TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law
Conformity assessment requirements The Security Assessment Measures require that secu - rity assessments verify compliance not only with the Security Standards but also with the Standards for Safety Control of Electronic Banking Business. Telecommunications For the telecoms sector, the CTCTI outlines the gen - eral technical standards for testing CTI equipment in various respects, such as access control, audit and system vulnerability, as well as specific standards for each category of critical telecommunications infra - structure equipment (CTE) based on the nature of their operation. Key provisions include the following. Vulnerability management The CTCTI specifically references the vulnerabilities database provided by the National Institute of Stand - ards and Technology (NIST) and the European Net - work and Information Security Agency (ENISA) for testing institutions to adopt when conducting vulner - ability scanning. Additionally, the CTCTI utilises the common vulnerabilities and exposures (CVE) and common vulnerability scoring system (CVSS) for vul - nerability management. For instance, CTE is prohibit - ed from containing known vulnerabilities with a CVSS For certified equipment, if a new vulnerability with a CVSS score of 7.0 or higher is later discovered, the manufacturer, importer, reseller or agent should sub - mit a patch test report within 90 days of the disclosure of the said vulnerability. Conformity assessment requirements The CTCTI requires the external assessment to be conducted and tested by the accredited laborato - ries. The scope of testing covers a range of technical standards, including, but not limited to, the level of access control, the required components of security logs, encryption standards such as TLS 1.2 and AES- 128 or above, as well as performance stability during an eight-hour anomalous traffic stress test (for firewall and router systems). score of 7.0 or higher. Patching and updates
ation reflects the distinct needs of the industry as well as the differing levels of complexity inherent to each product or service. That being said, to ensure that financial institutions maintain a consistent baseline of system security, the Banking Association has promul - gated the Measures for Financial Institutions to Con - duct Information Security Assessments of Computer Systems (the “Security Assessment Measures”) and the Information Security Standards for Financial Insti - tution Systems (the “Security Standards”). Some of the relevant key requirements are as follows. Vulnerability management The Security Assessment Measures establish a three- tiered framework for assessing computer systems based on their criticality – specifically, whether the system provides automatic customer access, requires human intervention or offers no access at all. Systems classified as Level 1 must undergo an annual assess - ment, Level 2 systems require assessment every two years and Level 3 systems are assessed every five years. Furthermore, the Security Assessment Meas - ures impose specific obligations regarding vulnerabil - ity management. Additionally, financial institutions are required to conduct vulnerability scans and remedia - tion for network equipment, servers and terminals, as well as targeted penetration testing for websites. Patching and updates According to the Security Assessment Measures, security assessments must include a review of secu - rity configurations, which entails verifying the update settings and current patch status of operating sys - tems, antivirus software, office applications and related components. The frequency of these assess - ments aligns with the tiered schedule described in the foregoing. Notably, if a system experiences a material information security incident, a re-assessment must be completed within three months to address any potential vulnerabilities. Post-market surveillance of products The Security Standards mandate that financial institu - tions implement surveillance systems capable of early detection of anomalies. Additionally, system log data must be retained for a sufficient period to support audit trails and investigations.
402 CHAMBERS.COM
Powered by FlippingBook