Management Duties per §38 BSIG
Legal Obligations
§38(1) -- Implementation and Supervision
Management is personally obligated to "implement" the risk management measures per §30 "and to supervise their implementation". According to the explanatory memorandum, management must first approve the measures as appropriate and continuously supervise their implementation; the management body remains ultimately responsible even where it relies on assistants (BT-Drs. 21/1501; cf. Art. 20(1) NIS2).
| Duty | Description | Evidence |
|---|---|---|
| Implementation | Responsibility for implementing all risk management measures per §30, also where delegated | Implementation orders, resource allocation |
| Approval | Formal approval of the measures as appropriate | Signed approval document |
| Supervision | Ongoing control of proper implementation | Regular security reports, KPI reviews |
§38(2) -- Liability
- Members of management who breach their duties under paragraph 1 are liable to their entity for culpably caused damage
- Liability follows the company law of the respective legal form (e.g. §43 GmbHG, §93 AktG)
- They are liable under the BSIG itself only where company law contains no corresponding liability rule
§38(3) -- Training Obligation
- Management must regularly participate in training – according to the explanatory memorandum, at least every three years
- Purpose: Sufficient knowledge for identifying and assessing risks
- Content: Risk management practices and their impact on the entity's services
Implementation at BAUER GROUP
Approval Process
| Step | Description | Documentation |
|---|---|---|
| 1. ISO prepares measure proposal | Based on risk analysis and §30 requirements | Measure plan |
| 2. Presentation to management | Explanation of risks and proposed measures | Presentation materials |
| 3. Discussion and adjustment | Management may request changes | Meeting minutes |
| 4. Formal approval | Management signature | Approval document with date and signature |
| 5. Implementation mandate | Resource allocation and responsibility assignment | Documented mandate |
Supervision Mechanisms
| Mechanism | Interval | Format |
|---|---|---|
| KPI dashboard | Monthly | Digital report |
| Quarterly management report | Quarterly | Presentation + discussion |
| Annual security report | Annually | Written report with action plan |
| Event-driven escalation | On High/Critical level | Immediate notification |
Training Evidence
| Aspect | Implementation |
|---|---|
| Frequency | At least annually |
| Format | In-person training or qualified webinar |
| Trainer | ISO or external cybersecurity expert |
| Evidence | Attendance confirmation with date, content, duration |
| Archival | Minimum 3 years |
Liability Minimization
To minimize the personal liability risk of management, the following is recommended:
| Measure | Description |
|---|---|
| Documented approval | Approve and archive every measure in writing |
| Regular reports | Demonstrable supervision through acknowledgment and discussion of reports |
| Documented training | Retain attendance records |
| Adequate resources | Allocate budget and personnel for information security |
| Timely response | Take prompt action when risks become known |