• Font Size:
  • S
  • M
  • L

Article NO. Content

Title:

Reference Directions for Information Operation Resilience of Service Providers in Securities and Futures Markets  CH

Amended Date: 2025.02.13 
Categories: Information Operations
Article 14
  1. When the core system is outsourced, an organization shall ensure, based on the scope and characteristics of outsourced services, the recovery level of the core system can meet the recovery time objective (RTO) and recovery point objective (RPO) of the system in order to support the core business for recovery to the minimum acceptable service level after an operational disruption to a supplier due to the following reasons. The organization shall further require that the supplier perform exercise either in collaboration with the organization or by itself to validate feasibility of the core system.
    1. disruption due to a natural disaster, man-made disaster, or information and communication security incident
    2. an unexpected breakdown of or alteration to equipment
    3. an adjustment to a function of or a material structural change to the system
    4. product end of life, with no more technical assistance and services offered and the product being no longer usable
  2. An organization shall include the above requirements on business continuity management in the outsource contract.

Interpretation: