中国人民银行业务领域网络安全事件报告管理办法

Search documents
事关金融业网络安全,中国人民银行发布管理办法
Xin Hua Wang· 2025-08-08 07:23
Core Viewpoint - The People's Bank of China (PBOC) has introduced a new management method for reporting cybersecurity incidents in its business areas, effective from August 1, aimed at enhancing the regulation and response to such events in the financial sector [1] Group 1: Regulatory Framework - The new management method specifies that financial institutions must report cybersecurity incidents to the PBOC or its local branches according to established guidelines [1] - It categorizes cybersecurity incidents into four levels: particularly significant, significant, relatively large, and general, with baseline standards for each category [1] - The method details specific requirements for reporting incidents at different stages: occurrence, during the event, and post-event, including the reporting process, content, timeliness, and channels [1] Group 2: Implementation Strategy - The PBOC plans to implement the new method through three main strategies: enhancing policy promotion to help financial institutions better understand the regulations, guiding institutions to refine their internal reporting responsibilities, and standardizing administrative enforcement to ensure compliance with reporting requirements [1]