Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
vulnerability classification system classification dimensions technical classification comprehensive classification three-dimensional classification system tree-shaped classification framework palladium alloy tube ultrasonic doppler fetal heart rate monitor optimize accessories technical requirement
GB/T 30279-2020 in English

GB/T 30279-2020 in English

VALID

Information security technology—Guidelines for categorization and classification of cybersecurity vulnerability

  • Issued on:2020-11-19
  • Implemented on:2021-06-01
  • File Format:PDF
  • Delivery:Via email within 5 business days
Price(USD): $340.00
$330.00
Standard No: GB/T 30279-2020
Document status: VALID
Title in English: Information security technology—Guidelines for categorization and classification of cybersecurity vulnerability
Title in Chinese: 信息安全技术 网络安全漏洞分类分级指南
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 5 business days
Issued on: 2020-11-19
Implemented on: 2021-06-01
Superseding: GB/T 30279-2013 Information Security Technology - Vulnerability Classification Guide
GB/T 33561-2017 Information security technology -- Vulnerabilities classification
ICS Classification: 35.040-Character sets and information coding
Chinese Classification: L80-Data encryption
Professional Classification: GB-National Standard
Related Keywords: vulnerability classification system classification dimensions
technical classification
comprehensive classification
three-dimensional classification system
tree-shaped classification framework
Related Topics: loophole
GB/T 30279-2013
GB/T+30279-2013
GB/T 30279
GB/T 30279-2013
gb/t+30279
Guidelines for Classifying Security Vulnerabilities
Information Security Technology Network Security Monitoring Basic Requirements and Implementation Guidelines
GB/T30279-2013
Information Security Technology Security Vulnerability Classification Guide
Information Security Technology Security Vulnerability Classification Guide
GBT30279
GB/T 30279-2013
GB/T 30279-2020
Network Security Vulnerability Management
GB/T 20986-2023 Information Security Technology Network Security Incident Classification and Grading Guidelines
GB/T 30279-2020
GB/T 30279-2020 Download
information security standards
Classification of network security incidents
information security
gb/t30279-2020

《GB/T 30279-2020信息安全技术 网络安全漏洞分类分级指南》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。


Introduction

Interpretation of the core content of the standard

GB/T 30279-2020 integrates the technical requirements of the original two standards and constructs a tree-shaped classification framework and a three-dimensional classification system. The standard innovatively separates technical classification from comprehensive classification, where technical classification focuses on the inherent attributes of vulnerabilities, and comprehensive classification considers the impact of environmental factors.


Analysis of Vulnerability Classification System

Classification Dimensions 2013/2017 Edition 2020 New Edition Technological Evolution
Framework Structure Linear Classification Tree Topology Support Multi-Level Refinement
Cause Classification Independent Chapter Integrated into 5 Major Categories New Environmental Issues Category
Typical Subcategories 23 subcategories 32 subcategories Specify new vulnerabilities such as Side channel attacks

Detailed explanation of the grading indicator system

Technical grading indicators

  • Exploitability indicators: including access path (network/adjacent/local/physical), trigger requirements (low/high), permission requirements (none/low/high), and interaction conditions (necessary/unnecessary)
  • Impact degree indicators: evaluated from the three dimensions of confidentiality, integrity, and availability, with values including severe, general, and none

New indicators for comprehensive grading

  • Environmental factor indicators: include three dimensions: exploit cost (low/medium/high), repair difficulty (high/medium/low), and impact scope (high/medium/low/none)

Implementation suggestions

  1. Product development stage: it is recommended to prioritize the repair of code problem vulnerabilities with a technical rating ≥ high risk
  2. Vulnerability management process: a 4-hour emergency response mechanism should be established for comprehensive graded ultra-critical vulnerabilities
  3. Risk assessment: it is recommended to combine the "impact scope" indicator of environmental factors with asset importance for weighted calculation

Application value of the standard

This standard realizes the decoupled assessment of vulnerability technical attributes and environmental attributes for the first time, and is particularly suitable for:

  • Enterprises build a vulnerability priority repair (VPT) system
  • Cloud service providers formulate SLA vulnerability response clauses
  • Regulators establish industry vulnerability reporting standards

Sample only — not a preview of GB/T 30279-2020
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend

  • GB/T 45240-2025 in English

    GB/T 45240-2025 in English

    General requirements for device-independent quantum random number generators

    2025-01-24
  • GB/T 25056-2018 in English

    GB/T 25056-2018 in English

    Information security technology—Specifications of cryptograph and related security technology for certificate authentication system

    2018-06-07
  • GB/T 33131-2016 in English

    GB/T 33131-2016 in English

    Information security technology一Specification for IP storage network security based on IPSec

    2016-10-13
  • GB/T 32213-2015 in English

    GB/T 32213-2015 in English

    Information security technology―Public key infrastructure―Specification for remote password authentication and key establishment

    2015-12-10
  • GB/Z 24294.1-2018 in English

    GB/Z 24294.1-2018 in English

    Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General

    2018-03-15
  • GB/T 35273-2020 in English

    GB/T 35273-2020 in English

    Information security technology—Personal information security specification

    2020-03-06
  • GB/T 29767-2013 in English

    GB/T 29767-2013 in English

    Information security techniques—Public key infrastructure—Bridge Certification Authority leveled certificate specification

    2013-09-18
  • GB/T 15843.1-2017 in English

    GB/T 15843.1-2017 in English

    Information technology―Security techniques―Entity authentication―Part 1:General

    2017-12-29