In order to speed up the level protection of information security, standardize the management of information security level protection, improve the ability and level of information security, safeguard national security, social stability and public interests, and guarantee and promote the informatization construction, the Ministry of Public Security, the State Secrecy Bureau, the State Cryptography Administration and the the State Council Press Office have formulated the Measures for the Management of Information Security Level Protection. The state organizes citizens, legal persons and other organizations to implement hierarchical security protection of information systems by formulating unified management norms and technical standards for hierarchical protection of information security, and supervises and manages the implementation of hierarchical protection. The public security organ is responsible for the supervision, inspection and guidance of information security level protection. The state secrecy department is responsible for the supervision, inspection and guidance of the secrecy work in the level protection work. The national password management department is responsible for the supervision, inspection and guidance of the password work in the level protection work. Matters under the jurisdiction of other functional departments shall be managed by the relevant functional departments in accordance with the provisions of national laws and regulations. The information work office of the State Council and the local information leading group office are responsible for the inter-departmental coordination of grade protection.
The competent department of information system shall, in accordance with these Measures and relevant standards and norms, supervise, inspect and guide the information security level protection work of information system operators and users in this industry, department and local area. The classification protection of national information security adheres to the principle of independent classification and independent protection. The level of security protection of information systems should be determined according to the importance of information systems in national security, economic construction and social life, and the degree of harm to national security, social order, public interests and the legitimate rights and interests of citizens, legal persons and other organizations after information systems are destroyed.
Legal basis: Chapter I General Measures for the Administration of Grade Protection of Information Security
Article 1 In order to standardize the management of information security level protection, improve the ability and level of information security, safeguard national security, social stability and public interests, and guarantee and promote information construction, these Measures are formulated in accordance with the Regulations of People's Republic of China (PRC) on the Security Protection of Computer Information Systems and other relevant laws and regulations.