Article 16
|
(Cyber-threat Protection Mechanism)
- A type 1 organization shall develop a cyber-threat protection mechanism to maintain business operation, e.g., intrusion detection and prevention mechanism, preventive measures against advanced persistent threats, and other protective mechanisms. A type 2 organization shall evaluate such development.
- A securities firm or futures commission merchant with online ordering service or an official website shall develop a protective mechanism against distributed denial-of-service attacks.
- A web application firewall shall be developed in the event an information and communication system offering external services is available.
|