Article Details

Scrape Timestamp (UTC): 2023-12-16 07:33:15.002

Source: https://thehackernews.com/2023/12/chinas-miit-introduces-color-coded.html

Original Article Text

Click to Toggle View

China's MIIT Introduces Color-Coded Action Plan for Data Security Incidents. China's Ministry of Industry and Information Technology (MIIT) on Friday unveiled draft proposals detailing its plans to tackle data security events in the country using a color-coded system. The effort is designed to "improve the comprehensive response capacity for data security incidents, to ensure timely and effective control, mitigation and elimination of hazards and losses caused by data security incidents, to protect the lawful rights and interests of individuals and organizations, and to safeguard national security and public interests, the department said. The 25-page document encompasses all incidents in which data has been illegally accessed, leaked, destroyed, or tampered with, categorized them into four hierarchical tiers based on the scope and the degree of harm caused - The new rules also require affected companies to make an assessment to determine the severity of the incident, and if deemed serious, report it immediately to the local industry supervision department without omitting or concealing any facts, or providing any false information. "If the local industry regulatory department initially determines that it is a particularly major or major data security incident, it should report it to the Mechanism Office in accordance with the requirements of '10 minutes by phone and 30 minutes in writing' after discovering the incident," the draft rules state. Based on the response level activated – Red or Orange – the Mechanism Office is expected to report the matter to the MIIT. The draft rules are open for public comments until January 15, 2024.

Daily Brief Summary

DATA BREACH // China Implements Color-Coded System for Data Security Response

China's Ministry of Industry and Information Technology (MIIT) has proposed a color-coded system to handle data security incidents.

The system aims to improve response capabilities, ensuring timely actions to mitigate damages from data incidents, and to protect individual, organizational, and national interests.

Data incidents include unauthorized access, leaks, destruction, or tampering, and are categorized into four levels based on harm and scope.

Companies must assess data incident severity and report serious cases promptly to local industry supervisory bodies, adhering to truthfulness in reporting.

A local regulatory department categorizing an incident as major must notify the Mechanism Office within a prescribed time frame—10 minutes by phone, 30 minutes in writing.

The Mechanism Office must then escalate Red or Orange level incidents to the MIIT, as per the response level triggered.

Public feedback on the draft rules is invited by the MIIT until January 15, 2024.