Promulgated by: Ministry of Industry and Information Technology (工业和信息化部).
Document No.: 工信部网安〔2024〕18号 (Gong Xin Bu Wang An [2024] No. 18).
Issued February 26, 2024.
Translation note — DCC. Translated in full from the annex to MIIT’s issuing notice as published on miit.gov.cn. The three boxed “columns” (专栏) in the original are rendered as titled sub-sections. Terminology follows DCC’s bilingual glossary and the earlier translation of the Industrial and Information Technology Data Security Measures (Trial), which this Plan implements; the underlying grading scheme is the Industrial Data Classification and Grading Guide (Trial).
Implementation Plan for Enhancing Data Security Capabilities in the Industrial Sector (2024–2026)
Data, as a new type of factor of production, is the foundation of digitalization, networking and intelligentization, and has rapidly become embedded in every link of production, distribution and circulation. Safeguarding data security bears on the overall situation of national security. This Plan is formulated in order to implement the spirit of General Secretary Xi Jinping’s important instructions on data security and the decisions and arrangements of the Party Central Committee and the State Council, to promote the implementation in the industrial sector of the Data Security Law of the People’s Republic of China, the Cybersecurity Law of the People’s Republic of China, the Measures for the Administration of Data Security in the Industry and Information Technology Sector (Trial) and other instruments, to accelerate the enhancement of data security protection capabilities in the industrial sector, to support high-quality industrial development, and to consolidate the security foundation for the development of new industrialization.
I. General Requirements
(1) Guiding ideology
Guided by Xi Jinping Thought on Socialism with Chinese Characteristics for a New Era, fully implement the spirit of the 20th National Congress of the Party, unswervingly implement the holistic approach to national security, adhere to the coordination of development and security, adhere to bottom-line thinking and extreme-case thinking, adhere to goal orientation and problem orientation, take the construction and improvement of a data security assurance system for the industrial sector as the main line, take the implementation of enterprises’ primary responsibility as the core, and focus on protecting important data, enhancing regulatory capacity and strengthening industrial support, so as to improve data security governance capacity, promote the secure and orderly flow of data elements and the release of their value, and provide solid support for accelerating new industrialization and building a manufacturing power, a cyber power and a Digital China.
(2) Basic principles
Coordinated advancement, key breakthroughs. Strengthen top-level planning and systematically advance the building of organizational structures, policies and systems, management mechanisms, standards and specifications and technical means for data security, together with industrial development. Take the strengthening of protection for key industries, key enterprises, important systems and platforms and important data as the entry point, and use key points to drive an overall improvement in protection levels.
Government guidance, collaborative governance. Make comprehensive use of positive incentives and negative constraints, select and promote benchmarks and models, strengthen regulatory enforcement, and press home enterprises’ primary responsibility. Give full play to industry associations, leading enterprises, professional institutions, institutions of higher education and other forces to form a favorable situation of collaborative governance of data security.
Scenario-driven, sector-specific policies. Ascertain the characteristics and patterns of risk-prone scenarios in key links of data processing, adhere closely to the data-protection needs of business scenarios, and strengthen scientific prevention and control. In light of industry characteristics and data features, provide differentiated guidance and precise policy measures to accelerate the improvement of data security management in each industry.
Innovation-driven, technology combined with management. Continuously innovate management models, technologies, products and services to adapt to the new situation, new characteristics and new demands of data security protection in the industrial sector in the new period. Emphasize the building and use of “managing data by technology” means, forming a joint force with routine supervision.
(3) Overall objectives
By the end of 2026, a data security assurance system for the industrial sector will be basically established. Awareness of data security protection will be generally improved, the primary responsibility of key enterprises for data security will be fully implemented, the level of data protection in key scenarios will be substantially raised, and major risks will be effectively prevented and controlled. Data security policies and standards, working mechanisms, the regulatory corps and technical means will be more sound. The industry’s supporting capabilities in data security technologies, products, services and talent will steadily improve.
— Basically achieve full coverage of the promotion of data security requirements among above-scale enterprises in every industrial sector.
