• Font Size:
  • S
  • M
  • L

Article NO. Content

Title:

Reference Directions for Information Operation Resilience of Service Providers in Securities and Futures Markets  CH

Announced Date: 2025.02.13 (Articles 2, 8, 12, 14 amended,English version coming soon)
Current English version amended on 2022.08.10 
Categories: Information Operations
Article 3
  1. Business continuity: Ability to handle and respond with flexibility when information operation is damaged, experiences irregularities or services are interrupted.
  2. Core business: Refers to necessary business that directly provides trading services to clients or supports continuous operation of trading business.
  3. Core system: Refers to necessary system that directly enables client trading or supports continuous operation of trading business. All other systems are non-core systems.
  4. Business impact analysis (BIA): Analysis method that identifies impacts on the organization as the period of interruption of core business lengthens.
  5. Maximum tolerable period of interruption (MPTD): The maximum tolerable period of interruption upon occurrence of interruption to the core business, with laws and regulations, revenue losses and interested party’s demand being taken into consideration.
  6. Recovery Time Objective (RTO):
    1. RTO for core business: After occurrence of a disruptive incident, the target time from occurrence of the disruptive incident to core business to recovery to the minimum tolerable service level, to be determined based on the results of BIA.
    2. RTO for core system: After occurrence of a disruptive incident, the target time from occurrence of the disruptive incident to core system to recovery to the minimum tolerable service level.
    3. RTO for core system shall be shorter than or equal to RTO for core business.
  7. Recovery Point Objective (RPO):
    1. RPO for core business: The value representing the tolerable amount of data loss pertaining to core business upon occurrence of a disruptive incident to be determined based on the nature of core business, which should be decided based on the results of BIA.
    2. RPO for core system: The value representing the tolerable amount of data loss pertaining to core system upon occurrence of a disruptive incident to be determined based on the nature of core business.
    3. RPO for core system shall be less than or equal to RPO for core business.
  8. Minimum tolerable service level: The minimum operation level scheduled and expected to be returned to within the recovery time objective (RTO) specific to the applicable core business based on the recovery objective of core business.
  9. Disaster response mechanism: Response, disaster risk reduction or recovery measures applicable to relevant operation procedure of an individual system upon occurrence of irregularity or interruption of core system caused by disaster.

Interpretation: