|
Regulations Governing Internal Control and Auditing SystemsFSC
|
Financial enterprises within the applicable sector rules |
Board-approved internal controls, independent audit, annual plans, findings, reporting and tracked remediation. |
|
Source
|
|
Cyber Security Management ActExecutive Yuan and cybersecurity authorities
|
Government agencies and designated specific non-government agencies |
Cyber governance, risk programmes, incident response, reporting, audits and improvement measures. |
|
Source
|
|
Cybersecurity Incident Reporting and Response RegulationsCybersecurity authorities
|
Entities designated under the Cyber Security Management Act |
Incident classification, time-bound reporting, response, status updates, investigation and corrective-action evidence. |
|
Source
|
|
Personal Data Protection ActPDPC
|
Government and non-government agencies processing personal data |
Purpose limitation, security safeguards, data-subject rights, incident accountability and damage prevention. |
|
Source
|
|
Financial Operational Resilience on Cybersecurity Ecosystem BlueprintFSC
|
Financial institutions and industry bodies participating in the supervisory resilience programme |
Sector cyber governance, operational resilience, coordinated incident response, continuity, monitoring, exercises and assurance. |
|
Source
|