Valid

GB/T 28450-2020Cybersecurity technology - Guidelines for information security management systems auditing (English PDF)

Preview PDF

Also coversGBT28450-2020

This is a limited preview

Buy now to download the full PDF

Need quotation for your management?

Get a formal quotation for GB/T 28450-2020 in 30 minutes.

Issued by

State Administration for Market Regulation, Standardization Administration of China

Level / Type

National · Recommended

Issue date

May 25, 2026

Implementation date

December 1, 2026

Scope

GB/T 28450-2020 (Cybersecurity technology - Guidelines for information security management systems auditing) is available as an English-translated PDF.

GB/T 28450-2020 — Based on GB/T 19011-2021, this document provides guidelines for the management and auditing of Information Security Management System (ISMS) audit schemes. Guidelines on implementation and ISMS auditor competence, etc. This document is applicable to all organizations that need to understand or implement internal or external audits of ISMS, or that need to manage ISMS audit programs.

Found what you need?

Document preview — GB/T 28450-2020

National Standard of the People's Republic of China

ICS
35.030
Classification
L 80
Replacing
GB/T 28450-2020

Issued by: State Administration for Market Regulation, Standardization Administration of China

Contents

  • Preface
  • 1.Scope1
  • 2 Normative References1
  • 3.Terms and Definitions1
  • 4.Audit Principles1
  • 5.Management of the audit plan1
  • 5.1 General Provisions1
  • 5.2 Establish the objectives of the audit plan1
  • 5.3 Identify and evaluate the risks and opportunities of the audit plan2
  • 5.4 Establish an audit plan2
  • 5.5 Implement the audit plan3
  • 5.6 Monitoring and Auditing Scheme4
  • 5.7 Review and Improvement of the Audit Plan4
  • 6.Implementation of the audit4
  • 6.1 General Provisions4
  • 6.2 Initiation of the Audit4
  • 6.3 Preparation for the Audit Activity4
  • 6.4 Implementation of Audit Activities5

Foreword

This document complies with the provisions of GB/T 1.1-2020 "Standardization Work Guidelines Part 1.Structure and Drafting Rules of Standardization Documents".

Drafting.

This document supersedes GB/T 28450-2020 "Information Technology Security Technology - Guidelines for Auditing Information Security Management Systems" and is consistent with...

Compared with GB/T 28450-2020, apart from structural adjustments and editorial changes, the main technical changes are as follows.

---All sections on "General Principles," "Establishing Audit Programs," and "Identifying and Assessing Audit Program Risks" in the chapter "Management of Audit Programs" have been deleted.

Contents (see sections 5.1 and 5.3.4 of the 2020 edition);

---The section "Risks and Opportunities Identified When Planning an ISMS" in the chapter "Management of Audit Programs" has been removed [see 2020 edition].

5.2.1d)];

---The section on "Implementing the Audit Program" in the chapter on "Management of Audit Programs" has been deleted. Specifically, the section on "IS5.4.2 specifies the objectives, scope, and..." has been removed.

The "Evaluation of the process for maintaining and effectively improving the ISMS" in the "Guidelines" [see 5.4, 5.4.2.1b) of the 2020 edition];

---The section on "Distribution of Audit Reports" in the chapter on "Conducting the Audit" has been deleted. The original text stated, "When distributing audit reports, appropriate measures should be taken to ensure the reports are properly distributed."

"Confidentiality" (see 6.5 and 6.5.2.1 in the 2020 edition).

This document adopts the ISO /IEC 27007.2020 standard, "Information security, network security and privacy protection, information security management system audit".

guide".

The following minimal editorial changes have been made to this document.

---The standard's name has been changed to "Guidelines for Auditing Information Security Management Systems in the Field of Cybersecurity."

---Added Appendix A with a plan for the changes (see A.3.3);

---The order of continuous improvement and non-compliance corrective actions in Appendix A has been changed.

Please note that some content in this document may involve patents. The issuing organization of this document assumes no responsibility for identifying patents.

This document was proposed and is under the jurisdiction of the National Cybersecurity Standardization Technical Committee (SAC/TC260).

1 Scope

Based on GB/T 19011-2021, this document provides guidelines for the management and auditing of Information Security Management System (ISMS) audit schemes.

Guidelines on implementation and ISMS auditor competence, etc.

This document is applicable to all organizations that need to understand or implement internal or external audits of ISMS, or that need to manage ISMS audit programs.

2 Normative references

The contents of the following documents, through normative references within the text, constitute essential provisions of this document. Dated citations are not included.

For references to documents, only the version corresponding to that date applies to this document; for undated references, the latest version (including all amendments) applies.

This document.

GB/T 19011-2021 Guidelines for Management System Auditing (ISO 19011.2018, IDT)

GB/T 29246-2023 Information Security Technology - Overview and Glossary of Information Security Management Systems (ISO /IEC 27000.2018)

IDT)

3 Terms and Definitions

The terms and definitions defined in GB/T 19011-2021 and GB/T 29246-2023 apply to this document.

4 Review Principles

The principles in Chapter 4 of GB/T 19011-2021 apply.

5 Management of the audit plan

5.1 General Provisions

The guidelines in section 5.1 of GB/T 19011-2021 apply.

5.2 Establish the objectives of the audit plan

5.2.1 The guidelines in section 5.2 of GB/T 19011-2021 apply. Section 5.2.2 has been added.
5.2.2 When establishing the objectives of the ISMS audit program, the following may be included.

a) Information security requirements for identification;

b) Requirements of GB/T 22080-2025;

c) The auditee's performance level as reflected in the occurrence of information security incidents and events, and the effectiveness of the ISMS;

Note. For more information on performance monitoring, measurement, analysis and evaluation, see ISO /IEC 27004.

d) Information security risks of relevant parties, namely the auditee and the audit commissioner.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — all pages — is available in the English PDF.

Referenced standards

Normative references

ISO 19011.2018 · GB/T 29246-2023 · IEC 27000.2018

How to Download GB/T 28450-2020

  1. 1

    Add to cart

    Click "Download PDF" on this page and choose "Buy this standard". You can add more standards before checkout.

  2. 2

    Checkout

    Enter your email and billing details. Payment is processed securely by Stripe (cards or bank transfer). Prefer bank details? Request a quotation (min. order $300).

  3. 3

    Instant delivery (0–9 sec)

    Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.

  4. 4

    Invoice included

    A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 28450-2020

$595.00