TAIWAN Trends and Developments Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law
tion plan to help them achieve sustained, long-term reductions in cybersecurity risks across the entire supply chain. For instance, enterprises should perform due diligence on their suppliers in accord - ance with established C-SCRM requirements. This should include information about the supplier’s organisation and security protocols, and a record of security performance. Additionally, organisa - tions should integrate C-SCRM requirements into their contractual agreements, which serve as the primary enforcement mechanism. • Flow-down control: The NIST Framework requires prime contractors to extend applicable security requirements to subcontractors and vendors throughout the system development life cycle. This establishes clear expectations for all suppliers and subcontractors, ensuring they can effectively man - age cybersecurity risks across the entire supply chain. • Information sharing: To better identify, assess, monitor and respond to risks, enterprises should incorporate information-sharing processes into their C-SCRM. This can involve establishing infor - mation-sharing agreements with peers, partners and suppliers. • Continuous monitoring: In the contract and its management, enterprises should include the peri - odic revalidation of supplier adherence to security requirements to ensure continual compliance. In general, the NIST Framework is mandatory for US federal agencies. For private sector entities and other non-governmental organisations, however, the Frame - work is applicable on a voluntary basis. EU NIS2 Directive (EU) 2022/2555, known as NIS2, builds upon the original NIS framework and, together with related regulations – including the NIS2 Implementing Regula - tions, international standards and national frameworks – creates a comprehensive legal structure. This frame - work applies to essential and important entities (regu - lated entities) and is designed to bolster the security of network and information systems across the EU. Article 21 of NIS2 outlines ten essential measures that regulated entities must implement. Among these measures is a specific mention of supply chain secu -
rity, encompassing the relationship between entities and their direct suppliers or service providers. The NIS2 recital further emphasises that regulated enti - ties should integrate cybersecurity risk management into their contracts with direct suppliers and service providers while also considering risks that may arise from other tiers within the supply chain. Additionally, the later-published guidance of the European Network and Information Security Agency (ENISA) outlines key requirements for ensuring supply chain security, including the following. • Supply chain security policy: Regulated entities must establish a formal policy to govern their relationships with direct suppliers and service pro - viders and communicate their roles in the supply chain to these parties. • Due diligence: Before contracting with suppliers, regulated entities must apply specific criteria, such as assessing the suppliers’ cybersecurity prac - tices, the risks associated with their ICT products or services and their resilience. • Flow-down control: Regulated entities must ensure that contracts with direct suppliers include specific cybersecurity obligations. These obligations should include the specification of cybersecurity require - ments for products or services, an obligation for suppliers to notify the entity promptly of any incidents presenting a risk and the right to audit suppliers or receive audit reports. • Continuous monitoring: Regulated entities should review their supply chain policies at least once a year and must monitor for significant changes in a supplier’s operations or risk posture. Unlike the NIST Framework, NIS2 imposes legally binding requirements on both public and private entities, provided certain conditions are met. How - ever, as a directive, NIS2 only establishes a baseline framework allowing member states to enforce more stringent cybersecurity requirements. Additionally, the NIS2 Implementing Regulations have been adopted to impose further enhances and rigorous security measures on certain critical entities, such as Domain Name System (DNS) providers, cloud providers and data centres.
412 CHAMBERS.COM
Powered by FlippingBook