and issue relevant certificates. The BSI publishes product recommendations, issues
technical guidelines for the use of these products and lists products that were
issued a German IT security evaluation certificate.
Goal 3: Respect confidentiality
Unprotected digital communications are extremely vulnerable, easy to intercept
and manipulate. Therefore, the security of the German information society and
Germany as a place to do business depend on the availability of reliable, innovative
and trusted encryption products that guarantee confidential communication. The
Federal Government is promoting the development and the German manufacturers
of adequate products, in accordance with the 1999 decision concerning encryption;
in addition, it will use encryption and security applications for its own communications.
When awarding IT and IT security contracts at federal level, public authorities will
pay greater heed to national security interests on the one hand and the reliability
and trustworthiness of bidders on the other.
The business sector is made particularly aware of the risks associated with information theft (e.g. caused by economic espionage) and the possibilities and benefits
of preventing such theft by using reliable German encryption products.
Goal 4: Putting safeguards in place
It is necessary to put coordinated technical, physical, organizational, and structural
safeguards in place. Responsibilities, duties and roles for all tasks related to IT
protection must be clearly defined. Adequate IT security measures are being implemented in all public authorities at federal level. The federal ministries in charge
will ensure that IT security strategies for federal authorities are kept up to date
and are implemented effectively. The Federal Government is improving IT security
management coordination within the federal administration to ensure uniform
and generally comparable, efficient, and transparent processes and work-flows
from the highest ministerial level down to every single authority within the remit
of each ministry. All businesses and organizations are firmly called upon to make
adequate arrangements for protecting their IT systems.
Page 10