• Font Size:
  • S
  • M
  • L

Article NO. Content

Title:

Reference Guidelines on the Protection of the Information and Communication Systems of Service Enterprises in Securities and Futures Markets  CH

Announced Date: 2024.01.09 (Articles 15 amended,English version coming soon)
Current English version amended on 2022.04.26 
Categories: Information Operations
Article 20     (System Development Life Cycle – Deployment, Maintenance and Operation, and Outsourcing Stage)
  1. An organization shall update and rectify the information and communication system against relevant security threats and flaws and also disable unnecessary services and portals in the deployment environment.
  2. An organization shall inspect the existing information and communication system, set and use quality passwords, and avoid using default passwords.
  3. An organization shall implement version control and management revision during the maintenance and operation stage of the development life cycle of the information and communication system.
  4. If an organization outsources the development of the information and communication system, it shall incorporate by level the safety requirements (including confidentiality, availability, integrity) of the system of each stage of the development life cycle in the outsourcing contract.