KRITIS

PROTECT YOUR CRITICAL INFRASTRUCTURES


Critical Infrastructures (KRITIS)

Critical infrastructures are organizational and physical structures and facilities of such vital importance to a nation’s society and economy that their failure or degradation would result in sustained supply shortages, significant disruption of public safety and security, or other dramatic consequences.

Definition by BSI


 

With increasing digitization, modern infrastructures are becoming more efficient and intelligent – but also more susceptible to disruptions and breakdowns, for example through attacks by cybercriminals. In order to provide the best possible protection for these infrastructures, which are essential to the general public, the German Federal Office for Information Security (BSI) has issued legal regulations.

The BSI Act requires operators of critical infrastructures (KRITIS) to take appropriate organizational and technical precautions to protect against disruptions to the availability, integrity, authenticity and confidentiality of their information technology systems, components or processes. The state of the art shall be observed.

ARE YOU AN OPERATOR OF CRITICAL INFRASTRUCTURES?


For each KRITIS-relevant sector, the BSI has defined different thresholds. If a company reaches the threshold value, it is considered an operator of critical infrastructures.

.

Even if your company is not classified as a KRITIS company, IT security certifications may be necessary for you. Especially if you are a partner or supplier of a KRITIS company.

 

The regulation applies to the following sectors:

  • Energy (electricity and gas supply)
  • Water
  • Nutrition
  • Information technology and telecommunications
  • Health
  • Transport and traffic
  • Finance and insurance

HOW DO YOU OBTAIN THE PROOF OF COMPLIANCE?

As an operator of critical systems, you must present a special audit report to the BSI to confirm that your IT security is state of the art. For this purpose, an independent, accredited testing agency will test your IT security in the course of a KRITIS audit in accordance with § 8a paragraph 3 BSIG. Which security requirements you have to meet in detail depends on your industry. These requirements are fleshed out in industry-specific security standards recognized by the BSI (B3S).

In order to prepare yourself optimally for the audit, you should

  • Create a network structure plan
  • Conduct risk assessments
  • Perform an internal pre-audit

HOW CAN WE HELP?

As an IT security consulting firm and accredited Qualified Security Assessor with many years of experience in a wide variety of IT security consulting projects and audits, we are the optimal partner for your KRITIS audit. While our team conducts the audit at your premises, we work closely with an accredited testing agency which confirms the test report for the BSI.

On the BSI website you can read about the strict conditions we have to meet in order to be allowed to conduct tests according to § 8a paragraph 3 BSIG. These include, for example:

  • Uniformity in security assessments
  • Independence and neutrality
  • Competent employees and extensive human resources
  • Secure infrastructure, systems and applications
  • Sound knowledge in the areas of information security and information security management systems (ISMS)
  • Familiarity with common norms and standards of IT and information security
 

SYNERGY EFFECTS WITH OTHER CERTIFICATIONS

 
 

Existing IT security certifications can be accredited for the KRITIS proof. Use synergies and combine, for example, your KRITIS audit with your PCI DSS assessment. This saves you time and effort.

 
 

 

OUR APPROACH

  • PHASE 1

    Audit preparation, including determination of audit basis and audit scope

  • PHASE 2

    Creation of the audit plan

  • PHASE 3

    Documentation review

  • PHASE 4

    On-site audit

  • PHASE 5

    On-site audit follow-up

  • PHASE 6

    Creation of the audit report

YOUR KRITIS AUDIT


Is your company subject to the KRITIS regulation? Do you need support with the KRITIS proof or do you have any questions?

Get a non-binding consultation from our experts.

Contact us