[eu]cite

Home› Cybersecurity & IT Security› BSIG-EN

Part 3 · IT Security of Entities  ›  Chapter 2 · Risk Management, Reporting, Registration, Verification and Notification Obligations › Section 36

Feedback from the BSI to reporting entities

(1) In the case of a report from an entity under section 32, the BSI transmits to it, without delay and where possible within 24 hours, a confirmation of receipt of the report and, at the entity's request, guidance or operational advice on remedial measures. The BSI may, at the entity's request, provide additional technical support.
(2) Where public awareness is necessary to prevent or manage a significant security incident, or the disclosure of the significant security incident is otherwise in the public interest, the BSI may, after hearing the entity concerned, oblige it to inform the public of the significant security incident. The BSI may, in accordance with the conditions under the first sentence, also itself inform the public. Where the entity concerned is a federal administration entity, section 4(3) applies accordingly to informing the public.

←→ also move between sections