in article 15.1.1 of this law from relevant state organizations, officials, inpiduals, and legal persons; 15.1.3.submit recommendations, requirements, and warnings related to ensuring cyber security to inpiduals and legal persons; 15.1.4.operate a quantitative analytical laboratory for the purposes of fighting against cyber-attacks and violations, verify equipment and software, conduct research and development work, and issue conclusions. Article 16.State-owned legal person 16.1.State-owned legal persons shall have the following obligations in relation to ensuring cyber security: 16.1.1.adopt internal operational procedures on ensuring cyber security; 16.1.2.comply with recommendations and requirements issued by relevant authorities on ensuring cyber security; 16.1.3.in cases of harm or potential harm from cyber-attacks and violations, immediately notify the center against cyber-attacks and violations; 16.1.4.incorporate the funds and operational expenses necessary for ensuring cyber security into the budget annually; 16.1.5.store information system action log for the time period stipulated in the common procedure for ensuring cyber security. Article 17.Legal person 17.1.Legal persons providing information technology services in the processing, storing, distributing, computer analytics, and ensuring the normal operations through shared information systems within the cyber space, shall have the following obligations: 17.1.1.adopt internal procedures to ensure cyber security; 17.1.2. immediately notify the center against cyber-attacks and violations of cyber-attacks, obtain assistance if unable to terminate such attacks; 17.1.3. store information system action log for the time period stipulated in the common procedure for ensuring cyber security; 17.1.4.obtain professional and methodology assistance from relevant state organization, and collaborate therewith in ensuring cyber security; 17.1.5.havean officer or unit on staff in charged with ensuring cyber security; 17.1.6.have cyber security risk assessments conducted every two years, and where the circumstances stipulated in the relevant procedures have arisen have such assessments done immediately for each case, and take measures in accordance with the conclusion, recommendations, and requirements issued in relation thereto; 17.1.7. have information security audits conducted every year, and where the circumstances stipulated in the relevant procedures have arisen have such audits done immediately for each case, and take measures in accordance with the conclusion, recommendations, and requirements issued in relation thereto; 17.1.8.have the relevant cyber security verification and check-ups each time new information technology products, services, and their updates and modifications are introduced; 17.1.9.notify users immediately of cyber-attacks and violations.

Select target paragraph3