Regulations Governing Cyber Security Information Sharing
1.中華民國一百零七年十一月二十一日行政院院臺護字第 1070213547 號 令訂定發布全文 11 條;施行日期,由主管機關定之 中華民國一百零七年十二月五日行政院院臺護字第 1070217128 號令發 布定自一百零八年一月一日施行 2.中華民國一百十年八月二十三日行政院院臺護字第 1100182012 號令修 正發布第 3、11 條條文;並自發布日施行 中華民國一百十一年八月二十四日行政院院臺規字第 1110184307 號公 告第 3 條第 1 項、第 2 項、第 3 項、第 9 條、第 10 條、第 11 條第 1 項所列屬「行政院」之權責事項,自一百十一年八月二十 七日起改由「數位發展部」管轄 3.中華民國一百十五年一月五日數位發展部數授資法字第 1145000409 號 令修正發布全文 13 條;並自發布日施行
資料來源:全國法規資料庫(ChOrder.json,版本 2026/7/24 上午 12:00:00)・政府資料開放授權
These Regulations are prescribed pursuant to Paragraph 2, Article 9 of the Cyber Security Management Act (hereinafter referred to as the “Act”).
1The term "cyber security information" (hereinafter referred to as the "Information") as used in these Regulations refers to any of the following information:
21. Malicious reconnaissance or information gathering activities targeting information and communication systems.
32. Security vulnerabilities of information and communication systems.
43. Methods that render the security control measures of information and communication systems ineffective or exploit security vulnerabilities.
54. Information related to malware.
65. The actual damage or possible negative impact caused by cyber security incidents.
76. Relevant measures for detecting, preventing, or responding to the circumstances set out in the pre ceding five subparagraphs, or for mitigating the damage thereof.
87. Other information relating to cyber security incidents.
1The competent authority shall conduct international cooperation regarding the sharing of the Information.
2The competent authority and government agencies shall mutually share the Information.
3The central competent authority in charge of the relevant sector and the specific non-government agencies under its jurisdiction shall mutually share the Information.
4Except for the competent authority or the central competent authority in charge of the relevant sector, other government agencies or specific non-government agencies are not required to re-share the Information that has already been shared or publicly disclosed.
5Where the competent authority or the central competent authority in charge of the relevant sector determines that the Information shared under Paragraph 2 or 3 is sufficient to prevent the occurrence of cyber security incidents in other agencies or to mitigate the resulting damage, the competent authority or the central competent authority in charge of the relevant sector may grant commendations.
1The Information under any of the following circumstances shall not be shared:
21. Information involving trade secrets or relating to the business operations of an individual, juristic person, or group, the disclosure or provision of which would infringe upon the rights or other legitimate interests of a government agency, individual, juristic person, or group; provided, however, that this restriction shall not apply where it is otherwise provided by laws and regulations, is necessary for the public interest or for the protection of the lives, bodies, or health of the people, or is made with the consent of the parties concerned.
32. Other circumstances where information is required by laws or regulations to be kept confidential or its disclosure is restricted or prohibited.
4Where the Information contains content that shall not be shared pursuant to the preceding paragraph, only the remaining parts may be shared.
In sharing the Information, government agencies or specific non-government agencies (hereinafter referred to as “agencies”) shall first analyze and integrate the Information and shall plan appropriate security maintenance measures to prevent the content of the Information, or any information that shall not be shared under laws or regulations, from being leaked, accessed without authorization, or tampered with.
1For the Information received, agencies shall identify the reliability and timeliness of their sources, conduct timely threat and vulnerability analysis, assess potential risks, and take corresponding prevention or response measures.
2The competent authority or the central competent authority in charge of the relevant sector may notify the agencies receiving the designated Information to report back on the measures referred to in the preceding paragraph.
1Agencies may conduct correlation analysis and integration with their internal Information based on the source, date of receipt, period of availability, and types of the information, the characteristics of threat indicators, and other appropriate matters.
2Agencies shall share the Information regarding new types of threats identified through the analysis and integration referred to in the preceding paragraph.
For the Information received, agencies shall take appropriate security maintenance measures to prevent the content of the Information, or any information that shall not be shared under laws or regulations, from being leaked, accessed without authorization, or tampered with.
1In sharing the Information, agencies shall proceed in the respective manner designated by the competent authority or the central competent authority in charge of the relevant sector.
2Where agencies are unable for any reason to share the Information in the manner prescribed in the preceding paragraph, they may, with the consent of the competent authority or the central competent authority in charge of the relevant sector, respectively, use one of the following methods:
31. In writing.
42. By fax.
53. By email.
64. Through an information and communication system.
75. By other appropriate methods.
1Individuals, juristic persons, or groups not subject to the Act may mutually share the Information with the consent of the competent authority or the central competent authority in charge of the relevant sector.
2In giving consent to individuals, juristic persons, or groups for sharing the Information under the preceding paragraph, the competent authority or the central competent authority in charge of the relevant sector shall enter into a written agreement with them stipulating that they shall comply with the provisions of Articles 4 through 9.
Where information and communication systems, services, or products are deemed to raise concerns of harm to national cyber security, the matter shall be handled in accordance with the Regulations for the Review of Products Harmful to National Cyber Security.
The competent authority may delegate matters relating to sharing the Information, commendations, and other related matters set out in these Regulations to the Administration for Cyber Security, Ministry of Digital Affairs.
These Regulations shall come into effect on the date of promulgation.