2. gather and analyse information on security risks and security precautions and provide the results to
other authorities as needed for them to fulfil their tasks or preserve their security interests;
3. studying security risks involved in the use of information technology, and developing security
precautions, especially information technology processes and devices for information technology security
(IT security products) as needed by the Federation to fulfil its tasks, including research as part of its
legally mandated tasks;
4. developing criteria, procedures and tools to test and evaluate the security of information technology
systems or components and to test and evaluate compliance with IT security standards;
5. testing and evaluating the security of information technology systems or components and issuing
security certificates;
6. testing information technology systems and components and confirming compliance with IT security
standards defined in the Federal Office’s technical guidelines;
7. testing, evaluating and approving information technology systems or components to be used in
processing or transmitting official confidential information in accordance with Section 4 of the Security
Clearance Check Act (SÜG) in the federal area or by companies in the context of federal contracts;
8. producing key data and operating cryptography and security management systems for federal
information security systems used to protect official confidentiality or in other areas at the request of the
authorities concerned;
9. providing support and advice on organizational and technical security measures and carrying out
technical tests to protect confidential official information in accordance with Section 4 of the Security
Clearance Check Act against unauthorized access;
10. developing technical security standards for federal information technology and for the suitability of
information technology contractors in special need of protection;
11. making IT security products available to federal bodies;
12. providing support for the federal bodies responsible for the security of information technology,
especially where these bodies undertake advisory or supervisory tasks; support for the Federal
Commissioner for Data Protection and Freedom of Information shall take priority and shall be provided in
line with the autonomy granted the Federal Commissioner in carrying out his/her tasks;
13. providing support for
a) the police and prosecution authorities in carrying out their legally mandated tasks,
b) the authorities for the protection of the Constitution in analysing and evaluating information derived
from surveillance of terrorist activities or from intelligence activities as authorized by federal and state law,
c) the Federal Intelligence Service in carrying out its legally mandated tasks.
3/10