CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners
banking) or internal management activities, finan - cial institutions are still required to follow one of the applicable CBDT processes. However, if the transfer falls within the specific scenarios and data categories of certain data subjects listed in Appendix II of the Financial Data Cross-Border Transfer Guidelines, reg - ulators generally acknowledge the necessity of such transfers, meaning that the approval or filing process is expected to be smoother and more efficient. For example, for tax filing purposes under the compliance and internal control scenario, the cross-border trans - fer of corporate clients’ name, internal ID, country/ region, nationality, document issuing authority, docu - ment validity period, partially masked address, birth date, document type or contact details, are generally recognised as necessary. 3.6 Threat-Led Penetration Testing China has not established a unified regime equivalent to the Threat-Led Penetration Testing (TLPT) frame - works adopted in the EU and USA; moreover, in certain scenarios, TLPT is expressly restricted. In particular, pursuant to Article 31 of the CIIO Regulation, active vulnerability scanning and penetration testing against CII are, in principle, prohibited unless prior approval or authorisation is obtained from competent authorities. Instead, a functionally comparable set of requirements has evolved out of China’s financial regulatory and cybersecurity governance system, which collectively form a closed-loop mechanism covering threat detec - tion, defensive controls, incident response, continu - ous testing and simulation exercises. • Under Article 23 of the CSL and Article 5 of the NFRA DSL, financial institutions are required to establish threat detection, risk monitoring and early-warning processes, including continuous monitoring and risk analysis for cyber and data security threats. While under sectoral administra - tion measures, sectoral regulators require timely escalation and reporting of identified risks. • Under Article 23 of the CSL, institutions must implement preventive and defensive security controls. This is primarily achieved through MLPS, which network operators need to focus on the major risks and vulnerabilities identified through assessments, thoroughly investigate the root causes, comprehensively analyse security protec -
tion needs, propose rectification ideas, and finally formulate a protection work plan based on actual conditions. These controls aim to prevent, detect, and mitigate cyberattacks affecting critical busi - ness systems. • Under Article 27 of the CSL, incident response and emergency handling are set as core compliance obligations. Financial institutions must establish incident response processes, activate incident response plans upon detection of security inci - dents, and report material incidents to competent authorities within prescribed timelines. Response measures are expected to balance containment, service recovery, evidence preservation and stake - holder communication. • Under Article 23 of the CSL, regulators set forth continuous monitoring as a form of long-term and normalised safeguards. Institutions are required to maintain effective security protection through ongoing monitoring processes, including log reten - tion, system filing and record-keeping, and incident account management. For network systems clas - sified at third-level or above under MLPS, relevant protection work plans must be filed with local PSB and sectoral regulator (if applicable) on an annual basis. Finally, under the Measures for the Administration of Emergency Response Financial Services of Banking and Insurance Institutions and CIIO Regulation, sim - ulation exercises and drills play a role analogous to TLPT stress scenarios. A banking or insurance institu - tion shall conduct an emergency response plan drill at least once every three years, and those designated as CIIO shall conduct at least one cybersecurity test and risk assessment annually. Taken together, China’s approach achieves TLPT-like objectives through a layered combination of statutory duties, sectoral supervision, baseline standards and recurring exercises.
4. Cyber-Resilience 4.1 Cyber-Resilience Legislation
Constituents to China’s statutory framework for cyber resilience include the CSL, DSL, CIIO Regulation,
84 CHAMBERS.COM
Powered by FlippingBook