BSI ID: G 0.29
If an institution's information, business processes and IT systems are inadequately secured (e.g. through inadequate security management), this can lead to violations of legal provisions relating to information processing or existing contracts with business partners. The laws that must be observed depend on the type of institution and its business processes and services. Depending on where an institution is located, different national regulations may also apply.
The following examples illustrate this:
The handling of personal data is regulated by a large number of regulations in Germany. These include the Federal Data Protection Act and the state data protection laws, but also a large number of sector-specific regulations.
The management of a company is obliged to exercise due care in all business processes. This also includes compliance with recognised security measures. In Germany, various legal provisions apply, such as KonTraG (Law on Control and Transparency in Business), GmbHG (Law on Limited Liability Companies) and AktG (Stock Corporation Act), from which the management or executive board of a company can derive corresponding obligations to act and liabilities with regard to risk management and information security.
The proper processing of accounting data is regulated by various laws and regulations. In Germany, these include the Commercial Code (e.g. HGB §§ 238 ff.) and the Fiscal Code (AO). The proper processing of information naturally includes its secure processing. In many countries, both must be demonstrated on a regular basis, for example by auditors as part of their audit of the annual financial statements. If serious security deficiencies are identified, a positive audit report cannot be issued.
In many industries (e.g. the automotive industry), it is common for manufacturers to require their suppliers to comply with certain quality and safety standards. In this context, information security requirements are also increasingly being imposed. If a contractual partner violates contractually agreed security requirements, this can result in contractual penalties, but also in the termination of contracts and even the loss of business relationships. Only a few security requirements arise directly from legislation. However, legislation is generally based on the state of the art as a general basis for assessing the level of security that can be achieved. If an institution's existing security measures are not in proportion to the assets to be protected and the state of the art, this can have serious consequences.