A/68/156/Add.1
complexity and the novelty of digital attacks, and the secrecy obscuring individual
incidents.
Efforts taken at the national level
In 1991, the Federal Office for Information Security (Bundesamt für Sicherheit
in der Informationstechnik, BSI) was established as the first and foremost central
information technology security service provider for the Federal Government. In
this function, BSI publishes binding minimum information technology security
standards for the federal administration and serves as its central information
technology incident reporting office. It furthermore operates as a neutral office for
consultancy and support in the field of information technology security. Main
achievements of the work done by the office were, for example, the Information
Technology Security Management Standard (IT-Grundschutz), the computer
emergency response team for federal agencies (CERT-Bund) as a platform for
incident handling and information exchange (dating back to 1994) and the Citizen
Computer Emergency Response Team (Buerger-CERT), founded in 2006, as a
means to address larger parts of society and raise awareness. Moreover, BSI issues
warnings on malware and security vulnerabilities in information technology
products and services, informs concerned parties (including information technology
vendors and general public) and delivers recommendations for countermeasures.
The 2005 national plan for the protection of information infrastructures,
targeting both government and industry, was followed by the cyber security strategy
adopted by the Federal Government in February 2011. Its core is critical
infrastructure protection.
Since 2008, the German Government and German critical infrastructure
operators have been cooperating in a public private partnership. This “CIP
Implementation Plan” (UP KRITIS) maintains working groups for different aspects
of cyber security, such as crisis management, exercises and availability of critical
services.
The National Information Technology Situation Centre (Nationales ITLagezentrum), which is operated by BSI, keeps track of the national and global
information technology security situation in order to rapidly detect and analyse
major information technology security incidents and recommend protective
measures. In case of an information technology-related crisis, it expands its capacity
and becomes the National Information Technology Crisis Reaction Centre
(Nationales IT-Krisenreaktionszentrum), concentrating capabilities for handling
information technology crises, covering all national aspects, including governmental
networks and critical infrastructures.
In keeping with the 2011 cyber security strategy, all Government authorities
that deal with cyber security issues are to work closely and directly with each other
and with the private sector within the National Cyber Response Centre (Nationales
Cyber-Abwehrzentrum), which is led and hosted by BSI.
With regard to policy, the National Cyber Security Council (Nationaler CyberSicherheitsrat) at the State secretary level addresses key cyber security issues and
the position of Germany on them. This includes coordinating cyber foreign policy,
including aspects of foreign, defence, economic and security policy.
6/24
13-47545