[eu]cite

Home› Cybersecurity & IT Security› BSIG-EN

Part 3 · IT Security of Entities  ›  Chapter 3 · Information Security of Federal Administration Entities › Section 46

Information security officers of the departments

(1) The heads of the individual departments, and the heads of other supreme federal authorities, each appoint an information security officer of the department, responsible, having regard to the concerns of IT operations, for steering and monitoring information security management within the department or within the supreme federal authority and its portfolio, and designate at least one person authorised to act as deputy. The information security officer of the department works towards implementing information security within their department.
(2) Targeted training of the information security officers of the departments is necessary for performing their tasks. The information security officer of the department must acquire the expertise necessary to perform their tasks.
(3) The information security officers of the departments each coordinate the further development of information security guidelines for their department. They inform the department's leadership of their activity and of the state of information security within the department, of resource and staffing levels, and of security incidents. They perform their reporting and advisory tasks independently and free of instructions.
(4) In justified individual cases, the information security officer of the department may, in consultation with the department's respective IT officer, wholly or partly prohibit the use of particular IT products in federal administration entities within the respective department. The BSI must be informed of a prohibition.
(5) The information security officer of the department may, in consultation with the BSI, partially or wholly exempt federal administration entities within the department from obligations under this Part by issuing an exemption notice. This requires that objective grounds exist for issuing an exemption notice and that no adverse effects on the Federation's information security are to be feared as a result of the exemption. The BSI must be informed of exemption notices issued. The first sentence does not apply where the respective federal administration entity satisfies the conditions of section 28(1), first sentence or section 28(2), first sentence.
(6) The information security officer of the department must be involved in all legislative, regulatory and other important projects within the department, insofar as the projects touch on questions of information security. They have a right of direct access to the department's respective leadership. They may not be removed from office or disadvantaged by their respective entity on account of performing their tasks.

←→ also move between sections