Cybersecurity in the Securities and Futures Industry in China will be improved.

Cybersecurity in the Securities and Futures Industry in China will be improved.

Cybersecurity in the Securities and Futures Industry in China will be improved.

The China Securities Regulatory Commission (“CSRC”) published for public comment the draft Administrative Measures for Cybersecurity in the Securities and Futures Industry (“Draft Measures”) on April 29, 2022.

The CSRC first published interim information security protection measures in 2005, which were eventually updated by the present version in 2012. There were few laws or regulations on cybersecurity or data protection in China at the time.

Since 2016, a slew of key rules and regulations have been adopted, rendering the current CSRC information security procedures obsolete. The Chinese cybersecurity and data protection regulatory landscape has been formed by the Cyber Security Law (“CSL”), the Data Security Law (“DSL”), and the Personal Information Protection Law (“PIPL”). The CSRC released the Draft Measures in light of the regulatory developments.

Observations and key provisions

The Draft Measures apply to the three types of entities listed below:

  1. Core Institutions, refer to the institutions that perform public functions or operate information infrastructures in the securities and futures markets, such as securities and futures exchange houses, securities depository and clearing institutions, and futures margin safe deposit monitoring agencies;
  2. operational institutions, referring to securities and futures operation institutions, such as securities companies, futures companies, and fund management companies; and
  3. Information Technology (IT) Service Institutions, refer to institutions that provide development, testing, integration, evaluation, maintenance, and daily security management products or services for important information systems of securities and futures business.

While the Draft Measures focus on the Core Institutions and Operational Institutions, suppliers of relevant information technologies should also pay attention to the measures that apply to them.

The Core Institutions and Operational Institutions are required to take a number of steps to protect the network system’s security. Among the most important indicators are:

  1. establishing a sound cybersecurity management system that consists of information technology governance, decision-making, management, execution, and supervision;
  2. making the person in charge of the institution (usually the legal representative) primarily responsible for cybersecurity and the person in charge of technology directly responsible for cybersecurity;
  3. ensure an adequate number of qualified staff and sufficient funding that are appropriate for the business activities;
  4. ensuring adequate performance, capacity, reliability, expandability, and security of the information system and infrastructure;
  5. implementing the cybersecurity multi-level protection scheme (“MLPS”), which is the central regime for protecting cybersecurity under the CSL, and reporting the implementing details to CSRC;
  6. Precautionary measures before launching, altering, or taking down important information systems;
  7. notifying investors of the impact and alternatives and other responding measures before suspending or terminating any online services;
  8. establishing a sound early-warning system;
  9. establishing data back-up and failure and disaster recovery facilities;
  10. conducting a pressure test on important information systems at least every six months and also taking part in the industry-wide pressure test organized by the CSRC;
  11. strengthening its management of supplies of information products and services;
  12. continuing to improve controllable and autonomously-developed technologies; and
  13. taking effective measures to protect the institutions’ own intellectual properties.

If they provide products and services to the Core Institutions and Operational Institutions, IT Service Institutions must also set up a cybersecurity management system and file a report with the CSRC.

Data security procedures for the Core Institutions and Operational Institutions are also outlined in the Draft Measures, including:

  1. establishing and perfecting data security management systems and organizational structure;
  2. formulating industrial data standards and implementing data multi-level categorized management;
  3. formulating a data access authorization strategy; and
  4. establishing a data quality evaluation framework.

The CSRC dedicates a chapter to the CII’s cybersecurity. While the majority of the criteria are similar to the CII Regulation, the Draft Measures further require CII operators in the securities and futures business to:

  1. It is necessary to establish a designated cybersecurity leadership group or department that is adequately staffed with cybersecurity specialists;
  2. conduct expert evaluation before altering or taking down any operation of the CII, which may affect the steady operation of the market;
  3. ensure adequate system performance and network capacity; and
  4. establish same-site and multi-site disaster recovery centers.

The Draft Measures are CSRC’s response to the CSL, the DSL, and the PIPL’s regulatory framework’s enhanced cybersecurity and data protection standards. The CSRC is working with other financial authorities to put these standards in place in the financial industry.

Financial institutions in the securities and futures business, as well as their IT providers, should keep up with the latest developments and be ready for new standards that will be imposed soon.

 

 

 

Share this post


WhatsApp chat

By continuing to use the site, you agree to the use of cookies. more infomation

The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.

Close