Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
information security management assurance control information security management assurance control class information systems security management assurance information security management assurance capability management assurance control class – management domestic waste treatment axial constant amplitude scopethis method acacia tannin extract
GB/T 20274.3-2008 in English

GB/T 20274.3-2008 in English

VALID

Information security technology Evaluation framework for information systems security assurance Part 3: Management assurance

  • Issued on:2008-07-18
  • Implemented on:2008-12-01
  • File Format:PDF
  • Delivery:Via email within 1~3 business days
Price(USD): $140.00
$136.00
Standard No: GB/T 20274.3-2008
Document status: VALID
Superseded by: GB/T 20274.2-2026 Cybersecurity technology—Evaluation framework for information systems security assurance—Part 2: Security assurance requirements
Superseded on: 2026-12-01
Title in English: Information security technology Evaluation framework for information systems security assurance Part 3: Management assurance
Title in Chinese: 信息安全技术 信息系统安全保障评估框架 第3部分:管理保障
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 1~3 business days
Issued on: 2008-07-18
Implemented on: 2008-12-01
ICS Classification: 35.040-Character sets and information coding
Chinese Classification: L80-Data encryption
Professional Classification: GB-National Standard
Related Keywords: information security management assurance control
information security management assurance control class
information systems security management assurance
information security management assurance capability
management assurance control class – management
Related Topics: security
Information Technology Software Security Assurance
Assure
Security System Railway
assessment framework
Railway Security System
assessment framework
Environmental protection 3 tubes 3 must tubes
Information Security Planning
Technical Support Section
Value Guarantee
GB/T 20274.3
GB/T 20274.3-2008
Information security technology machine learning algorithm security assessment
information security standards
Information Technology Software Security Assurance
information security
Information system annual failure rate international
Information Security Test Score

《GB/T 20274.3-2008信息安全技术 信息系统安全保障评估框架 第3部分:管理保障》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
GB/T20274《信息系统安全保障评估框架》分为以下四个部分,本部分是GB/T20274的第3部分。GB/T20274的本部分建立了信息系统安全管理保障的框架,确立了组织机构内启动、实施、维护、
评估和改进信息安全管理的指南和通用原则。本部分定义和说明了信息系统安全管理保障中反映组织机构信息安全管理保障能力的安全管理能力级,以及提供组织机构信息安全管理保障内容的管理保障控制类要求。
本部分适用于涉及信息系统安全管理工作的组织机构的所有用户、开发者和评估者。


1 Scope

This part of GB/T 20274 establishes the framework for information systems security management assurance and the guideline & general principle for the organization starting, implementing, maintaining, evaluating and improving information security management. This part defines and explains the security management capability level that reflects the information security management assurance capability of the organization in the information system security management assurance work and provides the security management assurance control class requirements of the organization's information security management assurance contents.
This part is applicable to all of the organization’s users, developers and evaluation personnel involved in the information system security management.

2 Normative References

The following documents contain provisions which, through reference in this text, constitute provisions of this part. For dated reference, subsequent amendments to (excluding any corrigendum), or revisions of, any of these publications do not apply. However, parties to agreements based on this standard are encouraged to investigate the possibility of applying the most recent editions of the standards indicated below. For any undated references, the latest edition of the document referred to applies.
GB/T 20274.1 Information Security Technology - Evaluation Framework for Information Systems Security Assurance - Part 1: Introduction and General Model

3 Terms and Definitions

For the purposes of this part of GB/T 20274, the terms and definitions specified in GB/T 20274.1 and the following ones apply.
3.1
Control
The methods to manage risks include policy, procedure, guide, practice or the structure of the organization and control may be management, technology or engineering control.
Note 1: "control" is synonymous with "control measures" and "protective measures".
Note 2: in this part, the control of management methods for managing risks will be mainly discussed, i.e. management control.
3.2
Information processing facility
Information processing facility refers to all services or infrastructure or the physical location to place them.

4 Structure of This Part

The organization structure of this part of GB/T 20274 is as follows:
a) Chapter 1 introduces the range of this part;
b) Chapter 2 introduces the normative references of this part;
c) Chapter 3 describes the terms and definitions applicable to this part;
d) Chapter 4 describes the organization structure of this part;
e) Chapter 5 describes the framework for information systems security management assurance and further summarizes the control class and capability level of management assurance.

