Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
covered application protection firmware security program authenticity refined soft white sugar
GB/T 24364-2023 in English

GB/T 24364-2023 in English

VALID

Information security technology—Implementation guide for information security risk management

  • Issued on:2023-05-23
  • Implemented on:2023-12-01
  • File Format:PDF
  • Delivery:Via email within 5 business days
Price(USD): $750.00
$728.00
Standard No: GB/T 24364-2023
Document status: VALID
Title in English: Information security technology—Implementation guide for information security risk management
Title in Chinese: 信息安全技术 信息安全风险管理实施指南
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 5 business days
Issued on: 2023-05-23
Implemented on: 2023-12-01
Superseding: GB/Z 24364-2009 Information security technology—Guidelines for information security risk management
Chinese Classification: L80-Data encryption
Professional Classification: GB-National Standard
Related Topics: Security Risk
Safety Risk Substances
safety insurance
Next Generation Information Security
Information Security Technology Information Security Risk Assessment Implementation Guide
Information Security Technology Network Security Monitoring Basic Requirements and Implementation Guidelines
With the implementation of technical guidelines
Information Security Technology Information Security Risk Treatment Implementation Guide
Information Security Technology Industrial Control System Risk Assessment Implementation Guide
Practical rules for information technology and information security management
Information Technology Security Technical Information Security Incident Management Guidelines
Information Security Technology Information Security Risk Treatment Implementation Guide
Information Security Technology Information Security Risk Assessment Implementation Guide
"Information Technology - Practical Rules for Information Security Management" Industry Latest
information security standards
Technology risk index standardization method
Implementation Guidelines for Feed Quality and Safety Management Standards
Vehicle chip information security
information security
Encore information
Insurance information security risk assessment index system
gb/t 24364-2023
Wind measurement tower safety management specifications

《GB/T 24364-2023信息安全技术 信息安全风险管理实施指南》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准委。


Introduction

Standard Evolution and Core Changes

This standard replaces GB/Z24364-2009. The main technical upgrades include:

  • The risk management object is expanded from information system to ubiquitous risk subject
  • New structural contents such as management framework and guarantee mechanism
  • Reconstruct the risk management process into 6 modules (originally 4 stages)

Risk Management Implementation Framework

ComponentsCore RequirementsImplementation Points
Management Principles Graded/comprehensive/dynamic/scientific It is necessary to establish risk classification standards and dynamic adjustment mechanisms
Guarantee mechanism 4 major mechanism systems Focus on the implementation of major risk consultation and expert consultation mechanisms
Management capabilities 8 core capabilities Risk monitoring, early warning and information sharing capabilities need to be strengthened

Key points for implementation of key processes

1. Establish context

Implement a three-stage workflow:

  1. Risk management preparation: The scope boundaries and overall plan need to be clarified
  2. Object investigation and analysis: Covering 5 dimensions such as business characteristics, laws and regulations
  3. Security Requirements Analysis: Risk assessment and acceptance criteria need to be formulated

Typical case: A financial institution determined that the RTO of the core system was ≤4 hours through business impact analysis

2. Risk Assessment

Implementation Points Comparison Table:

Phase Input Output
Preparation Phase Context Establishment Report Assessment Plan
Element Identification Asset/Threat/Vulnerability List Assignment Matrix

Note: Need to be used in conjunction with Vulnerability scanning tools and other technical means


Industry implementation recommendations

Financial industry

Focus on strengthening:

  • Special management of supply chain risks
  • Building APT attack monitoring capabilities
  • Regulatory compliance risk management

Manufacturing

Pay attention to:

  • Industrial control system vulnerability management
  • Production data leakage risk
  • Third-party operation and maintenance risk transfer

Document system management

Core documents required by the standard:

ProcessRequired documentsShelf life
Context establishmentSafety requirements analysis report≥3 years
Risk disposalCost-benefit analysis report≥5 years

* Risk assessment report must strictly control the scope of knowledge

Sample only — not a preview of GB/T 24364-2023
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend

  • GB/T 33133.2-2021 in English

    GB/T 33133.2-2021 in English

    Information security technology—ZUC stream cipher algorithm—Part 2:Confidentiality algorithm

    2021-10-11
  • GB/T 25068.3-2022 in English

    GB/T 25068.3-2022 in English

    Information technology—Security techniques—Network security—Part 3: Threats, design techniques and control for network access scenarios

    2022-10-12
  • GB/T 31167-2023 in English

    GB/T 31167-2023 in English

    Information security technology—Security guidance for cloud computing services

    2023-05-23
  • GB/T 17902.1-2023 in English

    GB/T 17902.1-2023 in English

    Information technology―Security techniques―Digital signatures with appendix―Part 1:General

    2023-03-17
  • GB/T 41387-2022 in English

    GB/T 41387-2022 in English

    Information security technology—Smart home general security specification

    2022-04-15
  • GB/T 39204-2022 in English

    GB/T 39204-2022 in English

    Information security technology—Cybersecurity requirements for critical information infrastructure protection

    2022-10-12
  • GB/T 28451-2023 in English

    GB/T 28451-2023 in English

    Information security technology—Technical specification for network intrusion prevention system

    2023-05-23
  • GB/Z 41288-2022 in English

    GB/Z 41288-2022 in English

    Information security technology—Guidelines of cyber security protection for important industrial control system

    2022-03-08
  • GB/T 29246-2023 in English

    GB/T 29246-2023 in English

    Information security technology—Information security management systems—Overview and vocabulary

    2023-12-28
  • GB/T 43435-2023 in English

    GB/T 43435-2023 in English

    Information security technology—Security requirements for software development kit (SDK) in mobile internet applications (App)

    2023-11-27