(1) To avert significant dangers to the protected interests named in subsection (3), the BSI may order that a provider of publicly available telecommunications services within the meaning of the Telecommunications Act 1. take the measures described in section 169(6) and (7) of the Telecommunications Act, or 2. distribute technical commands for cleaning a specifically named piece of malware to the information technology systems affected, provided and insofar as the provider of publicly available telecommunications services is technically capable of doing so and it is economically reasonable for it. Before ordering measures under the first sentence, nos. 1 or 2, the BSI must consult the Bundesnetzagentur. Before ordering the measure under the first sentence, no. 2, the BSI must additionally reach agreement with the Federal Commissioner for Data Protection and Freedom of Information. The data to be accessed by the measure under the first sentence, no. 2 must be named in the order. Section 8(8), second to eighth sentences applies accordingly. An objection and an action for annulment against orders under the first sentence have no suspensive effect.
(2) To avert significant dangers to the protected interests named in subsection (3), the BSI may distribute technical commands for cleaning a specifically named piece of malware to the information technology systems affected. Subsection (1), second and third sentences applies accordingly. The service provider concerned is obliged to support the BSI in implementing the first sentence and, in particular, to provide all information necessary for creating and distributing the command.
(3) Protected interests within the meaning of subsection (1), first sentence are the availability, integrity or confidentiality of 1. the communications technology of the Federation, of an essential entity or of an important entity, 2. information or communications services, or 3. information, where its availability, integrity or confidentiality is impaired by unauthorised access to a significant number of users' telecommunications or information technology systems.
(4) Where the BSI orders a measure under subsection (1), first sentence, no. 1, it may also order the provider of publicly available telecommunications services to redirect the data traffic to a connection identifier named by the BSI.
(5) The BSI may process data redirected by a provider of publicly available telecommunications services under subsection (1), first sentence, no. 1 and subsection (4), in order to obtain information on malware or other security risks in information technology systems. The transmitted data may be stored by the BSI for as long as necessary to fulfil the purpose named in the first sentence, but for at most three months. Section 8(8), second to eighth sentences applies accordingly. The BSI informs the Federal Commissioner for Data Protection and Freedom of Information, each by 30 June of the following year, of the total number of data redirections ordered.
Home› Cybersecurity & IT Security› BSIG-EN
Part 2 · The BSI › Chapter 1 · Tasks and Powers › Section 16
Orders of measures by the BSI against providers of telecommunications services
←→ also move between sections