This document is under active development and has not been finalized.
Skip to content

Governance

LEGAL BASIS

§38(1) BSIG – Management of essential and important entities is obligated to approve the risk management measures taken by these entities per §30 and to supervise their implementation.

§38(3) BSIG – Management must regularly participate in training to acquire sufficient knowledge and skills for identifying and assessing risks and risk management practices.

Management Duties

The German NIS2 implementation establishes personal obligations of management for cybersecurity:

DutyDescriptionEvidence
ApprovalFormal approval of risk management measuresDocumented sign-off
SupervisionOngoing control of implementationRegular reports
TrainingPersonal participation in cybersecurity trainingAttendance record
LiabilityPersonal liability for breach of duty (§38(2) BSIG)

LIABILITY

Under §38(2) BSIG, management is personally liable for damages resulting from breach of their approval and supervision duties. Waiver agreements and settlements are void.

Governance Structure

RoleResponsibility
ManagementApproval of measures, resource allocation, personal training
Information Security Officer (ISO)Operational control, risk analysis, incident coordination, BSI contact
IT LeadTechnical implementation, system security, patch management
Department HeadsCompliance with security policies in their area

Reporting

ReportRecipientInterval
Security statusManagementQuarterly
Incident reportsManagementEvent-driven (high/critical immediately)
Annual security reportManagementAnnually
KPI reportISO / ManagementMonthly

Management Training Obligation

Management participates at least annually in cybersecurity training covering:

  • Current threat landscape and relevant incidents
  • NIS2/BSIG obligations and liability
  • Risk management and measure assessment
  • Incident response process and escalation

AI Act Synergy

The AI Act governance framework complements NIS2 governance requirements for AI-powered systems. Details in the AI Act Governance Documentation.

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT