This lesson examines the practical implementation of information security management frameworks by tax administrations, the support provided by the Global Forum, and the peer review process that monitors compliance with information security standards.

 

  • ISM Implementation Support: The Global Forum Secretariat is focused on providing continuous support to Global Forum members in the implementation of ISM, which is critical in cross-border exchange of information for tax purposes . New ISM tools are regularly made available to member jurisdictions, including toolkits, templates, guidance documents, and e-learning courses .

  • The ISM Network: The Global Forum has established an ISM Network to facilitate the sharing of experiences and knowledge among information security and information technology professionals from Global Forum member jurisdictions . Through its ISM Network, its quarterly live hour events, and the annual ISM Day, the Secretariat encourages members to continuously further their ISM practices to establish adequate levels of information security across all tax administrations and regions of the world .

  • ISM Day: The Global Forum Secretariat organises an annual ISM Day, a virtual event focused on information security management for tax administrations . The event covers topics such as information security governance, cyber risks, implementation of a secure perimeter for the automatic exchange of information, and secure remote working . Experts from various jurisdictions discuss concrete information security topics and share their valuable experiences .

  • Peer Review of ISM: Tax administrations are subject to peer review that assesses the effectiveness of their information security frameworks. The peer review questionnaire examines multiple elements, including:

    • Planning documentation to develop, update, and implement security information systems .

    • Configuration management and security controls .

    • Risk assessment to identify risks and the potential impact of unauthorised access, use, and disclosure of information .

    • Contingency planning for emergency response, backup operations, and post-disaster recovery of information systems .

    • Systems and services acquisition to ensure third-party providers apply appropriate security controls .