— More than 45,000 enterprises will carry out classified and graded data protection, covering at least the above-scale industrial enterprises ranking in the top 10% by annual revenue in their industry in each province (autonomous region, municipality).
— No fewer than 100 national, industry, association and other data security standards and specifications will be initiated and developed.
— No fewer than 200 typical data security cases will be selected, covering no fewer than 10 industries.
— Data security training will cover 30,000 person-times, and more than 5,000 industrial data security professionals will be trained.
II. Key Tasks
(1) Enhancing the data-protection capabilities of industrial enterprises
1. Strengthen awareness of data security protection. Intensify the promotion and training of data security laws, regulations, policies and standards, and raise data security awareness among enterprises in all industries. Urge enterprises to implement their primary responsibility for data security in accordance with laws and regulations, press home the primary responsibility for data security of each unit’s legal representative or principal person in charge, establish and improve data security management systems and working mechanisms, staff data security positions and teams adequately, and conduct data security education and training regularly. Guide enterprises to implement the principle of attaching equal importance to development and security, integrate data security management requirements into their development strategies and performance-assessment mechanisms, and strengthen the joint planning, deployment, implementation and assessment of data security work and business development.
2. Carry out security protection of important data. Guide enterprises to establish and improve security management systems such as classified and graded data protection, regularly sort out and identify important data and core data, form catalogues and file them promptly. Urge processors of important data and core data to designate persons responsible for data security and management bodies, implement graded protection requirements, conduct a data security risk assessment at least once a year, promptly discover and rectify security hazards, and submit assessment reports as required. Guide enterprises to strengthen risk monitoring and emergency response for important data and core data and to report major risk incidents promptly. Promote the use of commercial cryptography by enterprises in all industries to protect data security.
3. Strengthen data security management of key enterprises. Select enterprises that hold key core technologies, represent the level of industry development, bear on the security and stability of industrial chains or bear on national security, and compile on a rolling basis a roster of key enterprises for data security risk prevention and control in the industrial sector. Treat the enterprises on the roster as the focus of data security supervision, and urge them, on the basis of implementing data security requirements, to focus on enhancing their capabilities in risk monitoring, situational awareness, threat assessment and emergency response. Give play to the role of the competent departments at the ministry and provincial levels, coordinate the data security monitoring and early-warning means and technical forces of all parties, strengthen technical support, and jointly protect enterprise data security.
4. Deepen data security protection in key scenarios. Guide enterprises to examine weak points in data security protection around key data-processing scenarios such as data aggregation, sharing, export and entrusted processing, and to implement data-protection measures suited to industry characteristics. Focus on typical business scenarios such as upstream–downstream supply-chain collaboration, service outsourcing and migration to cloud and platforms, clarify the interfaces of data security responsibility among multiple parties and the modes of connection between them, and establish a whole-chain, all-round data security protection system. For risk-prone and frequently occurring scenarios such as ransomware attacks, vulnerabilities and backdoors, non-compliant operations by personnel and uncontrolled remote operation and maintenance, strengthen risk self-inspection and self-correction and adopt precise management and protection measures. For typical scenarios of large-scale circulation and trading of data elements, develop a set of security solutions.
Column 1 — Data Security Protection Foundation Project
-
Consolidate the foundation of data classification and grading. Study and formulate detailed rules for the identification of important data and core data by industry and by field, forming a “1+N” system of data classification and grading specifications for the industrial sector to guide implementation in each industry scientifically. Continuously iterate the catalogues of important data and core data, progressively ascertain the scale, distribution and processing of important data in each industry, and clarify the key data objects to be protected in each industry.
-
Prepare practice guides for data protection. In light of the data security protection needs and difficulties in key data-processing scenarios, typical business scenarios and risk-prone scenarios, study and formulate a series of practice guides for data security protection in the industrial sector, providing practical references for enterprises’ data protection and risk prevention. For key industries with substantial data-export needs, formulate data-export security guidelines by category to guide enterprises in conducting data-export security assessments in accordance with laws and regulations.
-
Advance a leap in data security protection capabilities sector by sector. On the basis of orderly advancement of promotion and training and of classified and graded protection, and proceeding from the actual conditions of industries such as steel, automobiles, textiles and integrated circuits, focus on key scenarios, key links, important systems and platforms and important data, further strengthen the implementation of primary responsibility for data security and the intensity of protection in each industry, and achieve an overall leap in industry data security protection capabilities.
