China orders annual security reviews for all critical information infrastructure operators
- Reference: 1629273492
- News link: https://www.theregister.co.uk/2021/08/18/china_critical_information_infrastructure_rules/
- Source link:
An [1]announcement by the Cyberspace Administration of China (CAC) said that cyber attacks are currently frequent in the Middle Kingdom, and the security challenges facing critical information infrastructure are severe. The announcement therefore defines infosec regulations and and responsibilities.
The CAC referred to critical infrastructure as "the nerve center of economic and social operations and the top priority of network security". China's definition of critical information infrastructure can be found in Article 2 of the State Council's " [2]Regulations on the Security Protection of Critical Information Infrastructure " and boils down to any system that could suffer significant damage from a cyber attack, and/or have such an attack damage society at large or even national security.
[3]
"The regulations clarify that important network facilities and information systems in key industries and fields belong to critical information infrastructure," wrote the CAC in its announcement (as translated from Mandarin), adding that the state was adopting measures to monitor, defend and handle network risks and intrusions, originating domestically and globally.
[4]
[5]
The regulations themselves are lengthy and detailed, but the theme is that all Chinese enterprises whose operations depend on networks must conduct an annual security reviews, report breaches to government, and establish teams to monitor security constantly.
Those teams get to develop emergency plans and carry out emergency drills on a regular basis, in accordance with disaster management national plans.
[6]
If an incident is ever discovered, reporting and escalation to national authorities is mandatory.
[7]China stops networked vehicle data going offshore under new infosec rules
[8]Chinese espionage group targets Israel while suggesting the source could be Iran
[9]Chinese state media describes gaming as 'spiritual opium' that stunts education and destroys families
The lengthy document also details a variety of organizational and logistical "clarifications", while also outlining the state's ability to adjust identification rules dynamically, how safeguarding measures can be implemented, and legal responsibilities and penalties for negligent parties.
It does not, however, offer specific technical advice.
China's not alone in not not doing so The USA's ( [10]Cybersecurity Information Sharing Act ) [PDF], which came into law in December 2015, is broad. It was designed to allow companies to share cyber attack information with government and other companies, but was considered by some as bad on the privacy front.
Last month, a bipartisan effort in the US [11]introduced the Cyber Incident Notification Act of 2021. The Act requires federal agencies, government contractors and critical infrastructure owners to report attacks to CISA within one day of their occurrence, granting limited immunity to those reporting a breach and allowing data protection procedures to move ahead. ®
Get our [12]Tech Resources
[1] http://www.cac.gov.cn/2021-08/17/c_1630790665977485.htm
[2] http://www.gov.cn/zhengce/content/2021-08/17/content_5631671.htm
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YRzaYJCeJW0mXzoPBVH1VQAAAE4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRzaYJCeJW0mXzoPBVH1VQAAAE4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YRzaYJCeJW0mXzoPBVH1VQAAAE4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRzaYJCeJW0mXzoPBVH1VQAAAE4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2021/08/13/china_networked_car_rules/
[8] https://www.theregister.com/2021/08/11/china_unc215_israel_attacks/
[9] https://www.theregister.com/2021/08/04/china_gaming_spiritual_opium/
[10] https://www.cisa.gov/sites/default/files/publications/Cybersecurity%20Information%20Sharing%20Act%20of%202015.pdf
[11] https://www.theregister.com/2021/07/26/in_brief_security
[12] https://whitepapers.theregister.com/
Re: Unusual - a bit of common sense from governments
IIRC for Y2K, all board members of Chinese air carriers had to be airborne at zero hour. Pretty compelling!
Mandatory Security Teams
...establish teams to monitor security constantly.
Yes, can we have some of that please?
If private companies are to perform public duties (water, power etc) it would be nice if they put the service before the pocket (profit). But since they don't: legislate.
Re: Mandatory Security Teams
And that is why unregulated capitalism cannot be accepted at a governmental level.
