Bildquelle: Perseus Technologies
08.02.2022

Focus on security: Safer Internet Day and the BSI's IT security label

Cyber security | IT protection | BSI

Security in the digital world has many facets. It ranges from technical requirements to recognising misinformation and fake news. From protecting your own privacy to protecting company secrets and protecting against malware. At Perseus, we strive to present the various information on this topic in a way that is easy to understand and accessible.

 

But cybersecurity is complex. If you often face challenges in this area, it is not your fault. Rather, it is an indication that you are engaging with the topic intensively enough to recognise how diverse it is.

We are therefore delighted to present two resources in this blog post to help you find your way around: the IT security label from the German Federal Office for Information Security (BSI) and the materials and activities for Safer Internet Day.

 

8 February 2022 is Safer Internet Day

Safer Internet Day is mainly aimed at children, young people, parents and teachers. This is actually quite a narrow target group. But the sheer variety of information and teaching materials speaks for itself. Security gaps, misinformation, fraud attempts and data protection already affect even the youngest internet users. If you have children, look after children, teach children or are under 18 yourself, you will find lots of practical information here. For example, what you can do about cyberbullying, how to use smartphones smartly and, particularly helpful, the clearly summarised terms and conditions of WhatsApp, Snapchat and Instagram, among others.

 

The BSI IT security label

In future, the IT security label from the German Federal Office for Information Security (BSI) will provide additional guidance – at least for some devices and services. Are you planning to buy a new router soon? Or a new email address? Then keep an eye out for the new IT security label! We explain what it means, what advantages it has and what its limitations are below.

 

What does the IT security label stand for?

In general terms, the IT security label represents a manufacturer’s voluntary commitment to comply with security standards specified by the BSI. The BSI defines these standards in a special, publicly available guideline for the respective product or service group. In addition to complying with technical specifications, manufacturers also undertake to report security vulnerabilities to the BSI and remedy them without delay.

Important: The IT security label is not a guarantee that a product or service is completely secure and cannot be compromised. Although this is less likely with higher security standards, it is still possible in principle. In the worst case scenario, however, you can quickly find details of the relevant security vulnerabilities using the IT security label – or report a compromise yourself.

 

Which products already carry the IT security label?

IT security labels will initially be awarded for email services and routers. Other product groups will follow. On 1 February 2022, the first email service received the IT security label. You can find the current status in the BSI’s directory of IT security labels.

 

How does the BSI check the IT security mark?

When awarding the mark, the BSI relies primarily on self-disclosure and self-commitment by the manufacturers. Their written application is checked for plausibility and rejected if necessary. It can also be rejected if the products or the manufacturer are known for security gaps or problems.

After the seal has been awarded, the BSI can check the products or services at any time. For example, as part of random checks or after a security vulnerability has become known. If this check is negative, the BSI can withdraw the IT security mark.

 

What are the advantages of the IT security mark?

For consumers: The IT security label shows you that a product or service meets the BSI’s security standards. You can find out what these are and obtain additional security information on a detailed page on the BSI website.

For manufacturers: The IT security label allows you to quickly and credibly demonstrate your commitment to cyber security.

 

What does the IT security label look like?

You will find the IT security label in the header of our article on the manufacturer’s website. For devices such as routers, it will also be displayed on the packaging and, if applicable, on the router itself.

The QR code and link for each IT security label take you to a special product information page on the BSI website. Here you will find important information about the device or service, such as security vulnerabilities and updates. You can also report security vulnerabilities yourself here.

Our assessment: The easy-to-find information on updates is particularly helpful for routers. Experience has shown that many people have never updated their router and often do not know exactly where to look for a relevant update. The information is now easy to find on the BSI product information page.

 

What are the disadvantages of the IT security label?

The biggest disadvantage we see for consumers is that the technical guidelines for the BSI security standards are only available in English. This makes these standards more difficult to understand for interested parties. A German translation would facilitate the desired transparency, despite the many technical terms it contains.

 

Would you like even more security on the Internet?

Digital devices and services that meet meaningful security standards are an important building block for your cyber security. But you are even more important. More precisely: your security-conscious use of devices, services and the Internet itself.

Our online training courses can help you with this. Why not try them out for free for 30 days? You can concentrate fully on the content, as your trial period ends automatically with no further obligations.