Purpose
The Finance and Taxation Bureau, Chiayi City (hereinafter referred to as the Bureau) has established this Information Security Policy to ensure the secure use of information and communication systems, strengthen the information security environment of local tax service platforms, and maintain the accuracy and integrity of taxpayers' personal information.
By implementing an information security management system that conforms to internationally recognized standards, the Bureau aims to establish comprehensive information security protection measures and provide a secure, efficient, and reliable information technology environment. The policy also seeks to minimize risks and losses arising from human error, malicious attacks, or natural disasters that may result in the theft, alteration, unauthorized use, disclosure, damage, or destruction of information assets. Furthermore, this policy ensures compliance with applicable laws and regulations while meeting the information security expectations and requirements of both internal and external stakeholders.
Legal Basis
This policy is established in accordance with the Cyber Security Management Act and other applicable information security laws and regulations. It also references relevant information security management requirements issued by the Executive Yuan, the Ministry of Finance, the Chiayi City Government, and the international standard ISO/IEC 27001.
Scope
This policy applies to:
Roles and Responsibilities
Information Security Policy
To ensure the continuous and secure operation of the Bureau's services, all personnel shall comply with this policy to prevent information or information systems from unauthorized access, use, control, disclosure, destruction, alteration, deletion, or any other form of compromise.
The Bureau is committed to maintaining the:
of its information assets and information systems.
Information Security Objectives
Establish an information security risk management mechanism and regularly review its effectiveness in response to changes in the internal and external information security environment.
Protect the confidentiality and integrity of sensitive information and information systems to prevent unauthorized access or modification.
Ensure that the collection, processing, and use of official information comply with applicable laws and regulations.
Strengthen the resilience of critical information systems to ensure the continuity of the Bureau's operations and public services.
Periodic Review of the Information Security Policy and Objectives
The Information Security Policy and its objectives shall be reviewed periodically during Information Security Management Review Meetings to ensure their continuing suitability, adequacy, and effectiveness.
Policy Review
This policy shall be reviewed at least once a year by the Information Security Management Committee, or whenever required due to changes in applicable laws and regulations, supervisory authority requirements, technologies, or business operations.
The policy may be revised whenever necessary to ensure the practicality and effectiveness of the Bureau's information security management practices.
Approval of the Information Security Policy and Objectives
The Information Security Policy and its objectives shall be reviewed periodically during Information Security Management Review Meetings and approved through the Bureau's established management review process.
Communication of the Information Security Policy and Objectives
The Bureau shall communicate its Information Security Policy and objectives annually to all personnel through appropriate channels such as:
The effectiveness of these communication activities shall be evaluated regularly.
The Bureau shall also communicate its Information Security Policy and objectives annually to relevant interested parties, such as IT service providers and organizations connected to the Bureau's information systems, through training sessions, meetings, the official website, or other appropriate means. The effectiveness of these communication activities shall likewise be reviewed.
Implementation
This Information Security Policy shall become effective upon approval by the authorized authority. Any subsequent amendments shall follow the same approval and implementation procedure.