Regulations on the Management of Security Vulnerabilities in Network Products

Jurisdiction
People's Republic of China
Region
Asia/Pacific
Requirement
Required
Organization
Ministry of Industry and Information Technology
Provision
Article 5, Article 6
Applies to
Network product providers, network operators and network product security vulnerability collection platforms
Date
July 2021
Description
Article 5: Network product providers, network operators and network product security vulnerability collection platforms shall establish and improve channels for receiving network product security vulnerability information and keep them open, and retain network product security vulnerability information receiving logs for no less than 6 months.  Article 6: "Encourages relevant organizations and individuals to report security vulnerabilities in their products to network product providers" and "Encourage network product providers to establish a reward mechanism for security vulnerabilities in the network products they provide, and reward organizations or individuals who discover and report security vulnerabilities in the network products they provide."