Governance
LEGAL BASIS
§38(1) BSIG – Management of essential and important entities is obligated to implement the risk management measures to be taken by these entities per §30 and to supervise their implementation.
§38(3) BSIG – The management of essential and important entities must regularly participate in training in order to acquire sufficient knowledge and skills for identifying and assessing risks and risk management practices in the field of information technology security, and in order to be able to assess the impact of risks and risk management practices on the services provided by the entity.
Management Duties
The German NIS2 implementation establishes, for the first time, personal obligations of management for cybersecurity:
| Duty | Description | Evidence |
|---|---|---|
| Implementation | Responsibility for implementing the measures per §30 – also where tasks are delegated (§38(1) BSIG) | Implementation orders, resource allocation |
| Approval | Formal approval of the measures as appropriate (explanatory memorandum to §38(1); Art. 20(1) NIS2) | Documented sign-off |
| Supervision | Ongoing control of implementation (§38(1) BSIG) | Regular reports |
| Training | Personal participation in cybersecurity training (§38(3) BSIG) | Attendance record |
| Liability | Liability towards the entity itself for culpable breach of duty (§38(2) BSIG) | — |
LIABILITY
Under §38(2) BSIG, members of management who breach their duties under paragraph 1 are liable to their entity for culpably caused damage – under the company-law rules of the entity's legal form (e.g. §43 GmbHG, §93 AktG). Only where company law contains no such liability rule do they become liable directly under the BSIG.
Governance Structure
| Role | Responsibility |
|---|---|
| Management | Responsibility for implementation, approval and supervision of measures, resource allocation, personal training |
| Information Security Officer (ISO) | Operational control, risk analysis, incident coordination, BSI contact |
| IT Lead | Technical implementation, system security, patch management |
| Department Heads | Compliance with security policies in their area |
Reporting
| Report | Recipient | Interval |
|---|---|---|
| Security status | Management | Quarterly |
| Incident reports | Management | Event-driven (high/critical immediately) |
| Annual security report | Management | Annually |
| KPI report | ISO / Management | Monthly |
Management Training Obligation
Management participates at least annually in cybersecurity training covering:
- Current threat landscape and relevant incidents
- NIS2/BSIG obligations and liability
- Risk management and measure assessment
- Incident response process and escalation
AI Act Synergy
The AI Act governance framework complements NIS2 governance requirements for AI-powered systems. Details in the AI Act Governance Documentation.