{"id":1610,"date":"2017-05-22T19:00:50","date_gmt":"2017-05-22T19:00:50","guid":{"rendered":"https:\/\/jsis.washington.edu\/eacenter\/?p=1610"},"modified":"2017-09-12T18:17:42","modified_gmt":"2017-09-12T18:17:42","slug":"cybersecurity-strategy-advice-trump-administration-us-china-relations","status":"publish","type":"post","link":"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/","title":{"rendered":"Cybersecurity Strategy Advice for the Trump Administration: US-China Relations"},"content":{"rendered":"<p><em>This post is part of\u00a0a series making cybersecurity strategy recommendations for the new Trump Administration.\u00a0<a href=\"https:\/\/jsis.washington.edu\/news\/cybersecurity-strategy-advice-trump-administration-us-russia-relations\/\">US-Russia relations<\/a>,\u00a0<a href=\"https:\/\/jsis.washington.edu\/news\/cybersecurity-strategy-advice-trump-administration-us-mexico-relations\/\">US-Mexico relations<\/a>,\u00a0<a href=\"https:\/\/jsis.washington.edu\/news\/cybersecurity-strategy-advice-trump-administration-us-india-relations\/\">US-India relations<\/a>,\u00a0<a href=\"https:\/\/jsis.washington.edu\/news\/cybersecurity-strategy-advice-trump-administration-us-turkey-relations\/\">US-Turkey relations<\/a>,\u00a0<a href=\"https:\/\/jsis.washington.edu\/news\/cybersecurity-strategy-advice-trump-administration-us-south-korea-relations\/\">US-South Korea relations<\/a>,\u00a0<a href=\"https:\/\/jsis.washington.edu\/news\/cybersecurity-strategy-advice-trump-administration-us-japan-relations\/\">US-Japan relations<\/a>,\u00a0<a href=\"https:\/\/jsis.washington.edu\/news\/cybersecurity-strategy-advice-trump-administration-us-asean-relations\/\">US-ASEAN relations<\/a>,\u00a0<a href=\"https:\/\/jsis.washington.edu\/news\/cybersecurity-strategy-advice-trump-administration-us-cuba-relations\/\">US-Cuban relations<\/a>,\u00a0<a href=\"https:\/\/jsis.washington.edu\/news\/cybersecurity-strategy-advice-trump-administration-us-brazil-relations\/\">US-Brazil relations<\/a>,\u00a0<a href=\"https:\/\/jsis.washington.edu\/news\/cybersecurity-strategy-advice-trump-administration-us-cameroon-relations\/\">US-Cameroon relations<\/a>,\u00a0<a href=\"https:\/\/jsis.washington.edu\/news\/cybersecurity-strategy-advice-trump-administration-us-eu-relations\/\">US-EU relations<\/a>, and <a href=\"https:\/\/jsis.washington.edu\/news\/cybersecurity-strategy-advice-trump-administration-us-myanmar-relations\/\">US-Myanmar relations<\/a> were the topics of previous pieces.<\/em><\/p>\n<div class=\"announcement\">\n<h2>Central Challenge<\/h2>\n<p>Cybersecurity is of vital importance to US-China relations, particularly in relation\u00a0to national information security and the business market. While it is a new realm for trust and cooperation between China and the US, it\u00a0has already led to a high level of tension.<\/p>\n<h2>Recommendations<\/h2>\n<ol>\n<li>The US should encourage tech companies to continue scrutinizing cyber intrusions, but also the US government should keep engaging with China on cyber-espionage.<\/li>\n<li>The US should work to restore the trust of Chinese government and Chinese market in the aftermath of Snowden\u2019s revelations.<\/li>\n<li>In light of the new Chinese cybersecurity law, the US should maintain its rhetoric of Internet freedom and continue to protest any Chinese move that signals possible protectionism against foreign tech firms.<\/li>\n<li>The US should consider implementing various measures to press the Chinese government to not discriminate foreign tech companies and uphold a free-trade environment.<\/li>\n<\/ol>\n<\/div>\n<p>In recent years, cyber-espionage has become a pivotal issue in US-China cybersecurity relations. Cyber-espionage related tension is not necessarily due to political and military espionage, which the US has considered legitimate and normal activity between governments. Instead, the tension is due to government-backed economic espionage meant to aid Chinese state-owned firms.<\/p>\n<p>In September 2015, President Obama stated his\u00a0concern over economic espionage\u00a0explicitly in a business roundtable talk saying that, \u201cWe understand traditional intelligence-gathering functions that all states, including us, engage in\u2026 [t]hat it fundamentally different from your government or its proxies engaging directly in industrial espionage and stealing trade secrets, stealing propriety information from companies.\u201d <a href=\"https:\/\/www.whitehouse.gov\/the-press-office\/2015\/09\/16\/remarks-president-business-roundtable\">He also\u00a0indicated that economic espionage is considered \u201can act of aggression.\u201d<\/a>\u00a0Further, <a href=\"https:\/\/www.whitehouse.gov\/the-press-office\/2013\/03\/11\/remarks-tom-donilon-national-security-advisor-president-united-states-an\">in March National Security Advisor Tom Donilon singled out China in his remarks to the President stating \u201csuch activities from any country\u201d cannot be tolerated by the international community.