Intrinsec
China's Regulations on Network Product Security Vulnerabilities
Pages
23
Time to read
28 mins
Publication
Language
English
Pages
23
Time to read
28 mins
Publication
Language
English
This report is a detailed examination of the Regulations on the Management of Network Product Security Vulnerabilities (RMSV) in China, which extends the 2017 Cybersecurity Law. The RMSV targets hardware and software companies, as well as cybersecurity researchers, imposing strict rules on the collection, sale, and disclosure of vulnerability information that could jeopardize information system security. It mandates that companies establish systems for reporting discovered vulnerabilities and maintain logs for six months. The report outlines the obligations for companies to audit and report vulnerabilities to the government within 48 hours and highlights the prohibition of public communication regarding vulnerabilities without government consent during significant national events. The RMSV encourages the establishment of 'Bug Bounty' programs to incentivize vulnerability discovery. Furthermore, the report discusses the implications of these regulations on international collaboration and the strategic exploitation of vulnerabilities by the Chinese government, as evidenced by a decline in submissions to national databases and the obfuscation of vulnerability data.