• Font Size:
  • S
  • M
  • L

Article NO. Content

Title:

Operating Procedures for the Assessment of Information and Communication Security of Information and Communication Systems by Securities Firms  CH

Announced Date: 2025.07.03 
Article 3     Classification and Assessment Cycle of Information and Communication Systems
  1. Information and communication systems are classified into three categories based on their importance:
  2. Testing may be conducted by sampling where the equipment comprise a multitude of systems and the economic rights of such equipment are owned by the company. The sampling rate shall be at least 10% of all the equipment in the system or a minimum of 100 units each time.
  3. Where a material information and communication security incident occurs in a single system and is confirmed to constitute a personal data breach or a hacker attack, an information and communication security assessment must be re-conducted and completed within three months

Attachment:

Interpretation: