GB/T 36959-2018 in English
VALIDInformation security technology—Capability requirements and evaluation specification for assessment organization of classified protection of cybersecurity
- Issued on:2018-12-28
- Implemented on:2019-07-01
- File Format:PDF
- Delivery:Via email within 5 business days
$350.00
《GB/T 36959-2018信息安全技术 网络安全等级保护测评机构能力要求和评估规范》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Analysis of the Standard Core Framework
| Capability Dimensions | Level I Requirements | Level II Enhanced Requirements | Level III Enhanced Requirements |
|---|---|---|---|
| Registered Capital | More than 5 million | More than 10 million | More than 10 million |
| Technical Personnel | 15 people (2 penetration persons) | 30 people (3 penetration persons) | 50 people (5 penetration persons) |
| Evaluation Tools | Basic detection tools | Add protocol analysis/source code audit tools | Add penetration testing tools |
Key technical capability requirements
Assessment implementation capabilities need to cover:
- Security technology assessment (physical/network/equipment/application security)
- Security management assessment (strategy/organization/operation and maintenance management)
- Risk analysis capabilities (using standard analysis methods)
Level III institutions need to have penetration testing tools and an automated report generation platform.
Key nodes of the assessment process
- Initial assessment: including document review (40+ documents), on-site witness (simulated system testing), rectification acceptance
- Periodic assessment: irregular spot checks during the validity period of the certificate
- Capability re-evaluation: comprehensive review in a 3-year cycle
Implementation suggestions
1. Staff training: it is necessary to ensure that the certification rate of assessors is 100%, and senior assessors should have presided over provincial and ministerial projects
2. Equipment management: all assessment tools must pass CNAS certification and establish a dedicated encrypted storage environment
3. Quality control: it is recommended to introduce blockchain technology to prevent assessment records from being tampered with

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 27422-2019 in English
Conformity assessment -- Requirements for bodies providing audit and certification of business continuity management systems
2019-12-10 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/T 17901.1-2020 in English
Information technology—Security techniques—Key management—Part 1: Framework
2020-03-06 -

GB/T 24363-2009 in English
Information security technology—Specifications of emergency response plan for information security
2009-09-30 -

GB/T 38249-2019 in English
Information security technology—Security guide of cloud computing services for government website
2019-10-18