[eu]cite

Home› Cybersecurity & IT Security› BSIG-EN

Part 2 · The BSI  ›  Chapter 1 · Tasks and Powers › Section 7

Control of the Federation's communications technology; rights of entry

(1) The BSI is empowered to control the security of the Federation's communications technology and its components, including the technical infrastructures necessary for operating the Federation's communications technology. For that purpose it may 1. require the provision of the information necessary for performing the tasks under section 3(1), second sentence, nos. 1 and 20, in particular technical details and strategies, plans and rules relating to the Federation's communications technology, including organisational and process structure, and 2. inspect the records and data carriers of the operator of the respective communications technology of the Federation, or of a third party engaged to provide operating services, and require the free-of-charge surrender of copies of those records and documents, including in electronic form, insofar as secrecy-protection interests or predominant security interests of the operator do not preclude this.
(2) The BSI must be granted access, during the times the premises are normally available for the respective business or operational use, to the land and business premises, including data-processing installations and devices, used for the Federation's communications technology, insofar as necessary for the purposes under subsection (1).
(3) In the case of installations of a third party at which an interface to the Federation's communications technology exists, the BSI may control the security of the interface on the third party's side of the facility only with the third party's consent. For that purpose it may, with the third party's consent, inspect the information necessary for performing the task, in particular technical details and strategies, plans and rules, and inspect the operator's records and data carriers and make copies free of charge, including in electronic form.
(4) The BSI informs about the result of its controls under subsections (1) to (3) 1. the respective operator examined, 2. the information security officer of the department, and 3. the competent legal and technical oversight body.
(5) Before finalising the examination report, the BSI conducts a clarification of the facts with the entity examined. In its communication the BSI should include proposals for improving information security, in particular for remedying the defects found. Section 4(3) applies accordingly to the communication to bodies outside the operator. The BSI may, in agreement with the information security officer of the respective competent department, instruct federal administration entities to implement the proposals for improvement within a reasonable period.
(6) Exempt from the powers under subsections (1) to (3) are controls of foreign information and communications technology under section 9(2) of the Act on the Foreign Service, insofar as it is located abroad or is operated for use abroad or for users abroad. The provisions for the interfaces of the Federation's communications technology domestically remain unaffected. Further details on the first sentence are regulated by an administrative agreement between the Federal Ministry for Digital Affairs and State Modernisation and the Federal Foreign Office.
(7) The powers under subsections (1) to (3) do not apply, within the portfolio of the Federal Ministry of Defence, to the control of the information and communications technology used by the armed forces for their own purposes or by the Military Counter-Intelligence Service. Not exempt is the information and communications technology of third parties, in particular of IT service providers, insofar as it is not operated exclusively for the purposes of the armed forces. The provisions for the interfaces of the Federation's communications technology remain unaffected by the first and second sentences. Further details are regulated by an administrative agreement between the Federal Ministry for Digital Affairs and State Modernisation and the Federal Ministry of Defence.
(8) Where the BSI determines, in the course of its controls, that an infringement of the obligations under this Act may result in a breach of the protection of personal data within the meaning of Article 4, point 12 of Regulation (EU) 2016/679 that must be notified under Article 33 of that Regulation, it must inform the competent supervisory authorities without delay.
(9) The BSI informs the Budget Committee of the German Bundestag, each calendar year by 30 June of the year following the reporting year, of the application of this provision.

←→ also move between sections