[eu]cite

Home› Cybersecurity & IT Security› BSIG-EN

Part 3 · IT Security of Entities  ›  Chapter 3 · Information Security of Federal Administration Entities › Section 43

Information security management

(1) The management of the federal administration entity is responsible for creating the conditions for ensuring information security, having regard to the concerns of IT operations. Federal administration entities must demonstrate to the BSI, at the latest five years after this Act enters into force and thereafter regularly in accordance with its requirements, that they satisfy the requirements under the first sentence.
(2) The management of the federal administration entity must regularly attend training to acquire sufficient knowledge and skills to identify and assess risks and information-security risk management practices, and to be able to assess the impact of risks and risk management practices on the services provided by the entity.
(3) Insofar as bodies organised under public or private law are engaged to provide services for the Federation's information technology, it must be ensured by contract that they undertake to comply with the conditions for ensuring information security. This also applies where interfaces to the Federation's communications technology are established. The obligations of the management of the federal administration entity under subsection (1) remain unaffected by this.
(4) Registration of federal administration entities under section 33 is the responsibility of the management of the federal administration entity.
(5) Where, beyond the reporting obligations arising from section 32, federal administration entities become aware of information under section 4(2), no. 1 that is significant for the performance of tasks or for the security of the Federation's communications technology, the federal administration entities must inform the BSI of this without delay, insofar as other provisions do not preclude this. Exempt from the reporting obligations for federal administration entities under section 32 and under the first sentence of this subsection is information that may not be passed on under secrecy-protection provisions or agreements with third parties, or whose passing on would be inconsistent with the constitutional position of a member of the Bundestag or of a constitutional organ, or with the statutorily regulated independence of individual bodies. The federal administration entities report to the BSI, each calendar year by 31 January, the total number of items of information not transmitted under the second sentence. Exempt from the obligation under the third sentence are the Federal Intelligence Service and the Federal Office for the Protection of the Constitution.
(6) The Federal Ministry of the Interior issues, in agreement with the departments, general administrative provisions to implement subsection (5).

←→ also move between sections