The National Financial Regulatory Administration has drafted the "Measures for Cybersecurity Management in the Banking and Insurance Sectors (Exposure Draft)" to enhance the supervision and regulation of cybersecurity for banking institutions, insurance institutions, and financial holding companies, and to standardize cybersecurity practices. The draft is now open for public comment.
The proposed measures implement the decisions and arrangements of the Party Central Committee and the State Council regarding cybersecurity, adhering to the principle of balancing development and security. They aim to promote the implementation of laws and regulations such as the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law, and the Regulations on the Security Protection of Critical Information Infrastructure. These measures provide support for the regulator to better fulfill its duties in supervising the cybersecurity and critical information infrastructure of banking institutions, insurance institutions, and financial holding companies. The content of these draft measures aligns with the "Measures for Cybersecurity Management in the Financial Industry (Exposure Draft)" which was opened for public comment on July 3.
The draft comprises eight chapters and 72 articles, setting forth clear requirements in core areas including cybersecurity governance, cybersecurity construction and operational management, cybersecurity risk monitoring, cybersecurity incident response and handling, critical information infrastructure management, and supervision and regulation.
The drafting of the measures primarily follows these key principles: First, to implement the requirements of superior laws and ensure the effective application of relevant national laws and regulations within the banking and insurance sectors, clarifying the implementation pathways. Second, to draw from practical experience, summarizing the achievements of technology supervision work in recent years and converting practical experience into institutional outcomes to improve working mechanisms. Third, to fully consider the business characteristics of banking and insurance institutions, promoting the implementation of cybersecurity protection responsibilities, reflecting a broad concept of cybersecurity, and emphasizing a governance philosophy of unified group-wide management, collaboration between technology and business, and the coordinated governance of the three lines of defense. Fourth, to reflect a tiered and classified management approach, proposing overall cybersecurity management requirements for banking and insurance institutions while setting higher standards specifically for the management of critical information infrastructure.
Feedback from all sectors of society is welcomed. The National Financial Regulatory Administration will carefully study the opinions received, further revise and improve the draft measures, and release them for implementation at the appropriate time.
Annex: Announcement from the National Financial Regulatory Administration on Soliciting Public Comments for the "Measures for Cybersecurity Management in the Banking and Insurance Sectors (Exposure Draft)"
https://www.nfra.gov.cn/cn/view/pages/ItemDetail.html?docId=1264207&itemId=951&generaltype=2