GB/T 33132-2016 in English
VALIDInformation security technology―Guide of implementation for information security risk treatment
- Issued on:2016-10-13
- Implemented on:2017-05-01
- File Format:PDF
- Delivery:Via email within 5 business days
$359.00
《GB/T 33132-2016信息安全技术 信息安全风险处理实施指南》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Overview of the Information Security Risk Management Implementation Guide
| Dimensions | Content Overview | Standard Requirements |
|---|---|---|
| Risk Management Principles | Compliance, Effectiveness, Controllability, and Optimal Benefits | Ensure that measures comply with laws and regulations, effectively reduce risks, clarify resource requirements, and optimize cost-benefit ratio |
| Handling Methods | Reduce, avoid, transfer, accept | Choose or combine multiple methods for risk management according to different situations |
| Implementation Process | Preparation phase, implementation phase, evaluation phase | Full process management from plan formulation to program implementation and then to effect evaluation |
Case analysis of the actual application of risk management methods
Take a certain company as an example. In terms of risk management in data backup, they chose manual backup and regular testing. Although this method is low-cost, it has the problem of poor data real-time performance, and residual risks include the possibility of media damage and data leakage.
Explanation of professional terms and practical application
Risk Reduction: Reduce the impact of threats through technical means. For example, adopt identity authentication measures to resist counterfeiting.
Risk Transfer: Transfer risk responsibility to a third party. For example, purchase insurance for expensive equipment.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 27422-2019 in English
Conformity assessment -- Requirements for bodies providing audit and certification of business continuity management systems
2019-12-10 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 29241-2012 in English
Information security technology—Public key infrastructure—PKI interoperability evaluation criteria
2012-12-31 -

GB/T 32213-2015 in English
Information security technology―Public key infrastructure―Specification for remote password authentication and key establishment
2015-12-10 -

GB/T 28449-2018 in English
Information security technology-Testing and evaluation process guide for classified protection of cybersecurity
2018-12-28 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 41266-2022 in English
Security testing methods for critical network devices—Switch
2022-03-09 -

GB/T 32905-2016 in English
Information security technology SM3 cryptographic hash algorithm
2016-08-29 -

GB/T 15843.1-2017 in English
Information technology―Security techniques―Entity authentication―Part 1:General
2017-12-29