For the purposes of this Act:
1. "near miss" means an event that could have affected the availability, integrity or confidentiality of stored, transmitted or processed data or of the services offered or accessible through information technology systems, components and processes, but whose occurrence was successfully prevented or, for other reasons, did not occur;
2. "authorised access requester" means
a) the BSI,
b) the Land authorities that the Länder have designated as the competent authorities for the supervision of public administration bodies at regional level under Article 2(2)(f)(ii) of the NIS 2 Directive,
c) prosecuting authorities,
d) the police forces of the Federation and of the Länder, and
e) the authorities for the protection of the constitution of the Federation and of the Länder;
3. "ground infrastructure" means facilities relating to the space sector that serve to control the launch, flight or possible landing of space objects;
4. "cloud computing service" means a digital service that enables, on demand, the administration of a scalable and elastic pool of shareable computing resources and comprehensive remote access to that pool, even where the computing resources are distributed across several locations;
5. "content delivery network" or "CDN" means a group of geographically distributed, interconnected servers, together with the infrastructure required for that purpose, that are connected to the internet and serve to deliver digital content and services to internet users on behalf of content and service providers, with the aim of ensuring high availability, accessibility or delivery with the lowest possible latency;
6. "cyber threat" means a cyber threat within the meaning of Article 2, point 8 of Regulation (EU) 2019/881;
7. "data traffic" means data transmitted by means of technical protocols; it may include telecommunications content within the meaning of section 3(1) of the Telecommunications and Digital Services Data Protection Act and usage data within the meaning of section 2(2), no. 3 of the Telecommunications and Digital Services Data Protection Act;
8. "DNS service provider" means a natural or legal person that
a) provides publicly available recursive domain name resolution services for internet end users, or
b) provides authoritative domain name resolution services for use by third parties, with the exception of root name servers;
9. "domain name registry service provider" means a registrar, or a body acting on behalf of registrars, in particular a provider or reseller of privacy or proxy registration services;
10. "significant cyber threat" means a cyber threat that has the potential, on account of the particular technical characteristics of the cyber threat, to significantly affect information technology systems, components and processes; an effect is significant where it may cause significant material or non-material damage;
11. "significant security incident" means a security incident that
a) has caused or may cause severe operational disruption of the services or financial loss for the entity concerned, or
b) has affected or may affect other natural or legal persons by causing significant material or non-material damage, unless the statutory instrument under section 56(5) provides a more specific definition;
12. "research institution" means an establishment whose primary goal is to conduct applied research or experimental development with a view to using the results of that research for commercial purposes; educational establishments are not deemed research institutions;
13. "management" means a natural person who, by statute, articles of association or partnership agreement, is called upon to conduct the affairs of, and represent, an essential entity or important entity; the heads of federal administration entities under section 29 are not deemed management;
14. "ICT service" means an ICT service within the meaning of Article 2, point 13 of Regulation (EU) 2019/881;
15. "ICT product" means an ICT product within the meaning of Article 2, point 12 of Regulation (EU) 2019/881;
16. "ICT process" means an ICT process within the meaning of Article 2, point 14 of Regulation (EU) 2019/881;
17. "information security" means the adequate protection of the confidentiality, integrity and availability of information;
18. "information technology" means a technical means of processing information;
19. "social security institutions" means corporate bodies under section 29 of Book Four of the Social Code, working groups under section 94 of Book Ten of the Social Code, the German Statutory Accident Insurance (Deutsche Gesetzliche Unfallversicherung e. V.), and Deutsche Post AG, insofar as it is entrusted with the calculation or payment of social benefits;
20. "Internet Exchange Point" or "IXP" means an infrastructure that
a) enables the interconnection of more than two independent autonomous systems, used primarily for the exchange of internet traffic,
b) serves only the interconnection of autonomous systems, and
c) does not require that aa) the internet traffic passing between any two participating autonomous systems pass through a third autonomous system, or bb) the traffic concerned be altered or otherwise interfered with;
21. "the Federation's communications technology" means information technology that is operated by, or on behalf of, one or more federal administration entities and that serves communication or data exchange within a federal administration entity, between federal administration entities, or between federal administration entities and third parties; the communications technology of the Federal Constitutional Court, of the federal courts insofar as they do not perform public-law administrative tasks, of the Bundestag, of the Bundesrat, of the Federal President, and of the Federal Court of Auditors is not deemed "the Federation's communications technology", insofar as it is operated exclusively within their own competence;
22. "critical facility" means a facility within the meaning of section 2, no. 3 of the Critical Infrastructure Umbrella Act;
