[eu]cite

Home› Cybersecurity & IT Security› BSIG-EN

Part 3 · IT Security of Entities  ›  Chapter 2 · Risk Management, Reporting, Registration, Verification and Notification Obligations › Section 40

National liaison body and central reporting and single point of contact for essential and important entities

(1) The BSI is the national liaison body and the central reporting and single point of contact for the supervision of IT security for essential entities and important entities.
(2) In performing its task as national liaison body, the BSI coordinates 1. the cross-border cooperation of the Land authorities that the Länder have designated as competent authorities for the supervision of public administration bodies at regional level under Article 2(2)(f)(ii) of the NIS 2 Directive, and of the Bundesnetzagentur and the Federal Financial Supervisory Authority, with the authorities of other Member States competent for supervising the application of the NIS 2 Directive and, where appropriate, with the European Commission and the European Union Agency for Cybersecurity, and 2. the cross-sectoral cooperation of the Land authorities named in no. 1, the Federal Office of Civil Protection and Disaster Assistance, the Bundesnetzagentur and the Federal Financial Supervisory Authority.
(3) In performing its task as central reporting point, the BSI must 1. collect and evaluate the information material for averting dangers to IT security, in particular information on vulnerabilities, malware and attacks, 2. in cooperation with the competent supervisory authorities and the Federal Office of Civil Protection and Disaster Assistance, analyse the relevance of the information under no. 1 for the availability of critical services, 3. continuously update the situational picture regarding the IT security of critical facilities, essential entities and important entities, and 4. inform, without delay, the following persons or bodies: a) operators of critical facilities of information concerning them under nos. 1 to 3, under section 33(1), no. 2, b) the competent authorities of another Member State of the European Union of significant disruptions reported under subsection (5) or under comparable provisions that have effects in that Member State, having regard to national security and defence interests, and c) the Federal Foreign Office of significant security incidents with an international connection reported under section 32(1), and d) within the framework of processes agreed in advance between the BSI and the recipients for passing on information and maintaining the necessary confidentiality, the authorities designated to the BSI by the Länder as central points of contact for this purpose, or the competent federal authorities, of the information necessary for the performance of their tasks.
(4) In performing its task as single point of contact, the BSI must 1. accept requests from the bodies named in subsection (2) and forward them to the competent bodies named in subsection (2), 2. draw up responses to the requests named in subsection (2), first sentence, no. 2, involving the bodies named in subsection (1), or forward responses of the bodies named in subsection (2), first sentence to the bodies named in subsection (2), first sentence, forward reports received under section 32 to the single points of contact of the other Member States of the European Union affected, 3. where a significant security incident affects two or more Member States of the European Union, inform the other Member States affected and the European Union Agency for Cybersecurity of the significant security incident, stating the type of information obtained under section 32(2), and preserving the economic interest of the entity and the confidentiality of the information provided.
(5) During a significant security incident under section 32(1), the BSI may, in agreement with the respective competent federal supervisory authority, require the operators of critical facilities affected to surrender the information necessary for managing the disruption, including personal data. Operators of critical facilities are entitled, at the BSI's request, to transmit to it the information necessary for managing the disruption, including personal data, insofar as necessary for managing a significant security incident.
(6) Insofar as personal data is processed within the framework of this provision, processing for other purposes going beyond the preceding subsections is inadmissible. Section 8(8), third to ninth sentences applies accordingly.

←→ also move between sections