GB/T 39276-2020 in English
VALIDInformation security technology—General security requirements of network products and services
- Issued on:2020-11-19
- Implemented on:2021-06-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$156.00
《GB/T 39276-2020信息安全技术 网络产品和服务安全通用要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Interpretation of the core content of the standard
GB/T39276-2020 standard builds a basic and enhanced level of hierarchical protection system from the two dimensions of security functions and security assurance of network products and services. The standard is applicable to the security design and implementation of various network hardware equipment, system software and services.
Comparison of security function requirements
| Security dimensions | Basic level requirements | Enhanced level requirements |
|---|---|---|
| Identity authentication | Basic identification and credential protection | Add password complexity check and failure lock mechanism |
| Access control | Principle of least authorization | Fine-grained permission division |
| Log audit | Basic operation records | Storage capacity and retention time configuration |
| Data protection | Basic protection of personal information | Encrypted transmission and storage of sensitive information |
Analysis of security assurance system
Requirements in the development phase
The standard requires the establishment of a Security Development Lifecycle (SDL) process. Typical cases include: a cloud service provider implements threat modeling in the development of a cloud platform, performs SBOM management on third-party components, and discovers potential vulnerabilities through fuzz testing.
Delivery implementation specifications
The enhanced level requirements place special emphasis on the integrity verification of deliverables, such as a network equipment manufacturer providing a digital signature verification tool for firewall equipment to ensure supply chain security.
Technology evolution and compliance recommendations
The standard reflects three major trends in the field of network security: privacy protection enhancement (such as GDPR connection), supply chain security management, and full life cycle security management. Recommendations for enterprises:
- Establish a product security maturity assessment model
- Implement a security-shift-left development strategy
- Build a closed-loop vulnerability management mechanism

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 36618-2018 in English
Information security technology—Specification for financial information service security
2018-09-17 -

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 20979-2019 in English
Information security technology—Technical requirements for iris recognition system
2019-08-30 -

GB/T 34095-2017 in English
中华人民共和国国家质量监督检验检疫总局 中国国家标准化管理委员会
2017-07-31 -

GB/T 28449-2018 in English
Information security technology-Testing and evaluation process guide for classified protection of cybersecurity
2018-12-28 -

GB/T 24363-2009 in English
Information security technology—Specifications of emergency response plan for information security
2009-09-30 -

GB/T 39680-2020 in English
Information security technology—Technique requirements and evaluation criteria for server security
2020-12-14