This support may be provided only where necessary to prevent or investigate activities directed against
the security of information technology or activities carried out using information technology. The Federal
Office shall keep a record of requests for support;
14. advising and warning federal and Länder bodies as well as producers, distributors and users with
regard to the security of information technology, keeping in mind the possible consequences of the lack of
security precautions or of inadequate security precautions;
15. creating appropriate communications structures to recognize crises at an early stage, respond and
manage crises and to coordinate efforts to protect critical information infrastructures in cooperation with
private industry.
(2) The Federal Office may assist the Länder in securing their information technology upon request.
table of contents
Section 4
Central clearinghouse for IT security
(1) The Federal Office shall be the central clearinghouse for cooperation among federal authorities in
matters related to the security of information technology.
(2) To perform this task, the Federal Office shall
1. gather and evaluate all information necessary to prevent threats to IT security, especially information
concerning security gaps, malware, successful or attempted attacks on IT security and the means used
to carry out such attacks;
2. inform the federal authorities without delay about information as referred to in no. 1 concerning them
and of the facts of the matter ascertained.
(3) If other federal authorities become aware of information as referred to in subsection 2 no. 1 which is
significant for carrying out tasks or for the IT security of other authorities, as of 1 January 2010 these
federal authorities shall inform the Federal Office of this information without delay, unless prohibited by
other provisions.
(4) An exception to the reporting requirements under subsection 2 no. 2 and subsection 3 shall be made
for information which may not be disclosed due to confidentiality regulations or agreements with third
parties, and for information whose disclosure would conflict with the constitutional status of a member of
the German Bundestag or of a constitutional body, or with the legally mandated autonomy of individual
bodies.
(5) The provisions regarding the protection of personal data shall remain unaffected.
(6) With the approval of the Council of Chief Information Officers of the federal ministries, the Federal
Ministry of the Interior shall issue general administrative regulations for carrying out subsection 3.
table of contents
4/10