<\/a><\/p>\n<p>Since the first report of Chinese hackers breaching US federal government systems in the early 2000s \u2014 the so-called <a href=\"http:\/\/foreignpolicy.com\/2010\/01\/22\/the-top-10-chinese-cyber-attacks-that-we-know-of\/\">\u201cTitan Rain\u201d attack<\/a> &#8212; there have been an increasing number of reported cases of Chinese intrusion into government agencies and\u00a0private industry. According to a study by Jon R. Lindsay and Tai Ming Cheung, there were 37 reported Chinese hacking incidents before\u00a02014, of which only nine targeted government agencies &#8212; the rest of the targets were either commercial entities or were mixed in their targets.<a href=\"#_ftn1\" name=\"_ftnref3\">[1]<\/a> Another study by P.W. Singer and Allan Friedman also found that 96% of recorded, state-affiliated cyber-espionage attacks on private businesses and intellectual property in 2012 can be traced back to China.<a href=\"#_ftn2\" name=\"_ftnref4\">[2]<\/a> Some of the notable targets include Dupont, Lockheed Martin, Superconductor, Chesapeake Energy, British Gas, Google, and Coca Cola.<\/p>\n<p><a href=\"http:\/\/www.nytimes.com\/2013\/02\/19\/technology\/chinas-army-is-seen-as-tied-to-hacking-against-us.html?pagewanted=all&amp;_r=0\">Despite the Chinese government\u2019s constant denial of involvement in the attacks, a 2013 report by American cybersecurity firm Mandiant revealed that the People\u2019s Liberation Army (PLA) Unit 61398 was\u00a0behind most of the industrial espionage activities that strain US-China bilateral relations.<\/a>\u00a0The tension between the US and China on cyber-espionage was further heightened in 2014, when the Justice Department alleged that five Chinese military officers hacked US companies. <a href=\"https:\/\/www.justice.gov\/opa\/pr\/us-charges-five-chinese-military-hackers-cyber-espionage-against-us-corporations-and-labor\">The victims included Westinghouse, SolarWorld, U.S. Steel, ATI Technologies, and Alcoa &#8212; all of which are major US industrial and energy firms.<\/a>\u00a0However, <a href=\"http:\/\/www.wsj.com\/articles\/SB10001424052702304422704579571604060696532\">this accusation drew an angry response from the Chinese Foreign Ministry and its spokesman stated that the allegations were \u201cbased on fabricated facts.\u201d<\/a> <a href=\"http:\/\/www.reuters.com\/article\/us-china-us-cyber-idUSBRE93C05T20130413\">He stated\u00a0that in response to the accusations China would suspend its participation in a US-China working group on cybersecurity<\/a>, which was set up in 2013 to smooth the relationship and build trust.<\/p>\n<p>China\u2019s cyber-espionage remained a contentious issue for much of 2015, as the US accused China of attacking the Office of Personal Management\u2019s databases and stealing information about more than 20 million people. <a href=\"http:\/\/www.nytimes.com\/2015\/08\/01\/world\/asia\/us-decides-to-retaliate-against-chinas-hacking.html\">Although the case seemed to fall into the domain of political espionage, the vast scope and ambition caused the Obama administration to consider economic sanctions as a punitive measure.<\/a><\/p>\n<p>Nonetheless, in 2015 there was also great breakthrough in US-China relations in cyberspace. During Chinese President Xi\u2019s visit to the U.S in September 2015, the US and China still managed to reach an agreement that <a href=\"https:\/\/www.whitehouse.gov\/the-press-office\/2015\/09\/25\/fact-sheet-president-xi-jinpings-state-visit-united-states\">\u201cneither government will conduct or knowingly support cyber-enabled theft of intellectual property.\u201d<\/a>\u00a0Meanwhile,\u00a0<a href=\"https:\/\/www.whitehouse.gov\/the-press-office\/2015\/09\/25\/fact-sheet-president-xi-jinpings-state-visit-united-states\">both sides also agreed to initiate \u201ca high-level joint dialogue mechanism on fighting cybercrime and related issues.\u201d<\/a>\u00a0The first US-China High-Level Joint Dialogue on Cybercrime and Related Issues took place in December with significant outcomes, <a href=\"https:\/\/www.justice.gov\/opa\/pr\/first-us-china-high-level-joint-dialogue-cybercrime-and-related-issues-summary-outcomes-0\">such as the establishment of hotline mechanism to avoid escalation of issues and a\u00a0plan for a tabletop exercise in spring 2016.<\/a><\/p>\n<p>Since the 2015 cyber agreement, US-China cybersecurity relations seem to have taken a promising turn. <a href=\"https:\/\/www.fireeye.com\/content\/dam\/fireeye-www\/current-threats\/pdfs\/rpt-china-espionage.pdf\">According to a report released by FireEye in June 2016<\/a>, the active network compromises\u00a0by suspected Chinese groups has dropped significantly from nearly 40 cases per month to less than ten after the US-China agreement. The New York Times reported again on Unit 61398, which it had originally argued was responsible for most of China\u2019s economic espionage cases in cyberspace, stating that the unit <a href=\"http:\/\/www.nytimes.com\/2016\/06\/21\/us\/politics\/china-us-cyber-spying.html\">\u201cappears to be largely out of business, its hackers dispersed to other military, private and intelligence units.\u201d<\/a>\u00a0While there were still attacks seen from China\u2019s side on the semiconductor and aerospace industries, the reduced number does point out that the rapprochement is a good first step.<\/p>\n<h2>Chinese New Cyber Law and US Companies<\/h2>\n<p>While the cyber agreement between China and the US eased tensions and seemed to turn their bilateral relationship towards cooperation, the new Chinese Cyber Law could complicate this positive arc. The new Chinese Cyber Law was approved in November 2016 and has significant implications for US technology companies in China.<\/p>\n<p>The stated purpose of the law is said to stop cyberattacks and prevent cyber-terrorism; however, foreign observers find several parts of the law problematic. For instance, the law\u2019s Article 24 asks all companies to verify users\u2019 real identity when providing <a href=\"http:\/\/www.npc.gov.cn\/npc\/xinwen\/2016-11\/07\/content_2001605.htm\">\u201cinformation dissemination and instant messaging services.\u201d<\/a> <a href=\"https:\/\/www.lawfareblog.com\/understanding-chinas-cybersecurity-law\">This article may further erode the country\u2019s Internet freedom.<\/a>\u00a0The most controversial rules in the law are Article 28, 37 and 38, <a href=\"http:\/\/www.economist.com\/news\/china\/21710001-foreign-firms-are-worried-china-adopts-tough-cyber-security-law\">which require Internet operators to provide technical support for the government\u2019s security and crime investigation, asks those in \u201ccritical information infrastructure\u201d to store all personal information and \u201cimportant data\u201d collected in-country in China, and requires companies to undergo security reviews by government agencies annually.<\/a><\/p>\n<p>Although the law will not be in effect until June 2017 and how the government will implement the law is still unclear, it has received criticism from foreign business groups. <a href=\"http:\/\/www.economist.com\/news\/china\/21710001-foreign-firms-are-worried-china-adopts-tough-cyber-security-law\">James Zimmerman, chairman of the US Chamber of Commerce, has called the law \u201ca step backwards for innovation\u201d without much security benefit.<\/a>\u00a0Foreign firms\u2019 major concerns are that under requirement for \u201ctechnical support,\u201d they may be forced to hand over source code and other proprietary information. In the law,\u00a0<a href=\"http:\/\/www.wsj.com\/articles\/china-approves-cybersecurity-law-1478491064\">\u201ccritical\u201d areas required to give up information are defined by the government to include telecommunication, energy, transportation, information services, e-government, and finance.<\/a>\u00a0Furthermore, the rules are suspected to be motivated by protectionist sentiment worsening the investment environment in China.<\/p>\n<p>The anxiety of foreign companies, especially the US firms that have significant market share in China, is not ungrounded. The discussion of the law has been on-going since the first draft came out in July 2015 and some of the regulations were mentioned in other cybersecurity-related laws and implemented against foreign companies even earlier.<\/p>\n<p>Since Edward Snowden\u2019s revelation in 2013 about National Security Agency\u2019s surveillance on US tech products for espionage purposes, China has tightened its control over the tech market to ensure the technology products supplied to government agencies and vital infrastructure sectors are from more reliable sources &#8211; meaning Chinese domestic companies. By the end of 2013, IBM, HP, Microsoft and Cisco had all experienced a decline in sales in China and executives indicated that despite the slowing Chinese economy, Chinese actors had begun to favor indigenous products. <a href=\"http:\/\/www.wsj.com\/articles\/SB10001424052702303789604579198370093354680\">Cisco executives were explicit that Chinese customers may be cutting purchasing of US products in response to Snowden&#8217;s revelations.<\/a>\u00a0Qualcomm CEO pointed out that <a href=\"http:\/\/www.wsj.com\/articles\/SB10001424052702304337404579214353783842062\">it was a pressure shared by all US tech companies.<\/a><\/p>\n<p><a href=\"http:\/\/www.npc.gov.cn\/npc\/xinwen\/lfgz\/flca\/2014-11\/03\/content_1885027.htm\">In response to the revealed NSA surveillance<\/a>, <a href=\"http:\/\/www.xinhuanet.com\/legal\/2015-12\/27\/c_128571798.htm\">the November 2014 initial draft of the Chinese Counterterrorism Law for the first time mentioned the requirement that\u00a0all telecommunication operators and Internet service providers to report cryptography, to provide technical support for terrorism cases, and to store all relevant equipment and locally collected user data in China.