| Home > Security |
Security |
| font size: |
 |
|
 |
|
| |
National Tax Administration, Southern Taiwan Province Information Safety Policy
Amended on: 2011/03/18 |
| Information Security Policy :[PDF][Word] |
| |
Basis |
- The Information Security Management System ISO27001 and CNS27001 Standard.
- The Information Security Management Practices of The Executive Yuan and Affiliated Organizations.
- The Information Security Management Essentials of The Executive Yuan and Affiliated Organizations.
- The Information Security Management Guidelines of Ministry of Finance and Affiliated Organizations (Institutions).
|
| |
Application Objects |
This policy applies to all the workers of National Tax Administration of Southern Taiwan Province (NTAS), the external organizations who have business contacts with NTAS, and the manufactures and visitors who provided services or labor for NTAS. |
| |
Declarations |
- Enhancing the Information Security Management. Ensuring the confidentiality, integrity and availability of information assets. Providing safe and efficiency information services. Protecting the taxpayer’s Rights and earned the people’s trust.
- Every worker of NTAS will execute information security works, strive to achieve the fully use of tax data by law, and ensure to process information with integrity and accuracy.
- Maintaining the security environment for the continuity of information service operation.
|
| |
Principles |
- Establishing “Information Security Task Force”(ISTF). The responsibility of ISTF is composing this policy, coordinating and discussing information security plan and resource allocation.
- While executing information work, should comply with “Tax Collection Act”, “Computer-Processed Personal Data Protection Law”, other related regulations, and all procedures composed by NTAS.
- Information asset should be inventoried, categorized and graded regularly. With systemized analysis of risk assessment, assets are evaluated of risk level and composed the related risk countermeasure plan to mitigate the impact and keep track of it.
- Setting “Information Service Business Continuity Management Plan ” and exercising regularly.
- The worker of NTAS should be trained with duty related information security training, be acquainted with one’s own information security responsibility, and should comply with related regulations.
- Information security incidents should be reported by following the response procedure, and should take countermeasure as soon as possible. Afterward, Information security incidents should be reviewed and to be improved.
7) The violator of the information security regulation should be charged according to the correction rule of NTAS or other legal law.
|
| |
Review |
ISTF should review this policy regularly and improve the efficiency and applicability continually, in order to qualify for government’s information security policy, law regulations, security technology, and the operation requirements of NTAS. The review should be processed once a year periodically, or when significant changes happened in business or technology.
|
|