(1) The management of essential entities and important entities is obliged to implement the risk management measures to be taken by those entities under section 30, and to monitor their implementation.
(2) Management that infringes its obligations under subsection (1) is liable to its entity for culpably caused damage under the rules of company law applicable to the entity's legal form. Under this Act it is liable only where the company-law provisions material for the entity contain no liability rule under the first sentence.
(3) The management of essential entities and important entities must regularly attend training to acquire sufficient knowledge and skills to identify and assess risks and IT-security risk management practices, and to be able to assess the impact of risks and risk management practices on the services provided by the entity.
Home› Cybersecurity & IT Security› BSIG-EN
Part 3 · IT Security of Entities › Chapter 2 · Risk Management, Reporting, Registration, Verification and Notification Obligations › Section 38
Implementation, monitoring and training obligation for the management of essential entities and important entities
←→ also move between sections