GB/T 35283-2017 in English
SUPERSEDEDInformation security techniques—Specification for the structure of desktop core configuration baseline
- Issued on:2017-12-29
- Implemented on:2018-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
$466.00
《GB/T 35283-2017信息安全技术 计算机终端核心配置基线结构规范》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Standard Background and Technical Evolution
As a component of the government terminal security series of standards, this standard further standardizes the XML structured representation method of the core configuration baseline based on GB/T 30278-2013. By drawing on the Windows WMI configuration management mechanism, a seven-layer nested tag system is established to achieve machine readability and automated processing of configuration policies.
Analysis of the Four Elements of the Core Configuration Baseline
| Element | Functional Description | XML Tag Example |
|---|---|---|
| Product Information | Defines the applicable operating system/software environment | OperatingSystemInfo |
| Configuration Item | The minimum management unit of security parameters | SettingDiscoveryInfo |
| Configuration Group | A collection of configuration items grouped by security function | SettingGroup |
| Version Information | Version identification of baseline and components | VersionControl |
Key technologies of XML tagging rules
Case of deep tagging of configuration items
Take Password length configuration as an example, its seventh-layer tag includes:
- Assignment path: Computer Configuration\Windows Settings\Security Settings
- Vulnerability description: Dictionary attack/brute force cracking risk
- Countermeasures: More than 8 characters are recommended
Implementation suggestions
- Tool development: Need to support multi-source value acquisition methods such as WMI/registry defined in Section 6.7.2
- Baseline verification: Refer to Appendix C to establish a configuration item conflict detection mechanism
- Enterprise deployment: It is recommended to use GUID identification to achieve baseline version traceability

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 24363-2009 in English
Information security technology—Specifications of emergency response plan for information security
2009-09-30 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 25056-2018 in English
Information security technology—Specifications of cryptograph and related security technology for certificate authentication system
2018-06-07 -

GB/T 41266-2022 in English
Security testing methods for critical network devices—Switch
2022-03-09 -

GB/T 31495.1-2015 in English
Information security technology―Indicator system of information security assurance and evaluation methods―Part 1:Concepts and model
2015-05-15