• Font Size:
  • S
  • M
  • L

Amendments

Title:

Establishing Information Security Inspection Mechanisms for Securities Firms  CH

Amended Date: 2025.04.11 (Articles 1, 2, 3, 4, 6, 7, 8, 9, 10, 12, 14 amended,English version coming soon)
Current English version amended on 2024.11.12 
Categories: Market Supervision > Regulation of Securities Firms

Title: Establishing Information Security Inspection Mechanisms for Securities Firms(2024.02.05)
Date:
1 1. Risk Assessment and Management (CC-11000, applicable to securities firms placing orders via the Internet, but not applicable to those doing so via telephone or in the traditional manner; annual audit) A. All of the company's information assets within the scope of applicable information security risk and all owners of such assets shall be identified. B. The acceptable level of information security risk for each of the company's operations shall be determined. C. The company shall prepare written reports on information security risk evaluations. An evaluation shall be carried out at least once per year and all relevant records retained. D. The core system should be examined with regard to tolerable time period for interruption, recovery time objective (RTO), and recovery point objective (RPO), and the tolerable time period for interruption to the core system shall be determined based on the market share of brokerage business and percentage scale of clients who are natural persons.