TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law
3.3 Key Operational Resilience Obligations In addition to what has been established under the CSMA and its relevant regulations, the FSC, along with the associations of various financial institutions (eg, the Bank Association, the Insurance Association and the Securities Association), has announced sever - al self-regulatory rules and guidelines to maintain the cybersecurity resilience of the financial institutions’ ICT systems. For instance, the Banking Association has stipulated the Resilience Standards for Informa - tion Operations of Financial Institutions (Resilience Standards), which have been submitted to the FSC for its reference. According to the Resilience Standards, financial insti - tutions must establish specific practices. Key provi - sions include the following. • Governance: (i) establish a business continuity management unit, with appropriate manpower and budget, to promote, co-ordinate and review business continuity management matters; and (for subsidiaries or branches of foreign financial institu - tions) (ii) compare the provisions of the resilience regulations of the parent company’s jurisdiction with Taiwan’s regulations, and adopt the stricter provisions. • Risk management: (i) identify critical business, critical ICT and important supporting informa - tion systems on an annual basis – additionally, the business should execute a business impact analysis (BIA) and produce the specific results (eg, the recovery time objective (RTO) and the recov - ery point objective (RPO)); and (ii) based on the analysis result, establish a backup and redundancy mechanism. • Incident management obligations: (i) establish a business continuity plan (BCP), identifying the risk scenarios that could interrupt the critical busi - ness and critical ICT systems, and enactment of the response plan; and (ii) perform annual drills to verify the implementation of the BCP and deter - mine if the recovery mechanism successfully met expectations (such as the RTO and RPO). For incident reporting, the FSC has also stipulated corresponding regulations. For instance, the Report - ing Procedures and Other Compliance Matters for
• the extent to which service disruptions or data breaches could affect the institution’s reputation, operational objectives, customer rights or coun - terparties, or the stability of the broader financial market; • the costs associated with the outsourcing services; • the costs involved in transitioning to an alternative service provider should the original arrangement fail; • the aggregate exposure of risk to a single service provider when multiple operations are consolidated under one vendor; and • the financial institution’s capacity to maintain effec - tive internal controls and comply with regulatory obligations throughout the outsourcing relation - ship. Documents to be submitted to the FSC for approval and financial institutions’ additional obligations Key documents include, but are not limited to: • internal policies for engaging an outsourcing arrangement; • board meeting resolution document; • the necessity and legal compliance analysis; • outsourcing arrangement proposals, including risk analysis and management, customer data protec - tion mechanisms, cybersecurity and contingency plans; • outsourcing agreements; and • a statement from the service provider certifying no major fraud, security or operational incidents over the past three years. Additionally, the financial institution must adhere to further obligations, including performing security examinations of its information systems at prescribed intervals. It should also conduct, or engage qualified third parties to conduct, both general and special examinations annually. Furthermore, outsourcing agreements must clearly outline the responsibilities related to the transition of outsourced services, as well as the penalties applicable in the event of ser - vice failures.
399 CHAMBERS.COM
Powered by FlippingBook