• Font Size:
  • S
  • M
  • L

Article NO. Content


Reference Guidelines on the Supply Chain Risk Management of Service Enterprises in Securities and Futures Markets  CH

Announced Date: 2023.11.13 (Articles 4, 7, 10 amended,English version coming soon)
Current English version amended on 2022.04.26 
Categories: Information Operations
Article 13     (Termination, Rescission, or End of a Project)
  1. After a project is terminated, rescinded, or ends, an organization shall immediately suspend the authorization physical access and logical access grantedto an information service supplier, and reclaim, or request the information service supplier to destroy, the organization’s information assets and trade secrets; where necessary, the organization may request the information service supplier to prove such destruction.
  2. An organization shall define the requirements for service continuity following the termination of IT outsourcing, including the following:
    1. information security requirements with which the initial information service supplier and the organization shall comply, if it is decided the product or service is to be transferred by the initial information service supplier back to the organization or to another information service supplier
    2. the organization’s information assets which are used in the IT outsourcing project, to facilitate their return to the organizationin an intact form, or ensure their destruction or transfer to another information service supplier,upon termination of the project
    3. the procedure for the above return, transfer, or destruction, and supporting documents to be presented where necessary
    4. the survival of the confidentiality undertakings after the IT outsourcing is terminated
    5. time limit for the completion of the termination procedure