Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

Field of law

Information security

Information security law consists of a multitude of separate rules. Art. 32 GDPR alone reaches everyone who processes personal data. The others attach to sector and size, to a critical installation or to the manufacturer role. None of them names a measure, because all four require appropriateness and the state of the art. Standards such as ISO 27001 and the German IT-Grundschutz fill that gap without being binding themselves.

What decides which of them applies to you

Where to begin turns on which of the rules applies at all. Three of them attach to a characteristic, namely sector and size, an installation, or a role in the market. The rules do not exclude one another as a matter of principle.

What applies to your business?

Select as many as apply. The assignment follows from the statutes and does not replace an examination of the individual case.

This applies to us

Then this binds you(0 von 4)

Select on the left what applies to your business.

Security of processingArt. 32 GDPR

Binds every controller and every processor, irrespective of sector and size. The only binding rule without a precondition.

Triggered by: We process personal data

Risk management and reporting dutiesSection 30 BSIG

Binds the entities in section 28 BSIG. Whether an entity is among them is decided by the activity actually carried on together with headcount, turnover and balance sheet total. That is established by the entity itself.

Triggered by: We operate in one of the sectors listed in the annexes to the BSIG and have at least 50 employees, We operate a critical installation

Product requirements and vulnerability reportingArt. 13 CRA

Binds manufacturers of products with digital elements. Under Art. 3(13) CRA a manufacturer is also anyone who has a product developed and markets it under their own name. The reporting duty in Art. 14 CRA already applies, the product requirements from 11.12.2027.

Triggered by: We place software or connected devices on the market under our own name

Physical resilienceSection 13 KRITISDachG

Binds operators of critical installations and concerns not cybersecurity but physical protection, access control and emergency power. The clock has not started there, because the implementing regulation is still outstanding under section 8(8) KRITISDachG.

Triggered by: We operate a critical installation

Information security law is technology neutral

What a concrete technical implementation has to look like appears in no statute, and that is deliberate, because a provision naming a key length would age with the next attack.

Three yardsticks, not one measure

MerkmalArt. 32(1) GDPRSection 30(1) BSIGSection 13(2) KRITISDachG
What is requiredA level of security appropriate to the riskAppropriate, proportionate and effective measuresProportionate technical, security-related and organisational measures
What it is measured byState of the art, cost, nature and purpose of the processing, riskExposure to risk, size, cost of implementation, likelihood and severityMeans-end relation, effort against risk, capability
What is not in itA single concrete measureTen subjects, but no measureExamples, but no requirement

The third row is the same for all three. What is required is a procedure, and what follows from it is decided by the individual case.

The gap is filled by standards such as the German IT-Grundschutz and ISO 27001, whose legal rank is regularly overestimated. Under section 30(2) sentence 1 BSIG they are to be taken into account and not complied with, and under Art. 32(3) GDPR a certification is a factor in demonstrating compliance. Binding force would follow only from a confirmation of suitability under section 30(8) BSIG. According to the federal office’s overview none has been confirmed under the new law so far.

A management system shortens the implementation considerably, because risk analysis, effectiveness review and documentation are already in place. What follows from the statute and not from the technology it does not cover, namely registration, reporting channels and management duties.

Practical questions on this

Frequently asked questions

Is certification to ISO 27001 enough?

As evidence it helps, as compliance it does not suffice. Art. 32(3) GDPR names an approved certification mechanism expressly as a factor and not as compliance, and section 30(2) sentence 1 BSIG requires the relevant standards to be taken into account. On top of that the scope of a certificate is self-chosen, and registration, reporting channels and management duties do not appear in it at all.

What separates the IT-Grundschutz from ISO 27001?

The shape of the work. The Grundschutz supplies modules with requirements already written out, from which a selection is made. ISO 27001 describes a management system and leaves the derivation of measures to the risk treatment. For a business without a security team of its own the first route is usually shorter, for one operating internationally the second.

Is there a recognised sector standard?

Under section 30(8) BSIG industry associations may propose security standards whose suitability the federal office confirms on application. According to its own overview none has been confirmed under the new law so far. The thirteen published standards come from the former section 8a BSIG.

We are a critical installation. What applies in addition?

Alongside cybersecurity under the BSIG, physical resilience under the KRITIS framework Act, that is, physical protection, access control, emergency power and a resilience plan filed with the Federal Office of Civil Protection. The clock has not started there, because under section 8(8) KRITISDachG the registration procedure is only set once the implementing regulation is in force, and that is still outstanding.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.