Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
industrial control system security management standards security control security management fundamental requirements security management system security level requirements energy efficiency scopethis standard processing plant construction mobile internet introductionthis standard
GB/T 36323-2018 in English

GB/T 36323-2018 in English

VALID

Information security technology--Security management fundamental requirements for industrial control systems

  • Issued on:2018-06-07
  • Implemented on:2019-01-01
  • File Format:PDF
  • Delivery:Via email within 5 business days
Price(USD): $630.00
$612.00

《GB/T 36323-2018信息安全技术 工业控制系统安全管理基本要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。


Introduction

Core framework of industrial control system security management standards

The standard builds a security management system that includes DCS, SCADA, PLC and other systems, and forms a closed-loop management through six key activities such as top-level commitment, planning and evaluation.


Classification system of security control measures

Control categoryTypical measuresCoverage dimensions
Management systemSecurity assessment (CA), system acquisition (SA)4 control families
Operation and maintenance managementMedia protection (MP), incident response (IR)9 control families
Technical managementAccess control (AC), identification authentication (IA)3 control families

Key points for the implementation of key control measures

Physical and Environmental Security (PE)

Emergency Power Off (PE-9) requires the installation of an independent power switch, and the fourth-level system needs to add protection against misoperation. Taking a chemical plant as an example, a dual-channel UPS + diesel generator combination is deployed in the DCS control room to meet the PE-10 emergency power supply requirements.

Access Control (AC)

Systems above level 3 must implement multi-factor authentication (IA-2), such as a power grid SCADA system uses a two-factor authentication of smart card + dynamic password.


Differentiated security level requirements

Appendix A divides control measures into four levels:

  • Level 1: Basic requirements, such as CA-2 security assessment must include three items a)~c)
  • Level 4: Enhanced requirements, such as CA-6 continuous monitoring must achieve seven items a)~g)

Implementation recommendations

  1. Establish a cross-departmental ICS security joint management team (5.2.3)
  2. Prioritize the implementation of CA-3 connection management and AC-9 remote access control
  3. Refer to Appendix A to tailor control measures

Sample only — not a preview of GB/T 36323-2018
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend

  • GB/T 45240-2025 in English

    GB/T 45240-2025 in English

    General requirements for device-independent quantum random number generators

    2025-01-24
  • GB/Z 24294.1-2018 in English

    GB/Z 24294.1-2018 in English

    Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General

    2018-03-15
  • GB/T 20009-2019 in English

    GB/T 20009-2019 in English

    Information security technology—Security evaluation criteria for database management system

    2019-08-30
  • GB/T 29767-2013 in English

    GB/T 29767-2013 in English

    Information security techniques—Public key infrastructure—Bridge Certification Authority leveled certificate specification

    2013-09-18
  • GB/T 15278-1994 in English

    GB/T 15278-1994 in English

    Information processing-Data encipherment-Physical layer interoperability requirements

    1994-01-02
  • GB/T 24363-2009 in English

    GB/T 24363-2009 in English

    Information security technology—Specifications of emergency response plan for information security

    2009-09-30
  • GB/T 25056-2018 in English

    GB/T 25056-2018 in English

    Information security technology—Specifications of cryptograph and related security technology for certificate authentication system

    2018-06-07
  • GB/T 40018-2021 in English

    GB/T 40018-2021 in English

    Information security technology—Certificate request and application protocol based on multiple channels

    2021-04-30