Germany’s IT Security Act Update

Author photo: Thomas Menze
By Thomas Menze

Germany’s IT Security Act, in force since 2015, aims to increase the security of information technology systems and make Germany's IT systems and digital infrastructures the most secure in the world.  Especially in critical infrastructures (KRITIS,) such as electricity and water supply, finance and food, a failure can have dramatic consequences.  In May of 2020, an update to this law was drafted.  The draft focuses primarily on Germany’s Federal Office for Information Security (BSI) and expands its powers in the future.  In essence, the authority will take on the role of a consumer Germany’s IT Security Actprotector.

 One focus of the update is on KRITIS core components.  These include those assets that are directly necessary for the operation of a critical system.  In the new draft of the law, the BSI now defines minimum standards for these components.  Furthermore, the only components that may be used have to be from manufacturers to whom a "declaration of trustworthiness" has been issued, i.e. products with a BSI security label that makes their IT security visible.  This requirement extends along the entire supply chain of the manufacturers.

In the future, the BSI will also expand its focus to other networked systems, e.g. industrial control systems (ICS devices) or Internet of Things systems (IoT devices).  In the context of the above-mentioned KRITIS core components, the focus in the future will be a holistic view for operators of critical infrastructures.

Which companies are operators of critical infrastructure in the sense of the IT Security Act?  This question is clarified by a regulation published in 2016.  The ordinance enables operators of critical infrastructures to check, based on measurable and comprehensible criteria, whether their facilities fall under the scope of the BSI Act.  For example, the degree of coverage is determined based on threshold values for each system category in the respective KRITIS sector.  A typical threshold value is 500,000 people serviced.

The new draft also contains a number of other changes.  Those mentioned in this blog represent a significant part of the overall package of changes, especially those aimed at the provisions relevant for operators of critical infrastructures.

Experiences from the first IT Security Act shows that adjustments in content are still possible until the binding draft law is passed.  Nevertheless, this second draft gives a clear direction, especially for operators of critical infrastructures.  For this reason, these companies should take the formulated requirements into account in their security strategies today.

ARC will continue to blog about future developments.

 

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients