Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
security database management system database management system a.4 security database management system a.3 user management database management system ssodb security management defatted raw milk energy transmission medium chian era documents
GB/T 20273-2006 in English

GB/T 20273-2006 in English

SUPERSEDED

Information security technology Security techniques requirement for database management system

  • Issued on:2006-05-31
  • Implemented on:2006-12-01
  • File Format:PDF
  • Delivery:Via email within 1~3 business days
Price(USD): $140.00
$136.00
Standard No: GB/T 20273-2006
Document status: SUPERSEDED
Superseded by: GB/T 20273-2019 Information security technology—Security technical requirements for database management system
Superseded on: 2020-03-01
Title in English: Information security technology Security techniques requirement for database management system
Title in Chinese: 信息安全技术 数据库管理系统安全技术要求
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 1~3 business days
Issued on: 2006-05-31
Implemented on: 2006-12-01
ICS Classification: 35.040-Character sets and information coding
Chinese Classification: L80-Data encryption
Professional Classification: GB-National Standard
Related Keywords: security database management system
database management system a.4 security
database management system a.3 user management
database management system
ssodb security management
Related Topics: database
laboratory security data security
System Security Technology
Technical Data English
Food Information Database
Technical parameter system
How to manage the database
database management system
Safety technical requirements for pipe benders
GBT20273
GB/T 20273-2006
GB/T 20273-2019
Safety Technical Requirements for Automobile Data Processing
Information Security Technology Information System Physical Security Technical Requirements
System Security Technical Requirements
Public security internal affairs management system database structure
Casting safety factor
Safety technical requirements for the use of sulfuric acid
gb/t 20273 2019
gb/t 20273
gb/t 20273-

《GB/T 20273-2006信息安全技术 数据库管理系统安全技术要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
本标准规定了各个安全等级的数据库管理系统所需要的安全技术要求。本标准适用于按等级化要求进行的安全数据库管理系统的设计和实现。


1 Scope

This standard specifies the security techniques requirement required for database management system of each security grade according to the classification of five security protection grades in GB 17859-1999 and the role of database management system in information system.
This standard is applicable to the design and realization of security database management system according to the requirements of hierarchization and the test and management of the security of database management system may refer to this standard.

2 Normative References

The following standards contain provisions which, through reference in this standard, constitute provisions of this standard. For dated reference, subsequent amendments to (excluding correction to), or revisions of, any of these publications do not apply. However, the parties to agreements based on this standard are encouraged to investigate the possibility of applying the most recent editions of the standards. For undated references, the latest edition of the normative document referred to applies.
GB 17859-1999 Classified Criteria for Security Protection of Computer Information System
GB/T 20271-2006 Information Security Technology - Common Security Techniques Requirement for Information System

3 Terms, Definitions and Abbreviations

3.1 Terms and Definitions
For the purposes of this standard, the terms and definitions defined in GB 17859-1999 and GB/T 20271-2006 and those listed below apply.
3.1.1
Security of database management system
Characterization of the confidentiality, integrity and availability of the stored, transported and processed information in database management system.
3.1.2
Security technology of database management system
All security technologies required for realizing the security of all kinds of database management systems.
3.1.3
Security subsystem of database management system
A generic term for security protection devices in database management, including hardware, firmware, software and combined entity responsible for executing security policy. It establishes a basic security protection environment of database management system and provides additional user service required by security database management system.
Note: SSODB (security subsystem of database management system) is TCB of database management system according to the definition of TCB (trusted computing base) in GB 17859-1999.
3.1.4
SSODB security policy
A group of rules to manage, protect and distribute SSODB resource. One SSODB may have one or more security policies.
3.1.5
Security function policy
Security policy adopted to realize the function required for SSODB security element.

