China Cybersecurity Law MLPS classified protection evidence map
Build the evidence trail for network inventory, MLPS classification, filing, control implementation, assessment and remediation.
The amended Cybersecurity Law creates the classified-protection duty. GB/T 22240-2020 guides the five-level decision; level 2 and above networks are filed, and level 3 and above networks follow the annual assessment route in the cited MPS guidance.
Use this evidence map in sequence: define one , determine its from the harm test, file a level 2 or above network, map the applicable legal and GB/T controls, assess level 3 or above networks on the required cycle, close findings, and reopen the record after material change.
1
Section 1
1. Establish the protected object and level
Begin with a complete inventory of networks and protected objects, including cloud, mobile, Internet of Things, industrial-control and big-data environments. Define each boundary, operator, business function, service population, data, dependencies and technology context. For a new network, determine the during planning and design rather than after launch.
GB/T 22240-2020 is the current recommended national classification guide, published on 28 April 2020 and implemented on 1 November 2020. It tests two factors: the interest harmed when the is damaged and the severity of that harm. The affected interests are the lawful rights and interests of citizens, legal persons and other organisations; social order and public interests; and national security.
Level 1 covers harm to citizens, legal persons or other organisations without harm to national security, social order or public interests. Level 2 covers serious or especially serious harm to those private interests, or harm to social order or public interests, without harm to national security. Level 3 covers serious harm to social order or public interests, or harm to national security. Level 4 covers especially serious harm to social order or public interests, or serious harm to national security. Level 5 covers especially serious harm to national security. Keep the harm analysis and any sector guidance or authority review with the record; do not choose a level from system size, data sensitivity, or a vendor label alone.
Protected-object record: system name and identifier, operator, owner, architecture, locations, interfaces, service users, business functions, data and external dependencies.
2. Complete filing and map the applicable controls
Networks at level 2 or above are filed with the . Under the 2007 classified-protection management measures, an operating level 2 or above information system is filed within 30 days after its level is determined, and a new one within 30 days after it enters operation. Apply any current sector procedure and filing channel to the . Level 1 remains subject to the Cybersecurity Law's Article 23 baseline even though the cited filing route starts at level 2.
Keep the submitted classification and filing materials, filing receipt or certificate, authority questions and responses, and the final accepted system boundary. A filing record shows that the materials were accepted; it does not prove that every control operates effectively.
Build the control map from Article 23 and the standards that apply to the recorded level and technology context. separates technical requirements for the secure communications network, secure area boundary, secure computing environment and security management centre from management requirements for policies, organisation, personnel, construction and operations.
Filing evidence: filed forms, classification rationale, supporting diagrams, authority receipt or certificate, corrections and final accepted details.
Clause map: standard clause, applicability decision, control owner, implementation description, evidence location, gap, remediation owner and due date.
Technical evidence: configurations, access and privilege records, network and boundary protections, malware and intrusion controls, monitoring, backups, encryption and security-management-centre outputs.
Management evidence: approved policies, accountable security roles, personnel screening and training, supplier controls, secure development and change records, operations procedures and incident plans.
Article 23 evidence: monitoring and records of network status and security events, including network logs retained for at least six months.
3. Assess, remediate and retain operating evidence
Assess the controls against the same object, level, standard clauses and technology extensions used in the control map. The MPS implementation guidance directs level 3 and above operators to use a qualified assessment institution once each year and submit the assessment report to the that accepted the filing and to the industry authority. It also directs a new level 3 or above network to pass assessment before operation.
Track every finding to a responsible owner, corrective action, completion date and retest result. Preserve evidence from normal operation as well as the assessment package. A policy, filing certificate or assessment report cannot substitute for current configurations, logs, access reviews, incident exercises, backups and completed remediation.
Assessment package: scope confirmation, assessor qualifications, plan, evidence requests, test records, findings, report, submission evidence and management response.
Remediation package: finding identifier, risk, affected clause and asset, corrective action, owner, due date, implementation evidence and retest or closure decision.
Recurring evidence: access and privilege reviews, monitoring alerts, network logs, vulnerability and patch records, backup and recovery tests, supplier reviews, security training and incident exercises.
Exception evidence: approved reason, affected requirement, compensating measure, risk owner, expiry date and reassessment trigger.
Change evidence: impact analysis showing whether the object boundary, level, filing, control map or assessment must be updated.
answers how a network is classified and protected. It does not by itself decide whether a system is CII, whether a procurement requires cybersecurity review, whether data is important data, whether a personal-information or important-data export route applies, or whether an app needs MIIT filing.
Reuse verified system, architecture, data and supplier facts, but keep each scope decision and its evidence separate. For CII, classified protection is the baseline on top of which the enhanced CII duties apply.
Do not describe as a certification or approval of a specific system.
Do not use a high level as proof that the protection department has identified the system as CII.
Do not use an filing or assessment report as a substitute for cybersecurity review, data-export or app-filing analysis.
Do not keep stale evidence after material architecture, function, data or hosting changes.
Current GB/T 22239-2019 record for the level 1-4 general requirements and cloud, mobile, IoT, industrial-control and big-data extensions; effective 1 December 2019.
Current national classification guide, published 28 April 2020 and effective 1 November 2020, for determining a protected object's security protection level.
Article 15 sets the 30-day filing rules for operating and newly operated level 2 or above information systems; Article 16 identifies the filing materials for level 3 or above systems.
Official implementation guidance for annual assessment of level 3 and above networks, pre-operation assessment of new level 3 and above networks, report submission, and standards-based construction and remediation.
Article 6 states that CII operators apply additional necessary protection measures on the basis of classified protection; Articles 8-10 establish the separate authority-led CII recognition process.