.1NIST CSF 2.0CISA Zero Trust MM v2.0NIST AI RMF + GenAI ProfileMITRE ATT&CK v19 / ATLASMythos-Ready (CSA/SANS/OWASP)OWASP Agentic Top 10 (ASI)MRIS for ISO 27001 (v1.8)★ ISO/IEC 27002 + MRIS
Norm / standardPractice frameworkCommunity workKnowledge baseMRIS for ISO 27001Combination (hardened framework)

Qualitative expert scoring (0–10 scale), methodology and rubric fully disclosed in the work. Assessment status: July 2026. Full data, error bars and reading: market comparison on the ISO page →

The module

14 requirements. Three levels. One information domain.

Each requirement follows the BSI requirement format (MUST/SHOULD), names its level and responsibility and can be adopted individually into the security concept – or, where an ISO/IEC 27001 ISMS is additionally operated, into its Statement of Applicability. Expanding shows the core statement, MHC origin, Annex A reference and the corresponding safeguard in the implementation guidance.

RequirementLevelResponsibility
MRIS.bd.1.A1Reassessing Effectiveness AssumptionsBCISO

Reassess the effectiveness and probability assumptions of all implemented safeguards against the AI threat landscape; identify friction-based safeguards and feed the results into the risk analysis and the SoA.

MHCMRIS reassessment (ch. 10.2)
ISO/IEC 27001 · Annex Aentire Annex A
ImplementationSafeguard MRIS.bd.1.M1
MRIS.bd.1.A2Phishing-Resistant Multi-Factor AuthenticationBCISO

FIDO2/WebAuthn (passkeys or hardware tokens) mandatory for privileged, externally reachable and particularly sensitive access; SMS and simple push excluded for new access, legacy with a dated phase-out plan.

ISO/IEC 27001 · Annex Aflanks A.5.17, A.8.5
ImplementationSafeguard MRIS.bd.1.M2
MRIS.bd.1.A3Immutable Backups with Restore TestsBIT Operation

At least one immutable or air-gapped copy per business-critical data set, dedicated backup access paths, quarterly documented restore tests.

ISO/IEC 27001 · Annex Adeepens A.8.13
ImplementationSafeguard MRIS.bd.1.M3
MRIS.bd.1.A4Behaviour-Based Attack Detection with Event CorrelationBCISO

Detection via behavioural patterns and event correlation aligned with MITRE ATT&CK, with measured and regularly reviewed technique coverage; threat hunting or an MDR service.

ISO/IEC 27001 · Annex Aflanks A.8.16, A.8.12
ImplementationSafeguard MRIS.bd.1.M4
MRIS.bd.1.A5Workload Identities and Identity-Based Access ControlBIT Operation

Cryptographically verifiable, short-lived identities for privileged workloads; authorisation never based on network location alone; no long-lived plain-text secrets on critical paths.

ISO/IEC 27001 · Annex Aflanks A.5.16, A.8.20, A.8.21
ImplementationSafeguard MRIS.bd.1.M5
MRIS.bd.1.A6Cryptographic Inventory and Post-Quantum StrategyBCISO

Complete cryptographic inventory; for long-lived confidential data a documented migration strategy towards quantum-safe mechanisms, hybrid during the transition.

ISO/IEC 27001 · Annex Aflanks A.8.24
ImplementationSafeguard MRIS.bd.1.M6
MRIS.bd.1.A7Regulated Use of AI AgentsBCISO

Inventory of all production AI agents; treated as privileged systems with their own technical identity, complete person-attributable logging, named shutdown responsibility, approval for irreversible actions and an allow list for components.

ISO/IEC 27001 · Annex Aextends A.5.9, A.5.16, A.8.27
ImplementationSafeguard MRIS.bd.1.M7
MRIS.bd.1.A8SBOM and Build ProvenanceSDeveloper

Automatic SBOMs per build including transitive dependencies; exposure to new vulnerabilities determinable within 24 hours; build provenance for critical artefacts.

ISO/IEC 27001 · Annex Aflanks A.5.21, A.8.30
ImplementationSafeguard MRIS.bd.1.M8
MRIS.bd.1.A9Automated Security Testing in the PipelineSDeveloper

SAST, DAST and SCA automated on every change; severe findings block the merge; AI-generated code as a distinct risk category; KEV patches for exposed systems under 24 hours.

