GB/T 20274.2-2008

Active

Information security technology - Evaluation framework for information systems security assurance Part 2: Technical assurance

信息安全技术 信息系统安全保障评估框架 第2部分:技术保障

Standard Type
GBT
ICS
35.040
CCS
L80
Status
Active
Issue Date
2008-07-18
Implementation
2008-12-01
Centralized Committee
国家标准委
Issuing Authority
中华人民共和国国家质量监督检验检疫总局、中国国家标准化管理委员会

Application Summary AI generated

This standard defines the technical assurance requirements and evaluation methodology for information system security, focusing on technical controls such as cryptography, access control, and audit mechanisms. It is applied in China for assessing and certifying the security of IT products and systems, particularly in government, finance, and critical infrastructure sectors. The standard provides a structured framework for security evaluators and developers to ensure systems meet specified technical security assurance levels.

Related Standards

Transparency note: The application summary and key sentences on this page were automatically generated by AI from the standard's original text. This content has not been human-verified and should not be used for compliance or regulatory purposes. Always refer to the official standard document from the issuing authority.