(2) Enhancing data security regulatory capacity
5. Improve data security policies and standards. Establish and improve the data security management system for the industrial sector, and promote the issuance of policy documents such as detailed rules for the implementation of risk assessment, emergency plans and guidance on the exercise of discretion in administrative penalties. Continuously improve the whole-process regulatory mechanism for the identification, filing, graded protection and risk assessment of important data, and strengthen supervision and inspection. Form an industry standardization organization for network and data security in the industrial sector, publish a guide to building the data security standards system, and accelerate the development of urgently needed standards on the identification of important data, security protection, risk assessment, product testing and cryptography application. Encourage localities to formulate local data security policies by reference.
6. Strengthen data security risk prevention and control. Improve the working mechanism for the reporting and sharing of data security risk information in the industrial sector, form an expert group for data security risk analysis, dynamically manage the pool of direct-reporting units for risks, coordinate and strengthen local forces, and carry out risk monitoring, reporting, early warning and response on a normalized basis. Ascertain the characteristics and patterns of data security risk incidents, establish a case library of major risk incidents, and strengthen case analysis and risk alerts. Carry out the “Data Security Escort” special campaign for key industries and regularly organize “Data Security Shield” emergency drills, to raise the level of rapid response, standardized handling and coordinated linkage for incidents.
Column 2 — Building Data Security Risk Prevention and Control Brands
-
“Data Security Escort” (数安护航) special campaign. Carry out concentrated screening and prevention of data security risks by industry and in batches, focusing on prominent risks such as data leakage, tampering, misuse, non-compliant transmission, unlawful access and traffic anomalies, and using enterprise self-inspection, remote testing, on-site diagnosis and other means to enhance risk-response and handling capabilities in a targeted way.
-
“Data Security Shield” (数安铸盾) emergency drills. For key industries, simulate typical risk-prone data security incidents such as ransomware attacks and supply-chain attacks, organize all-element, whole-process emergency drills, continuously optimize incident-response processes and mechanisms, and train and develop a group of emergency-support teams.
7. Advance the building of technical means for data security. Build as a whole a data security management platform for the industry and information technology sector, establish a data security toolkit for the industrial sector, and form integrated technical capabilities covering data resource management, situational awareness, reporting and sharing of risk information, technical testing and verification and incident emergency response, strengthening coordination with cybersecurity and cryptographic technical means. Promote the accelerated establishment of technical means such as data security risk monitoring and emergency response by localities, industries and enterprises with the necessary conditions, strengthen three-level “ministry–province–enterprise” linkage of technical capabilities, and continuously raise the level of technical assurance.
Column 3 — Data Security Technical Assurance Project
-
Build as a whole the data security management platform for the industry and information technology sector. Establish and improve system functions for data security monitoring, information reporting and sharing, emergency management and security assessment in the industrial sector; strengthen the unified aggregation, analysis, assessment and notification of risks; support incident emergency response, decision support, tracking and tracing; provide services such as risk assessment, data-export security assessment and protection-capability assessment; and cover no fewer than 20 provincial (industry) nodes and 500 enterprise nodes.
-
Establish a data security toolkit for the industrial sector. Around data classification and grading, security protection, testing and assessment, compliance inspection, emergency response, attack tracing and cryptography application, develop a set of standardized, portable tools to support the efficient conduct of data security supervision and protection.
8. Forge data security regulatory and enforcement capacity. Standardize the procedures for investigating and handling data security incidents and enrich the methods and means of evidence collection. Accelerate the improvement of data security enforcement processes and working mechanisms, promote the inclusion of data security by local industry and information technology competent departments in their lists of administrative enforcement matters, guide all industries and localities in strictly handling unlawful conduct in accordance with law, and strengthen the publicizing of enforcement cases and warning education. Establish and improve mechanisms for complaints and reports of data security violations, and collect leads on violations through multiple channels. Intensify the training of regulatory and enforcement personnel, promote the strengthening of data security regulatory forces by local industry and information technology competent departments, and build a professional and standardized regulatory and enforcement corps.
