Article Content
Section 4 Information Security System
| Article 24 | Financial holding companies and the banking business shall establish a dedicated information security unit subordinate to the general manager, which shall not concurrently handle information technology operations or other operations that present a conflict of interest with its duties, and shall allocate appropriate human resources and equipment, and appoint a person ranked vice general manager or above, or a person with equivalent responsibilities, to serve as Chief Information Security Officer (CISO) to oversee the promotion of information security policies and the allocation of resources. However, where the competent authority has provided otherwise for credit cooperatives and bills finance companies, such provisions shall govern.
The CISO of a financial holding company and banking business shall report the overall implementation of information security from the preceding year to the board of directors each year, and report material information security issues in a timely manner.
Personnel of the dedicated information security unit of a financial holding company and banking business shall receive at least fifteen (15) hours of professional information security training courses or functional training annually; other information technology personnel shall receive at least six (6) hours of professional information security training courses or functional training annually. Personnel of the head office, domestic and foreign business units, finance and custody units, and other management units of a banking business shall receive at least three (3) hours of information security awareness courses annually.
The Bankers Association of the Republic of China, the National Federation of Credit Cooperatives, and the R.O.C. Bills Finance Association shall establish and regularly review the self-disciplinary regulations of information security. |
| Article 25 | The matters to be performed by the dedicated information security unit shall at least include:
1. Taking charge of the planning, management, and execution of the information security system to manage information security risks.
2. Supervising each unit in implementing the information security system, and ensuring the confidentiality, integrity, and availability of communication systems, services, and information.
3. Establishing mechanisms related to cyber security protection, assessment and response to cyber security intelligence, and reporting of and response to cyber security incidents.
4. Incorporating the overall implementation of information security from the preceding year into the assessment of the implementation of the internal control system referred to in Paragraph 1 of Article 8 annually. |