GB/T 35317-2017 in English
VALIDInformation classified security protection requirements for systems of IoTPS
- Issued on:2017-12-29
- Implemented on:2017-12-29
- File Format:PDF
- Delivery:Via email within 5 business days
$359.00
《GB/T 35317-2017公安物联网系统信息安全等级保护要求》由312(公安部)归口,主管部门为公安部。
Introduction
Interpretation of the Information Security Level Protection Requirements for the Public Security Internet of Things System
| Security Level | Physical Security Requirements | Network Security Requirements | Data Security Requirements |
|---|---|---|---|
| Level 1 | Basic requirements such as physical access control, anti-theft and anti-destruction, and temperature and humidity control. | Structural security and access control meet the requirements of 5.1.2 of GB/T 22239-2008. | Data integrity, backup and recovery meet the requirements of 5.1.5 of GB/T 22239-2008. |
| Level 2 | Stricter physical location selection, anti-theft and sabotage measures, deployed in a location that is not easily damaged. | Access control is strengthened, support for heterogeneous network access detection, and terminal location privacy protection capabilities are available. | Data integrity is enhanced, sensitive data encryption requirements are required, and user privacy is ensured not to be leaked. |
| Level 3 | The physical environment avoids signal interference, and waterproof, anti-static and electromagnetic protection measures are added. | Network security audit function is upgraded to support the life cycle mechanism of business management. | Data availability is improved, sensitive data encryption requirements are stricter, and confidentiality of key business data transmission is ensured. |
| Level 4 | The physical environment has high-level protection capabilities such as fire prevention and waterproofing, and lightning protection measures are set up. | Network equipment protection is improved, supporting dedicated communication protocols or secure communication protocol services. | Data integrity is comprehensively strengthened, with recovery measures, and data confidentiality uses advanced encryption methods. |
Implementation suggestions
1. Determine the security level: Determine the applicable security protection level (level one to level four) based on the system's business needs and risk assessment results.
2. Formulate security strategies: According to standard requirements, formulate detailed security management systems and technical specifications to ensure that all links meet relevant requirements.
3. Technical implementation: Deploy corresponding security measures at the perception terminal, network equipment and system management levels, such as access control, encrypted transmission, data backup, etc.
4. Regular evaluation and optimization: According to the standard requirements, regular level evaluation and security management review shall be carried out to optimize security strategies and technical measures in a timely manner.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 44297-2024 in English
Data items of video and image information for public security
2024-08-23 -

GB/T 37715-2019 in English
Specification for base platform and application system software testing of IoTPS
2019-06-04 -

GB/T 42196-2022 in English
Technical requirements for video and image metadata analysis of internet of things of public security
2022-12-30