and issue relevant certificates. The BSI publishes product recommendations, issues technical guidelines for the use of these products and lists products that were issued a German IT security evaluation certificate. Goal 3: Respect confidentiality Unprotected digital communications are extremely vulnerable, easy to intercept and manipulate. Therefore, the security of the German information society and Germany as a place to do business depend on the availability of reliable, innovative and trusted encryption products that guarantee confidential communication. The Federal Government is promoting the development and the German manufacturers of adequate products, in accordance with the 1999 decision concerning encryption; in addition, it will use encryption and security applications for its own communications. When awarding IT and IT security contracts at federal level, public authorities will pay greater heed to national security interests on the one hand and the reliability and trustworthiness of bidders on the other. The business sector is made particularly aware of the risks associated with information theft (e.g. caused by economic espionage) and the possibilities and benefits of preventing such theft by using reliable German encryption products. Goal 4: Putting safeguards in place It is necessary to put coordinated technical, physical, organizational, and structural safeguards in place. Responsibilities, duties and roles for all tasks related to IT protection must be clearly defined. Adequate IT security measures are being implemented in all public authorities at federal level. The federal ministries in charge will ensure that IT security strategies for federal authorities are kept up to date and are implemented effectively. The Federal Government is improving IT security management coordination within the federal administration to ensure uniform and generally comparable, efficient, and transparent processes and work-flows from the highest ministerial level down to every single authority within the remit of each ministry. All businesses and organizations are firmly called upon to make adequate arrangements for protecting their IT systems. Page 10

Select target paragraph3