Article 17 The State shall boost the construction of a socialized service system for cybersecurity, and encourage enterprises and institutions concerned to provide such security services as the authentication, detection and risk evaluation of cybersecurity. Article 18 The State shall encourage the development of technologies for protecting and using network data, promote the availability of public data resources and propel technological innovation and social and economic development. The State supports the innovation of cybersecurity administrative methods, applying new network technologies and enhancing the level of cybersecurity protection. Article 19 People's governments at all levels and the relevant departments thereof shall organize and provide regular publicity and education on cybersecurity, and guide, supervise and urge relevant entities to provide such publicity and education on cybersecurity in an effective way. The mass media shall provide publicity and education on cybersecurity targeted at the public specifically. Article 20 The State supports enterprises, institutions of higher education, vocational schools and other education training institutions to carry out cybersecurity-related education and training, adopt multiple methods to cultivate talents for cybersecurity and promote the exchange of talents for cybersecurity. Chapter III Network Operation Security Section 1 General Provisions Article 21 The State implements the classified protection system for cybersecurity. Network operators shall fulfill the following obligations of security protection according to the requirements of the classified protection system for cybersecurity to ensure that the network is free from interference, damage or unauthorized access, and prevent network data from being divulged, stolen or falsified, 1. Formulate internal security management systems and operating instructions, determine the persons responsible for cybersecurity, and implement the responsibility for cybersecurity protection; 2. Take technological measures to prevent computer viruses, network attacks, network intrusions and other actions endangering cybersecurity; 3. Take technological measures to monitor and record the network operation status and cybersecurity incidents, and preserve relevant web logs for no less than six months according to the provisions; 4. Take measures such as data classification, and back-up and encryption of important data; and 5. Other obligations stipulated by laws and administrative regulations. Article 22 Network products and services shall comply with the compulsory requirements of the relevant national standards. Providers of network products and services shall not install malwares; when they discover that their network products or services are subject to risks such as security defects or bugs, such providers shall take remedial measures immediately, inform users of the said risks and report the same to the relevant competent departments in accordance with the provisions. Providers of network products and services shall provide security maintenance for their products and services; and shall not terminate the provision of security maintenance within the stipulated time limit or the time limit agreed by the parties concerned. Where network products and services have the function of collecting users' information, the providers shall clearly notify their users and obtain their consent. In the case of involving users' personal information, the providers shall also comply with the provisions regarding the protection of personal information as stipulated by this Law, relevant laws and administrative regulations. Article 23 Critical network equipment and specialized cybersecurity products shall, pursuant to the compulsory requirements of the relevant national standards, pass the security certification by qualified 4

Sélectionner le paragraphe cible3