Der IKT-Minimalstandard ist das Referenzwerk des Bundes für die Cybersicherheit kritischer und öffentlicher Infrastrukturen. Er basiert auf dem international etablierten NIST Cybersecurity Framework und übersetzt es in konkrete, prüfbare Massnahmen. Für Gemeinden ist er faktisch der Massstab geworden: Bei Prüfungen, nach Vorfällen und in kantonalen Vorgaben wird auf ihn verwiesen.
Die fünf Funktionen – in einem Satz erklärt
Identifizieren: Wissen, welche Systeme, Daten und Abhängigkeiten überhaupt existieren – ohne Inventar keine Sicherheit. Schützen: Zugriffe regeln, Systeme aktuell halten, Mitarbeitende schulen. Erkennen: Merken, wenn etwas nicht stimmt – und zwar bevor es der Angreifer meldet. Reagieren: Wissen, wer im Ernstfall was tut, wen informiert und wie kommuniziert. Wiederherstellen: Aus gesicherten Daten den Betrieb wieder aufnehmen können – nachweislich geübt, nicht nur behauptet.
Ist der Standard verbindlich?
Das hängt vom Kanton ab. Einige Kantone erklären ihn für Gemeinden ganz oder teilweise für verbindlich, andere empfehlen ihn. Entscheidend ist aber die faktische Wirkung: Wenn nach einem Vorfall Fragen gestellt werden – von der Aufsicht, der GPK oder der Öffentlichkeit – wird am Minimalstandard gemessen, ob eine Gemeinde ihre Sorgfaltspflicht wahrgenommen hat.
Der häufigste Fehler
Viele Gemeinden versuchen, alle rund hundert Massnahmen gleichzeitig anzugehen – und geben nach dem ersten Excel-Marathon auf. Der Standard ist als Reifegradmodell gedacht: Es geht nicht um Perfektion, sondern um einen dokumentierten, risikobasierten Weg.
Pragmatisch einsteigen: drei Schritte
1. Standortbestimmung: Eine strukturierte Ist-Aufnahme zeigt in zwei bis drei Wochen, wo die Gemeinde steht – verständlich aufbereitet für Gemeinderat und Verwaltungsleitung.
2. Priorisieren nach Risiko: Nicht alles ist gleich wichtig. Backup, Zugriffe, Updates und Meldewege zuerst – das deckt die häufigsten Angriffswege ab.
3. In den Budgetprozess einplanen: Massnahmen mit Kosten und Zeithorizont versehen und ordentlich budgetieren. Sicherheit wird so vom Notfallthema zum planbaren Legislaturziel.
Fazit
Der IKT-Minimalstandard ist kein bürokratisches Monster, sondern eine solide Landkarte. Wer sie mit Augenmass nutzt, erreicht mit vertretbarem Aufwand ein Sicherheitsniveau, das sich gegenüber Bürgerinnen, Bürgern und Aufsicht sehen lassen kann.
The ICT minimum standard is the federal reference framework for the cybersecurity of critical and public infrastructures. It is based on the internationally established NIST Cybersecurity Framework and translates it into concrete, verifiable measures. For municipalities it has effectively become the yardstick: audits, post-incident reviews and cantonal requirements all refer to it.
The five functions – explained in one sentence each
Identify: know which systems, data and dependencies exist at all – without an inventory there is no security. Protect: govern access, keep systems current, train employees. Detect: notice when something is wrong – before the attacker announces it. Respond: know who does what in an emergency, who informs whom and how to communicate. Recover: be able to resume operations from backed-up data – demonstrably rehearsed, not just claimed.
Is the standard binding?
That depends on the canton. Some cantons declare it fully or partially binding for municipalities, others recommend it. What matters, however, is its practical effect: when questions are asked after an incident – by the supervisory authority, the audit committee or the public – the minimum standard is the benchmark for whether a municipality exercised its duty of care.
The most common mistake
Many municipalities try to tackle all of the roughly one hundred measures at once – and give up after the first Excel marathon. The standard is designed as a maturity model: it is not about perfection, but about a documented, risk-based path.
Getting started pragmatically: three steps
1. Assessment: a structured stocktake shows within two to three weeks where the municipality stands – prepared understandably for the municipal council and administration lead.
2. Prioritise by risk: not everything is equally important. Backups, access, updates and reporting channels first – that covers the most common attack paths.
3. Plan it into the budget process: give measures costs and a time horizon and budget them properly. Security thus turns from an emergency topic into a plannable legislative-period goal.
Conclusion
The ICT minimum standard is not a bureaucratic monster, but a solid map. Used with a sense of proportion, it achieves a level of security at reasonable cost that stands up to citizens and supervisory bodies alike.