6. Illegal access to the confident code and legally encoded information of agencies, organization, or individuals; disclosure of information of civil code products; use of and trading in civil code products of unclear origin. Article 8. Treatment of network information security violation Any person, who commits an act in violation of regulations set forth herein shall, depending on the nature and level of violation, be subject to disciplinary or administrative treatment or penal proceedings, and to payment for any damage, if any, under current laws. CHAPTER II ASSURANCE OF NETWORK INFORMATION SECURITY Section 1 NETWORK INFORMATION PROTECTION Article 9. Classification of information 1. The organization with information in its possession shall classify it by confidentiality in order to take appropriate protection measures. 2. Information in the domain of state secret shall be classified and protected as set forth in regulations on protection of state secrets. The organization using classified or unclassified information for activities in its field shall be responsible for establishing regulations and procedures to handle information, to determine the contents and methods to record permitted accesses to classified information. Article 10. Administration of information sending 1. Sending network information shall ensure the requirements as follows: a) not faking the sending source; b) complying with regulations herein and relevant laws. 2. Organizations, individuals must not send commercial information to a recipient’s electronic address without his/her prior consent, request, or when the recipient refuses it, except for the cases where the recipient is obliged to receive the information under current laws. 3. Telecommunications companies, enterprises providing telecommunications application services, and enterprises rendering information technology services that send information shall: a) Comply with legal regulations on information storage, and protection of personal information and private information of organizations, individuals; b) Take measures to stop and respond upon receipt of any notice from organizations, individuals of sending information in violation of legal regulations; c) Make it available for recipients to have rights to refuse further receive information; d) Provide technical and professional conditions necessary for competent state bodies to, upon request, perform duties of state administration of network information security. Article 11. Prevention, detection, blocking and treatment of malware 4

Select target paragraph3