(1) To perform its tasks under section 3(1), second sentence, nos. 20 and 21, the BSI may 1. address the following warnings and information to the public or to the circles concerned: a) warnings of vulnerabilities and other security risks in information technology products and services, b) warnings of malware, c) warnings in the event of loss of, or unauthorised access to, data, d) information on security-relevant IT properties of products, and e) information on infringements by essential entities or important entities of the obligations under this Act, and 2. recommend security measures and the use of particular security products. The BSI may involve third parties in performing the tasks under the first sentence, where necessary for an effective and timely warning.
(2) The manufacturers of the products concerned must be informed in good time before publication of the warnings. This duty to inform does not exist 1. where this would jeopardise the achievement of the purpose pursued by the measure, or 2. where it can legitimately be assumed that the manufacturer has no interest in prior notification. Insofar as discovered vulnerabilities or malware are not to become generally known, in order to prevent further dissemination or unlawful exploitation, or because the BSI is obliged to maintain confidentiality towards third parties, it may restrict the circle of persons to be warned. Criteria for selecting the circle of persons to be warned under the third sentence are in particular the particular vulnerability of certain entities or the particular reliability of the recipient.
(3) To perform its tasks under section 3(1), second sentence, nos. 20 and 21, the BSI may, naming the designation and the manufacturer of the product or service concerned, inform the public 1. of vulnerabilities in information technology products and services and of malware, where sufficient indications exist that they give rise to dangers to IT security, or 2. recommend security measures and the use of particular information technology products and services. Where information given to the public subsequently proves incorrect, or the underlying circumstances prove to have been inaccurately reported, this must be made publicly known without delay. Warnings under the first sentence must be removed six months after publication, unless sufficient indications continue to exist that dangers to IT security persist. Where a warning under the third sentence is not removed, that decision must be regularly reviewed.
Home› Cybersecurity & IT Security› BSIG-EN
Part 2 · The BSI › Chapter 1 · Tasks and Powers › Section 13
Warnings
←→ also move between sections