As a government body, or if your organisation works closely with the government, there's no getting around it: the Baseline Information Security for Government (BIO). 

The BIO forms a basic framework for information security across all layers of government in the Netherlands. Its aim is to guarantee a clear and thorough level of security and to strengthen the safety of digital government. In this blog, we'll tell you more about it. 

In this blog:

The Baseline Information Security for Government (BIO)

The Baseline Information Security for Government (BIO) is a mandatory standard for information security within Dutch government and forms the basis for uniform and adequate security of government information. The framework translates international standards (such as ISO 27001 and 27002) into the context of Dutch government. It describes the countermeasures a government body needs to take in order to manage information securely.

The BIO has been in effect since 2019 and replaces the previous baselines for central government, municipalities, provinces and water authorities. The framework focuses on the security of information, including the identification, classification and implementation of security countermeasures. 

The Baseline Information Security for Government doesn't just apply to public institutions, but also to organisations and freelancers who work closely with government bodies and, in that context, have access to government information. This includes, for example, software suppliers, hosting providers and consultancy firms.

 

Key characteristics of the BIO

  • Risk based approach: The BIO encourages government organisations to follow a risk based approach when assessing and managing information security risks. This means that organisations identify, evaluate and prioritise risks. Countermeasures can then be taken to reduce these risks, which are set out in a risk treatment plan.
  • ISMS (Information Security Management System): The Baseline Information Security for Government places emphasis on the use of an ISMS, allowing government organisations to manage their information security in a structured way.
  • Technical and organisational countermeasures: The BIO sets out various technical and organisational countermeasures that can be implemented. These include encryption, patch management, awareness training and access controls, among others.
  • Compliance with laws and regulations: The BIO ensures that government bodies comply with relevant laws and regulations in the field of information security, such as the GDPR and the Cyber Security Act.
  • Continuous improvement: Lastly, the BIO drives continuous improvement of information security countermeasures.

 

The BIO and ISO 27001

The Baseline Information Security for Government is based on the latest version of ISO 27001 and ISO 27002. These two ISO standards form the basis, which the BIO then supplements for the Dutch government context.

Although the BIO is broadly harmonised with the ISO standards, it's important to know that the BIO includes specific requirements tailored to the needs and regulations of Dutch government bodies.

 

 

Benefits of the Baseline Information Security for Government

The BIO offers various benefits, both for government bodies and for organisations that work with them:

  • Consistency: The BIO ensures a uniform level of security within the government and prevents confusion.
  • Increased security: Thanks to the BIO, every government body has a baseline level of information security in place.
  • Greater trust: The Baseline Information Security for Government increases the trust in the digital government and in the security of the information it processes.
  • Cost savings: The government can save on maintenance costs relating to information security thanks to the consistency and standardisation the BIO provides.
  • Alignment with international regulations and standards: The BIO translates international standards to a government context.
  • Reduced administrative burden: Both for the government itself and for the organisations they work with. This reduced administrative burden comes from the uniform security standards.

 

Implementation of the BIO

Do you want to do business with the government as an organisation? Then you'll need to implement the BIO. A standard BIO implementation typically involves the following steps:

  1. Ensure awareness and involvement:
    Firstly, it's essential to make sure that both management and all your employees are aware of the BIO's requirements and what compliance means for the organisation.

    In addition, it's important tot determine the different risk areas within your organisation and who is responsible for security within each of these areas.

  2. Carry out a risk analysis:
    Next,you carry out a risk analysis within the organisation. This maps out the specific risks to information security. You then assess these based on the impact/damage to the organisation and the likelihood that a given risk will lead to an incident. This is done using a risk model (or risk matrix).

    The most practical way to carry out a risk analysis is by using an Information Security Management System (ISMS) such as Base27. The identified risks can easily be categorised and clearly presented within it, after which you can link the right treatment approach to each one.



  3. Develop an information security risk treatment plan:
    Once you've mapped out the risks, you can develop a detailed risk treatment plan describing the identified risks, their possible impact and the countermeasures to manage them. This treatment plan should take into account the technical and organisational countermeasures set out in the BIO.



  4. Provide training and guidance: 
    Various countermeasures will need to be taken to limit or prevent the risks identified earlier. An important part of this is training and educating your employees on the principles and practices of information security.

  5. Regularly monitor and evaluate:
    To ensure that countermeasures remain effective, it's important to monitor and evaluate them regularly. You can do this by carrying out a new risk analysis and/or by assessing the effectiveness of the countermeasures. 

The new BIO2

In 2025 the BIO was revised to further integrate changes in digital threats and the implementation of NIS2. This BIO2 is included in the obligations arising from the Cyber Security Act as part of the NIS2 implementation. Here, the BIO2 serves as the framework for the government's duty of care in the field of information security.

As an organisations, it's wise to start implementing the BIO2 already. You can do this, for example, by carrying out a gap analysis and mapping out the implementation costs. Another way is by complying with ISO 27001 and ISO 27002, since BIO2 is based on these.

 

Differences between the BIO and the new BIO2

Some key changes have been made in the new BIO2 compared to the BIO:

  • Abandoning fixed security levels: Instead of fixed levels, the BIO2 uses a risk based approach.
  • An ISMS becomes mandatory: It's now mandatory to set up an ISMS in line with ISO 27001.
  • Alignment with ISO 27002: From now on, the classification of controls and government countermeasures aligns with the updated classification used in ISO 27002.

 

Compliance with the BIO2 starts with Base27

The Baseline Information Security for Government (BIO) is the standard for secure information security within the government. With the arrival of the BIO2, the requirments are becoming even stricter and more up to date. For organisations working with government bodies, this means anticipating, adapting and continuing to meet the new requirements.

With Base27 you have a powerful ISMS that allowes you to set up your organisation's information security in line with the BIO2 with ease. From risk analysis to reporting, Base27 lets you manage everything in one system that grows with your organisation. Support is also provided for other frameworks, such as ISO 27001 and ISO 27002.

Thanks to Base27, you no longer need to do rushed updates or manual work. The frameworks can be applied within your organisation right away, keeping your information security up to date and in line with the latest requirements at all times.

Curious how to set up information security in line with the BIO2 using Base27?

We help businesses with their digital security