6. Illegal access to the confident code and legally encoded information of agencies,
organization, or individuals; disclosure of information of civil code products; use of and
trading in civil code products of unclear origin.
Article 8. Treatment of network information security violation
Any person, who commits an act in violation of regulations set forth herein shall,
depending on the nature and level of violation, be subject to disciplinary or administrative
treatment or penal proceedings, and to payment for any damage, if any, under current laws.
CHAPTER II
ASSURANCE OF NETWORK INFORMATION SECURITY
Section 1
NETWORK INFORMATION PROTECTION
Article 9. Classification of information
1. The organization with information in its possession shall classify it by
confidentiality in order to take appropriate protection measures.
2. Information in the domain of state secret shall be classified and protected as set
forth in regulations on protection of state secrets.
The organization using classified or unclassified information for activities in its field
shall be responsible for establishing regulations and procedures to handle information, to
determine the contents and methods to record permitted accesses to classified information.
Article 10. Administration of information sending
1. Sending network information shall ensure the requirements as follows:
a) not faking the sending source;
b) complying with regulations herein and relevant laws.
2. Organizations, individuals must not send commercial information to a recipient’s
electronic address without his/her prior consent, request, or when the recipient refuses it,
except for the cases where the recipient is obliged to receive the information under current
laws.
3. Telecommunications companies, enterprises providing telecommunications
application services, and enterprises rendering information technology services that send
information shall:
a) Comply with legal regulations on information storage, and protection of personal
information and private information of organizations, individuals;
b) Take measures to stop and respond upon receipt of any notice from organizations,
individuals of sending information in violation of legal regulations;
c) Make it available for recipients to have rights to refuse further receive information;
d) Provide technical and professional conditions necessary for competent state bodies
to, upon request, perform duties of state administration of network information security.
Article 11. Prevention, detection, blocking and treatment of malware
4