KRITIS-Audit

Security proof for operators of critical infrastructures

With increasing digitization, modern infrastructures are becoming more efficient and intelligent – but also more susceptible to disruptions and breakdowns, for example through attacks by cybercriminals. In order to provide the best possible protection for these infrastructures, which are essential to the general public, the German Federal Office for Information Security (BSI) has issued legal regulations.

The BSI Act requires operators of critical infrastructures (KRITIS) to take appropriate organizational and technical precautions to protect against disruptions to the availability, integrity, authenticity and confidentiality of their information technology systems, components or processes. The state of the art shall be observed.

Are You an Operator of Critical Infrastructures?

For each KRITIS-relevant sector, the BSI has defined different thresholds. If a company reaches the threshold value, it is considered an operator of critical infrastructures.

Even if your company is not classified as a KRITIS company, IT security certifications may be necessary for you. Especially if you are a partner or supplier of a KRITIS company.

The regulation applies to the following sectors:

  • Energy (electricity and gas supply)
  • Water
  • Nutrition
  • Information technology and telecommunications
  • Health
  • Transport and traffic
  • Finance and insurance

How Do You Obtain the Proof of Compliance?

As an operator of critical systems, you must present a special audit report to the BSI to confirm that your IT security is state of the art. For this purpose, an independent, accredited testing agency will test your IT security in the course of a KRITIS audit in accordance with Section 39 (formerly Section 8a) (3) BSIG. Which security requirements you have to meet in detail depends on your industry. These requirements are fleshed out in industry-specific security standards recognized by the BSI (B3S).

In order to prepare yourself optimally for the audit, you should

  • Create a network structure plan
  • Conduct risk assessments
  • Perform an internal pre-audit

How Does usd AG Support You in Securing Critical Infrastructure (KRITIS)?

As an IT security consulting firm and accredited Qualified Security Assessor with many years of experience in a wide variety of IT security consulting projects and audits, we are the optimal partner for your KRITIS audit.

On the BSI website you can read about the strict conditions we have to meet in order to be allowed to conduct tests according to Section 39 (formerly Section 8a) (3) BSIG. These include, for example:

  • Uniformity in security assessments
  • Independence and neutrality
  • Competent employees and extensive human resources
  • Secure infrastructure, systems and applications
  • Sound knowledge in the areas of information security and information security management systems (ISMS)
  • Familiarity with common norms and standards of IT and information security

Synergy effects with other certifications

Existing IT security certifications can be accredited for the KRITIS proof. Use synergies and combine, for example, your KRITIS audit with your PCI DSS assessment. This saves you time and effort.

How Does usd AG Approach KRITIS-Audits?

Phase 1

Audit preparation, including determination of audit basis and audit scope

Phase 4

On-site audit

 

Phase 2

Creation of the audit plan

Phase 5

On-site audit follow-up

Phase 3

Documentation review

 

Phase 6

Creation of the audit report

Keep Track with Your Proof of Compliance

The KRITIS proof of compliance must be provided every 3 years.

Contact

 

Please contact us with any questions or queries.

Phone: +49 6102 8631-190
Email: sales@usd.de
S/MIME
Contact Form

 

Kontakt usd Sales

Benedikt Krümmel
Head of Sales - Security Audits