<\/a>\u00a0Also, the new regulations adopted in January 2015 required the financial institutions to use \u201csecure and controlled\u201d equipment \u2014 <a href=\"http:\/\/www.nytimes.com\/2015\/01\/29\/technology\/in-china-new-cybersecurity-rules-perturb-western-tech-companies.html\">and will eventually require all tech companies that sell to Chinese banks to disclose source code to Chinese government.<\/a><\/p>\n<p>Both regulations caused the US government and foreign companies to protest, and as a result, when the law was formally passed in December 2015, the draft language on cryptography and data localization was removed, and the new policy on banking-sector was also suspended in April 2015. However, <a href=\"http:\/\/www.lexology.com\/library\/detail.aspx?g=328d911d-1c0e-40c2-9158-27d674bb696a\">the new cybersecurity law still articulates the requirement for data localization, and the new draft on insurance IT regulations issued in October 2015 is similar to that on banking.<\/a><\/p>\n<p>At the same time, the repercussions of the Snowden case continue to occur for US tech companies. China Daily, a news agency owned by Chinese State Council Information Office, <a href=\"http:\/\/usa.chinadaily.com.cn\/epaper\/2014-06\/04\/content_17561758.htm\">described Google and Apple as \u201ccyber security threats to Chinese users.\u201d The same article also noted Yahoo, Cisco, Microsoft and Facebook\u2019s transfer of users\u2019 information to NSA.<\/a>\u00a0In May 2014, <a href=\"http:\/\/www.scmp.com\/news\/china-insider\/article\/1516231\/china-shuns-microsofts-windows-8-it-opens-bids-government-use\">the government procurement center announced a ban on Microsoft Windows 8 for government computers and, in July 2014<\/a>, <a href=\"http:\/\/www.wsj.com\/articles\/china-labels-apple-iphone-a-security-threat-1405062978\">the Apple iPhone was called \u201ca national security concern\u201d by Chinese state broadcaster China Central Television.<\/a><\/p>\n<p>Chinese government\u2019s \u00a0suspicion of US companies did not remain verbal, but led to a series inspections. By the end of 2014, <a href=\"https:\/\/www.ft.com\/content\/31d5fdd8-31bf-11e4-a19b-00144feabdc0\">Microsoft and Qualcom had faced antitrust investigations<\/a> and <a href=\"https:\/\/www.washingtonpost.com\/news\/the-switch\/wp\/2014\/12\/29\/not-satisfied-with-gmail-china-seems-to-be-blocking-google-search-too\/?utm_term=.480aa50c3e57\">Google had seen all of its products blocked<\/a>.\u00a0In January 2015, Apple revealed the fact that the Chinese government had requested it undergo China\u2019s cybersecurity review. <a href=\"http:\/\/www.bjnews.com.cn\/news\/2015\/01\/21\/350845.html\">Apple agreed and became the first US company to participate in the review.<\/a><\/p>\n<p>Later in February 2015, <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2015-02-09\/china-fines-qualcomm-975-million-sets-patent-licensing-rates\">Qualcom was fined with $975 million by Chinese antitrust regulators as the result of investigation.<\/a>\u00a0The most recent case of China\u2019s security interrogations on foreign firms is Apple\u2019s involvement in Chinese cybersecurity review in May 2016 following Apple&#8217;s compliance with Chinese government demand for its source code. Consequently, in face of China\u2019s increasingly stiff cybersecurity regulations, <a href=\"http:\/\/www.wsj.com\/articles\/chinas-new-tech-rules-make-it-hard-for-u-s-firms-to-take-control-1464870481\">US companies feel coerced to\u00a0conduct businesses through Chinese business partners in order to maintain access to China.<\/a><\/p>\n<h2>Recommendation 1<\/h2>\n<p>While China\u2019s economic espionage behavior has declined significantly since the US-China cybersecurity agreement, China\u2019s cyber intrusions into US firms have continued. <a href=\"http:\/\/www.businessinsurance.com\/article\/20160621\/NEWS06\/160629960\">FireEye\u2019s 2016 report points out the decrease in numbers of cyber compromises conducted by suspected Chinese groups, but it also suggests the hackers installed \u201cback doors\u201d to enable future spying.<\/a><\/p>\n<p>However, the picture of current Chinese intrusions is unclear. As Laure Galante, the director of threat intelligence at FireEye, pointed out, security firms do not necessarily track attacks in real time for a variety of reasons.\u00a0<a href=\"http:\/\/fortune.com\/2016\/06\/25\/fireeye-mandia-china-hackers\/\">As FireEye CEO Kevin Mandia indicated, how well the companies keep logs may have impact on the investigation of malicious activities.<\/a>\u00a0Therefore, the data is not necessarily representative of what is actually happening. The uncertainty leads to the possibility that the report which came out in June may not accurately present the number of Chinese cyber breaches on US firms in 2016.<\/p>\n<p>Meanwhile, <a href=\"https:\/\/cybersecpolitics.blogspot.com\/2016\/09\/the-chinese-get-real.html\">Chinese hackers have increased their skill, allowing\u00a0more specific, concentrated, and higher-grade of hacking on strategic targets.