Valid

GB/T 24294.1-2026Cybersecurity technology - Implementation guide for the information security of internet-based e-government - Part 1: General (English PDF)

网络安全技术 基于互联网电子政务信息安全实施指南 第1部分:总则

Open the GB/T 24294.1-2026 preview as PDF

Preview — first pages of GB/T 24294.1-2026 (full document: 30 pages)

This is a limited preview

Buy now to download the full PDF (30 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

April 30, 2026

Implementation date

November 1, 2026

Scope

GB/T 24294.1-2026 is the English-translated version of 网络安全技术 基于互联网电子政务信息安全实施指南 第1部分:总则.

GB/T 24294.1-2026 is the Chinese national standard covering securing government services delivered over the public internet - the general part: the boundary between the internet-facing systems and the internal ones, the identity and access, the data classification and the incident response. Part 1 of the series, first edition, in force since 1 November 2026. It was issued on 30 April 2026 and takes effect on 1 November 2026, as a first edition. The document is under the responsibility of the Standardization Administration of China. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.

Document preview — GB/T 24294.1-2026

National Standard of the People's Republic of China

ICS
35.030
Classification
L 80

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 1 Scope
  • 2 Internet e-government network security technology system
  • 5 Reference Model
  • 5.3 Requirements Identification
  • 5.4 Safety Design
  • 5.6 Operation and Evaluation
  • 6 Technical System
  • 7 System Implementation Principles
  • 8 System Implementation Framework
  • 8.1 System Implementation Framework under Traditional Business Deployment Model
  • 8.2 System Implementation Framework under Cloud Computing Deployment Model

Foreword

This document complies with the provisions of GB/T 1.1-2020 "Standardization Work Guidelines Part

1.Structure and Drafting Rules of Standardization Documents". Drafting. This document is Part 1 of GB/T 24294 "Information Security Technology - Implementation Guidelines for Internet-based E-government Information Security". The "Information Security Technology Implementation Guidelines for Internet-based E-Government Information Security" has been released, including the following sections.

1.General Provisions;

2.Access Control and Security Switching;

3.Identity Authentication and Authorization Management;

4.Endpoint Security Protection. This document replaces GB /Z 24294.1-2018 "Information Security Technology - Implementation Guidelines for Internet-based E-government Information Security (Part 1)". Part. General Provisions. Compared with GB /Z 24294.1-2018, apart from structural adjustments and editorial changes, the main technical changes are as follows:

a) The Internet-based e-government information security reference model has been modified (see Chapter 5, Chapter 5 of the.2018 version);

b) The Internet-based e-government information security technology system has been revised (see Chapter 6, Chapter 6 of the.2018 edition);

c) The implementation principles of the system have been changed (see Chapter 7, Chapter 7 of the.2018 edition);

d) The implementation architecture of the system was changed (see Chapter 8, Chapter 8 of the.2018 edition);

e) Added Chapter 9, "Cryptography Use and Security Responsibilities" (see Chapter 9);

f) The risk assessment for the system has been removed (see Chapter 10 of the.2018 edition). Please note that some content in this document may involve patents. The issuing organization of this document assumes no responsibility for identifying patents. This document was proposed and is under the jurisdiction of the National Cybersecurity Standardization Technical Committee (SAC/TC260). This document was drafted by: Information Engineering University of the Cyberspace Force of the Chinese People's Liberation Army, National Information Center, and Beijing Municipal Bureau of Economy and Information Technology. The Cybersecurity Management Center of the Bureau of Natural Resources, Zhengzhou Yunzhixin Security Technology Co., Ltd., Beijing Topsec Network Security Technology Co., Ltd., and Huazhong University of Science and Technology Technical University, Beijing Shenzhou Green Alliance Technology Co., Ltd., Zhengzhou Xinda Jiean Information Technology Co., Ltd., Wuhan Minwei Technology Co., Ltd. Guangzhou Zhuoteng Technology Co., Ltd. The main drafters of this document are. Chen Xingyuan, Du Xuehui, Ren Zhiyu, Wang Na, Cao Lifeng, Wang Wenjuan, Zhang Dongwei, Sun Yi, Shan Dibin, and Liu Aodi. Liu Yingying, Liu Bei, Yan Guixun, Li Yuan, Zhang Qiankun, Zhang Nan, Gao Junwei, Peng Ming, Wang Yu, Chen Zhuo, Liu Yao, Jing Hongli, Luo Yuan, Xie Qin, Zhang Chao Wang Haoyu, Dong Feng, Zhao Yanjie, Ye Xiaohu, Fan Dunqiu, Huang Jun, Ye Jianwei, Liao Zhengyun, Mei Guangming, Cao Wanyu. The release history of this document and the document it replaces is as follows:

---First published in.2009 as GB /Z 24294-2009;

---First revised in.2018 as GB /Z 24294.1-2018;

1 Scope

GB/T 24294.1-2026 is the Chinese national standard covering securing government services delivered over the public internet - the general part: the boundary between the internet-facing systems and the internal ones, the identity and access, the data classification and the incident response. Part 1 of the series, first edition, in force since 1 November 2026. It was issued on 30 April 2026 and takes effect on 1 November 2026, as a first edition. The document is under the responsibility of the Standardization Administration of China. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.

1.Scope This document provides a reference model, cybersecurity technology system, system implementation principles, and system framework for internet-based e-government information security. Implement frameworks and cryptographic usage and security confidentiality responsibilities. This document applies to the construction and operation of internet e-government network security for municipal (and below) government units, and is for municipal (and below) level government units. (Below) Provide a basis for government agencies to carry out the construction and security of integrated government service platforms.

4.Abbreviations The following abbreviations apply to this document. App. Application API. Application Programming Interface DDoS. Distributed Denial of Service IPSec. IP Security Protocol PKI. Public Key Infrastructure SSL. Secure Sockets Layer VPN. Virtual Private Network

2 Internet e-government network security technology system

6.2 Boundary Protection Border protection includes the following.

a) It should have policy-based network access control functionality, implementing network-level access control based on the scope of government application services, and blocking incoming... Internet security threats;

b) When deploying virtual networks and devices in a cloud computing environment, it is advisable to deploy a virtual firewall to manage multi-tenant networks within the government cloud. To achieve isolation and control, it is advisable to implement isolation of government services based on container isolation rules, and to realize the virtualization of business resources. East-west data flow control, see GB/T 31168;

c) Network intrusion prevention is recommended, with real-time monitoring and alerting capabilities for typical malicious behaviors such as SYNFlood, DDoS, and webshell attacks. The alarm and tracing functions support both intrusion prevention capabilities for traditional government service deployment architectures and for government virtualization cloud environments. The ability to prevent intrusion;

d) A reliable and trustworthy isolation and exchange mechanism should be established between the internet-based government service area and the public government business area to prevent data transmission from the internet. The risks in the government service area have spread to the public government affairs area.

6.3 Device access security and secure communication network Device access to secure communication networks includes the following.

a) When user equipment accesses the network, it is advisable to implement equipment access protection. Specific access requirements are detailed in GB/T 31168.

b) Relying on internet infrastructure, it is advisable to adopt cryptographic technology, security policy management, secure tunnel management, security audit management, and dynamic evaluation. For technologies such as estimation, IPSec or SSL protocols should be adopted for communication between remote government agencies and government service centers, and between remote government office users and... Secure interconnection is established between government service centers to build a virtualized secure communication network between remote users and the government service platform;

c) It is advisable to use technologies such as user authentication, virtual security domain construction, access terminal status assessment, data encryption and decryption, and cloud environment micro-segmentation. Technology to ensure the security of government data transmission;

d) Network device connectivity should be achieved through technologies such as network device identification, user account management, network identity authentication, and network login control. Safety of connection;

e) Network architecture should be improved through methods such as subnetting and segmenting, redundant deployment of network devices, and enhancement of network bandwidth performance. Safety.