Foreword i
1 Scope
2 Normative References
3 Terms and Definitions
4 Structure of This Part
5 Framework for Information Systems Security Management Assurance
5.1 Overview of Information Management Assurance
5.2 Information Security Management Assurance Control
5.3 Information Security Assurance Management Capability Levels
6 Structure of Information Security Management Assurance Control Class
6.1 General
6.2 Structure of Management Assurance Control Class
6.3 Structure of Management Assurance Control Subclass
6.4 Structure of Management Assurance Control Component
6.5 Allowable Operation
7 MRM Management Assurance Control Class: Management of Risk
7.1 Object Establishment (MRM_TEM)
7.2 Risk Assessment (MRM_RAM)
7.3 Risk Control (MRM_RCT)
7.4 Communication and Monitoring (MRM_CAM)
8 MSP Management Assurance Control Class: Information Security Policy
8.1 Information Security Policy (MSP_SPL)
9 MSO Management Assurance Control Class: Information Security Organization
9.1 Management Support of Information Security (MSO_SOM)
9.2 Information Security Organization Structure (MSO_ORG)
9.3 Responsibility of Information Security (MSO_RES)
9.4 Communication and Cooperation (MSO_CAC)
10 MSP Management Assurance Control Class: Management of Personal Security
10.1 Personal Examination (MPS_PEC)
10.2 Security Awareness and Training (MPS_SAT)
10.3 Examination and Reward & Punishment (MPS_CRP)
10.4 Management of Personnel Change (MPS_PCM)
11 MAM Management Assurance Control Class: Management of Asset
11.1 Asset Register Management (MAM_ARM)
11.2 Asset Management Responsibility (MAM_AMR)
11.3 Asset Classification Management (MAM_ACM)
12 MPE Management Assurance Control Class: Management of Physical and Environmental Security
12.1 Management of Physical Security Area (MPE_PSA)
12.2 Supporting Infrastructure Security (MPE_SIS)
12.3 Equipment Security (MPE_EMS)
13 MCM Management Assurance Control Class: Management of Compliance
14 MSP Management Assurance Control Class: Management of Information Security Planning
15 MSD Management Assurance Control Class: Management of System Development
16 MOP Management Assurance Control Class: Management of Operation
17 MBD Management Assurance Control Class: Management of Business Continuity and Disaster Recovery
17.1 Business Continuity Management (MBD_BCM)
18 MCM Management Assurance Control Class: Management of Emergency Response
18.1 Report Security Event and Security Vulnerability (MER_REW)
18.2 Management of Emergency Response (MER_IMI)
19 Description of Security Management Capability Levels
19.1 General
19.2 Description of Security Management Capability Levels
19.3 Application of Information System Security Assurance Management Capability Levels
Bibliography
Figure 1 Information System Security Management Assurance Control Class
Figure 2 Structure of Management Assurance Control Class
Figure 3 Structure of Management Assurance Control Subclass
Figure 4 Structure of Management Assurance Control Component
Figure 5 Structure of Management Assurance Control Class - Management of Risk (MRM)
Figure 6 Structure of Management Assurance Control Class - Information Security Policy (MSP)
Figure 7 Structure of Management Assurance Control Class - Information Security Organization (MSO).
Figure 8 Structure of Management Assurance Control Class – Management of Personal Security (MPS)
Figure 9 Structure of Management Assurance Control Class - Management of Asset (MAM)
Figure 10 Structure of Management Assurance Control Class - Management of Physical and Environmental Security (MPE)
Figure 11 Structure of Management Assurance Control Class - Management of Compliance (MCM)
Figure 12 Structure of Management Assurance Control Class - Management of Information Security Planning (MSP)
Figure 13 Structure of Management Assurance Control Class - Management of System Development (MSD)
Figure 14 Structure of Management Assurance Control Class - Management of Operation (MOP)
Figure 15 Structure of Management Assurance Control Class - Management of Business Continuity and Disaster Recovery (MBD)
Figure 16 Structure of Management Assurance Control Class - Management of Emergency Response (MER)
Figure 17 Example of the Required Levels of Information System Security Assurance Management Capability

Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend

  • GB/T 28449-2018 in English

    GB/T 28449-2018 in English

    Information security technology-Testing and evaluation process guide for classified protection of cybersecurity

    2018-12-28
  • GB/T 45240-2025 in English

    GB/T 45240-2025 in English

    General requirements for device-independent quantum random number generators

    2025-01-24
  • GB/T 39276-2020 in English

    GB/T 39276-2020 in English

    Information security technology—General security requirements of network products and services

    2020-11-19
  • GB/T 24363-2009 in English

    GB/T 24363-2009 in English

    Information security technology—Specifications of emergency response plan for information security

    2009-09-30
  • GB/Z 24294.1-2018 in English

    GB/Z 24294.1-2018 in English

    Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General

    2018-03-15
  • GB/T 33746.2-2017 in English

    GB/T 33746.2-2017 in English

    Technical specification of NFC security--Part 2: Security mechanism requirements

    2017-09-07
  • GB/T 27422-2019 in English

    GB/T 27422-2019 in English

    Conformity assessment -- Requirements for bodies providing audit and certification of business continuity management systems

    2019-12-10
  • GB/T 15278-1994 in English

    GB/T 15278-1994 in English

    Information processing-Data encipherment-Physical layer interoperability requirements

    1994-01-02
  • GB/T 20009-2019 in English

    GB/T 20009-2019 in English

    Information security technology—Security evaluation criteria for database management system

    2019-08-30