CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners
Network Data Management Regulation, Administra - tive Provisions on Security Vulnerabilities of Cyber Products (“Cyber Product Vulnerability Provisions”, in Chinese 网络产品安全漏洞管理规定 ) and MLPS. • The CSL establishes foundational obligations for network operational security and mandates base - line requirements for critical equipment access and continuous security maintenance. • The DSL institutionalises the data classification and hierarchical protection system, requiring risk monitoring and emergency response mechanisms throughout the data lifecycle. • The CIIO Regulation emphasises special protection for core industries, mandating simultaneous plan, establishment and use of security measures to ensure business continuity. • The Network Data Management Regulation strengthens systemic robustness obligations for large-scale platforms and defines mandatory notice-and-report procedures for cyberattacks and supply chain disruptions. • The Cyber Product Vulnerability Provisions man - date a two-day reporting window for vulnerabilities, establishing a closed-loop response resilience process from discovery to patching. • The MLPS provides cross-sector technical bench - marks, requiring tiered defence and recovery capability building for cloud, IoT, and mobile archi - tectures. Regarding the scope of application, connected devic - es (IoT) are subject to specialised technical assess - ments focusing on the physical and perception layers; meanwhile, SaaS and cloud services must undergo cloud computing security evaluations to ensure multi- tenant isolation and business continuity. Furthermore, for digital services, the Network Data Management Regulation imposes heightened obligations on large- scale platform operators concerning systemic robust - ness and supply chain due diligence, reinforced by administrative sanctions calculated as a percentage of the entity’s global annual turnover. 4.2 Key Obligations Under Legislation According to the specific provisions of the CSL and Cyber Product Vulnerability Provisions, network operators are strictly responsible for vulnerability
management and formulating emergency plans for cybersecurity incidents and conducting activities such as cybersecurity certification, testing and risk assessment. Under Articles 27 and 28 of the CSL, upon discover - ing risks such as security defects or vulnerabilities in network products or services, network operators shall immediately take remedial measures, notify users in a timely manner, and report to the competent authori - ties. The Cyber Product Vulnerability Provisions further stipulate that network operators shall establish and improve channels for receiving information on net - work product security vulnerabilities and keep such channels open, and after discovering the vulnerability, report it to the cybersecurity threat and vulnerability information-sharing platform of MIIT within two days. Regarding post-market surveillance of products, Arti - cle 24 of the CSL explicitly stipulates that providers of network products and services should provide con - tinuous security maintenance for their products and services, and shall not terminate the provision of secu - rity maintenance within the prescribed period or the period agreed upon by the parties. The Network Data Management Regulation requires that when a network data security incident occurs, network data handlers shall activate incident response plans, take measures to prevent the expansion of harm, and report to com - petent authorities. As for conformity assessment, marking and certifi - cations, the CSL explicitly stipulates that equipment and products listed in the “Catalog of Critical Network Equipment and Specialized Cybersecurity Products” can only be sold or provided after being certified as qualified by a qualified institution or meeting the requirements of security testing. The CIIO Regulation stipulates that if the procurement of network products and services by CIIO may affect national security, it shall undergo a national security review organised by CAC in conjunction with relevant departments of the State Council. The DSL mentions that the state promotes the development of services such as data security testing, assessment and certification. In terms of product recall or withdrawal duties, the CSL stipulates that if critical network equipment and
85 CHAMBERS.COM
Powered by FlippingBook