(1) The BSI may, within the framework of its tasks under section 3(1), second sentence, no. 1, carry out queries at the interfaces of publicly accessible information technology systems to public telecommunications networks, in order to detect known vulnerabilities and other security risks, 1. to determine whether those interfaces may be inadequately protected and thereby endangered in their security or functionality, or 2. where the federal administration entities, or the essential or important entities, request the respective entities to do so. Where the BSI thereby obtains information protected under Article 10 of the Basic Law, it may process it only for the purpose of transmission under section 8(6) and (7). Insofar as the conditions of section 8(6) and (7) do not exist, information protected under Article 10 of the Basic Law must be deleted without delay.
(2) Where a known vulnerability or another security risk of an information technology system is detected through queries under subsection (1), first sentence, the BSI, as the general reporting point for IT security under section 5, informs without delay those responsible for the information technology system. Where the information technology system belongs to a federal administration entity, the information security officers of the federal administration entity concerned under section 45 and of the superior department under section 46 are informed at the same time. The BSI should in doing so point out existing possibilities for remedying the security risk. Where the persons responsible are not known to the BSI, or their identification is possible only with disproportionate effort or through a subscriber-data query under section 12, the operating service provider of the respective network or system must instead be notified without delay, unless predominant security interests preclude this.
(3) The BSI informs the Federal Commissioner for Data Protection and Freedom of Information, each by 30 June of the following year, of the number of queries carried out under subsection (1).
(4) The BSI submits to the Federal Commissioner for Data Protection and Freedom of Information, on request, a list of the systems examined of federal administration entities, essential entities and important entities in connection with the queries under subsection (1), for review.
(5) To perform its tasks, the BSI may deploy systems and procedures that simulate a successful attack to an attacker, in order to collect and evaluate the use of malware or other attack methods. In doing so the BSI may process the data necessary to evaluate the functioning of the malware and attack methods.
Home› Cybersecurity & IT Security› BSIG-EN
Part 2 · The BSI › Chapter 1 · Tasks and Powers › Section 15
Detection of attack methods and of security risks to network and IT security
←→ also move between sections