As the national authority in charge of IT security and as the Federal Government’s main IT security service provider, the Federal Office for Information Security (BSI) is responsible for coordinating the implementation of this National Plan. To enable the BSI to fulfil this task, the number of its staff has been and to some extent still will be increased and priorities will be redefined; overall, the BSI will be assigned a more active role as IT security advising institution. Cooperation between the federal government and the private sector In Germany, the majority of information infrastructures are run by private companies. Hence, protecting these infrastructures is primarily the task of private operators and service providers. However, given the dramatic consequences damage to those infrastructures might have for the state, the economy and large parts of the population, sole responsibility of individual operators is neither sufficient nor appropriate. This holds true also for critical infrastructures in Germany. Although the Federal Government defines the necessary requirements for the protection of information infrastructures, it is not capable of implementing them all by itself. For this reason, it will enter into precise agreements with private operators on how to fulfil the necessary tasks and respond effectively and in a concerted manner to IT security incidents. Therefore, the Federal Government calls upon its partners in the private sector to take an active part in implementing the National Plan, especially where it refers to critical infrastructures. The goal must be to ensure that protective measures are taken not only to safeguard one’s own business operations, but to promote Germany as a place to do business and to ensure its international competitiveness. To this effect, the Federal Government, together with operators of critical infrastructures, is preparing the CIP Implementation Plan (Umsetzungsplan KRITIS). It will lay down measures to raise the level of IT security considerably. The Federal Office for Information Security (BSI) as well as other competent public authorities will offer their expertise to assist the operators of critical infrastructures in carrying out the measures set out in the CIP Implementation Plan. Page 7

Select target paragraph3