17 February, 2017
China publishes draft rules on enhanced security review of online products and services
On 4 February 2017, the Cyberspace Administration of China (the “CAC”) published draft rules on the national security review of online products and services used by PRC information systems (the “Draft”).
The Draft seeks to put in place a national framework for security review of certain online products and services, as foreshadowed in the National Security Law, the Cybersecurity Law and the National Cyberspace Security Strategy. This framework is intended to operate in addition to the existing certification and technical standards with which IT products and services procured in the PRC are required to comply (which are not affected by the Draft).
Industry players (particularly those in key industries such as finance) and vendors of online products and services will need to consider how to comply with the review regime and monitor further cyber and sectoral rules and the practice as the regime develops.
The Draft’s consultation period lasts one month.
Issue |
Points to note |
Implications and other commentary |
Affected parties |
|
|
Review standards |
> Online products and services under review will be assessed for “security and controllability” with a focus on the risks of:
|
> These criteria, which are not defined in the National Security Law or Cybersecurity Law, will be a key part of how the review regime is implemented by the CAC in accordance with its National Cyberspace Security Strategy. They are unfortunately only addressed in broad terms, with no implementation guidance at this stage. |
Issue |
Points to note |
Implications and other commentary |
> The security and credibility of the product and services providers (in addition to the products themselves) will be scrutinised as part of the review. |
|
|
Review bodies and decisions |
|
|
Timeframe |
> No timelines are provided in the Draft for the effectiveness of the new proposed rules, the establishment of the Review Committee, the accreditation of the third party experts or the initiation, conduct and completion of the review process. |
> It appears that further work and rules to implement the Draft will be required before the Cybersecurity Law comes into effect in June 2017.
|
References:
> Online Products and Services Security Review Measures (Draft) (网络产品和服务安全审查办法(征求意见稿)), CAC, 4 February 2017
> Cybersecurity Law of the People’s Republic of China (中华人民共和国网络安全法), National People’s Congress Standing Committee, 7 November 2016
> National Security Law of the People’s Republic of China (中华人民共和国国家安全法), National People’s Congress Standing Committee, 1 July 2015
> National Cyberspace Security Strategy (国家网络空间安全战略), CAC, 27 December 2016
For further information, please contact:
Jian Fang, Partner, Linklaters
jian.fang@linklaters.com