Every licensee must comply with the Notice on Cyber Hygiene (FSM-N14) and protect customer information; licensees providing DPT services must also comply with the Notice on Technology Risk Management (FSM-N13) from 6 November 2024, and others should follow the Technology Risk Management Guidelines. Applicants offering online services must penetration test them and remediate high-risk findings before licensing.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.