BSIG-EN
🇩🇪 Auf Deutsch lesen (original text)
Sections
Part 1 General Provisions
Part 2 The BSI
Chapter 1 Tasks and Powers
- Section 3 — Tasks of the BSI
- Section 4 — Central reporting point for the IT security of the Federation
- Section 5 — General reporting point for IT security
- Section 6 — Exchange of information
- Section 7 — Control of the Federation's communications technology; rights of entry
- Section 8 — Averting malware and dangers to the Federation's communications technology
- Section 9 — Processing of logging data of the Federation's communications technology
- Section 10 — Orders of measures to avert or remedy security incidents
- Section 11 — Restoring the security or functionality of information technology systems in exceptional cases
- Section 12 — Disclosure of subscriber data
- Section 13 — Warnings
- Section 14 — Investigation of IT security, requests for information
- Section 15 — Detection of attack methods and of security risks to network and IT security
- Section 16 — Orders of measures by the BSI against providers of telecommunications services
- Section 17 — Orders of measures by the BSI against providers of digital services
- Section 18 — Orders of measures by the BSI against manufacturers of ICT products
- Section 19 — Provision of IT security products
Chapter 2 Data Processing
- Section 20 — Processing of personal data
- Section 21 — Restrictions on the rights of the data subject
- Section 22 — Duty to inform when collecting personal data
- Section 23 — Right of access of the data subject
- Section 24 — Right to rectification
- Section 25 — Right to erasure
- Section 26 — Right to restriction of processing
- Section 27 — Right to object
Part 3 IT Security of Entities
Chapter 1 Scope of Application
Chapter 2 Risk Management, Reporting, Registration, Verification and Notification Obligations
- Section 30 — Risk management measures of essential entities and important entities
- Section 31 — Special requirements for the risk management measures of operators of critical facilities
- Section 32 — Reporting obligations
- Section 33 — Registration obligation
- Section 34 — Special registration obligation for particular types of entity
- Section 35 — Notification obligations
- Section 36 — Feedback from the BSI to reporting entities
- Section 37 — Exemption notice
- Section 38 — Implementation, monitoring and training obligation for the management of essential entities and important entities
- Section 39 — Verification obligations for operators of critical facilities
- Section 40 — National liaison body and central reporting and single point of contact for essential and important entities
- Section 41 — Prohibition of the use of critical components
- Section 42 — Requests for information
Chapter 3 Information Security of Federal Administration Entities
- Section 43 — Information security management
- Section 44 — BSI requirements
- Section 45 — Information security officers of federal administration entities
- Section 46 — Information security officers of the departments
- Section 47 — Material digitalisation projects and communications infrastructures of the Federation
- Section 48 — Office of Coordinator for Information Security
Part 4 Domain Name Registration Data Databases
- Section 49 — Obligation to maintain a database
- Section 50 — Obligation to grant access
- Section 51 — Obligation to cooperate
Part 5 Certification, Declaration of Conformity and Label
- Section 52 — Certification
- Section 53 — Conformity assessment and declaration of conformity
- Section 54 — National cybersecurity certification authority
- Section 55 — Voluntary IT security label
Part 6 Authorisations to Issue Statutory Instruments, Restrictions of Fundamental Rights and Reporting Obligations
- Section 56 — Authorisation to issue statutory instruments
- Section 57 — Restriction of fundamental rights
- Section 58 — Reporting obligations of the BSI
Part 7 Supervision
- Section 59 — Competence of the BSI
- Section 60 — Centralised competence in the European Union for particular types of entity
- Section 61 — Supervisory and enforcement measures for essential entities
- Section 62 — Supervisory and enforcement measures for important entities
- Section 63 — Administrative coercion
- Section 64 — Infringements by social security institutions