TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law
into the early stages of development, as well as for producing software bills of materials (SBOM) to monitor vulnerabilities and establish the mecha - nism for version updates. • Implementing zero trust architecture (ZTA): Fol - lowing the Reference Guidance for Zero Trust Architecture in the Financial Sector, the FSC will prioritise adoption in high-risk areas. This transition will be measured through periodic surveys, gradu - ally incorporating ZTA principles into fundamental regulatory standards to elevate the overall defence baseline. • Enhancing security operations centres (SOC) effec - tiveness: Building on the foundation of SOC, the FSC will continuingly expand monitoring stand - ards to include cloud environments and encour - age financial institutions to regularly validate the effectiveness of their cybersecurity monitoring and defensive deployments. • Proactive response to emerging technology: Recognising the hidden risks in AI, the FSC will develop security and testing guidelines to include both the traditional internet threats and AI-specific attacks. Additionally, to counter the threat posed by quantum computing to traditional encryption, the FSC will develop a migration plan for post- quantum cryptography (PQC) • Enhancing the supply chain ecosystem: As finan - cial institutions’ reliance on third-party providers grows, the FSC plans to classify vendors based on risk and data sensitivity. It will provide standardised outsourcing contract clauses and encourage risk assessments and joint cyber drills across the sup - ply chain. • Automated intelligence and global collaboration: The Financial Information Sharing and Analysis Center (F-ISAC) will be upgraded with automated sharing and analysis platforms. Additionally, the FSC plans to establish channels for financial cyber - security vulnerability disclosure and response and hosting international online exchanges, to enhance cross-border early warning and incident response capabilities. • Advanced cybersecurity offensive and defensive drills: The Blueprint mandates continuous cyber - security offensive/defensive simulations. The scope will expand to include complex scenarios to
validate the notification, co-ordination and support efficiency of the collaborative defence network. • Multilayer redundancy for critical services: To ensure the availability of essential services, the FSC is pushing for a multilayer redundancy archi - tecture. 3.2 ICT Service Provider Contractual Requirements Taiwan’s ICT industry includes the following four sec - tors: • CR – Manufacture of electronic parts and compo - nents; • CS – Manufacture of computers, electronic and optical products; • JB – Telecommunications; and • JC – Computer-related and information services. In Taiwan, the term “ICT service providers” primarily refers to enterprises classified under “JC: Computer- related and information services industry” according to the official statistical definitions of the directorate- general of budget, accounting and statistics (DGBAS). This classification encompasses entities engaged in computer programming, system design, consultancy, data processing, information supply and other related information technology services. Official Classification The ICT sector in Taiwan is divided into manufactur - ing and services, with the services segment including: • computer programming, consultancy and related services; and • information services, such as data processing, internet service providers and other information technology support services. This classification is consistent with international standards, such as those of the OECD, and covers non-manufacturing ICT activities, including software development and digital services. The FSC has established a comprehensive regulatory framework governing the outsourcing of services by financial institutions to third-party service providers, such as data processing and cloud service vendors.
397 CHAMBERS.COM
Powered by FlippingBook