(1) To inform consumers about the IT security of products of particular product categories specified by the BSI, the BSI introduces a uniform IT security label. The IT security label makes no statement about the data-protection-related properties of a product.
(2) The IT security label consists of 1. an assurance by the manufacturer or service provider that the product satisfies particular IT security requirements for a specified period (manufacturer's declaration), and 2. information from the BSI on security-relevant IT properties of the product (security information).
(3) The IT security requirements to which the manufacturer's declaration relates result from a norm or a standard, or from an industry-agreed IT security specification, covering the respective product category, provided the BSI has determined, in a procedure regulated by statutory instrument under section 56(2), that the norm, standard, or industry-agreed IT security specification is suitable to reflect adequate IT security requirements for the product category. There is no entitlement to that determination. Where no determination under the first sentence exists, the IT security specifications result from a Technical Guideline published by the BSI covering the respective product category, provided the BSI has already published such a guideline. Where a product is covered by more than one existing norm, standard, industry-agreed IT security specification or Technical Guideline determined as suitable, the requirements are determined by the respective more specific existing norm, standard, industry-agreed IT security specification or Technical Guideline determined as suitable.
(4) The IT security label may be used for a product only where the BSI has approved the IT security label for that product. The BSI examines the approval of the IT security label for a product on application by the manufacturer or service provider. The application must be accompanied by the manufacturer's declaration for the product and all documents substantiating the particulars in the manufacturer's declaration. The BSI confirms receipt of the application and examines the plausibility of the manufacturer's declaration by reference to the documents submitted. The plausibility review may also be carried out by a qualified third party engaged by the BSI. The BSI may charge an administrative fee for processing the application.
(5) The BSI grants approval of the IT security label for the respective product where 1. the product belongs to one of the product categories the BSI has made known by general order published in the Federal Gazette, 2. the manufacturer's declaration is plausible and sufficiently substantiated by the documents submitted, and 3. any administrative fee charged has been paid. Approval is granted in writing and within a reasonable period specified in the statutory instrument under section 56(2). The exact course of the application procedure and the documents to be submitted are regulated by the statutory instrument under section 56(2).
(6) Where the BSI has granted approval, the IT security label must be affixed to the respective product or its outer packaging, insofar as this is possible given the nature of the product. The IT security label may also be published electronically. Where affixing is not possible given the nature of the product, publication of the IT security label must take place electronically. The IT security label refers to a website of the BSI on which the manufacturer's declaration and the security information can be retrieved. The exact procedure and design of the reference are laid down in the statutory instrument under section 56(2).
(7) Approval lapses after expiry of the specified period for which the manufacturer or service provider assured compliance with the IT security requirements, or after a declaration of withdrawal by the manufacturer or service provider to the BSI. The BSI includes a notice of the lapse of approval in the security information.
(8) The BSI may examine whether the requirements for approval of the IT security label for a product are complied with. Where deviations from the manufacturer's declaration given, or vulnerabilities, are found on examination, the BSI may take suitable measures to protect consumer trust in the IT security label, in particular 1. publish information on the deviations or vulnerabilities in a suitable manner in the security information, or 2. revoke approval of the IT security label. Subsection (7), second sentence applies accordingly.
(9) Before the BSI takes a measure under subsection (8), it gives the manufacturer or service provider the opportunity to remedy the deviations or vulnerabilities found within a reasonable period, unless weighty grounds of product security require immediate action. The BSI's power to warn under section 13 remains unaffected by this.
Home› Cybersecurity & IT Security› BSIG-EN
Part 5 · Certification, Declaration of Conformity and Label › Section 55
Voluntary IT security label
←→ also move between sections