GB/T 41574-2022 in English
VALIDInformation technology—Security techniques—Code of practice for protection of personal information in public clouds
- Issued on:2022-07-11
- Implemented on:2023-02-01
- File Format:PDF
- Delivery:Via email within 5 business days
$476.00
《GB/T 41574-2022信息技术 安全技术 公有云中个人信息保护实践指南》由TC260(全国信息安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Analysis of the core content of the standard
| Control categories | Differences in ISO/IEC27018 | New requirements |
|---|---|---|
| Definition of terms | Adopt the GB/T35273 terminology system | Specify that personal information processors are equivalent to entrusted persons |
| Cryptography technology | No specific requirements | Required to comply with national cryptography standards |
| Cross-border transmission | Not covered | Added B.7.14 Geographic location control measures |
Key technical requirements
Data lifecycle protection
The standard requires the implementation of full lifecycle management of personal information, with a focus on:
- Storage phase: Use encrypted storage and access control (9.4.1)
- Transmission phase: Public network transmission must be encrypted (B.7.6)
- Destruction phase: Specify the disposal methods such as delinking and degaussing (B.2.3)
Compliance implementation recommendations
Contract management points
The cloud service agreement should include:
- 72-hour notification mechanism for data loss (B.2.1)
- Prior disclosure clause for subcontractor processing (B.4.1)
- National list for cross-border transmission (B.7.14)
Technical implementation path
It is recommended to implement it in three stages:
| Stage | Work content | Period |
| Gap analysis | Evaluate against the 18 control categories of the standard | 2-4 weeks |
| System construction | Focus on improving the B.7 series of security controls | 8-12 weeks |
| Continuous improvement | Semi-annual review strategy (B.2.2) | Continue |
Standard Evolution Analysis
Compared with ISO/IEC27018:2019, this standard has the following major innovations:
- Added national standard compliance requirements for cryptographic technology (10.1.1)
- Strengthen data outbound control (Appendix B)
- Refine the division of cloud service roles and responsibilities (Appendix C)

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/Z 41288-2022 in English
Information security technology—Guidelines of cyber security protection for important industrial control system
2022-03-08 -

GB/T 20274.1-2023 in English
Information security technology - Evaluation framework for information systems security assurance - Part 1: Introduction and general model
2023-03-17 -

GB/T 30272-2021 in English
Information security technology—Public key infrastructure—Testing and assessment of compliance with standards
2021-08-20 -

GB/T 43435-2023 in English
Information security technology—Security requirements for software development kit (SDK) in mobile internet applications (App)
2023-11-27 -

GB/T 17902.1-2023 in English
Information technology―Security techniques―Digital signatures with appendix―Part 1:General
2023-03-17 -

GB/T 40813-2021 in English
Information security technology—Security protection technical requirements and testing evaluation methods of industrial control systems
2021-10-11 -

GB/T 39204-2022 in English
Information security technology—Cybersecurity requirements for critical information infrastructure protection
2022-10-12 -

GB/T 42829-2023 in English
Basic requirements of quantum secure communication applications
2023-08-06 -

GB/T 35274-2023 in English
Information security technology—Security capability requirements for big data services
2023-08-06 -

GB/T 24364-2023 in English
Information security technology—Implementation guide for information security risk management
2023-05-23