資通安全為國家重要政策之一,我國為因應國家整體安全,於2018年制訂資通安全管理法,2023年數位發展部提出資通安全管理法之修正草案,數位發展部資通安全署並相應舉辦多場工作坊及說明會,期能對草案凝聚共識。現行資通安全管理法在立法上,多參考美國FISMA及歐盟NIS指令的架構及思維,而為因應國際情勢發展,資通安全管理法的修正草案則參考歐盟ENISA的NIS 2指令新思維,如通報應變機制與資安聯防等。本文將先就我國資通安全法制發展進行蒐整,並兼述我國資通安全戰略報告與資通安全管理法之關連性。另外,除針對現行資通安全管理法之重點簡述外,將針對資通安全管理法修正草案中之重要觀念與相關法制之互動,參考美國及歐盟資訊安全法制進行討論,以期於結論中對於未來我國資通安全管理法制實踐提出建議。
Cybersecurity is one of the important national policies. In response to the overall national security, Taiwan formulated the Cyber Security Management Law in 2018. In 2023, the Ministry of Digital Affairs (MODA) proposed an amendment draft to the Cyber Security Management Law as well as held a number of workshops to build consensus on the draft. In terms of legislation, the current Cyber Security Management Law mostly refers to the structure and thinking of the US FISMA and the EU NIS directive. To cope with international trends and situations, the draft amendment to the Cyber Security Management Law refers to the new thinking of the EU ENISA NIS 2 directive, such as notification contingency mechanism and joint information security defense, etc. This article will first summarize the development of Taiwan's cyber-security legal system, together with the relationship between Taiwan's cyber-security strategic report. In addition to a brief overview of the key points of the current Cyber Security Management Law, the interaction between the important concepts in the draft amendment to the Information Security Management Law and relevant legal systems will be discussed with reference to the cyber-security legal frameworks of the United States and the European Union, with a view to drawing conclusions on suggestions are put forward for the future legal practices of Taiwan's cyber-security management.