Attack Detection Systems (SzA)
On this page
What is your Attack Detection System (SzA)?
Under the Act on the Federal Office for Information Security ("BSIG"), regulated operators must submit their evidence pursuant to Section 8a (3) BSIG to the Federal Office for Information Security ("BSI") every two years. These are the operators of so-called critical infrastructures, which are responsible for supplying the population with vital resources and services.
Operators of energy supply networks and of energy installations which are deemed "critical infrastructure" under the statutory ordinance must also demonstrate to the BSI, pursuant to Section 11 (1f) EnWG, that they meet the requirements of Section 11 (1e) EnWG – for the first time on 1 May 2023 and every two years thereafter.
For operators of energy supply networks and energy installations that are exempt from KRITIS regulation under the BSI Act, the requirements for attack detection systems apply in parallel pursuant to Section 11 (1e) and (1f) EnWG.
This means that not only KRITIS organisations are affected by this requirement, but – through Section 11 (1d) EnWG – also all network operators (electricity and gas networks, see IT Security Catalogue pursuant to Section 11 (1a) EnWG) and installation operators (see IT Security Catalogue pursuant to Section 11 (1b) EnWG) that do not explicitly fall under the KRITIS Ordinance.
Evidence of the proper use of the attack detection systems must be submitted to the BSI. This also includes transmitting the results of the audits, examinations or certifications of the attack detection systems carried out, including any security deficiencies identified.
RSM Certification GmbH carries out such audits so that you have evidence to submit to the BSI.
Benefits of an evidence audit
Process of an evidence audit
The basis for the audit is the "Guidance on the use of attack detection systems" (version 1.0 of 26 September 2022), including the modules
- OPS.1.1.5 Logging,
- DER.1 Detection of security-relevant events, and
- DER.2.1 Handling of security incidents
from the BSI's IT-Grundschutz Compendium.
The audit by RSM Certification GmbH is divided into the following phases:
- Document review
- Review of the SzA documentation
- Assessment of fundamental requirement fulfilment
- Assessment of whether a functionality review of the SzA can be carried out effectively
- Review of the mapping for implementing the requirements of the "Guidance on the use of attack detection systems"
- Functionality review / effectiveness review
- Review of the actual implementation and assessment of the effectiveness of, and compliance with, the required measures
- Documentation and handover of the necessary documents for the BSI
Your path to evidence of your implemented SzA
- Your path to evidence of your implemented SzA
- Complete our basic data as a basis for an initial understanding of your organisation and for calculating the audit time required
- Place the order with RSM Certification GmbH and jointly coordinate the next steps (including scheduling)
- Conducting the document review
- Conducting the effectiveness review
- Technical review of the auditor(s)' documentation by RSM Certification GmbH
- Handover of the audit documentation and the necessary documents for the BSI
Certification by RSM Certification GmbH
Would you like us to certify you? Feel free to get in touch with us without obligation.
Get in touch without obligation
FAQ
In our FAQs you will find further answers to frequently asked questions – whether general questions or questions on specific procedures. If the answers are not sufficient for you, please feel free to contact us.
The BSI has also set up an FAQ page on the topic of SzA.
The German Federal Office for Information Security (BSI) specifies a six-level implementation model in the "Guidance on the use of attack detection systems" (OH-SzA). This model is intended to assess the implemented technical and organisational measures in terms of the quality of the systems used pursuant to Section 8a (1a) BSIG or Section 11 (1e) EnWG.
The model is based on the defined requirements of the OH-SzA and thus on the BSI's IT-Grundschutz. It therefore defines so-called MUST, SHOULD and MAY requirements for the areas of detection, logging and response. If, for example, all MUST requirements have been met and the SHOULD requirements have ideally already been addressed, this corresponds to implementation level 3.
In principle, an implementation level of 4 should be achieved (all MUST requirements met, all SHOULD requirements met unless they have been excluded on substantiated and comprehensible grounds) in order to meet the requirements of Section 8a (1a) BSIG or Section 11 (1e) EnWG.
Yes, you can have an SzA audit carried out in combination with, for example, an audit to the IT Security Catalogue pursuant to Section 11 (1a) EnWG.
Please feel free to talk to us about your plans and we will examine the options available.
The scope of the SzA audit is defined in the "Guidance on the use of attack detection systems" published by the BSI. The time required depends on the complexity of your particular environment.
For sensible and reliable planning on all sides, we would like a lead time of approximately three months. However, the postponement of audits can repeatedly open up shorter-term opportunities to carry out an audit after all.
So please get in touch with us directly to discuss your requirements personally.