in article 15.1.1 of this law from relevant state organizations, officials, inpiduals, and legal persons;
15.1.3.submit recommendations, requirements, and warnings related to ensuring cyber
security to inpiduals and legal persons;
15.1.4.operate a quantitative analytical laboratory for the purposes of fighting against
cyber-attacks and violations, verify equipment and software, conduct research and development work, and
issue conclusions.
Article 16.State-owned legal person
16.1.State-owned legal persons shall have the following obligations in relation to ensuring cyber
security:
16.1.1.adopt internal operational procedures on ensuring cyber security;
16.1.2.comply with recommendations and requirements issued by relevant authorities on
ensuring cyber security;
16.1.3.in cases of harm or potential harm from cyber-attacks and violations, immediately
notify the center against cyber-attacks and violations;
16.1.4.incorporate the funds and operational expenses necessary for ensuring cyber
security into the budget annually;
16.1.5.store information system action log for the time period stipulated in the common
procedure for ensuring cyber security.
Article 17.Legal person
17.1.Legal persons providing information technology services in the processing, storing,
distributing, computer analytics, and ensuring the normal operations through shared information systems
within the cyber space, shall have the following obligations:
17.1.1.adopt internal procedures to ensure cyber security;
17.1.2. immediately notify the center against cyber-attacks and violations of
cyber-attacks, obtain assistance if unable to terminate such attacks;
17.1.3. store information system action log for the time period stipulated in the common
procedure for ensuring cyber security;
17.1.4.obtain professional and methodology assistance from relevant state organization,
and collaborate therewith in ensuring cyber security;
17.1.5.havean officer or unit on staff in charged with ensuring cyber security;
17.1.6.have cyber security risk assessments conducted every two years, and where the
circumstances stipulated in the relevant procedures have arisen have such assessments done
immediately for each case, and take measures in accordance with the conclusion, recommendations, and
requirements issued in relation thereto;
17.1.7. have information security audits conducted every year, and where the
circumstances stipulated in the relevant procedures have arisen have such audits done immediately for
each case, and take measures in accordance with the conclusion, recommendations, and requirements
issued in relation thereto;
17.1.8.have the relevant cyber security verification and check-ups each time new
information technology products, services, and their updates and modifications are introduced;
17.1.9.notify users immediately of cyber-attacks and violations.