GB/T 20274.3-2008

Active

Information security technology Evaluation framework for information systems security assurance Part 3: Management assurance

信息安全技术 信息系统安全保障评估框架 第3部分:管理保障

Standard Type
GBT
ICS
35.040
CCS
L80
Status
Active
Issue Date
2008-07-18
Implementation
2008-12-01
Centralized Committee
国家标准委
Issuing Authority
中华人民共和国国家质量监督检验检疫总局、中国国家标准化管理委员会

Application Summary AI generated

This standard specifies the management assurance requirements and evaluation criteria for information system security, focusing on organizational security management, personnel management, and operational management controls. It is applied in the security evaluation and certification of information systems, particularly for government, financial, and enterprise IT environments requiring formal security assurance assessments. The standard provides a framework for evaluating the effectiveness of management processes that support the overall security posture of an information system.

Related Standards

Transparency note: The application summary and key sentences on this page were automatically generated by AI from the standard's original text. This content has not been human-verified and should not be used for compliance or regulatory purposes. Always refer to the official standard document from the issuing authority.