---
title_en: "Guide to Cybersecurity Protection for Industrial Control Systems"
title_zh: "工业控制系统网络安全防护指南"
abbreviation: "ICS Cybersecurity Protection Guide"
hierarchy: "rule"
issuing_body: "Ministry of Industry and Information Technology"
adopted_date: 2024-01-19
effective_date: 2024-01-19
status: "effective"
related_laws: ["miit-industrial-data-security-measures", "industrial-data-security-risk-assessment-rules", "industrial-data-security-incident-emergency-plan", "industrial-data-classification-grading-guide", "industrial-data-security-capability-plan-2024-2026", "data-classification-grading-rules", "cii-protection-regulations", "csl", "dsl"]
domains: ["industrial", "critical-information-infrastructure", "data-security"]
url: https://datacompliancechina.com/laws/ics-cybersecurity-protection-guide/
summary: "Issued by the Ministry of Industry and Information Technology on January 19, 2024 as 工信部网安〔2024〕14号 (Gong Xin Bu Wang An [2024] No. 14), this Guide is the successor to MIIT's 2016 Guide to Information Security Protection for Industrial Control Systems and the baseline that every enterprise using or operating PLC, DCS, SCADA and similar systems in China is expected to meet. Its 33 numbered items are grouped into security management (asset lists, configuration baselines, supplier contracts, certified critical network equipment, training), technical protection (host hardening, zoned network architecture, restricted remote access, cloud migration, application testing, and a system-data-security section that imports the important-data and core-data classification together with the domestic-storage and export-assessment rules), security operations (monitoring, honeypots, operations centers, incident plans, six-month log retention, annual protection-capability assessments, vulnerability management) and responsibility. It is a guide rather than a rule carrying its own penalties, but MIIT inspections, the critical information infrastructure regime and the 2022 Industrial Data Security Measures treat it as the reference standard. Overseas counsel advising manufacturers, OT vendors or cloud providers in China will find here the concrete controls behind ICS security (工控安全) obligations."
---

> **Source: Data Compliance China** — https://datacompliancechina.com/laws/ics-cybersecurity-protection-guide/ · English rendering and annotations by DCC; the Chinese original governs. Cite as: Data Compliance China, "Guide to Cybersecurity Protection for Industrial Control Systems", https://datacompliancechina.com/laws/ics-cybersecurity-protection-guide/
**Promulgated by:** Ministry of Industry and Information Technology.  
**Document No.:** 工信部网安〔2024〕14号 (Gong Xin Bu Wang An [2024] No. 14).  
**Issued January 19, 2024. Effective January 19, 2024.**

> *Translation note — DCC. Translated in full from the official Chinese text
> (MIIT issuing notice and the annexed Guide, 33 numbered items in four parts;
> the Guide uses numbered items rather than articles, and the numbering is kept).
> Terminology follows DCC's bilingual glossary. The data-security items (20–21)
> apply the grades and export rules of the [Administrative Measures for Data
> Security in the Field of Industry and Information Technology (Trial)](/laws/miit-industrial-data-security-measures/);
> for operators whose systems are identified as critical information
> infrastructure, the Guide sits beneath the
> [Security Protection Regulations for Critical Information Infrastructure](/laws/cii-protection-regulations/).*

---

## Notice of the Ministry of Industry and Information Technology on Issuing the Guide to Cybersecurity Protection for Industrial Control Systems

工信部网安〔2024〕14号

To the industry and information technology authorities of all provinces, autonomous regions, municipalities directly under the Central Government and cities specifically designated in the State plan, and of the Xinjiang Production and Construction Corps, and to the relevant enterprises and public institutions:

The Guide to Cybersecurity Protection for Industrial Control Systems is hereby issued to you. Please implement it conscientiously.

Ministry of Industry and Information Technology  
January 19, 2024

---

## Guide to Cybersecurity Protection for Industrial Control Systems

Industrial control systems are the foundational core of industrial production and operation. This Guide is formulated in order to adapt to the cybersecurity situation of industrial control systems (hereinafter, ICS security (工控安全)) in the new period, to further guide enterprises in raising their level of ICS security protection, and to consolidate the security foundation for the development of new industrialization.

This Guide applies to enterprises that use and operate industrial control systems. The objects of protection include industrial control systems and other equipment and systems that, once subjected to a network attack, may directly or indirectly affect production and operation.

