GB/T 22240-2008 in English
SUPERSEDEDInformation security technology—Classification guide for classified protection of information systems security
- Issued on:2008-06-19
- Implemented on:2008-11-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$136.00
《GB/T 22240-2008信息安全技术 信息系统安全等级保护定级指南》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
依据国家信息安全等级保护管理规定制定本标准。本标准是信息安全等级保护相关系列标准之一。与本标准相关的系列标准包括:
―――GB/T22239―2008《信息系统安全等级保护基本要求》;
―――《GB/T 22240-2008信息系统安全等级保护实施指南》;
―――《GB/T 22240-2008信息系统安全等级保护测评准则》。 本标准规定了信息系统安全等级保护的定级方法,适用于为信息系统安全等级保护的定级工作提供指导。
1 Scope
This standard specifies the classification method for classified protection of information system security and is applicable to provide guidance for the classification work for classified protection of information system security.
2 Normative References
The following standards contain provisions which, through reference in this text, constitute provisions of this standard. For dated references, subsequent amendments (excluding corrections) to, or revisions, of any of these publications do not apply. However parties to agreements based on this standard are encouraged to investigate the possibility of applying the most recent editions of the normative documents indicated below. For undated references, the latest edition applies.
GB/T 5271.8 Information Technology - Vocabulary - Part 8: Security (GB/T 5271.8-2001; idt ISO/IEC 2382-8: 1998)
GB 17859 Classified Criteria for Security Protection of Computer Information System
3 Terminologies and Definitions
For the purposes of this standard, the terms and definitions given in GB/T 5271.8 and GB 17859 and the following apply.
3.1
Target of classified security
Specific information and information systems on which the classified protection work of information security directly acts.
3.2
Object
Social relations that are protected by law and that are infringed when the target of classified security is breached, such as national security, social order and public interests as well as legitimate rights and interests of citizens, legal persons or other organizations.
3.3
Objective
Objective external manifestations showing that the object is infringed, including the infringement way and the infringement result.
3.4
System service
Programmed process provided by the information system to support the businesses it bears.
Foreword i
Introduction ii
1 Scope
2 Normative References
3 Terminologies and Definitions
4 Classification Principle
4.1 Classified Protection of Information System Security
4.2 Classification Elements for Information System Security Protection Class
4.2.1 Infringed Objects
4.2.2 Degree of Infringement to Object
4.3 Relationship between Classification Element and Class
5 Classification Method
5.1 General Process of Classification
5.2 Determine the Object to Be Classified
5.3 Determination of Infringed Objects
5.4 Determination of Degree of Infringement to Objects
5.4.1 Objectives of Infringement
5.4.2 Comprehensive Judgment of Degree of Infringement
5.5 Determination of Security Protection Class of Objects to Be Classified
6 Class Change

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/T 36323-2018 in English
Information security technology--Security management fundamental requirements for industrial control systems
2018-06-07 -

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06