CSRC Proposes to Revise Regulations on Cybersecurity Management in Securities and Futures Industry

The CSRC (China Securities Regulatory Commission) is proposing to revise its rules on the management of cybersecurity issues in the securities and futures industry.
Fazzaco Live Webinar on 12th May: Vladimir Moshkov on How to Start a Crypto Exchange from Scratch
The revised rules seek to improve supervision over cybersecurity in the industry, prevent and resolve potential cybersecurity risks, and maintain the safe, stable and efficient operation of the capital market.
The draft rules focus on strengthening requirements for securities and futures firms to supervise and manage their cybersecurity systems, operation and emergency response measures, and the overall management of data security.
On data security, the rules clarify the specific requirements in terms of institutional mechanisms, organisational structure, industry data standards, authority management, quality assessment, and prevention of leakage and damage. Emphasis is placed on the classification of data, the protection of personal information, and controls over information release.
In relation to emergency response measures, firms are asked to establish a risk monitoring and early warning system, strengthen daily vulnerability scanning and security assessments, and eliminate "hidden risks" in a timely manner.
Securities and futures firms are also required to conduct regular emergency drills and strengthen the reporting, investigation and handling of cybersecurity incidents. The rules also cover system development and modification, information system backup capabilities, and stress testing.
The revised rules also highlight the importance of having strong governance frameworks, improving managerial roles, designating leading departments, and ensuring adequate resourcing for cybersecurity functions.
The rules set out baseline standards for information systems and related infrastructure for securities and futures firms, and requirements for firms to establish and document the obligations and responsibilities of key personnel.
Regulatory requirements are also imposed on information technology service institutions in the securities and futures industry, in relation to their systems, staffing, compliance and safety.
The CSRC said it will entrust professional institutions to conduct supervision and inspections of industry institutions, including in areas such as penetration testing, vulnerability scanning and risk assessment.
Subscribe Now

