ACSA Launches Joint Audit of 15 IT Service Providers to Bolster Government Outsourcing Security
Taiwan's Administration for Cyber Security (ACSA) today announced the official launch of the "Joint Cybersecurity Audit Program for Trustees." This initiative consolidates the authority of 121 government agencies to conduct a unified audit of 15 IT service providers. By establishing a common auditing standard, the program aims to enhance the cybersecurity of the government's outsourced supply chain.
📋 Article Processing Timeline
- 📰 Published: May 21, 2026 at 19:18
- 🔍 Collected: May 21, 2026 at 19:31 (13 min after Published)
- 🤖 AI Analyzed: May 21, 2026 at 20:01 (29 min after Collected)
(CNA, Taipei, May 21, by reporter Chao Min-ya) The Ministry of Digital Affairs' Administration for Cyber Security (ACSA) announced today the official launch of the "Joint Cybersecurity Audit Program for Trustees," uniting different public agencies to jointly conduct audits of outsourced vendors. This time, ACSA has consolidated authorization from 121 agencies to audit 15 IT service providers, aiming to strengthen the cybersecurity protection of the government's outsourced supply chain by establishing a common audit standard.
In a press release, ACSA explained that in the past, vendors creating systems for the government who served multiple agencies had to undergo numerous cybersecurity audits. This was repetitive and time-consuming for the vendors and also increased the government's administrative costs. To address this, ACSA promoted the "Joint Cybersecurity Audit for Trustees," allowing vendors to satisfy the cybersecurity management supervision and legal compliance requirements of multiple agencies through a single, comprehensive audit.
ACSA stated that the joint audit is conducted using a risk-oriented approach. Based on the number of agencies a vendor serves and the number of core information and communication systems they maintain, 15 key IT service providers were selected as audit targets, with 121 agencies, including various central government ministries, participating.
ACSA identified the 15 IT service providers as: Chunghwa Telecom Co., Ltd. Enterprise Business Group, Acer E-Enabling Service Business Inc., GSS Technology Inc., Systex Corporation, TISINC., Hyweb Technology Co., Ltd., Trade-Van Information Services Co., Tsaiweii International Inc., Hamastar Technology Co., Ltd., Kung-Ho Information System Co., Ltd., E-SHINE Information Co., Ltd., KFAI Technologies Co., Ltd., ASIA-INFO Co., Ltd., Arche-Group, and Kung-Ta Information Co., Ltd.
ACSA noted that this is the first year of implementation. Through cross-agency participation and sharing of audit results, it not only saves administrative manpower and operational costs for each agency but also effectively reduces the frequency of audits for vendors. This allows them to focus resources on service operations and cybersecurity enhancement. Future plans include gradually expanding participation to local governments and other branches of government such as the Legislative, Judicial, Examination, and Control Yuans.
ACSA emphasized that the core value of promoting the joint audit is to establish a consistent and common audit standard, which helps improve the cybersecurity quality of outsourced services. The agency hopes that this system will encourage IT service providers to continuously improve their cybersecurity management measures, strengthening the cybersecurity resilience of the government's outsourced supply chain from the source and achieving a win-win goal for both the government and the industry. (Editor: Huang Kuo-lun) 1150521
In a press release, ACSA explained that in the past, vendors creating systems for the government who served multiple agencies had to undergo numerous cybersecurity audits. This was repetitive and time-consuming for the vendors and also increased the government's administrative costs. To address this, ACSA promoted the "Joint Cybersecurity Audit for Trustees," allowing vendors to satisfy the cybersecurity management supervision and legal compliance requirements of multiple agencies through a single, comprehensive audit.
ACSA stated that the joint audit is conducted using a risk-oriented approach. Based on the number of agencies a vendor serves and the number of core information and communication systems they maintain, 15 key IT service providers were selected as audit targets, with 121 agencies, including various central government ministries, participating.
ACSA identified the 15 IT service providers as: Chunghwa Telecom Co., Ltd. Enterprise Business Group, Acer E-Enabling Service Business Inc., GSS Technology Inc., Systex Corporation, TISINC., Hyweb Technology Co., Ltd., Trade-Van Information Services Co., Tsaiweii International Inc., Hamastar Technology Co., Ltd., Kung-Ho Information System Co., Ltd., E-SHINE Information Co., Ltd., KFAI Technologies Co., Ltd., ASIA-INFO Co., Ltd., Arche-Group, and Kung-Ta Information Co., Ltd.
ACSA noted that this is the first year of implementation. Through cross-agency participation and sharing of audit results, it not only saves administrative manpower and operational costs for each agency but also effectively reduces the frequency of audits for vendors. This allows them to focus resources on service operations and cybersecurity enhancement. Future plans include gradually expanding participation to local governments and other branches of government such as the Legislative, Judicial, Examination, and Control Yuans.
ACSA emphasized that the core value of promoting the joint audit is to establish a consistent and common audit standard, which helps improve the cybersecurity quality of outsourced services. The agency hopes that this system will encourage IT service providers to continuously improve their cybersecurity management measures, strengthening the cybersecurity resilience of the government's outsourced supply chain from the source and achieving a win-win goal for both the government and the industry. (Editor: Huang Kuo-lun) 1150521
FAQ
「受託者資安聯合稽核計畫」是什麼?
這是由台灣數位發展部資安署推動的一項計畫,旨在整合多個政府機關的需求,對服務這些機關的資訊服務廠商進行一次性的統一資安稽核,以取代過去各機關分別進行的重複性稽核。
為什麼要推動這個聯合稽核計畫?
為了減少委外廠商因服務多個政府機關而需接受多次稽核所造成的資源浪費與時間消耗,同時降低政府的行政成本,並透過建立共通標準來提升整體供應鏈的資安防護水準。
這次稽核的對象是誰?
依據服務機關數量及維運核心系統的風險評估,選出15家重要的資訊服務業者,包括中華電信、宏碁資訊、叡揚資訊等。
有多少政府機關參與此計畫?
此次計畫獲得了中央各部會等121個機關的響應與授權參與。
這個計畫未來的規劃是什麼?
資安署表示,未來規劃將逐步擴大計畫範圍,納入地方政府及立法院、司法院、考試院、監察院等機關共同參與。