附录:最新政策法规体系(截至2026年5月)
一、核心法律
1. 《中华人民共和国网络安全法》(2025年修正)
2017年6月1日施行,2025年10月28日全国人大常委会通过修正决定,2026年1月1日起施行。首次重大修订,新增AI安全条款(第二十条),大幅提升违法处罚力度:造成关键信息基础设施丧失主要功能等特别严重后果的,处200万-1000万元罚款,对责任人处20万-100万元罚款。
2. 《中华人民共和国数据安全法》
2021年9月1日起施行。确立数据分类分级保护制度,明确数据处理活动的安全义务。
3. 《中华人民共和国个人信息保护法》
2021年11月1日起施行。规范个人信息处理活动,保护个人信息权益。
二、行政法规
1. 《网络数据安全管理条例》(国务院令第790号)
2025年1月1日起施行。建立网络数据分类分级保护、重要数据安全、个人信息保护合规审计、数据跨境安全管理等核心制度。
2. 《公共安全视频图像信息系统管理条例》(国务院令第799号)
2025年4月1日起施行。明确视频系统建设、备案、运行安全、数据保护等全链条管理要求。要求完善防攻击、防入侵、防病毒、防篡改、防泄露等安全技术措施。视频图像信息保存不少于30日。
3. 《关键信息基础设施安全保护条例》
2021年9月1日起施行。对关键信息基础设施实行重点保护。
三、等级保护标准体系(2025-2026年最新)
1. 等保定级与备案动态管理(公网安〔2025〕1001号/1846号):
- 所有二级及以上系统需按2025版模板重新填报备案,《备案证明》有效期统一为3年
- 测评结论从百分制改为"符合/基本符合/不符合"三级判定
- 符合率>90%且无重大风险隐患为"符合";引入"重大风险隐患"概念,需30日内整改完毕
2. 2026年2月1日实施的新标准(6项):
- GA/T 1390.6-2025 边缘计算安全扩展要求
- GA/T 1390.7-2025 大数据系统安全扩展要求
- GA/T 1390.8-2025 IPv6网络安全扩展要求
- GA/T 1390.9-2025 区块链安全扩展要求
- GA/T 2347-2025 云计算测评指引
- GA/T 2348-2025 5G接入安全测评要求
3. 等保数据安全新规(2026年6月1日实施):
- GA/T 2380-2026、GA/T 2381-2026、GA/T 2394-2026、GA/T 2395-2026
- 首次将数据安全作为独立体系全面纳入等保框架,测评时数据安全单独计分
- 覆盖数据全生命周期:采集→传输→存储→处理→交换→销毁
- 日志留存要求提升至≥12个月
- 重要数据备份要求:同城≥30公里,跨省市≥100公里
四、数据出境监管体系
"3+1=4"体系全面建成:3部法律(网络安全法/数据安全法/个人信息保护法)+ 1部行政法规(网络数据安全管理条例)+ 4部部门规章(数据出境安全评估办法/个人信息出境标准合同办法/个人信息出境认证办法/促进和规范数据跨境流动规定)。
《个人信息出境认证办法》2025年10月14日发布,2026年1月1日起施行,标志着数据出境合规体系的最后一块拼图落地。
Appendix: latest policy and regulatory framework as of May 2026. Core laws include the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law. Key administrative regulations include the Regulations on Network Data Security Management, the Public Security Video Image Information System Management Regulations, and the Critical Information Infrastructure Security Protection Regulations. The 2025 to 2026 MLPS updates strengthen dynamic filing management, change assessment conclusions to compliant, basically compliant, and non-compliant, and introduce the concept of major risk findings that must be remediated within the required period. New extension standards cover edge computing, big data, IPv6, blockchain, cloud computing, and industrial-control security. For video image systems, organizations should improve attack prevention, intrusion prevention, antivirus, tamper resistance, data-leak prevention, access auditing, and retention controls. Practical compliance work should start with asset inventory and system classification, then update filings, implement identity and boundary controls, strengthen data lifecycle protection, preserve audit evidence, and close remediation tasks on schedule.