ISO/IEC 27001 · Annex Aflanks A.8.29, A.8.25
ImplementationSafeguard MRIS.bd.1.M9
MRIS.bd.1.A10Automated Incident Response with Hardened PlaybooksSCISO

Predefined playbooks contain unambiguous incidents within minutes; human approval for large blast radius; the automation layer itself is hardened.

ISO/IEC 27001 · Annex Acomplements A.5.24–A.5.26
ImplementationSafeguard MRIS.bd.1.M10
MRIS.bd.1.A11Continuous Automated Effectiveness VerificationSCISO

Continuously and automatically verify the safeguards listed in the security concept or Statement of Applicability against target states (policy as code); deviations trigger a defined response, the verified share is measured and increased.

ISO/IEC 27001 · Annex Asupports A.5.35, A.5.36
ImplementationSafeguard MRIS.bd.1.M11
MRIS.bd.1.A12Signed Container Images and Protected Execution EnvironmentsHIT Operation

Production containers exclusively from signed, verified images of controlled registries, technically enforced; confidential computing with remote attestation for particularly high protection needs.

ISO/IEC 27001 · Annex Aflanks A.5.23, A.8.31
ImplementationSafeguard MRIS.bd.1.M12
MRIS.bd.1.A13Verifiable Tenant SeparationHIT Operation

Data, networks and compute resources separated per tenant, tenant-specific keys; effectiveness demonstrated through regular, preferably automated separation tests.

ISO/IEC 27001 · Annex Aflanks A.5.23, A.8.22
ImplementationSafeguard MRIS.bd.1.M13
MRIS.bd.1.A14Threat-Led Penetration Tests with AI ScenariosHCISO

TLPT with AI scenarios – fragmented chains, parallel multi-vector attacks, AI phishing including deepfake voice; purple teaming between cycles, dated remediation of critical findings.

ISO/IEC 27001 · Annex Acomplements A.5.35, A.8.29
ImplementationSafeguard MRIS.bd.1.M14
Integration

Adopting it into an existing ISMS

Adoption into the security concept

In IT-Grundschutz, adoption takes place via the modelling and the security concept of the information domain – the methodology has no SoA. If the organisation additionally operates an ISMS under ISO/IEC 27001, every requirement can be adopted directly into its Statement of Applicability; requirements that do not apply are excluded there with justification.

Sequence

Reassessment (A1) before investment · detection (A4) before response automation (A10) · SBOMs (A8) before pipeline testing (A9) · validation (A14) after the basic implementation.

Maturity levels

The Implementation Guide describes a cumulative three-level path per safeguard (Initial, Defined, Managed) with stage gates and key figures for management reporting.

Typical exclusions

A8/A9 for organisations without in-house development (the principle works through procurement), A13 without multi-tenant operation. NIS2/DORA reporting duties run via incident handling.

Download

Four artefacts. Both languages. One module.

BSI IT-Grundschutz · user-defined layer MRIS.bd

MRIS.bd.1 – Mythos-Resistant Hardening of the ISMS

⚠ User-defined module – not reviewed, approved or certified by the BSI.
ModulePDF · v1.2 · August 2026 · CC BY-NC 4.0
Implementation GuidancePDF · v1.2 · August 2026 · CC BY-NC 4.0
Machine-readable editionYAML · v1.2 · August 2026 · CC BY-NC 4.0
Cross-Reference TableXLSX · v1.2 · August 2026 · CC BY-NC 4.0

License: CC BY-NC 4.0 · © 2026 Richard Peddi · Use within IT security concepts based on IT-Grundschutz is expressly permitted.

Usage note and independence

MRIS.bd.1 is a user-defined module within the meaning of the IT-Grundschutz methodology (BSI Standard 200-2), which explicitly provides for custom modules covering topics not yet addressed – an independent, privately produced work (CC BY-NC 4.0, © 2026 Richard Peddi). The module has not been reviewed, approved or certified by the BSI, is not part of the IT-Grundschutz Compendium and does not replace any certification. "IT-Grundschutz" and "BSI" designate standards and institutions of the German Federal Office for Information Security; MRIS has no affiliation with the BSI. No legal or certification advice; use at your own responsibility.