23. "critical components" means ICT products designated as critical components in a statutory instrument issued under section 56(6);
24. "critical service" means a service within the meaning of section 2, no. 4 of the Critical Infrastructure Umbrella Act;
25. "Managed Security Service Provider" or "MSSP" means a managed service provider that carries out or provides support for activities relating to cybersecurity risk management;
26. "Managed Service Provider" or "MSP" means a provider of services relating to the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications or any other network and information systems, through support or active management on customers' premises or remotely;
27. "NIS 2 Directive" means Directive (EU) 2022/2555, in its respective current version;
28. "online marketplace" means a service within the meaning of section 312l(3) of the German Civil Code;
29. "online search engine" means a digital service within the meaning of Article 2, point 5 of Regulation (EU) 2019/1150;
30. "social networking services platform" means a platform on which end users on different devices can come into contact and communicate with one another, in particular through chats, posts, videos and recommendations, and can share and discover content;
31. "protocol data" means the control data of an information technology protocol for data transmission that
a) are necessary to ensure communication between the recipient and the sender, and
b) are transmitted independently of the content of the communication, or are stored on the servers involved in the communication; protocol data may include traffic data within the meaning of section 3, no. 70 of the Telecommunications Act and usage data within the meaning of section 2(2), no. 3 of the Telecommunications and Digital Services Data Protection Act;
32. "logging data" means records of technical events or states within information technology systems;
33. "qualified trust service" means a qualified trust service within the meaning of Article 3, point 17 of Regulation (EU) No 910/2014;
34. "qualified trust service provider" means a qualified trust service provider within the meaning of Article 3, point 20 of Regulation (EU) No 910/2014;
35. "data centre service" means a service comprising structures whose primary purpose is the central accommodation, interconnection and operation of IT or network equipment, providing data processing services, together with all facilities and infrastructure required for that purpose, in particular for power distribution and environmental control;
36. "malware" means programs and other information technology routines and procedures that serve to use or delete data without authorisation, or to interfere without authorisation with other information technology processes;
37. "interfaces of the Federation's communications technology" means security-relevant network transitions within the Federation's communications technology, and between it and the information technology of individual federal administration entities, the information technology of groups of federal administration entities, or the information technology of third parties; the components at the network transitions operated within the own competence of the courts and constitutional organs named in no. 21 are not deemed "interfaces of the Federation's communications technology";
38. "vulnerability" means a property of ICT products or ICT services that can be exploited by third parties to gain access to the ICT products or ICT services against the will of the entitled person, or to influence the functioning of the ICT products or ICT services;
39. "IT security" means compliance, through security precautions
a) in information technology systems, components or processes, or
b) in the application of information technology systems, components or processes, with particular security standards concerning the availability, integrity or confidentiality of information;
40. "security incident" means an event that affects the availability, integrity or confidentiality of stored, transmitted or processed data, or of the services offered or accessible through information technology systems, components and processes;
41. "attack detection systems" means processes, supported by technical tools and organisational integration, for detecting attacks on information technology systems, whereby attack detection is carried out by comparing the data processed in an information technology system with information and technical patterns indicative of attacks;
42. "Top Level Domain Name Registry" means a natural or legal person that administers and operates the registration of internet domain names within a specific top level domain (TLD), including operating its name servers, maintaining its databases, and distributing TLD zone files through the name servers, regardless of whether the operation is carried out by the natural or legal person itself or is outsourced; registers that use TLD names only for their own purposes are not a "Top Level Domain Name Registry";
43. "trust service" means a trust service within the meaning of Article 3, point 16 of Regulation (EU) No 910/2014;
44. "trust service provider" means a trust service provider within the meaning of Article 3, point 19 of Regulation (EU) No 910/2014;
45. "space-based services" means services relating to the space sector that are based on data and information either generated by, or relayed through, space objects, and whose disruption may lead to broader cascading effects that may have far-reaching and long-lasting negative impacts on the provision of services throughout the internal market;
46. "certification" means the determination by a certification body that a product, a process, a system, a protection profile (security certification), a person (personal certification) or an IT security service provider satisfies particular requirements.
Home› Cybersecurity & IT Security› BSIG-EN
Part 1 · General Provisions › Section 2
Definitions
←→ also move between sections