## I. Security Management

### (I) Asset Management

**1.** Comprehensively sort out typical industrial control systems such as programmable logic controllers (PLC), distributed control systems (DCS) and supervisory control and data acquisition (SCADA) systems, together with related equipment, software, data and other assets; clarify the department and person responsible for asset management; establish an industrial control system asset list, and update it promptly as the status of assets changes. Regularly conduct checks of industrial control system assets, covering but not limited to system configuration, permission allocation, log auditing, virus scanning and removal, data backup and equipment operating status.

**2.** Based on the importance and scale of the business carried, the degree of harm of a cybersecurity incident and other factors, establish a list of important industrial control systems, update it regularly, and implement priority protection. Key industrial hosts, network equipment, control equipment and the like related to important industrial control systems shall be redundantly backed up.

### (II) Configuration Management

**3.** Strengthen account and password management, avoid the use of default or weak passwords, and update passwords regularly. Follow the principle of least privilege, set account permissions reasonably, disable unnecessary system default accounts and administrator accounts, and promptly clean up expired accounts.

**4.** Establish a security configuration list for industrial control systems and a policy configuration list for security protection equipment. Regularly audit the configuration lists and adjust configurations promptly as security protection needs change; conduct strict security testing before implementing major configuration changes, and implement the change only after the test is passed.

### (III) Supply Chain Security

**5.** Agreements signed with industrial control system vendors, cloud service providers, security service providers and other suppliers shall clarify the security-related responsibilities and obligations each party must perform, including the scope of management, division of responsibilities, access authorization, privacy protection, codes of conduct and liability for breach.

**6.** Where an industrial control system uses PLCs or other equipment included in the catalogue of critical network equipment, equipment that has passed security certification by a qualified institution or that meets the requirements of security testing shall be used.

### (IV) Publicity and Education

**7.** Regularly conduct publicity and education on the laws, regulations, policies and standards relating to industrial control system cybersecurity, to enhance the cybersecurity awareness of enterprise personnel. For operation and maintenance personnel of industrial control systems and networks, regularly conduct professional ICS security skills training and assessment.

## II. Technical Protection

### (I) Host and Terminal Security

**8.** Deploy anti-virus software on engineer stations, operator stations, industrial database servers and other hosts, regularly update virus databases and scan for and remove viruses, and prevent the spread of ransomware and other malware. Media with storage functions shall be scanned for viruses, trojans and other malicious code before being connected to industrial hosts.

**9.** Hosts may adopt application software whitelisting technology, allowing only application software authorized by the enterprise and security-assessed to be deployed and run, and upgrades of operating systems, databases and other system software and of important application software shall be implemented in a planned manner.

**10.** Remove or seal unnecessary universal serial bus (USB), optical drive, wireless and other external device interfaces on industrial hosts, and close unnecessary network service ports. Where external devices are genuinely needed, strict access control shall be implemented.

**11.** Implement user identity authentication for access to industrial hosts, industrial smart terminal equipment (control equipment, smart instruments, etc.) and network equipment (industrial switches, industrial routers, etc.); adopt two-factor authentication for access to key hosts or terminals.

### (II) Architecture and Boundary Security

**12.** Based on the characteristics and scale of the business carried, the degree of importance to industrial production and other factors, implement zoned and domain-based management of industrial control networks composed of industrial Ethernet, industrial wireless networks and the like, and deploy industrial firewalls, network gap devices (网闸) and other equipment to achieve lateral isolation between domains. Where an industrial control network is connected to the enterprise management network or the Internet, implement vertical protection between the networks and conduct security audits of inter-network behavior. Identity authentication shall be performed when equipment is connected to an industrial control network.

**13.** When networking with fifth-generation mobile communications (5G), wireless local area network (WiFi) or other wireless communication technologies, formulate strict network access control policies, adopt identity authentication mechanisms for wireless access devices, regularly audit wireless access points, and disable the broadcast of wireless access public information (SSID), so as to prevent unauthorized device access.

**14.** Strictly control remote access. Prohibit industrial control systems from opening to the Internet unnecessary high-risk general-purpose network services such as Hypertext Transfer Protocol (HTTP), File Transfer Protocol (FTP), Internet remote login protocol (Telnet) and Remote Desktop Protocol (RDP); for network services that must be opened, adopt secure access proxies and other technologies for user identity authentication and application authorization. During remote maintenance, use Internet Protocol Security (IPsec), Secure Sockets Layer (SSL) and other protocols to build secure network channels (such as virtual private networks (VPN)), strictly limit the scope of access and the authorization period, and retain and audit logs.

