[eu]cite

Home› Cybersecurity & IT Security› BSIG-EN

Part 3 · IT Security of Entities  ›  Chapter 2 · Risk Management, Reporting, Registration, Verification and Notification Obligations › Section 31

Special requirements for the risk management measures of operators of critical facilities

(1) For operators of critical facilities, measures under section 30(1), first sentence that go, in comparison with other information technology systems, components and processes of essential entities, beyond the protection level of those entities, are also deemed proportionate for the information technology systems, components and processes material to the functionality of the critical facilities operated by them, where the effort required for this is not disproportionate to the consequences of a failure or impairment of the critical facility concerned.
(2) Operators of critical facilities are obliged to use attack detection systems for the information technology systems, components and processes material to the functionality of the critical facilities operated by them. The attack detection systems used must continuously and automatically capture and evaluate suitable parameters and characteristics from ongoing operation. They should be capable of continuously identifying and averting threats and of providing suitable remedial measures for disruptions that have occurred. In doing so the state of the art should be complied with. The effort required for this should not be disproportionate to the consequences of a failure or impairment of the critical facility concerned.

←→ also move between sections