Valid

GB/T 29240-2024Cybersecurity technology - General security technical specification for terminal computer (English PDF)

网络安全技术 终端计算机通用安全技术规范

Open the GB/T 29240-2024 preview as PDF

Preview — first pages of GB/T 29240-2024 (full document: 29 pages)

This is a limited preview

Buy now to download the full PDF (29 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

October 26, 2024

Implementation date

May 1, 2025

Scope

GB/T 29240-2024 is the English-translated version of 网络安全技术 终端计算机通用安全技术规范.

GB/T 29240-2024 is the Chinese general security technical specification for terminal computers, the standard against which desktop and laptop endpoints are assessed for use in Chinese organisations. It is written in two halves, which is what makes it usable: the security technical requirements, divided into security functional requirements and security assurance requirements, and then the test and evaluation method for each of them, so that the same document serves the manufacturer building the product and the laboratory certifying it. The functional requirements cover identification and authentication, access control, the trusted boot and integrity of the platform, the protection of stored data including encryption, the audit, the malicious code protection, the interface and peripheral control that governs removable media, the network access control and the residual information protection. The 2024 edition updates the specification for current hardware roots of trust and for domestic processors and operating systems. It takes effect on 1 May 2025.

Document preview — GB/T 29240-2024

National Standard of the People's Republic of China

ICS
35.030
Classification
L80

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 1 Scope1
  • 2 Normative references1
  • 3 Terms and Definitions1
  • 4 Abbreviations2
  • 5 Overview2
  • 6 Safety Technical Requirements2
  • 6.1 Security Functional Requirements2
  • 6.2 Security Requirements6
  • 7 Test Evaluation Method8
  • 7.1 General Description8
  • 7.2 Test Environment8
  • 7.3 Safety Function Requirements Testing and Evaluation8
  • 24 Reference25

Foreword

This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part

1.Structure and drafting rules for standardization documents" Drafting. This document replaces GB/T 29240-2012 "Information security technology terminal computer general security technical requirements and test evaluation method" Compared with GB/T 29240-2012, the main technical changes in addition to the editorial revisions are as follows:

--- Added "General Principles" (see Chapter 5);

--- Deleted "Hardware System" (see 4.1.1.1, 4.2.1.1, 4.3.1.1, 4.4.1.1,

4.5.1.1 of the.2012 edition);

--- Deleted "operating system" (see 4.1.1.2, 4.2.1.2, 4.3.1.2, 4.4.1.2,

4.5.1.2 of the.2012 edition);

--- Deleted "SSOTC own safety protection" (see 4.1.2, 4.2.2, 4.3.2, 4.4.2,

4.5.2 of the.2012 edition);

--- Deleted "Password support" (see 4.2.1.3.1, 4.3.1.3.1, 4.4.1.3.1, 4.5.1.3.1 of the.2012 edition);

--- Deleted "Data confidentiality protection" (see 4.2.1.3.4, 4.3.1.3.5, 4.4.1.3.7, 4.5.1.3.7 of the.2012 edition);

--- Deleted "SSOTC Management" (see 4.1.4, 4.2.4, 4.3.4, 4.4.4,

4.5.4 of the.2012 edition);

--- Added "Hardware Interface Security" (see 6.1.1);

1 Scope

GB/T 29240-2024 is the Chinese general security technical specification for terminal computers, the standard against which desktop and laptop endpoints are assessed for use in Chinese organisations. It is written in two halves, which is what makes it usable: the security technical requirements, divided into security functional requirements and security assurance requirements, and then the test and evaluation method for each of them, so that the same document serves the manufacturer building the product and the laboratory certifying it. The functional requirements cover identification and authentication, access control, the trusted boot and integrity of the platform, the protection of stored data including encryption, the audit, the malicious code protection, the interface and peripheral control that governs removable media, the network access control and the residual information protection. The 2024 edition updates the specification for current hardware roots of trust and for domestic processors and operating systems. It takes effect on 1 May 2025.

This document specifies general security technical requirements for terminal computers and describes test and evaluation methods. This document is intended to guide the design, development, testing, and evaluation of common security functions for terminal computers.

2 Normative references

The contents of the following documents constitute the essential clauses of this document through normative references in this document. For referenced documents without a date, only the version corresponding to that date applies to this document; for referenced documents without a date, the latest version (including all amendments) applies to This document.

GB/T 5271.1-2000 Information technology vocabulary Part

3 Terms and Definitions

GB/T 18336.1-2024, GB/T 18336.3-2024, GB/T 5271.1-2000 and GB/T 25069 and the following The following terms and definitions apply to this document.

3.1 terminal computer A computer for personal use that can independently process data and provide access to network services. Note

1.The terminal computers in this document do not include mobile smart terminals (mobile phones, tablets), vehicle-mounted smart terminals, smart TVs, wearable devices, etc. equipment. Note

2.Terminal computers usually consist of hardware systems, operating systems, and application systems (including tool software, security software, and other software that provide support for users to access the network). other application software) and other parts.

3.2 A general term for security protection components within terminal computers, including hardware, firmware, software, and a combination responsible for executing security policies.

Note. The terminal computer security subsystem establishes a basic terminal computer security protection environment and provides additional user services required by the terminal computer. The terminal computer security subsystem needs to provide security protection for the terminal computer from aspects such as hardware system, operating system, application system and system operation.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 29 pages — is available in the English PDF.

Referenced standards

Similar standards

GB 38031-2025|GB/T 29240|GB/T 29240-2012|GB/T29240-2024|GB/T 1.1-2020|GB/T 5271.1-2000|GB/T 18336.1-2024|GB/T 18336.3-2024

How to Buy GB/T 29240-2024

  1. 1Add to cart. Click the "Buy GB/T 29240-2024" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
29 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 29240-2024

$500.00

$425.00for partners