TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law
Regulations Governing the Review of Products Endangering National Cybersecurity The Regulations are enacted to establish a clear and consistent framework for government agencies and specific non-government agencies to submit ICT products for review when those products may present risks to national cybersecurity. Regulations on Audit of Implementation of Cyber Security Maintenance Plan In accordance with the recent amendment to the CSMA, which grants MODA the authority to audit gov - ernment agencies, these Regulations set forth the pro - cedures for auditing both government and designated non-government agencies. The Regulations establish clear legal standards for compliance verification and require that competent authorities, either MODA or competent authorities of certain industries, conduct annual, scheduled audits. These audits include on-site inspections to assess the effective implementation of cybersecurity maintenance plans. To ensure impartial - ity and transparency, audit teams must include repre - sentatives from government agencies. Sectoral Regulations Although MODA functions as the central competent authority, the direct supervision of the private sector is delegated to the relevant central authorities within specific industries, such as the Financial Supervisory Commission (FSC) and the Ministry of Health and Wel - fare (MOHW). Under the authorisation of the CSMA, these competent authorities have established their own regulations governing the cybersecurity man - agement practices of the non-governmental entities within their sectors. These regulations address essen - tial requirements, including the development, imple - mentation and auditing of cybersecurity maintenance plans. 1.3 Cybersecurity Regulators The competent authority for the CSMA is MODA. Within MODA, the Administration for Cyber Secu - rity works closely with the National Institute of Cyber Security, a non-departmental public body supervised by MODA, to develop and implement national cyber - security policies. Together, they promote cyberse - curity programmes, designate critical infrastructure providers and co-ordinate efforts among the compe -
The CSMA establishes obligations for two main cat - egories of entities: • government agencies, which include central and local government bodies as well as public legal entities, excluding military and intelligence agen - cies; and • specific non-government agencies, such as criti - cal infrastructure providers, government-owned enterprises, designated foundations and any enter - prise, organisation or institution under government control. At this time, there has been no indication or discus - sion concerning the application of the CSMA beyond Taiwan’s jurisdiction. The CSMA establishes the primary legal framework, while concurrently empowering the MODA to prom - ulgate supplemental and technical regulations that delineate the substantive requirements for cyberse - curity management. The relevant regulations include but are not limited to the following. Regulations on Classification of Cybersecurity Responsibility Levels The Regulations categorise government agencies and specific non-government agencies into levels A–E, primarily based on the sensitivity of the data they han - dle, such as national secrets; the volume of personal information; and the critical nature of their infrastruc - ture. This includes operations related to foreign affairs, national defence, national security or the management of essential public services and inter-agency shared ICT systems. Accordingly, the Regulations set forth specific cyber - security operational standards within the statutory appendices tailored to each classification level. Agencies are required to implement the prescribed administrative, technical and training measures cor - responding to their assigned level. These measures are designed to ensure that their information systems meet the stringent control requirements mandated under the CSMA.
393 CHAMBERS.COM
Powered by FlippingBook