(1) Essential entities and important entities are obliged to take suitable, proportionate and effective technical and organisational measures, specified in subsection (2), to prevent disruptions of the availability, integrity and confidentiality of the information technology systems, components and processes that they use for providing their services, and to keep the effects of security incidents as low as possible. In assessing the proportionality of the measures under the first sentence, the degree of risk exposure, the size of the entity, the costs of implementation, and the probability of occurrence and severity of security incidents, as well as their societal and economic impact, must be taken into account. Compliance with the obligation under the first sentence must be documented by the entities.
(2) Measures under subsection (1) should comply with the state of the art, take account of the relevant European and international standards, and must be based on an all-hazards approach. The measures must at least comprise: 1. concepts relating to risk analysis and IT security, 2. handling of security incidents, 3. maintaining operations, such as backup management and disaster recovery, and crisis management, 4. supply-chain security, including security-related aspects of relationships with direct suppliers or service providers, 5. security measures in the acquisition, development and maintenance of information technology systems, components and processes, including management and disclosure of vulnerabilities, 6. concepts and procedures for assessing the effectiveness of IT security risk management measures, 7. basic training and awareness measures in the field of IT security, 8. concepts and processes for the use of cryptographic procedures, 9. drawing up concepts for personnel security, access control and for the management of ICT systems, products and processes, 10. the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communication, and, where appropriate, secured emergency communication systems within the entity.
(3) The implementing act adopted by the European Commission under Article 21(5), first subparagraph of the NIS 2 Directive, laying down the technical and methodological requirements for the measures named in subsection (1) as regards DNS service providers, Top Level Domain Name Registries, cloud computing service providers, providers of data centre services, operators of content delivery networks, managed service providers, managed security service providers, providers of online marketplaces, online search engines and social networking services platforms, and trust service providers, takes precedence for the types of entity named above.
(4) Where the European Commission adopts an implementing act under Article 21(5), second subparagraph of the NIS 2 Directive laying down the technical and methodological requirements and, where necessary, the sector-specific requirements of the measures named in subsection (2), those requirements take precedence over the measures named in subsection (2) insofar as they conflict with them.
(5) Insofar as the European Commission's implementing acts under Article 21(5) of the NIS 2 Directive do not contain conclusive provisions on the technical and methodological requirements and, where necessary, the sector-specific requirements of the measures named in subsection (2) as regards essential entities and important entities, those provisions may be specified and extended by the Federal Ministry of the Interior, in agreement with the departments concerned, by statutory instrument not requiring the consent of the Bundesrat, having regard to the possible consequences of inadequate measures and the significance of particular entities.
(6) Essential entities and important entities may use ICT products, ICT services and ICT processes specified by statutory instrument under section 56(3) only where those products, services or processes have a cybersecurity certification under European schemes under Article 49 of Regulation (EU) 2019/881.
(7) Without prejudice to the prevention, investigation, detection and prosecution of criminal offences, the exchange of information under section 6 or the voluntary reporting under section 5 must not result in additional obligations being imposed on the reporting entity that would not have applied to it had it not made the report.
(8) Essential entities and their trade associations may propose sector-specific security standards to ensure the requirements under subsection (1). Those proposed security standards must take account of implementing acts of the European Commission in such a way that they do not conflict with the requirements named there and do not fall short of the requirements contained in them. The BSI determines, on application, whether the proposed security standards are sector-specific and suitable for ensuring the requirements under subsection (1), and publishes them on its website. The determination is made 1. in agreement with the Federal Office of Civil Protection and Disaster Assistance; 2. in agreement with the competent federal supervisory authority. In the health sector, insofar as no competent federal supervisory authority exists, consultation with the Federal Ministry of Health must, by way of derogation from the fourth sentence, no. 2, take place instead. For reasons of public interest, no fees or expenses are charged for the BSI's activity in making the determination.
(9) Operators of critical facilities may propose sector-specific security standards to ensure the requirements relating to critical facilities under section 30(1), first sentence in conjunction with section 31(1) and (2), first sentence. Subsection (8), second to sixth sentences applies accordingly.
Home› Cybersecurity & IT Security› BSIG-EN
Part 3 · IT Security of Entities › Chapter 2 · Risk Management, Reporting, Registration, Verification and Notification Obligations › Section 30
Risk management measures of essential entities and important entities
←→ also move between sections