GA/T 1389-2017 in English
VALIDInformation security technology—Guidelines for grading of classified protection of cyber security
- Issued on:2017-05-08
- Implemented on:2017-05-08
- File Format:PDF
- Delivery:Via email within 1~3 business days
$175.00
Introduction
Analysis of the Standard Core Framework
| Protection Level | Object of Infringement | Degree of Infringement | Typical Scenarios |
|---|---|---|---|
| First Level | Rights of Citizens/Organizations | General Damage | Non-core Systems such as Corporate Websites |
| Second Level | Social Public Interests | Serious Damage | Urban Traffic Dispatching System |
| Third Level | National Security | Extremely Serious Damage | Provincial Government Cloud Platform |
Analysis of Key Technical Elements
Cloud Computing Platform Classification Specifications
Cloud service providers' cloud computing platforms must be independently classified, and tenant systems must be individually classified based on their business attributes. Large cloud platforms must be divided by service domain, and the platform classification must not be lower than the highest classification of the hosting system.
Special Requirements for Industrial Control Systems
The field device layer, control layer, and monitoring layer should be classified as a whole. The production management layer can refer to Section 5.2.5. A typical case study of a DCS system in the petrochemical industry shows that control interruptions can result in direct economic losses of tens of millions of yuan per day.
Implementation Recommendations
- Identification of Classification Objects: Must meet three characteristics (clear responsible parties, independent business operations, and system elements)
- Matrix Comparison Method: Simultaneously evaluate the two dimensions of business information security and system service security
- Key Points for Expert Review: Systems above Level 2 require cross-disciplinary expert review, and Level 4 systems must be reported to the National Special Committee
Analysis of Standard Evolution
Compared to Document No. 43 of 2007, this standard adds classification specifications for new systems such as the Internet of Things and Mobile Internet, and clarifies that big data is generally classified as Level 3 or above, reflecting the high regard for data sovereignty.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GA/T 1390.3-2017 in English
Information security technology—General requirements for classified protection of cyber security—Part 3:Special security requirements for mobile interconnection
2017-05-08 -

GA/T 1390.2-2017 in English
Information security technology—General requirements for classified protection of cyber security—Part 2:Special security requirements for cloud computing
2017-05-08