GB/T 30279-2020 in English
VALIDInformation security technology—Guidelines for categorization and classification of cybersecurity vulnerability
- Issued on:2020-11-19
- Implemented on:2021-06-01
- File Format:PDF
- Delivery:Via email within 5 business days
$330.00
《GB/T 30279-2020信息安全技术 网络安全漏洞分类分级指南》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Interpretation of the core content of the standard
GB/T 30279-2020 integrates the technical requirements of the original two standards and constructs a tree-shaped classification framework and a three-dimensional classification system. The standard innovatively separates technical classification from comprehensive classification, where technical classification focuses on the inherent attributes of vulnerabilities, and comprehensive classification considers the impact of environmental factors.
Analysis of Vulnerability Classification System
| Classification Dimensions | 2013/2017 Edition | 2020 New Edition | Technological Evolution |
|---|---|---|---|
| Framework Structure | Linear Classification | Tree Topology | Support Multi-Level Refinement |
| Cause Classification | Independent Chapter | Integrated into 5 Major Categories | New Environmental Issues Category |
| Typical Subcategories | 23 subcategories | 32 subcategories | Specify new vulnerabilities such as Side channel attacks |
Detailed explanation of the grading indicator system
Technical grading indicators
- Exploitability indicators: including access path (network/adjacent/local/physical), trigger requirements (low/high), permission requirements (none/low/high), and interaction conditions (necessary/unnecessary)
- Impact degree indicators: evaluated from the three dimensions of confidentiality, integrity, and availability, with values including severe, general, and none
New indicators for comprehensive grading
- Environmental factor indicators: include three dimensions: exploit cost (low/medium/high), repair difficulty (high/medium/low), and impact scope (high/medium/low/none)
Implementation suggestions
- Product development stage: it is recommended to prioritize the repair of code problem vulnerabilities with a technical rating ≥ high risk
- Vulnerability management process: a 4-hour emergency response mechanism should be established for comprehensive graded ultra-critical vulnerabilities
- Risk assessment: it is recommended to combine the "impact scope" indicator of environmental factors with asset importance for weighted calculation
Application value of the standard
This standard realizes the decoupled assessment of vulnerability technical attributes and environmental attributes for the first time, and is particularly suitable for:
- Enterprises build a vulnerability priority repair (VPT) system
- Cloud service providers formulate SLA vulnerability response clauses
- Regulators establish industry vulnerability reporting standards

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 25056-2018 in English
Information security technology—Specifications of cryptograph and related security technology for certificate authentication system
2018-06-07 -

GB/T 33131-2016 in English
Information security technology一Specification for IP storage network security based on IPSec
2016-10-13 -

GB/T 32213-2015 in English
Information security technology―Public key infrastructure―Specification for remote password authentication and key establishment
2015-12-10 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 35273-2020 in English
Information security technology—Personal information security specification
2020-03-06 -

GB/T 29767-2013 in English
Information security techniques—Public key infrastructure—Bridge Certification Authority leveled certificate specification
2013-09-18 -

GB/T 15843.1-2017 in English
Information technology―Security techniques―Entity authentication―Part 1:General
2017-12-29