GB/T 29240-2024Cybersecurity technology - General security technical specification for terminal computer (English PDF)
网络安全技术 终端计算机通用安全技术规范
Open the GB/T 29240-2024 preview as PDF
This is a limited preview
Buy now to download the full PDF (29 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
October 26, 2024
Implementation date
May 1, 2025
Scope
GB/T 29240-2024 is the English-translated version of 网络安全技术 终端计算机通用安全技术规范.
GB/T 29240-2024 is the Chinese general security technical specification for terminal computers, the standard against which desktop and laptop endpoints are assessed for use in Chinese organisations. It is written in two halves, which is what makes it usable: the security technical requirements, divided into security functional requirements and security assurance requirements, and then the test and evaluation method for each of them, so that the same document serves the manufacturer building the product and the laboratory certifying it. The functional requirements cover identification and authentication, access control, the trusted boot and integrity of the platform, the protection of stored data including encryption, the audit, the malicious code protection, the interface and peripheral control that governs removable media, the network access control and the residual information protection. The 2024 edition updates the specification for current hardware roots of trust and for domestic processors and operating systems. It takes effect on 1 May 2025.
Document preview — GB/T 29240-2024
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L80
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- 1 Scope1
- 2 Normative references1
- 3 Terms and Definitions1
- 4 Abbreviations2
- 5 Overview2
- 6 Safety Technical Requirements2
- 6.1 Security Functional Requirements2
- 6.2 Security Requirements6
- 7 Test Evaluation Method8
- 7.1 General Description8
- 7.2 Test Environment8
- 7.3 Safety Function Requirements Testing and Evaluation8
- 24 Reference25
Foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part
1.Structure and drafting rules for standardization documents" Drafting. This document replaces GB/T 29240-2012 "Information security technology terminal computer general security technical requirements and test evaluation method" Compared with GB/T 29240-2012, the main technical changes in addition to the editorial revisions are as follows:
--- Added "General Principles" (see Chapter 5);
--- Deleted "Hardware System" (see 4.1.1.1, 4.2.1.1, 4.3.1.1, 4.4.1.1,
4.5.1.1 of the.2012 edition);
--- Deleted "operating system" (see 4.1.1.2, 4.2.1.2, 4.3.1.2, 4.4.1.2,
4.5.1.2 of the.2012 edition);
--- Deleted "SSOTC own safety protection" (see 4.1.2, 4.2.2, 4.3.2, 4.4.2,
4.5.2 of the.2012 edition);
--- Deleted "Password support" (see 4.2.1.3.1, 4.3.1.3.1, 4.4.1.3.1, 4.5.1.3.1 of the.2012 edition);
--- Deleted "Data confidentiality protection" (see 4.2.1.3.4, 4.3.1.3.5, 4.4.1.3.7, 4.5.1.3.7 of the.2012 edition);
--- Deleted "SSOTC Management" (see 4.1.4, 4.2.4, 4.3.4, 4.4.4,
4.5.4 of the.2012 edition);
--- Added "Hardware Interface Security" (see 6.1.1);
1 Scope
GB/T 29240-2024 is the Chinese general security technical specification for terminal computers, the standard against which desktop and laptop endpoints are assessed for use in Chinese organisations. It is written in two halves, which is what makes it usable: the security technical requirements, divided into security functional requirements and security assurance requirements, and then the test and evaluation method for each of them, so that the same document serves the manufacturer building the product and the laboratory certifying it. The functional requirements cover identification and authentication, access control, the trusted boot and integrity of the platform, the protection of stored data including encryption, the audit, the malicious code protection, the interface and peripheral control that governs removable media, the network access control and the residual information protection. The 2024 edition updates the specification for current hardware roots of trust and for domestic processors and operating systems. It takes effect on 1 May 2025.
This document specifies general security technical requirements for terminal computers and describes test and evaluation methods. This document is intended to guide the design, development, testing, and evaluation of common security functions for terminal computers.
2 Normative references
The contents of the following documents constitute the essential clauses of this document through normative references in this document. For referenced documents without a date, only the version corresponding to that date applies to this document; for referenced documents without a date, the latest version (including all amendments) applies to This document.
GB/T 5271.1-2000 Information technology vocabulary Part
3 Terms and Definitions
GB/T 18336.1-2024, GB/T 18336.3-2024, GB/T 5271.1-2000 and GB/T 25069 and the following The following terms and definitions apply to this document.
3.1 terminal computer A computer for personal use that can independently process data and provide access to network services. Note
1.The terminal computers in this document do not include mobile smart terminals (mobile phones, tablets), vehicle-mounted smart terminals, smart TVs, wearable devices, etc. equipment. Note
2.Terminal computers usually consist of hardware systems, operating systems, and application systems (including tool software, security software, and other software that provide support for users to access the network). other application software) and other parts.
3.2 A general term for security protection components within terminal computers, including hardware, firmware, software, and a combination responsible for executing security policies.
Note. The terminal computer security subsystem establishes a basic terminal computer security protection environment and provides additional user services required by the terminal computer. The terminal computer security subsystem needs to provide security protection for the terminal computer from aspects such as hardware system, operating system, application system and system operation.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 29 pages — is available in the English PDF.
Referenced standards
Normative references
GB/T 5271.1-2000 · GB/T 18336.1-2024 · GB/T 18336.3-2024
Similar standards
GB 38031-2025|GB/T 29240|GB/T 29240-2012|GB/T29240-2024|GB/T 1.1-2020|GB/T 5271.1-2000|GB/T 18336.1-2024|GB/T 18336.3-2024
How to Buy GB/T 29240-2024
- 1Add to cart. Click the "Buy GB/T 29240-2024" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 29240-2024
$500.00