GB/T 24364-2023 in English
VALIDInformation security technology—Implementation guide for information security risk management
- Issued on:2023-05-23
- Implemented on:2023-12-01
- File Format:PDF
- Delivery:Via email within 5 business days
$728.00
《GB/T 24364-2023信息安全技术 信息安全风险管理实施指南》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准委。
Introduction
Standard Evolution and Core Changes
This standard replaces GB/Z24364-2009. The main technical upgrades include:
- The risk management object is expanded from information system to ubiquitous risk subject
- New structural contents such as management framework and guarantee mechanism
- Reconstruct the risk management process into 6 modules (originally 4 stages)
Risk Management Implementation Framework
| Components | Core Requirements | Implementation Points |
|---|---|---|
| Management Principles | Graded/comprehensive/dynamic/scientific | It is necessary to establish risk classification standards and dynamic adjustment mechanisms |
| Guarantee mechanism | 4 major mechanism systems | Focus on the implementation of major risk consultation and expert consultation mechanisms |
| Management capabilities | 8 core capabilities | Risk monitoring, early warning and information sharing capabilities need to be strengthened |
Key points for implementation of key processes
1. Establish context
Implement a three-stage workflow:
- Risk management preparation: The scope boundaries and overall plan need to be clarified
- Object investigation and analysis: Covering 5 dimensions such as business characteristics, laws and regulations
- Security Requirements Analysis: Risk assessment and acceptance criteria need to be formulated
Typical case: A financial institution determined that the RTO of the core system was ≤4 hours through business impact analysis
2. Risk Assessment
Implementation Points Comparison Table:
| Phase | Input | Output |
|---|---|---|
| Preparation Phase | Context Establishment Report | Assessment Plan |
| Element Identification | Asset/Threat/Vulnerability List | Assignment Matrix |
Note: Need to be used in conjunction with Vulnerability scanning tools and other technical means
Industry implementation recommendations
Financial industry
Focus on strengthening:
- Special management of supply chain risks
- Building APT attack monitoring capabilities
- Regulatory compliance risk management
Manufacturing
Pay attention to:
- Industrial control system vulnerability management
- Production data leakage risk
- Third-party operation and maintenance risk transfer
Document system management
Core documents required by the standard:
| Process | Required documents | Shelf life |
|---|---|---|
| Context establishment | Safety requirements analysis report | ≥3 years |
| Risk disposal | Cost-benefit analysis report | ≥5 years |
* Risk assessment report must strictly control the scope of knowledge

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 33133.2-2021 in English
Information security technology—ZUC stream cipher algorithm—Part 2:Confidentiality algorithm
2021-10-11 -

GB/T 25068.3-2022 in English
Information technology—Security techniques—Network security—Part 3: Threats, design techniques and control for network access scenarios
2022-10-12 -

GB/T 31167-2023 in English
Information security technology—Security guidance for cloud computing services
2023-05-23 -

GB/T 17902.1-2023 in English
Information technology―Security techniques―Digital signatures with appendix―Part 1:General
2023-03-17 -

GB/T 41387-2022 in English
Information security technology—Smart home general security specification
2022-04-15 -

GB/T 39204-2022 in English
Information security technology—Cybersecurity requirements for critical information infrastructure protection
2022-10-12 -

GB/T 28451-2023 in English
Information security technology—Technical specification for network intrusion prevention system
2023-05-23 -

GB/Z 41288-2022 in English
Information security technology—Guidelines of cyber security protection for important industrial control system
2022-03-08 -

GB/T 29246-2023 in English
Information security technology—Information security management systems—Overview and vocabulary
2023-12-28 -

GB/T 43435-2023 in English
Information security technology—Security requirements for software development kit (SDK) in mobile internet applications (App)
2023-11-27