**15.** The use of encryption protocols and algorithms in industrial control systems shall comply with the requirements of relevant laws and regulations; the preferential adoption of commercial cryptography is encouraged, so as to achieve encrypted network communications, equipment identity authentication and secure data transmission.

### (III) Cloud Security

**16.** Where an industrial cloud platform is built by the enterprise itself, use user identity authentication, access control, secure communications, intrusion prevention and other technologies to ensure security protection and effectively block illegal operations, network attacks and other conduct.

**17.** When industrial equipment is migrated to the cloud, implement strict identification management of the equipment migrated, adopt mutual identity authentication when equipment connects to the industrial cloud platform, and prohibit unidentified equipment from connecting to the industrial cloud platform. When business systems are migrated to the cloud, ensure the secure isolation of the operating environments of different business systems.

### (IV) Application Security

**18.** User identity authentication shall be performed for access to manufacturing execution systems (MES), configuration software, industrial databases and other application services. For access to key application services, adopt two-factor authentication and strictly limit the scope of access and the authorization period.

**19.** Software related to industrial control systems that is independently developed by industrial enterprises shall pass security testing conducted by the enterprise itself or by a commissioned third-party institution, and may be put into use only after passing the test.

### (V) System Data Security

**20.** Regularly sort out the data generated by the operation of industrial control systems, carry out data classification and grading in light of actual business, identify important data and core data, and form a catalogue. Across the stages of data collection, storage, use, processing, transmission, provision and disclosure, protect data using cryptographic technology, access control, disaster recovery backup and other technologies.

**21.** Important data and core data that laws and administrative regulations require to be stored within the territory shall be stored within the territory; where it is truly necessary to provide such data abroad, a data export security assessment shall be conducted in accordance with laws and regulations.

## III. Security Operations

### (I) Monitoring and Early Warning

**22.** Deploy monitoring and auditing equipment or platforms in industrial control networks, so as to detect and give early warning of system vulnerabilities, malware, network attacks, network intrusions and other security risks promptly, on the premise of not affecting the stable operation of systems.

**23.** At the boundary between the industrial control network and the enterprise management network or the Internet, threat-trapping technologies such as industrial control system honeypots may be adopted to capture network attack behavior and enhance active defense capabilities.

### (II) Operations Center

**24.** Enterprises with the necessary conditions may establish an industrial control system cybersecurity operations center, using security orchestration, automation and response (SOAR) and other technologies to achieve unified management and policy configuration of security equipment, comprehensively monitor cybersecurity threats, and enhance capabilities for the centralized investigation of risks and hidden dangers and for rapid incident response.

### (III) Emergency Response

**25.** Formulate an emergency response plan for ICS security incidents, clarify reporting and handling procedures, assess and revise the plan as appropriate in light of actual conditions, and regularly conduct emergency drills. When an ICS security incident occurs, the emergency response plan shall be activated immediately, emergency handling measures taken, and the security incident handled promptly and properly.

**26.** Access and operation logs of important equipment, platforms and systems shall be retained for not less than six months and backed up regularly, so as to facilitate post-incident tracing and evidence collection.

**27.** Regularly conduct backup and recovery tests of important system applications and data, to ensure that in an emergency the industrial control system can be restored to normal operation within an acceptable time.

### (IV) Security Assessment

**28.** Before a newly built or upgraded industrial control system goes live, and before an industrial control network is connected to the enterprise management network or the Internet, a security risk assessment shall be conducted.

**29.** For important industrial control systems, enterprises shall, on their own or by commissioning a third-party professional institution, conduct an assessment relating to ICS security protection capabilities at least once a year.

### (V) Vulnerability Management

**30.** Closely follow the release of major ICS security vulnerabilities and their patches on the MIIT Cybersecurity Threat and Vulnerability Information Sharing Platform and the like, and promptly take upgrade measures; where an upgrade cannot be performed in the short term, targeted security hardening shall be carried out.

**31.** Regularly conduct vulnerability screening of important industrial control systems; where a major security vulnerability is discovered, patch upgrades or hardening shall be implemented only after the patch or hardening measures have been tested and verified.

## IV. Implementation of Responsibility

**32.** Industrial enterprises bear primary responsibility for the ICS security of their own enterprise, shall establish ICS security management systems, clarify responsible persons and responsible departments, and implement ICS security protection responsibilities in accordance with the principle of "whoever operates is responsible, whoever is in charge is responsible."

**33.** Strengthen enterprise resource guarantees, to ensure that security protection measures are planned, built and put into use simultaneously with industrial control systems.
