• Font Size:
  • S
  • M
  • L

Article NO. Content

Title:

Establishing Information Security Inspection Mechanisms for Securities Firms  CH

Amended Date: 2025.07.03 
Categories: Market Supervision > Regulation of Securities Firms
1     Risk Assessment and Management (CC-11000; annual audit)
  1. All of the company's information assets within the scope of applicable information security risk and all owners of such assets shall be identified.
  2. The acceptable level of information security risk for each of the company's operations shall be determined.
  3. The company shall conduct information security risk inspections at least once per year and keep the relevant records. Significant risks and control and management measures relating to operation (including risks in new products, new technologies and information systems) shall be covered by the risk assessment to ensure validity of company policies, procedures and control and management measures.