GB/T 35280-2017 in English
ABOLISHEDInformation security technology―Requirement and code of conduct for security testing bodies of information technology products
- Issued on:2017-12-29
- Implemented on:2018-07-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$214.00
| Standard No: | GB/T 35280-2017 |
| Document status: | ABOLISHED |
| Title in English: | Information security technology―Requirement and code of conduct for security testing bodies of information technology products |
| Title in Chinese: | 信息安全技术 信息技术产品安全检测机构条件和行为准则 |
| Language: | English |
| File Format: | Electronic (PDF) |
| Delivery: | Via email within 1~3 business days |
| Issued on: | 2017-12-29 |
| Implemented on: | 2018-07-01 |
| ICS Classification: | 35.040-Character sets and information coding |
| Chinese Classification: | L80-Data encryption |
| Professional Classification: | GB-National Standard |
| Related Topics: | product Safety
safety inspection Holographic technology Safety inspection Product Safety Testing information industry Holographic technology Technical conditions and products GBT35280 GB/T 35280-2017 Information technology products (safety performance) Information security products revolve around Casting machine safety technology |
《GB/T 35280-2017信息安全技术 信息技术产品安全检测机构条件和行为准则》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
GB/T 35280-2017: Information Security Technology Information Technology Product Security Testing Agency Standard Interpretation
| Dimensions | Basic requirements | Detailed description |
|---|---|---|
| Resource requirements | Personnel, facilities and equipment | The testing agency must have at least 5 professionals, including a technical director and a quality director, and provide a secure network environment and necessary testing tools. |
| Capability requirements | Technical capabilities and management capabilities | The agency must have the ability to discover malicious programs, analyze supply chain security and verify data interactions, and establish an effective management system. |
| Process management | Testing process and result reporting | Including method selection, sampling, sample disposal, technical records and quality control to ensure the accuracy and reliability of test results. |
Explanation of professional terms and practical application cases
Information technology products: refers to hardware, software and systems with data or information processing functions, such as computers and communication equipment.
Supply chain security: refers to ensuring that products are not affected by malicious tampering or vulnerabilities throughout their life cycle.
Implementation suggestions:
- Establish a testing process and management system that meets the standards, such as the management system required by GB/T 27025.
- Regularly train testers to ensure they master the latest security technologies and tools, such as vulnerability scanning tools and source code analysis tools.
- Develop emergency plans to deal with possible security risks, such as major vulnerabilities discovered during testing.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/T 15843.1-2017 in English
Information technology―Security techniques―Entity authentication―Part 1:General
2017-12-29 -

GB/T 37931-2019 in English
Information security technology—Security technology requirements and testing and evaluation approaches for Web application security detection system
2019-08-30 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15