6.4 Security of Government Cloud Services Government cloud service security includes the following.

a) Internet-based government cloud platforms should have malicious code protection functions; specific requirements are detailed in GB/T 31168.

b) Internet-based government cloud platforms should possess functions such as virtual machine image security, resource isolation of the virtualization platform, and virtual machine security isolation. Specifically... Requirements are specified in GB/T 31168;

5 Reference Model

5.1 Model Framework The reference model framework for internet-based e-government cybersecurity is shown in Figure 1. Figure

1 Reference Model Framework The Internet-based e-government cybersecurity reference model consists of "requirements identification, security design, security implementation, operation and evaluation, and system". The model comprises five phases. "migration and deprecation." Centered on security policy, it identifies, designs, implements, evaluates, and deprecates internet-based security measures. The network security system for e-government is built and maintained throughout its entire lifecycle.

5.2 Security Strategy A security policy is a set of rules used for all security-related activities. It occupies a central position in the reference model and should be adaptable to the system's needs. We dynamically adjust and optimize our approach to address the risks and needs we face in order to adapt to the ever-changing cybersecurity landscape. It includes various security devices such as secure interconnection devices, access control devices, secure switching devices, terminal security protection devices, and authentication and authorization devices. The security rules set by the device serve as the basis for implementing access control and authorization. In internet-based e-government systems, it is advisable to follow the system's security rules. Based on the attacks, intrusions, and user access behaviors related to business and data that occur within the system, adjust the security protection in network security devices. rule.

5.3 Requirements Identification

5.3.1 Security Object Identification Internet-based e-government applications are the targets of security protection. These targets include the following two categories.

a) Government Affairs. Internal business processes within government departments, such as document circulation, document processing, office management, and data sharing between government departments. Enjoy, etc.;

b) Government Services. Through various means such as online halls, service windows, mobile clients, and self-service terminals, combined with third-party platforms, face-to-face services are provided. The government provides one-stop services to the public, including information disclosure, social security and medical insurance, marriage and childbirth services, and interactive communication services. Content. Government services take many forms, including government websites, government apps, and government mini-programs.

5.3.2 Government Data Identification In municipal-level (and below) internet-based e-government systems, data that does not involve state e-government secrets includes the following. Two categories.

a) Internal Data. Internal data refers to information accessible to government personnel by level, scope, and unit, such as government office data. Documents, shared government data, and government meeting notices, etc.;

b) Public Data. Public data refers to information that can be made available to the public on the internet, such as government service procedures, government information disclosure, etc. Information on public services projects and enterprise services, etc.

5.3.3 Security Target Identification Security target identification includes the following.

a) The key points of security protection for government offices and their internal information mainly include the identification of government personnel and the authorization of access to government resources. Questions regarding data transmission protection, etc.;

b) The key security protection for government offices and their internal information mainly focuses on the integrity and availability of application systems and their information, as well as privacy. To ensure the confidentiality of private information and prevent unauthorized modification of data and leakage of privacy information, the internal information contained in government offices mainly... This includes important government documents, important government plans, business approvals, and personal privacy information.

5.3.4 Security Protection Level Identification Security protection level identification for internet-based e-government systems shall be conducted in accordance with GB/T 22240, and security framework design shall be carried out in accordance with GB/T 22239. Framework construction.

5.4 Safety Design

5.4.1 Select security control items Based on the application scope, application model, security requirements and expectations of the Internet-based e-government system, as well as the cloud computing and big data technologies adopted... Based on and traditional database and other application technologies, select appropriate security technologies and security controls, and construct corresponding security systems based on the internet, as described in Chapters 6 and 8. Implementation framework for cybersecurity in online e-government.

5.4.2 Design of Safety Technology System To ensure the secure application of internet-based e-government systems (including secure government office and trusted government services), and to realize government... For secure information transmission over the internet, it is advisable to rely on services such as digital certificates provided by PKI, and to comprehensively adopt cryptographic-based security measures. The entire technology suite covers perimeter protection, secure device access and secure communication networks, government cloud service security, government data security, and government cloud application security. It encompasses comprehensive security control and auditing, forming an integrated security protection system.