<\/a>\u00a0According to an intelligence report disseminated in September 2016, <a href=\"http:\/\/www.washingtontimes.com\/news\/2016\/sep\/28\/china-cyber-espionage-continues\/\">China\u2019s biggest cyber spying operation has been carried out since at least since October 2015 and involves the theft of 1.65 terabytes of proprietary data from a major US software company.<\/a>\u00a0In light of these activities, good agreements are necessary.<\/p>\n<p>The Russia-China cybersecurity agreement illustrates that such pacts are only the beginning of good relations. Although China signed a non-aggression cyber agreement with Russia in 2015, Kaspersky Lab, a cybersecurity company based in Russia noted in August 2016 that Chinese actors were hacking into Russian industries including defense, nuclear, and aviation. <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2016-08-25\/russia-more-prey-than-predator-to-cyber-firm-wary-of-china\">These hacks increased from 194 in the first two quarters of 2016 compared to 72 in the whole of 2015.<\/a>\u00a0Therefore, the cybersecurity agreement between China and the US is merely a starting point, and issue of economic espionage should be constantly brought up to Chinese high level officials in the bilateral cyber dialogues for pressure.<\/p>\n<p>The US should encourage tech companies to continue scrutinizing cyber intrusions and pay close attention to those originated from China. At the same time, the US government should keep engaging with China on cyber-espionage, and continue to hold bilateral talks at the senior level.<\/p>\n<h2>Recommendation 2<\/h2>\n<p>Snowden\u2019s revelations of NSA surveillance has damaged the vulnerable trust between China and the United States. Since then, the Chinese government has adopted stricter cyber regulations and continuously placed foreign businesses under security review. As US-China relations have\u00a0many possible domains of conflicts, the business ties between the Chinese market and US firms should be a stabilizing element. Therefore, it is necessary to restore the Chinese-US relationship both on the government level and on the market level. On the government level, it is necessary to pursue the rapprochement strategies mentioned in the agreement, such as having more frequent high level talks.<\/p>\n<p>At the same time, US tech companies have criticized\u00a0<a href=\"http:\/\/www.nytimes.com\/2015\/07\/08\/technology\/code-specialists-oppose-us-and-british-government-access-to-encrypted-communication.html\">the US government for demanding access to encrypted communication.<\/a>\u00a0In 2015, <a href=\"http:\/\/www.fool.com\/investing\/general\/2015\/05\/27\/apple-inc-and-google-inc-team-up-against-uncle-sam.aspx\">Apple, Google, Facebook and other major tech firms were reported to have signed a letter to the Obama administration to oppose lowering encryption standards and creating \u201cback door\u201d for government agencies.<\/a>\u00a0In 2016, Apple also took stand against the FBI on the matter of technological back door, which was echoed by Google, Microsoft and Facebook\u2019s joint statement that objected to the idea of putting \u201cback doors\u201d into products for law enforcement agencies.<\/p>\n<p>While the government needs to take measures to ensure national and civilian security, such\u00a0open letters send a signal to foreign governments, including China, about the innocence of US companies in surveillance and their genuine intent of doing business abroad. Thus, on the business level, the public denunciation of US government by these major tech firms may decrease the suspicions and reestablish trust, and should be encouraged.<\/p>\n<p>The US should restore the trust of the Chinese government and the Chinese market in the aftermath of Snowden\u2019s revelations\u00a0in 2013. More frequent high level talks on cyber-policy should be held to build mutual trust and prevent unexpected events from causing hostility. Meanwhile, the US government should welcome and encourage denunciations from tech firms as a sign of the firms&#8217; separation from US government policy.<\/p>\n<h2>Recommendation 3<\/h2>\n<p>The 2011 International Strategy for Cyber Space released by President Obama\u00a0declares that the US has national interest in constructing a \u201cinteroperable, secure and reliable cyberspace,\u201d and acknowledges the US commitment to freedom of expression, privacy and free flow of information. <a href=\"https:\/\/www.whitehouse.gov\/sites\/default\/files\/rss_viewer\/international_strategy_for_cyberspace.pdf\">The report also recognizes these policy priorities to be the basis of sustaining of a free-trade environment and protection of intellectual property.<\/a>\u00a0Internet censorship in China has long drawn criticisms for its abuses of freedom of speech and freedom of access to information.<\/p>\n<p>However, China\u2019s recent discriminatory moves against foreign firms and request for data localization creates new problems as the requests jeopardize the free-trade environment. Therefore, the US needs to reaffirm its stance and continue to protest China\u2019s violation of the concept of Internet freedom. This work should be done together with US business groups and with other governments that\u00a0hold same values as the US.<\/p>\n<p>Meanwhile, the US needs to make clear to the Chinese government that undermining free-trade and free flow of information will cause more harm to China than any theoretical\u00a0security gains under the new law. <a href=\"http:\/\/www.wsj.com\/articles\/u-s-business-groups-ask-china-to-postpone-new-cybersecurity-review-1422498245\">US businesses have already written a letter asking the Chinese government to reconsider elements of the cybersecurity law that would create discriminatory cybersecurity policy, isolate Chinese companies, and worsen cybersecurity issues.<\/a><\/p>\n<p>The U.S. should maintain its rhetoric of internet freedom, which is undermined by the new Chinese cyber law, and continue to protest any Chinese move that signals possible protectionism against foreign tech firms. It is necessary to emphasize the importance of a free market environment and the flow of information.<\/p>\n<h2>Recommendation 4<\/h2>\n<p>Apart from rhetorical protests, the US should prepare for imposing economic sanctions upon China and bringing the issue to the WTO. These measures have been effective in dealing with China in some of cases. For example, prior to President Xi\u2019s visit to the US for cybersecurity talks in September 2015, <a href=\"https:\/\/www.washingtonpost.com\/world\/national-security\/administration-developing-sanctions-against-china-over-cyberespionage\/2015\/08\/30\/9b2910aa-480b-11e5-8ab4-c73967a143d3_story.html\">the Obama administration was developing a package of unprecedented economic sanctions against Chinese companies and individuals that had benefitted from the government backed economic espionage.<\/a>\u00a0The sanctions attempt underlines the US government&#8217;s severe frustration over Chinese espionage activities.<\/p>\n<p>Although there is no direct evidence that the intent to impose sanctions led to the agreement, the timing of the two events makes it is reasonable to believe that the threat of sanctions provided positive results and facilitated the agreement. In another case,\u00a0China suspended its banking regulations in the IT sector in April 2015. Since the approval of regulations in January, <a href=\"http:\/\/www.wsj.com\/articles\/u-s-business-groups-ask-china-to-postpone-new-cybersecurity-review-1422498245\">US business groups and the US government had expressed their oppositions by directly writing letters to Chinese cybersecurity officials.<\/a>\u00a0The US&#8217;s vocalization of the criticism that the banking rules violated China\u2019s trade obligations and <a href=\"http:\/\/www.wsj.com\/articles\/china-halts-implementation-of-banking-tech-guidelines-1429181094\">communications send to the WTO questioning the Chinese bank rules succeeded in finally pressuring China to halt the regulations.<\/a>\u00a0Therefore, given the declining of Chinese economy, the Chinese government will be more cautious at making cybersecurity decisions when facing potential economic consequences.<\/p>\n<p>The U.S. should consider implementing various measures to press the Chinese government to not discriminate foreign tech companies and uphold a free-trade environment. Such measures include bringing the case to a multilateral organization for judgement and imposing economic sanctions. Despite the interdependency of US and Chinese economies, showing gestures of imposing the sanctions on targeted Chinese individuals and companies has proven effective in the past.\u00a0However, economic sanctions could lead to retaliation and should only be a\u00a0last resort.<\/p>\n<h2>Endnotes<\/h2>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a> Jon R. Lindsay and Tai Ming Cheung, From Exploitation to Innovation: Acquisition, Absorption and Application\u201d table 3.1.<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">[2]<\/a> P.W. Singer and Allan Friedman,\u00a0<em>Cybersecurity and Cyberwar: What Everyone Needs to Know<\/em>\u00a0(New York: Oxford University Press, 2014): 95.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This post is part of\u00a0a series making cybersecurity strategy recommendations for the new Trump Administration.