September 23, 2026
The National Institute of Cyber Security (NICS) under the Executive Yuan established a standardized set of security configurations (TWGCB) to govern government agencies' IT equipment (such as PCs, servers, and network devices). It functions like a security rulebook, specifying password strength, software update frequency, firewall settings, and more, keeping all computers in a secure state. TWGCB: settings modeled on the U.S. government configuration baseline, adapted for Taiwan's computing environment.
For financial institutions, the Financial Supervisory Commission (FSC) released the “Financial Cybersecurity Action Plan 2.0” on December 27, 2022, strengthening security oversight. Drawing on the Cyber Security Management Act, it applies more rigorous hardening to the IT environment, adding items not covered by the original TWGCB, providing risk levels and explanations for each setting, and incorporating parts of the international CIS and STIG standards.
CIS (Center for Internet Security): a nonprofit organization founded in 2000, with core members from ISACA, IIA, ISC2, and SANS. Its Benchmark series is widely adopted by international financial institutions as a system hardening standard.
STIG (Security Technical Implementation Guide): a set of guidelines published by the U.S. Department of Defense, based on NIST Special Publication 800-53.
| Comparison Item | GCB | FCB |
|---|---|---|
| Target Audience | Government and public sector agencies | Financial institutions |
| Reference Standards | TWGCB | TWGCB + CIS + STIG |
| Implementation Scope | Windows, Windows Server, PC Server, Linux | Windows Server, Linux |



| Item Count | TWGCB / TWGCB+ | FCB | Total |
|---|---|---|---|
| Windows Server 2012 R2 | 714 / 13 | 92 | 819 |
| Windows Server 2016 | 699 / 13 | 92 | 804 |
| Windows Server 2019 | 696 / 13 | 92 | 801 |
| Windows Server 2022 | 704 / 13 | 92 | 809 |
| Red Hat Enterprise Linux 8 | 290 / 3 | 22 | 315 |
| Red Hat Enterprise Linux 9 | 284 / 3 | 22 | 309 |
Supports a wide range of operating systems: Windows, Windows Server, macOS, Red Hat, Ubuntu, SUSE, and Rocky.

NICS document: Apple macOS 15 Government Configuration Baseline Documentation (Preview)
DragonSoft has extensive experience implementing and auditing GCB/FCB, with a strong track record across both government and financial institutions.
| Unit | Government | Financial |
|---|---|---|
| Agencies | ![]() | ![]() |
| Clients | ![]() | ![]() |
GCB/FCB is more than a regulatory requirement — it's a critical foundation for ensuring security across government agencies, financial institutions, and enterprises. Our audit tools help you achieve: