JR/T 0071.4-2020 in English
VALIDImplementation guidelines for classified protection of cybersecurity of financialindustry-Part 4: Guidelines for training
- Issued on:2020-11-11
- Implemented on:2020-11-11
- File Format:PDF
- Delivery:Via email within 1~3 business days
$204.00
本部分规定了网络安全培训的培训目标、培训原则、培训计划、培训对象、培训内容要求、培训实 施、培训考核和培训档案管理。本部分适用于实施网络安全等级保护的金融机构、测评机构和金融行业网络安全等级保护主管部 门。
Introduction
Standard Framework and Technological Evolution
As the 4th part of the JR/T 0071 series of standards, this document marks the completion of the financial industry's cybersecurity training system's transition from general requirements to special implementation. Compared with the 2012 version, the 2020 version mainly presents three major technical evolution characteristics:
| Dimensions | 2012 Version | 2020 Version |
|---|---|---|
| Covered Objects | Basic Position Personnel | Management Layer + Technical Layer + Audit LayerThree-dimensional System |
| Content Requirements | General Security Awareness | Level Protection Special Capability Matrix |
| Assessment Mechanism | Result Filing | Dual Veto System for Position Access |
Analysis of core elements
Design of layered training system
The standard innovatively establishes a four-level classification of training targets:
- Decision-making level (board of directors/senior executives): focus on cultivating network security strategic decision-making capabilities
- Management position (security supervisor): need to master risk governance framework and emergency response
- Technical position: requires technical capabilities for implementing graded protection
- Audit position: focuses on compliance inspection methodology
Typical case: A national commercial bank increased its graded protection compliance rate by 42% by linking training grading with job promotion channels
Implementation suggestions
Key points for preparing a training plan
- Adopt the PDCA cycle to manage the entire training process
- The training time for new technologies such as cloud computing/big data is recommended to account for ≥30%
- The annual training time for key positions should reach 16 hours/year
Innovation in the assessment mechanism
Article 9.4 of the standard clearly establishes a double veto mechanism:
| Assessment rounds | Handling measures | Management impact |
|---|---|---|
| First failure | Mandatory retraining | Performance deduction |
| Second failure | Position adjustment | Qualification freezing |
Compliance Implementation Path
Financial institutions are advised to advance in the following stages:
- Gap analysis (January-February): Conduct current status assessment against Appendix A of the standard
- System construction (March-June): Establish a three-level training management organizational structure
- Pilot operation (June-December): Select 2-3 business lines for verification
Regulatory reminder: Starting from 2024, the People's Bank of China will include the completeness of the training system in the financial technology rating indicators

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

JR/T 0067-2021 in English
The cybersecurity graded protection evaluation requirements for securities and futures industries
2021-08-30 -

JR/T 0048-2015 in English
Insurance base data model
2015-08-03 -

JR/T 0305-2025 in English
Standardization of the insurance industry information technology performance evaluation index system
2025-02-17 -

JR/T 0106-2014 in English
Trust business classification and coding
2014-10-16 -

JR/T 0320-2024 in English
Securities and fund management institutions operation and maintenance automation capability maturity specification
2024-11-20