(3) Enhancing the supporting capacity of the data security industry
9. Increase the supply of technologies, products and services. Strengthen the optimization and upgrading of common technologies such as intelligent classification and grading of industrial data, industrial database auditing and low-latency encrypted transmission. Intensify research on key technologies such as lightweight data encryption, privacy computing and ciphertext computing adapted to industrial business scenarios and data characteristics. Support the use of commercial cryptography to safeguard data security in the industrial sector. Around risks such as leakage, theft and tampering of industrial data, promote the development of products for traffic-anomaly monitoring, attack-behavior identification, and incident tracing and handling. Strengthen the design of data security architectures for emerging applications such as industrial cloud, industrial big data and industrial internet platforms. Support innovation in “product + service” supply models for data security in the industrial sector.
10. Promote application and supply–demand matching. Increase pilot applications in the industrial sector of technologies and products such as secure multi-party computation, data anti-ransomware, data provenance and commercial cryptography. Organize the selection of a set of general-purpose data security technologies and products with broad application value across industries, develop a set of data security solutions oriented to industries, scenarios and small and medium-sized enterprises, form a set of typical data security cases for the industrial sector, and carry out promotion by industry and by region. Promote supply–demand matching for data security technologies, products and services in all industries through themed salons, roadshows and similar channels. Give play to the role of the data security industry public-service platform and strengthen services such as information sharing and resource matching.
11. Establish and improve the talent-cultivation system. Oriented to the data security needs of different industries, positions and levels, promote the development of specialized and distinctive data security teaching materials and courses and standardize the accreditation of professional talent. Support cooperation among industry, academia, research and users, and jointly cultivate composite management talent and practical skilled talent through training centers, practical training bases and online learning platforms, continuously promoting the updating of knowledge and the enhancement of capabilities through skills competitions, technical exchanges, further study and on-the-job practice. Encourage industrial enterprises to establish and improve data security performance-evaluation mechanisms and strengthen incentives for data security talent.
III. Safeguard Measures
(1) Strengthen organization and coordination
The Ministry of Industry and Information Technology shall strengthen overall coordination and ensure alignment with the national data security work coordination mechanism. Local industry and information technology competent departments shall be responsible for organizing the implementation of this Plan in their regions. Localities are encouraged to formulate detailed work plans in light of actual conditions, strengthen cooperation with the relevant departments, and ensure that objectives and tasks are implemented. Give full play to the professional role of institutions of higher education, research institutes, third-party institutions and the like in the promotion of this Plan, guidance on the building of technical means, technical exchange and cooperation, and the application and promotion of results, and guide enterprises to strengthen the building of data security capabilities.
(2) Increase resource support
Make coordinated use of existing funding channels, increase investment in data security work in the industrial sector, and support research on key core technologies and the building of public-service platforms. Deepen industry–finance cooperation, support data security enterprises in participating in the “integration of science, technology, industry and finance” special program, and obtain convenient and efficient financial services through the national industry–finance cooperation platform. Encourage localities to include data security in local plans for the digital transformation and development of the industrial sector, and to specify data security requirements simultaneously when supporting digitalization, networking and intelligentization projects. Guide enterprises to allocate a certain proportion of funds to data security protection in their informatization construction.
(3) Strengthen evaluation of results
All industries and regions shall promptly track and schedule the implementation of this Plan, summarize experience and practices, evaluate the effectiveness of the work, strengthen communication and exchange, and promptly report major progress or problems. The Ministry of Industry and Information Technology shall commend regions, enterprises and units that have promoted the work forcefully and achieved notable results, and shall strengthen the distillation, summary, promotion and application of outstanding experience and practices.
(4) Conduct publicity and guidance
Make comprehensive use of industry activities, international cooperation and other means to publicize and popularize the concepts and measures of data security in the industrial sector, and raise the recognition of data security in the industrial sector among localities, enterprises and the public. Fully mobilize industry associations, learned societies, industry alliances and other forces, guide enterprises to strengthen self-discipline and build consensus, and foster a favorable atmosphere for data security protection in the industry.