This lesson focuses on the critical concept of the “secure perimeter” and the internationally agreed information security standards that tax administrations must implement to protect the confidentiality of exchanged data. It covers the physical, technical, and procedural safeguards required.
-
The Secure Perimeter: A secure perimeter means a physical and/or virtual environment within a tax administration with strong information security controls, in line with the internationally agreed requirements for AEOI . The Global Forum Secretariat has developed specific guidance for implementation of a secure perimeter for automatic exchange of information purposes, with a particular focus on developing countries . This guidance is part of the Global Forum Secretariat’s Strategy to unleash the potential of AEOI for developing countries .
-
Internationally Accepted Standards: The internationally accepted standards for information security are known as the “ISO/IEC 27000-series” . A tax administration should be able to document that it is compliant with the ISO/IEC 27000-series standards or that it has an equivalent information security framework and that taxpayer information obtained under an exchange agreement is protected under that framework .
-
Key Information Security Controls:Â The OECD’s information security framework covers a comprehensive range of controls:
-
Access Control: Policies limiting system access to authorised personnel and safeguarding data during transmission .
-
Identification and Authentication: Authenticating users and devices that require access to information systems .
-
Audit and Accountability: Ensuring system audits detect unauthorised access and that electronic actions are traceable .
-
System and Communications Protection: Monitoring, controlling, and protecting communications to and from information systems, including security and encryption requirements .
-
Media Protection: Securely storing and limiting access to confidential information in printed or digital form, and securely destroying media prior to disposal or reuse .
-
-
Physical Security: Tax administrations maintain policies on physical security to restrict entry to premises where confidential information is stored . This includes security guards, policies, and entry access procedures . Secure physical storage is required for confidential documents, with policies on receiving, processing, archiving, retrieving, and disposing of hard copies .
-
Personnel Security: Background investigations are required for employees and contractors who may have access to, use, or are responsible for protecting data received through exchange of information . This includes screening and background investigations, training and awareness programmes, and departure policies to terminate access to confidential information for departing employees and consultants .
-
Â