Cover Image for §30 BSIG: The 10 Mandatory Measures and What They Mean for Email

§30 BSIG: The 10 Mandatory Measures and What They Mean for Email

The 10 mandatory measures under §30 BSIG in detail – with specific email relevance for each individual measure.

3 minNIS2 & Compliance

§30 BSIG: The 10 Mandatory Measures and What They Mean for Email

§30 of the revised BSI Act is the centerpiece of NIS2 implementation in Germany. It defines ten specific areas of measures that affected companies must implement. Many of them have a direct connection to email security – the No. 1 attack vector.

The 10 Measures at a Glance

No. 1: Risk Analysis and Security Concepts

Legal requirement: Concepts for risk analysis and security for information systems.

Email relevance: Email is the most important attack vector. Every risk analysis must centrally consider the email infrastructure:

  • What sensitive data is sent via email?
  • What threats exist (phishing, BEC, malware)?
  • What protective measures are implemented?

Conbool solution: The dashboard provides real-time transparency across the entire mail flow. Compliance reports provide the basis for risk analysis.

No. 2: Management of Security Incidents

Legal requirement: Detection, analysis, containment, and management of security incidents.

Email relevance: Most incidents start via email. Required are:

  • Real-time detection of phishing, malware, and anomalous behavior
  • Automatic quarantine of suspicious emails
  • Complete traceability through tracing
  • Reporting processes: 24h early warning, 72h full report

Conbool solution: MailGuard detects threats with AI-based analysis. Quarantine, tracing, and audit logs enable rapid incident management.

No. 3: Business Continuity, Backup Management

Legal requirement: Business continuity management and crisis management.

Email relevance: Email availability is business-critical. Backup strategies for email configurations and archiving are required.

No. 4: Supply Chain Security

Legal requirement: Security in the supply chain including security-related aspects of relationships between entities and their service providers.

Email relevance: Communication with suppliers and partners must be encrypted. Even small suppliers without their own encryption must be included.

Conbool solution: The Message Portal enables encrypted communication with partners – even without their own S/MIME or PGP infrastructure.

No. 5: Security in Acquisition, Development, and Maintenance

Legal requirement: Vulnerability management and disclosure.

Email relevance: Email systems must be regularly checked for vulnerabilities and updated. Gateway solutions handle updates automatically.

No. 6: Effectiveness Assessment

Legal requirement: Concepts for assessing the effectiveness of risk management measures.

Email relevance: The effectiveness of spam filters, encryption, and access controls must be regularly evaluated. Audit logs and reports are essential for this purpose.

No. 7: Cyber Hygiene and Training

Legal requirement: Basic cyber hygiene practices and cybersecurity training.

Email relevance: Employee training on phishing detection is mandatory. Technical measures like MailGuard complement the human line of defense.

No. 8: Cryptography

Legal requirement: Concepts and procedures for the use of cryptographic methods and, where applicable, encryption.

Email relevance – THE central measure for email:

  • Encryption in transit: TLS for all email connections, configurable per domain
  • Content encryption: S/MIME and/or PGP for sensitive emails
  • Key management: Secure generation, storage, distribution, and destruction
  • Cryptography policy: Documentation of all methods in use
  • BSI TR-02102: Only current, considered-secure algorithms

Conbool solution: SecureMail automates all email encryption. Central certificate and key management with MPKI integration. BSI TR-02102 compliant algorithms.

No. 9: Personnel Security and Access Control

Legal requirement: Personnel security, access control concepts, and asset management.

Email relevance: Access to email administration and quarantine must be role-based. MFA for administrative access.

Conbool solution: Role-based access management with Entra ID/LDAP integration and SAML SSO.

No. 10: Secure Communication

Legal requirement: Use of multi-factor authentication solutions, secured voice, video, and text communication, as well as secured emergency communication.

Email relevance:

  • Secured email as the primary text communication channel
  • Encryption solution for recipients without their own infrastructure
  • Verifiable delivery with audit trail
  • Alternative communication when the email system is compromised

Conbool solution: Gateway encryption + Secure Message Portal for external recipients. Verifiable delivery with complete audit trail.

BSI TR-02102: The Permitted Algorithms

The cryptographic methods used must reflect the state of the art. The BSI Technical Guideline TR-02102 defines the approved algorithms:

Permitted:

  • AES-128, AES-192, AES-256 (symmetric)
  • RSA from 2048 bit (asymmetric)
  • ECDSA with at least 250 bit
  • SHA-256, SHA-384, SHA-512

No longer permitted:

  • MD5, SHA-1 (for security-critical applications)
  • RSA below 2048 bit
  • 3DES (no longer recommended since 2023)

Conbool SecureMail exclusively uses BSI TR-02102 compliant algorithms and automatically updates when new recommendations are issued.

Documentation Requirements

§30 BSIG requires not only the implementation but also the documentation of measures. For email, this means:

  1. Cryptography policy: Which methods are used, for which communication?
  2. Key management documentation: How are keys generated, distributed, and revoked?
  3. Incident response plan: How are email security incidents handled?
  4. Audit logs: Tamper-proof logs of all security-relevant events

Conclusion: Email Is the NIS2 Focal Point

Of the 10 mandatory measures under §30 BSIG, at least 6 directly affect email security. Email is not a peripheral topic of NIS2 compliance – it is the central attack point where encryption, threat protection, and auditing converge.

Conbool makes implementation simple: One platform for all email requirements, set up in minutes and auditable.

Try for free →


Further reading:

Weitere Artikel

Die neuesten Beiträge aus unserem Blog.