New Draft Rules Set Cybersecurity Framework for Financial Sector

China's central bank, along with other regulatory bodies, has released the "Financial Industry Cybersecurity Management Measures (Draft for Comment)" to solicit public feedback. The document outlines a comprehensive regulatory framework, signaling a move towards more systematic oversight of cybersecurity practices across the financial industry.

Mandatory Cybersecurity Protection Levels and Assessments

Under the proposed measures, all financial institutions are required to establish appropriate cybersecurity protection levels for their networks in accordance with the national multi-level protection scheme. This establishes an ongoing compliance process with several core obligations:

  • Classification and Filing: Institutions must determine the security level of their networks and file the classification with regulators.
  • Regular Evaluation: They must conduct periodic cybersecurity level assessments to verify the effectiveness of protective measures.
  • Risk Remediation: Any vulnerabilities or risks identified during assessments must be promptly addressed.

These steps are designed to shift the industry's approach from passive compliance to proactive risk management, fostering a continuous cycle of evaluation and improvement.

Enhanced Focus on Personal Data Security and Verification

The draft rules place significant emphasis on safeguarding customer data. Financial institutions are mandated to standardize their personal information handling activities in strict compliance with existing laws, regulations, and financial supervisory requirements to ensure data security.

A notable provision encourages institutions to adopt the national online identity authentication public service for verifying user identities. This push aims to promote a unified and secure digital identity ecosystem, which could streamline processes while mitigating risks associated with identity fraud.

The release of these draft measures represents a step towards more granular and stringent cybersecurity governance in finance. Institutions should begin evaluating their current security postures and data management practices to align with the upcoming requirements.