Foreword I
Introduction I
1 Scope
2 Normative References
3 Terms, Definitions and Abbreviations
3.1 Terms and Definitions
3.2 Abbreviations
4 Basic Requirements for Security Function of Database Management System
4.1 Identity Authentication
4.1.1 User Identification
4.1.2 User Authentication
4.2 Discretionary Access Control
4.2.1 Access Operation
4.2.2 Access Rule
4.2.3 Authorization Propagation Restriction
4.3 Label
4.3.1 Subject Label
4.3.2 Object Label
4.4 Mandatory Access Control
4.4.1 Security Policy of Access Control
4.4.2 Granularity and Characteristic of Access Control
4.5 Data Flow Control
4.6 Security Audit
4.7 User Data Integrity
4.7.1 Body Integrity and Reference Integrity
4.7.2 User Defined Integrity
4.7.3 Integrity of Data Manipulation
4.8 User Data Confidentiality
4.8.1 Stored Data Confidentiality
4.8.2 Transported Data Confidentiality
4.8.3 Object Reuse
4.9 Trusted Path
4.10 Inference Control
5 Graded Requirements for Security Technology of Database Management System
5.1 Grade 1: the User's Discretionary Protection Grade
5.1.1 Security Function
5.1.2 SSODB Self-security Protection
5.1.3 SSODB Design and Realization
5.1.4 SSODB Security Management
5.2 Grade 2: System Audit Protection Grade
5.2.1 Security Function
5.2.2 SSODB Self-security Protection
5.2.3 SSODB Design and Realization
5.2.4 SSODB Security Management
5.3 Grade 3: Security Label Protection Grade
5.3.1 Security function
5.3.2 SSODB Self-security Protection
5.3.3 SSODB Design and Realization
5.3.4 SSODB Security Management
5.4 Grade 4: Structured Protection Grade
5.4.1 Security Function
5.4.2 SSODB Self-security Protection
5.4.3 SSODB Design and Realization
5.4.4 SSODB Security Management Requirements
5.5 Grade 5: Access Verification Protection Grade
5.5.1 Security Function
5.5.2 SSODB Self-security Protection
5.5.3 SSODB Design and Realization
5.5.4 SSODB Security Management
Appendix A (Informative) Explanation of Standard Concept
A.1 Composition and Interrelationship
A.2 Special Requirements for Security of Database Management System
A.3 User Management of Database Management System
A.4 Security of Database Management System
A.5 Classification of Security Protection Grade of Database Management System
A.6 About the Subject and Object of Database Management System
A.7 About SSODB, SSF, SSP, SFP and their Interrelationship
A.8 About Inference Control
A.9 About Encryption Technology and Database Encryption
Bibliography

Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend

  • GB/T 45240-2025 in English

    GB/T 45240-2025 in English

    General requirements for device-independent quantum random number generators

    2025-01-24
  • GB/Z 28828-2012 in English

    GB/Z 28828-2012 in English

    Information security technology - Guideline for personal information protection within information system for public and commercial services

    2012-11-05
  • GB/T 17901.1-2020 in English

    GB/T 17901.1-2020 in English

    Information technology—Security techniques—Key management—Part 1: Framework

    2020-03-06
  • GB/T 27422-2019 in English

    GB/T 27422-2019 in English

    Conformity assessment -- Requirements for bodies providing audit and certification of business continuity management systems

    2019-12-10
  • GB/T 22186-2016 in English

    GB/T 22186-2016 in English

    Information security techniques―Security technical requirements for IC card chip with CPU

    2016-08-29
  • GB/T 37931-2019 in English

    GB/T 37931-2019 in English

    Information security technology—Security technology requirements and testing and evaluation approaches for Web application security detection system

    2019-08-30
  • GB/Z 24294.1-2018 in English

    GB/Z 24294.1-2018 in English

    Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General

    2018-03-15
  • GB/T 29828-2013 in English

    GB/T 29828-2013 in English

    Information security technology―Trusted computing specification―Trusted connect architecture

    2013-11-12
  • GB/T 24363-2009 in English

    GB/T 24363-2009 in English

    Information security technology—Specifications of emergency response plan for information security

    2009-09-30
  • GB/T 41266-2022 in English

    GB/T 41266-2022 in English

    Security testing methods for critical network devices—Switch

    2022-03-09