\u00a0US-Russia relations,\u00a0US-Mexico relations,\u00a0US-India relations,\u00a0US-Turkey relations,\u00a0US-South Korea relations,\u00a0US-Japan relations,\u00a0US-ASEAN relations,\u00a0US-Cuban relations,\u00a0US-Brazil relations,\u00a0US-Cameroon relations,\u00a0US-EU relations, and US-Myanmar relations were the topics of previous pieces. In recent years, cyber-espionage has become a pivotal issue in US-China cybersecurity relations. Cyber-espionage related tension is not necessarily<\/p>\n<div><a class=\"more\" href=\"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/\">Read more<\/a><\/div>\n","protected":false},"author":506,"featured_media":1664,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9],"tags":[],"class_list":["post-1610","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","region-china"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Cybersecurity Strategy Advice for the Trump Administration: US-China Relations - East Asia Center<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cybersecurity Strategy Advice for the Trump Administration: US-China Relations - East Asia Center\" \/>\n<meta property=\"og:description\" content=\"This post is part of\u00a0a series making cybersecurity strategy recommendations for the new Trump Administration.\u00a0US-Russia relations,\u00a0US-Mexico relations,\u00a0US-India relations,\u00a0US-Turkey relations,\u00a0US-South Korea relations,\u00a0US-Japan relations,\u00a0US-ASEAN relations,\u00a0US-Cuban relations,\u00a0US-Brazil relations,\u00a0US-Cameroon relations,\u00a0US-EU relations, and US-Myanmar relations were the topics of previous pieces. In recent years, cyber-espionage has become a pivotal issue in US-China cybersecurity relations. Cyber-espionage related tension is not necessarily\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/\" \/>\n<meta property=\"og:site_name\" content=\"East Asia Center\" \/>\n<meta property=\"article:published_time\" content=\"2017-05-22T19:00:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2017-09-12T18:17:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/jsis.washington.edu\/eacenter\/wp-content\/uploads\/sites\/9\/2017\/05\/china-cyberlaw-ap_16312221997516.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"720\" \/>\n\t<meta property=\"og:image:height\" content=\"480\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"jgdarn\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"jgdarn\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/\",\"url\":\"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/\",\"name\":\"Cybersecurity Strategy Advice for the Trump Administration: US-China Relations - East Asia Center\",\"isPartOf\":{\"@id\":\"https:\/\/jsis.washington.edu\/eacenter\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jsis.washington.edu\/eacenter\/wp-content\/uploads\/sites\/9\/2017\/05\/china-cyberlaw-ap_16312221997516.jpg\",\"datePublished\":\"2017-05-22T19:00:50+00:00\",\"dateModified\":\"2017-09-12T18:17:42+00:00\",\"author\":{\"@id\":\"https:\/\/jsis.washington.edu\/eacenter\/#\/schema\/person\/1775f4a67ddf36101f67482eb59eb797\"},\"breadcrumb\":{\"@id\":\"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/#primaryimage\",\"url\":\"https:\/\/jsis.washington.edu\/eacenter\/wp-content\/uploads\/sites\/9\/2017\/05\/china-cyberlaw-ap_16312221997516.jpg\",\"contentUrl\":\"https:\/\/jsis.washington.edu\/eacenter\/wp-content\/uploads\/sites\/9\/2017\/05\/china-cyberlaw-ap_16312221997516.jpg\",\"width\":720,\"height\":480,\"caption\":\"FILE - In this Aug. 16, 2016 file photo, a worker is silhouetted against a computer display showing a live visualization of the online phishing and fraudulent phone calls across China during the 4th China Internet Security Conference (ISC) in Beijing. China's legislature has approved a cybersecurity law on Monday, Nov. 7, 2016 that human rights activists warn will tighten political controls and foreign companies say might isolate Chinese industries. (AP Photo\/Ng Han Guan, File)\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/jsis.washington.edu\/eacenter\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity Strategy Advice for the Trump Administration: US-China Relations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/jsis.washington.edu\/eacenter\/#website\",\"url\":\"https:\/\/jsis.washington.edu\/eacenter\/\",\"name\":\"East Asia Center\",\"description\":\"Just another The Henry M. Jackson School of International Studies Sites site\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/jsis.washington.edu\/eacenter\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/jsis.washington.edu\/eacenter\/#\/schema\/person\/1775f4a67ddf36101f67482eb59eb797\",\"name\":\"jgdarn\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jsis.washington.edu\/eacenter\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/7dcc19cb39ea8ce8535d6396dc965b6b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/7dcc19cb39ea8ce8535d6396dc965b6b?s=96&d=mm&r=g\",\"caption\":\"jgdarn\"},\"url\":\"https:\/\/jsis.washington.edu\/eacenter\/author\/jgdarn\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cybersecurity Strategy Advice for the Trump Administration: US-China Relations - East Asia Center","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/","og_locale":"en_US","og_type":"article","og_title":"Cybersecurity Strategy Advice for the Trump Administration: US-China Relations - East Asia Center","og_description":"This post is part of\u00a0a series making cybersecurity strategy recommendations for the new Trump Administration.\u00a0US-Russia relations,\u00a0US-Mexico relations,\u00a0US-India relations,\u00a0US-Turkey relations,\u00a0US-South Korea relations,\u00a0US-Japan relations,\u00a0US-ASEAN relations,\u00a0US-Cuban relations,\u00a0US-Brazil relations,\u00a0US-Cameroon relations,\u00a0US-EU relations, and US-Myanmar relations were the topics of previous pieces. In recent years, cyber-espionage has become a pivotal issue in US-China cybersecurity relations. Cyber-espionage related tension is not necessarily","og_url":"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/","og_site_name":"East Asia Center","article_published_time":"2017-05-22T19:00:50+00:00","article_modified_time":"2017-09-12T18:17:42+00:00","og_image":[{"width":720,"height":480,"url":"https:\/\/jsis.washington.edu\/eacenter\/wp-content\/uploads\/sites\/9\/2017\/05\/china-cyberlaw-ap_16312221997516.jpg","type":"image\/jpeg"}],"author":"jgdarn","twitter_card":"summary_large_image","twitter_misc":{"Written by":"jgdarn","Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/","url":"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/","name":"Cybersecurity Strategy Advice for the Trump Administration: US-China Relations - East Asia Center","isPartOf":{"@id":"https:\/\/jsis.washington.edu\/eacenter\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/#primaryimage"},"image":{"@id":"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/#primaryimage"},"thumbnailUrl":"https:\/\/jsis.washington.edu\/eacenter\/wp-content\/uploads\/sites\/9\/2017\/05\/china-cyberlaw-ap_16312221997516.jpg","datePublished":"2017-05-22T19:00:50+00:00","dateModified":"2017-09-12T18:17:42+00:00","author":{"@id":"https:\/\/jsis.washington.edu\/eacenter\/#\/schema\/person\/1775f4a67ddf36101f67482eb59eb797"},"breadcrumb":{"@id":"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/#primaryimage","url":"https:\/\/jsis.washington.edu\/eacenter\/wp-content\/uploads\/sites\/9\/2017\/05\/china-cyberlaw-ap_16312221997516.jpg","contentUrl":"https:\/\/jsis.washington.edu\/eacenter\/wp-content\/uploads\/sites\/9\/2017\/05\/china-cyberlaw-ap_16312221997516.jpg","width":720,"height":480,"caption":"FILE - In this Aug. 16, 2016 file photo, a worker is silhouetted against a computer display showing a live visualization of the online phishing and fraudulent phone calls across China during the 4th China Internet Security Conference (ISC) in Beijing. China's legislature has approved a cybersecurity law on Monday, Nov. 7, 2016 that human rights activists warn will tighten political controls and foreign companies say might isolate Chinese industries. (AP Photo\/Ng Han Guan, File)"},{"@type":"BreadcrumbList","@id":"https:\/\/jsis.washington.edu\/eacenter\/2017\/05\/22\/cybersecurity-strategy-advice-trump-administration-us-china-relations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/jsis.washington.edu\/eacenter\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity Strategy Advice for the Trump Administration: US-China Relations"}]},{"@type":"WebSite","@id":"https:\/\/jsis.washington.edu\/eacenter\/#website","url":"https:\/\/jsis.washington.edu\/eacenter\/","name":"East Asia Center","description":"Just another The Henry M. Jackson School of International Studies Sites site","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/jsis.washington.edu\/eacenter\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/jsis.washington.edu\/eacenter\/#\/schema\/person\/1775f4a67ddf36101f67482eb59eb797","name":"jgdarn","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jsis.washington.edu\/eacenter\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/7dcc19cb39ea8ce8535d6396dc965b6b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7dcc19cb39ea8ce8535d6396dc965b6b?s=96&d=mm&r=g","caption":"jgdarn"},"url":"https:\/\/jsis.washington.edu\/eacenter\/author\/jgdarn\/"}]}},"_links":{"self":[{"href":"https:\/\/jsis.washington.edu\/eacenter\/wp-json\/wp\/v2\/posts\/1610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jsis.washington.edu\/eacenter\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jsis.washington.edu\/eacenter\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jsis.washington.edu\/eacenter\/wp-json\/wp\/v2\/users\/506"}],"replies":[{"embeddable":true,"href":"https:\/\/jsis.washington.edu\/eacenter\/wp-json\/wp\/v2\/comments?post=1610"}],"version-history":[{"count":0,"href":"https:\/\/jsis.washington.edu\/eacenter\/wp-json\/wp\/v2\/posts\/1610\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jsis.washington.edu\/eacenter\/wp-json\/wp\/v2\/media\/1664"}],"wp:attachment":[{"href":"https:\/\/jsis.washington.edu\/eacenter\/wp-json\/wp\/v2\/media?parent=1610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jsis.washington.edu\/eacenter\/wp-json\/wp\/v2\/categories?post=1610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jsis.washington.edu\/eacenter\/wp-json\/wp\/v2\/tags?post=1610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}