2. gather and analyse information on security risks and security precautions and provide the results to other authorities as needed for them to fulfil their tasks or preserve their security interests; 3. studying security risks involved in the use of information technology, and developing security precautions, especially information technology processes and devices for information technology security (IT security products) as needed by the Federation to fulfil its tasks, including research as part of its legally mandated tasks; 4. developing criteria, procedures and tools to test and evaluate the security of information technology systems or components and to test and evaluate compliance with IT security standards; 5. testing and evaluating the security of information technology systems or components and issuing security certificates; 6. testing information technology systems and components and confirming compliance with IT security standards defined in the Federal Office’s technical guidelines; 7. testing, evaluating and approving information technology systems or components to be used in processing or transmitting official confidential information in accordance with Section 4 of the Security Clearance Check Act (SÜG) in the federal area or by companies in the context of federal contracts; 8. producing key data and operating cryptography and security management systems for federal information security systems used to protect official confidentiality or in other areas at the request of the authorities concerned; 9. providing support and advice on organizational and technical security measures and carrying out technical tests to protect confidential official information in accordance with Section 4 of the Security Clearance Check Act against unauthorized access; 10. developing technical security standards for federal information technology and for the suitability of information technology contractors in special need of protection; 11. making IT security products available to federal bodies; 12. providing support for the federal bodies responsible for the security of information technology, especially where these bodies undertake advisory or supervisory tasks; support for the Federal Commissioner for Data Protection and Freedom of Information shall take priority and shall be provided in line with the autonomy granted the Federal Commissioner in carrying out his/her tasks; 13. providing support for a) the police and prosecution authorities in carrying out their legally mandated tasks, b) the authorities for the protection of the Constitution in analysing and evaluating information derived from surveillance of terrorist activities or from intelligence activities as authorized by federal and state law, c) the Federal Intelligence Service in carrying out its legally mandated tasks. 3/10

Select target paragraph3