5.5 Safety Implementation Based on the identification of internet-based e-government systems, and according to security strategies and the designed security technology system, a security system is constructed. The mechanisms and security measures should be designed to build a secure government network and a secure government office platform, focusing on three aspects. government networks, government offices, and government services. The Trusted Government Service Platform provides security protection for internet-based e-government systems, specifically as follows:

a) Employing technologies such as cryptography, firewalls, VPNs, and micro-segmentation, relying on the internet, and using various means such as wired and wireless connections, at each access point... A virtual, secure government service network is formed between the unit and the government service center;

b) Employ technologies such as government personnel identity authentication, authorized access to government resources, and classified protection of government information to safeguard the internal operations of government departments. Security protection should be provided for government affairs processing systems (such as government office and government approval management systems) to achieve secure government office operations;

c) Employ security technologies such as government personnel identity verification, government information release review, and reliable operation of government services to safeguard one-stop government services. The platform is protected for security purposes to ensure reliable government services.

d) For the general public, corporate entities, and other recipients of government services, it is advisable to use real-name registration, identity verification, password or token login, and backend access control. Through methods such as limitation and control, convenient and reliable integrated government services can be achieved.

5.6 Operation and Evaluation

5.6.1 Authorizing e-government systems Based on the security risk assessment report of the Internet-based e-government system, the current security status and security risks of the e-government system are determined. Within the scope of authorization, the e-government system is permitted to continue operating, and the organization is authorized to conduct regular testing and evaluation of security strategies and technologies. And the effectiveness of operational measures.

5.6.2 Monitor safety status Real-time monitoring of internet e-government systems is achieved through system identification, security monitoring, surveillance analysis, security auditing, and situational awareness. Monitoring and analyzing network and host activity, user and system behavior, statistically tracking abnormal network behavior, and identifying violations of security policies enable management to... Personnel are able to effectively monitor, control, and evaluate security behaviors in internet-based e-government systems.

5.6.3 Assess the security system For internet-based e-government systems under construction or in operation, methods such as analysis, verification, inspection, scanning and detection, and penetration testing are employed. A security assessment was conducted in accordance with relevant national standards for graded protection, cryptographic applications, and cloud applications, and the system underwent compliance verification and security risk assessment. The assessment aims to ensure that all security mechanisms comply with the requirements for implementing cybersecurity in internet-based e-government and reduce cybersecurity risks. Safety assessments generally include two types. project acceptance assessments and periodic assessments during operation. This applies to internet-based e-government systems. After conducting a security assessment, a cybersecurity assessment report is provided, and based on the results of the cybersecurity risk assessment, recommendations are made for internet-based e-government systems. A comprehensive safety rectification campaign will be carried out.

5.7 System Migration and Decommissioning Before the termination or partial termination of an internet-based e-government system, systems, devices, or storage media containing data shall be managed in accordance with security policies. To completely, thoroughly, and securely erase and overwrite it, making it unrecoverable and unusable; for important devices or storage media containing sensitive information, it is necessary to... Choose a qualified organization to carry out safe destruction and keep a record of the process. Before migrating an internet-based e-government system, data should be backed up as needed, and the migration should be carried out according to business migration standards to ensure the security of government operations. A completely smooth migration supports the availability, stability, and continuity requirements of government services.

6 Technical System

6.1 Overview To ensure the cybersecurity of internet-based e-government networks built upon internet infrastructure, internet-based e-government networks shall be constructed in accordance with GB/T 22239. The network security technology system is shown in Figure 2. Figure

7 System Implementation Principles

7.1 Principle of Protection as Needed In the construction of internet-based e-government, network security resources should be rationally allocated and appropriate security measures should be taken according to security requirements. Effective security management should be implemented, with comprehensive prevention measures taken from various aspects, including management and technology.

7.2 Principle of Minimum Access The principle of minimization should be applied to access permissions for government applications.

7.3 System Domain Control Principle The protection of e-government information systems is carried out through domain-based storage and domain-based management, depending on the importance and sensitivity of the system and its data. Boundary protection and inter-domain access control.

7.4 Dynamic Protection Principle By employing security measures such as identity authentication, authorization management, access control, and dynamic evaluation, a security system is built that encompasses users, entities, networks, and government resources. Dynamic security protection architecture.

7.5 Principles of Residual Information Protection For any residual information content of sensitive resources in internet-based e-government systems, user authentication must be implemented during resource allocation or release. Completely erasing the storage space containing other information requires completely erasing the storage space containing files, directories, and database records within the system. Clear.

7.6 Supply Chain Security Principles The construction of the government affairs platform involves servers, terminals, firmware, software, and graphics cards, as well as the open-source frameworks used in government affairs websites and apps. Frameworks and open-source software, etc., must use secure and reliable hardware and software products. Specific requirements are specified in GB/T 43698 and GB/T 36637.

8.1 System Implementation Framework under Traditional Business Deployment Model

8.1.1 Basic Structure In the construction of internet-based e-government systems, relevant municipal and prefecture-level government departments, based on application needs, adopted traditional hardware server deployment models. This involves building data storage and application systems using a traditional business deployment model. Under this model, administrative office areas such as counties/townships utilize... The internet facilitates data sharing and management, enabling remote work users to securely access data remotely via the network, thus requiring a more robust security system. Note the network security of the Internet e-government application area and the user side. Its implementation framework is shown in Figure 3.

8.1.2 User side The user side refers to users who access the e-government application area via the internet. This includes. public users/corporate entities, and remote workers. Users, county and district administrative office users, and township administrative office users.

8.1.3 Boundary protection equipment Boundary protection devices are typically high-performance firewalls located at the boundary of the internet e-government application area, implementing network security policies. Network access control and intrusion prevention.

8.1.4 VPN Gateway Located behind the border protection equipment, together with the VPN gateway or VPN client on the user side, they jointly construct an internet-based virtual network. A simulated secure government network enables secure mobile access for remote administrative users, supporting secure access for district/county/township administrative users. Full office and information exchange.

8.1.5 Internet-based e-government application areas The area of internet-based e-government applications encompasses data storage, data processing, network operation and maintenance, and security management. The area for data management and security services includes four zones. internal data processing zone, public data processing zone, security management zone, and security service zone. Internal The data processing area stores database servers and application services related to government affairs, such as the internet-based e-government office platform and data sharing platform. The public data processing area stores databases of internet-based government service systems and administrative approval systems that are accessible to the general public and corporate entities. Servers and application servers. The security management area stores terminals or servers that centrally manage user identities, permissions, policies, and other information. The security service area is a convenient space for users to perform security operations and maintenance, storing security services such as patch update downloads, website anti-tampering, and malicious code protection. Server. In areas where e-government is used, internal government data and publicly available data are stored separately according to their sensitivity levels. Effective isolation is achieved through domain control devices, and one-way controlled exchange of information between different data processing areas is realized using secure data exchange technology. Mutual support for the compliant use of government data.

8.1.6 Public Administration Business Area Public government service areas and e-government application areas are securely isolated. When cross-domain data sharing is required, it is done through security... All switching devices share data.

8.2 System Implementation Framework under Cloud Computing Deployment Model

8.2.1 Basic Structure Unlike traditional business deployment models, the construction and operation of internet-based government systems rely on government cloud infrastructure. This is achieved through cloud computing deployment. Under this model, municipal and prefecture-level government departments build government cloud and data centers, or cascade them with higher-level government clouds, and build separate servers on the basis of the government cloud. Government office applications for government personnel, government service applications for the public and enterprise users, and security management platforms for security management and operation. The platform is a security service platform for preventing malicious code and providing patch updates. It is integrated with the subordinate municipal and prefecture-level vertical management departments, township administrative office areas, and... Secure access and interconnection for remote office users, building a virtualized and secure government network to achieve secure remote government office work and secure data sharing. Information reporting and aggregation. The security system implementation framework under the cloud computing deployment model is shown in Figure 4.

8.2.2 Government Cloud In the application of e-government via the internet, cloud computing deployment models include. public cloud, private cloud, hybrid cloud, and cloud leasing, etc., which are collectively referred to here. This is called government cloud. When municipal and prefecture-level government departments adopt a cloud deployment model, they can choose cloud service providers that have passed the evaluation. The selection of cloud service providers and deployment requirements... See GB/T 31167 for details, or you can rent other internet-connected e-government services...

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 30 pages — is available in the English PDF.

How to Buy GB/T 24294.1-2026

  1. 1Add to cart. Click the "Buy GB/T 24294.1-2026" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
30 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 24294.1-2026

$245.00

$210.00for partners