商务支持

技术支持

About Guangxun

关于光迅

MPS Decree No.151 Fully Implemented: How All-Optical Networks Achieve Compliance of Internet Behavior Auditing
2026-07-27 09:40:19 2

MPS Decree No.151 Fully Implemented: How All-Optical Networks Achieve Compliance of Internet Behavior Auditing

In recent years, public security authorities have carried out regular cybersecurity supervision and inspections targeting internet-connected entities. The Provisions on Internet Security Supervision and Inspection by Public Security Organs (MPS Decree No.151) was issued in November 2018 and took effect on November 1, 2018. It defines statutory obligations for internet-connected entities concerning user real-name authentication, log retention and security protection.

For enterprise campuses, all-optical networks carrying office, R&D, production and visitor networks are evolving from mere "connectivity tools" into compliance infrastructure. This article sorts out core requirements stipulated by Decree No.151 and discusses how the AINOPOL all-optical network architecture helps enterprises implement compliant internet behavior auditing.

I. Core Requirements of MPS Decree No.151 for Enterprise Campuses

As "internet-connected entities", enterprise campuses are subject to inspection items specified in Article 10 of Decree No.151. Key points directly related to internet behavior auditing include:

  1. Filing and subject responsibility: Complete filing formalities for internet-connected entities, submit basic information of access providers and users together with updates, and appoint a dedicated network security person-in-charge.
  2. Log retention: Adopt technical measures to record and retain user registration information and internet access logs as required by law.
  3. Security protection: Deploy technical measures to defend against computer viruses, network attacks and intrusions.
  4. Classified protection obligations: Fulfill statutory requirements of Cybersecurity Classified Protection.

In practice, public security authorities generally require internet access logs for public Wi-Fi and campus networks to be retained for no less than six months.

Enterprises failing to implement real-name authentication or maintain complete log records may face warnings, fines, internet disconnection orders or rectification shutdown penalties in accordance with Article 59 of the Cybersecurity Law. Compliance is no longer optional; it has become a fundamental threshold for enterprise campus network construction.

II. Common Difficulties for Enterprise Campuses to Implement Internet Behavior Auditing

Traditional campus networks are mostly built with patchwork multi-vendor, multi-layer architectures, frequently encountering compliance obstacles:

  • Decentralized auditing: Internet behavior management, firewalls and authentication systems operate on separate hardware with inconsistent log formats, making aggregation and retrieval difficult.
  • Insufficient real-name mechanism: Mixed access by employees, visitors and IoT terminals without a unified real-name authentication portal, making it impossible to link online activities to specific individuals.
  • Inadequate retention standards: Short log storage cycles and incomplete fields, lacking complete evidence for official cybersecurity spot checks.
  • Poor platform interconnection: Absence of standard interfaces to connect with public security monitoring platforms, requiring manual log export during inspections with low efficiency.
  • Fragmented branch management: Independent policies and audit ledgers across multiple campuses and branches, hindering unified governance by headquarters.

III. How All-Optical Networks Support Compliant Auditing: Integrated Communication & Security Solution

The AINOPOL Integrated Communication & Security enterprise campus solution adopts all-optical networks as the digital foundation, converging network transmission and native security capabilities onto one unified infrastructure to simplify compliance implementation at the architectural level.

  1. All-Optical Foundation: The PON passive optical network carries full services including office communications, voice, surveillance and R&D. It reduces active network nodes and shrink the attack surface, providing a streamlined traffic entry point for centralized auditing.
  2. Security Multi-Service Gateway: Deployed at the campus egress, it integrates routing, firewall, internet behavior management, real-name authentication and log auditing capabilities. It eliminates complexity caused by fragmented multi-hardware deployment and enables centralized, controllable audit policies.
  3. Internet Behavior Management: Identifies more than 3,000 application protocols, restricts irrelevant applications and implements intelligent traffic control to guarantee office bandwidth while generating traceable records of online activities.
  4. Real-Name Authentication: Supports DingTalk, WeCom, SMS verification code and mini-program authentication covering employees and visitors, implementing the principle of whoever accesses the network shall be accountable.
  5. Log Auditing: Fully records MAC address, IP address, authenticated account, timestamp, accessed URL and other mandatory fields. Local storage supports log retention up to 180 days, meeting the common six-month requirement. It supports one-click export and interconnection with public security monitoring platforms.
  6. EAAS Cloud O&M Platform: Delivers a real-time online user dashboard displaying connected device MAC, IP, authenticated accounts and online duration, facilitating rapid verification during inspections. It also supports remote status monitoring and fault location.

IV. Implementation Recommendations for Enterprise Campus Compliance

  1. Complete filing procedures for internet-connected entities and maintain management ledgers with an appointed network security person-in-charge.
  2. Deploy an egress gateway supporting unified real-name authentication and log auditing, ensuring complete log fields and retention for a minimum of six months.
  3. Physically or logically separate employee internal networks and visitor networks, enforcing real-name registration for guest internet access.
  4. Formulate and enforce documented network security management systems and operational procedures.
  5. Fulfill Cybersecurity Classified Protection requirements and conduct assessments and rectification as needed.
  6. Conduct regular self-inspections of log integrity and equipment operational status to support one-click evidence export during official inspections.

Compliant network hardware constitutes critical technical support for enterprises to fulfill statutory obligations. Nevertheless, full implementation of Decree No.151 relies on coordinated management systems, filing formalities and classified protection work.

The AINOPOL Integrated Communication & Security solution enables enterprises to build unified capabilities for real-name authentication, behavior auditing and long-term log retention. Implementation should be coordinated with professional security services and specific requirements issued by local public security cybersecurity departments.

FAQ

Q: How long does MPS Decree No.151 require internet access logs to be retained?
A: Decree No.151 mandates internet-connected entities adopt technical measures to record and retain user registration information and internet access logs. For public Wi-Fi and campus scenarios, public security authorities generally require logs to be retained for no less than six months. The exact standard shall comply with requirements issued by local cybersecurity authorities.

Q: Are enterprise campuses required to implement Cybersecurity Classified Protection?
A: Article 10 of MPS Decree No.151 explicitly lists fulfillment of Classified Protection obligations as a supervision and inspection item. Enterprises operating important information systems or critical information infrastructure shall complete grading filing, assessment and rectification in accordance with regulations.

Q: What is the relationship between all-optical networks and internet behavior auditing?
A: The all-optical network provides a unified infrastructure capable of carrying diversified services. By deploying a security multi-service gateway at the network egress, enterprises can implement real-name authentication, behavior management and log auditing within the same architecture. Compliance capabilities are deployed alongside the network, reducing audit blind spots caused by patchwork multi-device networking.