China Securities Regulatory Commission releases Measures on Network and Information Security of Securities and Futures Industry
Description:In order to effectively implement the relevant requirements of the "Network Security Law", "Data Security Law", "Personal Information Protection Law" and "Regulations on the Security Protection of Critical Information In

Recently, the China Securities Regulatory Commission officially issued the "Securities and Futures industry network and information security Management Measures" (hereinafter referred to as the "Measures"). The Measures will be officially implemented on May 1, 2023.


In order to effectively implement the relevant requirements of the "Network Security Law", "Data Security Law", "Personal Information Protection Law" and "Regulations on the Security Protection of Critical Information Infrastructure", standardize the network and information security management of the securities and futures industry, prevent and resolve the network and information security risks of the industry, and maintain the safe, stable and efficient operation of the capital market, the CSRC formulated and issued the "Measures".


From April 29, 2022 to May 29, 2022, the CSRC solicited public opinions on the draft Measures. On the whole, all parties have a high degree of recognition of the drafting ideas and main contents of the draft Measures. After careful study, the SFC has absorbed and adopted some of these opinions.


The Measures focus on the field of network and information security, and on the basis of summarizing practical experience, clarify the path for the implementation of the upper Law in the securities and futures industry. The Measures comprehensively cover all types of entities, including key information infrastructure operators of securities and futures, core institutions, operating institutions, and information technology system service institutions, taking security as the basic principle and putting forward normative requirements for network and information security management, the main contents include: Network and information security operation, investor personal information protection, network and information security emergency response, critical information infrastructure security protection, network and information security promotion and development, supervision and management and legal responsibility.


The CSRC said that the CSRC will organize relevant special training and continue to do a good job of supervision and implementation. The subject of reference and application provided for in the Measures does not need to submit the annual report on network and information security management provided for in Article 59 of the Measures. Regarding the implementation of the data backup obligations stipulated in Article 20 of the Measures with reference to the applicable subjects, the China Securities Regulatory Commission will guide relevant industry associations to further refine the relevant requirements.


Responsible Editor: Zhao Chengfeng


Hot
What is SearchFx?

SearchFx website aims to provide a public complaint platform for the victims of financial investment, and at the same time, it will do its best to solve the exposure for investors, so as to finally achieve a public welfare website with the goal of recovering losses. More>