Skip to content

Management Duties per §38 BSIG

§38(1) -- Implementation and Supervision

Management is personally obligated to "implement" the risk management measures per §30 "and to supervise their implementation". According to the explanatory memorandum, management must first approve the measures as appropriate and continuously supervise their implementation; the management body remains ultimately responsible even where it relies on assistants (BT-Drs. 21/1501; cf. Art. 20(1) NIS2).

DutyDescriptionEvidence
ImplementationResponsibility for implementing all risk management measures per §30, also where delegatedImplementation orders, resource allocation
ApprovalFormal approval of the measures as appropriateSigned approval document
SupervisionOngoing control of proper implementationRegular security reports, KPI reviews

§38(2) -- Liability

  • Members of management who breach their duties under paragraph 1 are liable to their entity for culpably caused damage
  • Liability follows the company law of the respective legal form (e.g. §43 GmbHG, §93 AktG)
  • They are liable under the BSIG itself only where company law contains no corresponding liability rule

§38(3) -- Training Obligation

  • Management must regularly participate in training – according to the explanatory memorandum, at least every three years
  • Purpose: Sufficient knowledge for identifying and assessing risks
  • Content: Risk management practices and their impact on the entity's services

Implementation at BAUER GROUP

Approval Process

StepDescriptionDocumentation
1. ISO prepares measure proposalBased on risk analysis and §30 requirementsMeasure plan
2. Presentation to managementExplanation of risks and proposed measuresPresentation materials
3. Discussion and adjustmentManagement may request changesMeeting minutes
4. Formal approvalManagement signatureApproval document with date and signature
5. Implementation mandateResource allocation and responsibility assignmentDocumented mandate

Supervision Mechanisms

MechanismIntervalFormat
KPI dashboardMonthlyDigital report
Quarterly management reportQuarterlyPresentation + discussion
Annual security reportAnnuallyWritten report with action plan
Event-driven escalationOn High/Critical levelImmediate notification

Training Evidence

AspectImplementation
FrequencyAt least annually
FormatIn-person training or qualified webinar
TrainerISO or external cybersecurity expert
EvidenceAttendance confirmation with date, content, duration
ArchivalMinimum 3 years

Liability Minimization

To minimize the personal liability risk of management, the following is recommended:

MeasureDescription
Documented approvalApprove and archive every measure in writing
Regular reportsDemonstrable supervision through acknowledgment and discussion of reports
Documented trainingRetain attendance records
Adequate resourcesAllocate budget and personnel for information security
Timely responseTake prompt action when risks become known

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT