China: Adopted Cybersecurity Standard Practice Guidelines - Cybersecurity Assessment Guidelines for Large Internet Platforms

Description

Adopted Cybersecurity Standard Practice Guidelines - Cybersecurity Assessment Guidelines for Large Internet Platforms

On 25 June 2024, the National Information Security Standardization Technical Committee (TC260) issued the Cybersecurity Standard Practice Guidelines - Cybersecurity Assessment Guidelines for Large Internet Platforms. The guidelines aim to provide standardised practice guidance on network security laws, regulations, policies, standards, and current issues. Large internet platforms include intermediary platforms with over 50 million users in the last year, offering services such as instant messaging, social networks, e-commerce, live streaming, short videos, and online payments. The guidelines are designed to assist large-scale internet platforms in carrying out annual cybersecurity assessments. The suggested process involves establishing working groups, consider important changes in business data practices, assess business risks such as disaster recovery and control of data provided to third parties, and the compilation of a report. The Guidelines also include a template for the cybersecurity assessment.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
digital payment provider (incl. cryptocurrencies), platform intermediary: user-generated content, platform intermediary: e-commerce, software provider: app stores, messaging service provider, platform intermediary: other
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2023-12-23
in consultation

On 23 December 2023, the National Information Security Standardization Technical Committee (TC260) …

2024-01-05
processing consultation

On 5 January 2024, the National Information Security Standardization Technical Committee (TC260) c…

2024-06-25
adopted

On 25 June 2024, the National Information Security Standardization Technical Committee (TC260) iss…