Without governmental meddling, there is no industry that would, on its own, decide to implement filters to reduce the pollutants being spewed in the air.
Without laws, no company would say "let's not dump these toxic chemicals into the river and, instead, spend millions every year on water treatment".
None of that would happen because capitalism is "shareholder interest" and that interest is money, not the environment.
The Internet has taken up such a space in our lives that it has reached the level of a public utility. Companies, however, are still doing whatever they want, deciding on what level of IT they are willing to pay for to make things work. The only reason there are any security protocols in place is not for the safety of customer data, it's for the safety of the company - because down time costs money and makes for lost sales.
We do need laws to bring home to the Board that their customer data is a treasure that needs proper protection, not just good-enough-protection.
We're getting there, but China is clearly leading the way.
Re: Mandatory Security Teams
Agreed.
In a thread a week or two back someone asked "What's wrong with capitalism?". You've answered that nicely.
Focussing on ICT, the unfettered reliance on information systems, specifically internetworking, by (essentially) all industries has created a house of cards. This is not only limited to capitalist states, but as you say, they inherently are not regulated sufficiently. This needs addressing by those knowledgable, ie. not politicians with a limited time in office. But parliaments create laws, so the relationship between the politicians and the "knowledgable" needs to be managed first.
Re: Mandatory Security Teams
None of that would happen because capitalism is "shareholder interest"
That's rather a corporate socialism.
Re: Mandatory Security Teams
I disagree ever so slightly. Capitalism optimizes itself to maximize profit by delivering what customers value - i.e. what customers will actually pay for. If customers valued clean air, clean water, good working conditions, environmental policies, etc., then they would prefer companies that prioritized those things even if they had to pay more for their products. Those companies would then make more money for their shareholders, and their competitors would have to change or go out of business. That's capitalism. The reason we need regulated capitalism is largely due to the hypocrisy of us, the customer. While most of us would say, for example, that the environment is important, if it means paying more for stuff or waiting longer for it to arrive from environmentally responsible companies then principles go out the window.
Today's customers want the cheapest thing, delivered the quickest with no delivery charges and today's capitalism has optimized itself to do just that.
Re: Mandatory Security Teams
"... China is clearly leading the way."
Indeed. My own personal experience tells me that China also led the way in offensive intrusions into computer systems in industry and commerce all over the planet. I can only surmise that this latest move by the Chinese government must be a response to the fact that the rest of the planet is catching up with their offensive capabilities.
Some jolly good ideas
" ... establish teams to monitor security constantly "
This is, and always has been, the key. However monitoring is not widely understood. Indeed international security standards contain very little guidance to date, and the almost exclusive emphasis has been "vulnerability reporting".
In reality, monitoring must incorporate multiple threads of activity: changes to the threat landscape, changes to the organisation's external state (e.g. third party changes, customer behaviour change), changes to the organisation's internal state (e.g. new services, reorgs, acquisitions), day to day changes in operational performance (e.g. network activity, resource access) and more. Every organisation's risk management function should include all such monitoring. The problem is that it doesn't show a continuous financial reward, so it's looked on as unnecessary until after the data breach.
Re: Some jolly good ideas
Agreed.
...it doesn't show a continuous financial reward...
Much like Health and Safety.
Most H&S related incidents are limited locally, few have wide geographical impact (exceptions being core meltdowns and the like).
Because H&S risk is observable by the "commoner" it has been addressed. Yeah, it took a while. ICT risk is not so easily understood by non-techies ( cf safe backdoored encryption as desired by FUD pushers). So, not only is pushing safeguards through legislation retarded, it's unlikely (in my mind) that it'll be done correctly. I'd like to optimistic and hope I'm proven wrong.
Unusual - a bit of common sense from governments
And in the case of China there is even a fairly good chance of the requirements being adhered to as the government of China has shown itself willing to hurt the big bosses not just the underlings when a company goes against its wishes.