(1) A person who provides telecommunications services, or contributes to their provision, must take reasonable technical precautions and other measures 1. to protect the secrecy of telecommunications, and 2. against infringement of the protection of personal data. The state of the art is to be taken into account in doing so.
(2) A person who operates a public telecommunications network or provides publicly available telecommunications services must take reasonable technical and organisational precautions and other measures, in the telecommunications and data-processing systems operated for this purpose, 1. to protect against disruptions that lead to significant impairment of telecommunications networks and services, including where these disruptions may be caused by external attacks and the effects of disasters, and 2. to manage the risks to the security of telecommunications networks and services. In particular, measures, including, where appropriate, measures in the form of encryption, are to be taken to secure telecommunications and data-processing systems against unauthorised access and to keep the effects of security breaches on users, other telecommunications networks, and services as low as possible. In taking these measures, a level of security of network and information systems appropriate to the existing risk is to be ensured, having regard to the state of the art, the relevant European and international standards, and the costs of implementation. In assessing whether measures are appropriate to the existing risk, regard is to be had to the extent of the risk exposure and the size of the operator or provider, and to the probability of occurrence and severity of security incidents and their societal and economic effects.
(2a) Measures under subsection (2) taken by operators of public telecommunications networks and providers of publicly available telecommunications services that are essential entities within the meaning of section 28(1), first sentence, point 3, of the BSI Act, or important entities within the meaning of section 28(2), first sentence, point 2, of the BSI Act, must be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from security incidents, and must cover at least the following: 1. policies on risk analysis and information system security, 2. incident handling, 3. business continuity, such as backup management and disaster recovery, and crisis management, 4. supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers, 5. security measures in acquiring, developing, and maintaining network and information systems, including vulnerability handling and disclosure, 6. policies and procedures to assess the effectiveness of measures under subsection (2) in the area of network and service security, 7. basic procedures and training in the area of network and service security, 8. policies and procedures regarding the use of cryptography and encryption, 9. personnel security, access control policies, and asset management, 10. the use of multi-factor authentication or continuous authentication solutions, secured voice, video, and text communications, and secured emergency communication systems within the entity, where appropriate.
(2b) The management bodies of operators of public telecommunications networks and providers of publicly available telecommunications services that are essential entities within the meaning of section 28(1), first sentence, point 3, of the BSI Act, or important entities within the meaning of section 28(2), first sentence, point 2, of the BSI Act, are obliged to implement the measures to be taken by these entities under subsection (2) and to monitor their implementation.
(2c) Management bodies that breach their duties under subsection (2b) are liable to their entity for damage culpably caused, in accordance with the rules of company law applicable to the entity's legal form. They are liable under this Act only where the company-law provisions applicable to the entity do not contain a liability rule under the first sentence.
(2d) The management bodies of operators of public telecommunications networks and providers of publicly available telecommunications services that are essential entities within the meaning of section 28(1), first sentence, point 3, of the BSI Act, or important entities within the meaning of section 28(2), first sentence, point 2, of the BSI Act, must regularly attend training in order to acquire sufficient knowledge and skills to identify and assess risks, and risk management practices, in the area of information technology security, and to be able to assess the effects of risks and risk management practices on the services provided by the entity.
(3) Operators of public telecommunications networks and providers of publicly available telecommunications services may deploy attack detection systems within the meaning of section 2, point 41, of the BSI Act as an appropriate measure within the meaning of subsection (2). Operators of public telecommunications networks and providers of publicly available telecommunications services with increased threat potential must deploy corresponding attack detection systems. The attack detection systems deployed must be capable of identifying hazards or threats through continuous and automatic capture and analysis. They should also be capable of averting identified hazards or threats and of providing for suitable remedial measures for disruptions that have occurred. The Federal Network Agency may lay down further details in the catalogue of security requirements under section 167.
(4) Critical components within the meaning of section 2, point 23, of the BSI Act may be deployed by an operator of public telecommunications networks with increased threat potential only where they have been examined and certified by a recognised certification body before first use.
(5) A person operating a public telecommunications network must take measures to ensure the proper operation of its networks and thereby to ensure the continued availability of the services provided via these networks.
(6) Technical precautions and other protective measures are reasonable where the technical and economic effort required for them is not disproportionate to the importance of the telecommunications networks or services to be protected. Section 62(1) of the Federal Data Protection Act applies correspondingly.
(7) In the case of shared use of a site or of technical facilities, each party involved must fulfil the obligations under subsections (1) to (5), insofar as specific obligations cannot be assigned to a specific party.
(8) In the event of a security incident occurring, or the determination of a significant danger, the Federal Network Agency may order measures to remedy the security incident or avert the danger, and time limits for their implementation.
(9) The Federal Network Agency may order operators of public telecommunications networks or providers of publicly available telecommunications services to undergo an examination by a qualified independent body or a competent national authority, determining whether the requirements under subsections (1) to (7) are satisfied. Without prejudice to the first sentence, operators of public telecommunications networks with increased threat potential must undergo an examination by a qualified independent body or a competent national authority every two years, determining whether the requirements under subsections (1) to (7) are satisfied. The Federal Network Agency determines the date of the first examination. The party obligated under the first and second sentences must transmit a copy of the examination report without delay to the Federal Network Agency and to the Federal Office for Information Security, insofar as the latter did not carry out the examination. It bears the costs of this examination. Assessment of the examination, and any resulting determination of security deficiencies in the security concept under section 166, is carried out by the Federal Network Agency in agreement with the Federal Office for Information Security.
(10) The Federal Network Agency informs the Federal Office for Information Security without delay of deficiencies discovered in satisfying the information technology security requirements, and of the remedial measures required by the Federal Network Agency in this connection.
(11) The Federal Network Agency may call upon a computer security incident response team under Article 10 of Directive (EU) 2022/2555 for support, within the scope of its assigned functions. The Federal Network Agency may further consult the Federal Office for Information Security, the competent national law enforcement authorities, and the Federal Commissioner for Data Protection and Freedom of Information.
Home› Telecommunications & Digital Services› TKG (EN)
Part 10 · Public Safety and Emergency Preparedness › Division 1 · Public Safety › Section 165
Technical and organisational protective measures
←→ also move between sections