
Effective October 1, 2026, the Measures for Public Security Organs’ Supervision and Inspection of Cyberspace Security (Ministry of Public Security Order No.176) will be officially implemented, replacing Order No.151 issued in 2018. Compared with the previous version, the new measures expand the scope of supervision and inspection to cyberspace security fields including network security, data security and information security. It also specifies multiple inspection methods: online patrols, vulnerability scanning, remote detection and on-site examinations.
For office buildings and industrial parks, network security rectification is no longer merely about “having firewalls and written policies”. Office networks, guest networks, access control, surveillance, conference systems and networks operated by different enterprises within the building coexist for a long time. Uncontrolled terminal access, improperly configured permissions or ineffective security appliances can all become entry points for network risks.
Rather than rushing to patch vulnerabilities right before inspections, enterprises should conduct systematic network security self-inspections in advance. Check and remediate hidden risks in the campus network across network architecture, terminal admission, access permissions and security protection.
More critically, without clear access boundaries between different enterprises and departments, once one terminal is compromised, attackers may use the interconnected internal network for lateral scanning and expand the scope of impact.
Therefore, the first priority in self-inspection is to verify: whether terminals require identity authentication, whether device access is permission-controlled, and whether clear isolation boundaries exist between different business zones.
These seemingly administrative issues can easily turn into cybersecurity vulnerabilities.
Self-inspections should cover not only “who can access the internet”, but also “what resources each user can access”. Office staff should not be able to freely access sensitive systems for finance, R&D and HR simply by connecting to the campus network. Guest terminals should also be segregated from the enterprise core network.
In particular, systems commonly deployed in office parks such as OA, ERP and enterprise portals require thorough inspection of their defense capabilities and the ability to detect and block abnormal access promptly once exposed online.
Records of who connected to the network, connection time, accessed resources and response measures taken after anomalies are essential. Without centralized logging, security incidents often lead to situations where “no evidence can be found and facts cannot be clarified”.
As such, network logs, access records, security events and related audit information form key components of campus network self-inspections.
Faced with increasingly stringent cybersecurity inspection requirements, simply adding more security hardware cannot resolve all network issues for parks. A more sensible approach is to redefine security boundaries at the underlying network layer and build a full closed loop covering access, isolation, permission control, protection and auditing.
On this foundation, terminal identity and access permission controls are enforced, so users can only access authorized business systems instead of gaining excessive network access after connecting.
For multi-tenant office buildings, this architecture further enables network isolation between tenants and prevents unnecessary cross-enterprise network communication.
Through identity authentication, MAC address whitelisting and port binding, terminals including employee PCs, printers, cameras and access control devices are managed by category. Unauthorized unknown terminals cannot freely join the internal network. Fixed devices can be bound to corresponding ports and identities to reduce security risks brought by unauthorized device access or device tampering.
Under this model, the campus security perimeter is no longer limited to a single firewall at the egress. The defense line starts right at terminal access.
IPS identifies and blocks network attacks, while WAF defends against web application-layer attacks. Combined with malware detection, it delivers multi-layer defense against external intrusions, malicious access and abnormal traffic.
The paradigm shifts from “patching vulnerabilities after discovery” to “blocking attacks before they penetrate”, enabling campus network security to evolve from passive rectification to active protection.
Zhihui Guangxun embeds Zero Trust principles into all-optical networks. User and terminal identities are verified before access is granted, and access is approved only according to business permissions. Least-privilege rules and behavior auditing reduce internal privilege escalation risks.
For data transmission security, the converged connectivity-security framework can be adopted to jointly design communication networks and cryptographic security capabilities. Network construction focuses not only on stable data delivery but also effective protection of data in transit, delivering comprehensive safeguards for critical campus business data.
Zhihui Guangxun all-optical networks leverage a unified management platform to centrally manage network devices, terminals, policies and services, consolidating network configurations and security rules previously scattered across separate hardware.
When staff changes, new devices are added or network permissions adjusted, policy updates can be completed quickly. For abnormal terminals or network faults, the unified platform and log data support rapid localization, easing manual device-by-device troubleshooting workloads.
In 2026, cybersecurity supervision expands to cover broader cyberspace security. Self-inspections for office buildings and industrial parks should no longer stop at checking hardware deployment. Inspectors must verify whether the network is manageable, controllable, isolable, traceable and protected.
For parks undergoing network renovation or security rectification, continuously stacking hardware on legacy architectures is less ideal than redesigning from the network foundation. Built upon all-optical infrastructure, integrating terminal admission, service isolation, Zero Trust, security defense, log auditing and converged connectivity & security enables campus networks to progress beyond mere inspection compliance toward persistent security.
Completing cybersecurity self-inspections before the new rules officially take effect, and closing the loop for risk detection, remediation and long-term operation, is a more reliable approach for office buildings and industrial parks to meet the new round of cybersecurity requirements.
Q: What impacts will Order No.176 bring to office buildings and industrial parks?
A: Regulated entities expand from two original categories to eight. Operators of office buildings and industrial parks act simultaneously as network operators, data processors and personal information processors. Inspection items are extended to data security and algorithm security, with new remote vulnerability scanning and penetration testing added to inspection methods.
Q: What standards apply to log retention?
A: User registration and internet access logs must be recorded and retained in accordance with the law, typically for no less than 6 months (180 days). Log fields must include real-name information, IP address, MAC address, login/logout timestamps and visited URLs. The Mengxiang series gateways from Zhihui Guangxun feature built-in local storage and support one-click export of compliance reports.