Financial Regulator Seeks Public Feedback on Draft Cybersecurity Rules for Banking and Insurance Sectors

Deep News
07/10

The National Financial Regulatory Administration has drafted the "Measures for Cybersecurity Management in the Banking and Insurance Sectors (Exposure Draft)" to enhance the supervision and regulation of cybersecurity for banking institutions, insurance institutions, and financial holding companies, and to standardize cybersecurity practices. The draft is now open for public comment.

The proposed measures implement the decisions and arrangements of the Party Central Committee and the State Council regarding cybersecurity, adhering to the principle of balancing development and security. They aim to promote the implementation of laws and regulations such as the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law, and the Regulations on the Security Protection of Critical Information Infrastructure. These measures provide support for the regulator to better fulfill its duties in supervising the cybersecurity and critical information infrastructure of banking institutions, insurance institutions, and financial holding companies. The content of these draft measures aligns with the "Measures for Cybersecurity Management in the Financial Industry (Exposure Draft)" which was opened for public comment on July 3.

The draft comprises eight chapters and 72 articles, setting forth clear requirements in core areas including cybersecurity governance, cybersecurity construction and operational management, cybersecurity risk monitoring, cybersecurity incident response and handling, critical information infrastructure management, and supervision and regulation.

The drafting of the measures primarily follows these key principles: First, to implement the requirements of superior laws and ensure the effective application of relevant national laws and regulations within the banking and insurance sectors, clarifying the implementation pathways. Second, to draw from practical experience, summarizing the achievements of technology supervision work in recent years and converting practical experience into institutional outcomes to improve working mechanisms. Third, to fully consider the business characteristics of banking and insurance institutions, promoting the implementation of cybersecurity protection responsibilities, reflecting a broad concept of cybersecurity, and emphasizing a governance philosophy of unified group-wide management, collaboration between technology and business, and the coordinated governance of the three lines of defense. Fourth, to reflect a tiered and classified management approach, proposing overall cybersecurity management requirements for banking and insurance institutions while setting higher standards specifically for the management of critical information infrastructure.

Feedback from all sectors of society is welcomed. The National Financial Regulatory Administration will carefully study the opinions received, further revise and improve the draft measures, and release them for implementation at the appropriate time.

Annex: Announcement from the National Financial Regulatory Administration on Soliciting Public Comments for the "Measures for Cybersecurity Management in the Banking and Insurance Sectors (Exposure Draft)"

https://www.nfra.gov.cn/cn/view/pages/ItemDetail.html?docId=1264207&itemId=951&generaltype=2

免責聲明:投資有風險,本文並非投資建議,以上內容不應被視為任何金融產品的購買或出售要約、建議或邀請,作者或其他用戶的任何相關討論、評論或帖子也不應被視為此類內容。本文僅供一般參考,不考慮您的個人投資目標、財務狀況或需求。TTM對信息的準確性和完整性不承擔任何責任或保證,投資者應自行研究並在投資前尋求專業建議。

熱議股票

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10