CYBERSECURITY: Attack Detection as a Key Component of an Effective IT Security Strategy

In mid-June 2022, the German Federal Office for Information Security (BSI) published a draft guidance document on the implementation of Systems for Attack Detection (SzA). Until August 19, 2022, the public was invited to submit comments and proposed revisions.

The community draft further specifies the requirements introduced by Germany’s IT Security Act 2.0, which came into force in May 2021. 

CYBERSECURITY - Angriffserkennung ist Bestandteil der sicherheitsstrategie

The legislation requires organizations to plan, implement, and operate effective attack detection systems covering three key areas:

  • Logging
  • Detection
  • Response

The guidance outlines the minimum requirements for each of these areas.

Organizations operating Critical Infrastructure (KRITIS), energy facilities, and energy supply networks—as well as accredited auditing bodies—were required to implement appropriate organizational and technical security measures by May 1, 2023. Their information systems, components, and processes must ensure integrity, authenticity, and confidentiality. The effectiveness of deployed security measures is assessed using a multi-level maturity model.

Organizations must also demonstrate compliance with the legal requirements every two years through standardized compliance documentation, such as the reporting requirements under Section 8a (1a) BSIG and Section 11 (1d) EnWG.

To support implementation, the BSI recommends establishing an Information Security Management System (ISMS) certified in accordance with DIN EN ISO/IEC 27001, ideally with the support of experienced cybersecurity specialists.

1. Logging

The BSI defines the following minimum requirements for logging:

  • Establish a centralized logging infrastructure.
  • Collect and make log data available for security analysis.
  • In larger IT environments, store all security-relevant log data in a centralized location.
  • Ensure the logging infrastructure is adequately sized and supported by sufficient technical, financial, and personnel resources.
  • Filter, normalize, aggregate, and correlate collected log data to enable efficient analysis and reporting.

2. Detection

The BSI specifies the following minimum requirements:

  • Continuous monitoring and analysis of log data
  • Deployment of additional detection systems
  • Use of a centralized logging infrastructure for evaluating security events
  • Integration of information from external threat intelligence sources
  • Analysis of log data by qualified security specialists
  • Centralized detection and real-time evaluation of security events
  • Automated responses to security-relevant incidents

3. Response

The guidance requires organizations to meet all fundamental requirements for handling security incidents.

Attack detection systems should be capable of automatically initiating measures to prevent, contain, and eliminate attack-related disruptions without affecting the availability of critical services.

Recommended Next Steps

For operators of critical infrastructure, the BSI recommends the following three-step approach:

  • Inventory all IT assets and review data flows.
  • Develop a comprehensive logging strategy.
  • Implement a centralized logging infrastructure.

A proven implementation model combines:

  • A Security Operations Center (SOC) for continuous monitoring and rapid incident response.
  • A Security Information and Event Management (SIEM) platform for centralized event collection, analysis, and correlation.

Where appropriate, the SIEM environment can be enhanced with an Intrusion Prevention System (IPS) to provide automated threat prevention.

For more information and expert support, visit: https://www.secusys.de/it-sicherheit/

Newsletter

Stay Informed

Subscribe to our newsletter to receive regular insights into Identity & Access Management.

    By subscribing, you agree to our Privacy Policy.

    Read More

    Related Articles

    Ready for an Initial Consultation?

    Let's assess together how resilient and future-ready your Identity & Access Management strategy really is.