Valid

GB/T 30278-2024Cybersecurity technology - Government client computer core configuration specifications (English PDF)

网络安全技术 政务计算机终端核心配置规范

Open the GB/T 30278-2024 preview as PDF

Preview — first pages of GB/T 30278-2024 (full document: 36 pages)

This is a limited preview

Buy now to download the full PDF (36 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

November 28, 2024

Implementation date

June 1, 2025

Scope

GB/T 30278-2024 is the English-translated version of 网络安全技术 政务计算机终端核心配置规范.

GB/T 30278-2024 specifies the core security configuration for the computers used in Chinese government work. It is the Chinese equivalent of a government security baseline: rather than describing objectives, it states the actual settings a terminal must carry, which makes it directly usable by the administrators who have to deploy them and directly informative to anyone who wants to know how a Chinese government endpoint is hardened. It gives an overview of the core configuration approach, then the configuration requirements in detail, for the BIOS, for the operating system, for office software, for the browser, for the email client and for the other components that make up a working terminal, covering account and password policy, audit, access control, network services, removable media, patching and the security functions that must be enabled or disabled. It then covers the implementation and management of the configuration, its verification and the handling of deviations. The 2024 edition brings the baseline up to date with current operating systems and domestic software. It takes effect on 1 June 2025.

Document preview — GB/T 30278-2024

National Standard of the People's Republic of China

ICS
35.030
Classification
L80

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 1 Scope1
  • 2 Normative references1
  • 3 Terms and Definitions1
  • 4 Abbreviations2
  • 5 Overview2
  • 6 Configuration Requirements3
  • 6.1 BIOS Configuration Requirements3
  • 6.2 Operating System Configuration Requirements4
  • 6.3 Office Software Configuration Requirements6
  • 6.4 Browser Configuration Requirements6
  • 6.5 Email Client Configuration Requirements6
  • 6.6 Security protection software configuration requirements7
  • 6.7 Instant messaging software configuration requirements7
  • 7 Automated deployment and monitoring requirements8
  • 7.1 Logical architecture of automated deployment and monitoring platform8
  • 7.2 Configuration Editing Function Requirements8
  • 7.3 Configuration Verification Function Requirements9
  • 7.4 Configuration and deployment functional requirements9
  • 7.5 Configuration monitoring function requirements9
  • 9 Configuration Requirements Verification Method12
  • 27 Reference32

Foreword

This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part

1.Structure and drafting rules for standardization documents" Drafting. This document replaces GB/T 30278-2013 "Information Security Technology Government Computer Terminal Core Configuration Specification" and GB/T 35283- 2017 "Information Security Technology Computer Terminal Core Configuration Baseline Structure Specification". This document is based on GB/T 30278-2013 and includes Compared with GB/T 30278-2013 and GB/T 35283-2017, in addition to structural adjustments and compilation In addition to logical changes, the main technical changes are as follows:

--- Added instant messaging software and 5 security control points (see 5.1, 5.2);

--- Added configuration requirements for identity authentication, access control, trusted verification, and data confidentiality (see 6.1);

---Added configurations for trusted verification, data confidentiality, data backup and recovery, personal information protection, application management, and data transmission control Requirements (see 6.2);

--- Added configuration requirements for access control, intrusion prevention, personal information protection, residual information protection, and data transmission control (see 6.4);

--- Added instant messaging software configuration requirements (see 6.7);

--- Added configuration requirement verification method and automated deployment and monitoring requirement verification method (see Chapter 9, Chapter 10);

--- Added normative reference document ISO /IEC 18180.2013 to replace the custom baseline configuration automation file format (see Appendix Record A). Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents. This document was proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260). This document was drafted by: China Cyberspace Security Technology Co., Ltd., National Information Center, Kylin Software Co., Ltd., Huawei Technologies Co., Ltd., Beijing Topsec Network Security Technology Co., Ltd., Changyang Technology (Beijing) Co., Ltd., Tongxin Software Technology Co., Ltd., E-Government National Engineering Laboratory for Cloud Technology Application, China Electronics Standardization Institute, Lenovo (Beijing) Co., Ltd., Beijing Shengxin Network Technology Co., Ltd. Ltd., China Science and Technology Information Security Common Technology National Engineering Research Center Co., Ltd., Alibaba Cloud Computing Co., Ltd., Zhengzhou Xindajiean Information Technology Co., Ltd., Beijing Qihoo Technology Co., Ltd., 360 Technology Group Co., Ltd., Xi'an University of Posts and Telecommunications, Kunlun Technology (Beijing) Technology Co., Ltd., Beijing Shenzhou Green Alliance Technology Co., Ltd., Qi'anxin Technology Group Co., Ltd., Xi'an Jiaotong University Jabil Network Technology Co., Ltd. Technology Co., Ltd., Beijing Zhongke Weilan Technology Co., Ltd., Inspur (Shandong) Computer Technology Co., Ltd., Jilin Information Security Evaluation Center, Beijing Beixinyuan Software Co., Ltd., Beijing Shanshi Network Technology Co., Ltd., Shenzhen Nengxinan Technology Co., Ltd., Venusstar Information Technology Group Co., Ltd., National Confidentiality Technology Evaluation Center, State Grid Xinjiang Electric Power Co., Ltd. Power Science Research Institute, Datang Gaohong Xinan (Zhejiang) Information Technology Co., Ltd., the Fifth Electronic Research Institute of the Ministry of Industry and Information Technology, and Antiy Technology Group Co., Ltd. Company, China Software Evaluation Center (Software and Integrated Circuit Promotion Center of the Ministry of Industry and Information Technology), Beijing University of Posts and Telecommunications, China Unicom (Sichuan) Industry INTERNET LIMITED. The main drafters of this document are. Zhang Jianjun, Liu Bei, Yang Shangxin, Meng Yaping, Chen Yunran, Wang Qiang, Zhan Mao, Dong Junping, Wang Zhen, Gui Yao, Zhang Yu, An Gaofeng, Zhao Hua, He Xuelin, Xu Tao, Yan Guixun, Li Zhanwei, Zhu Hua, Li Ruxin, Liu Jun, Sun Liang, He Jianfeng, Bian Jianchao, Dudu, Hu Jianxun, Long Qin, Liu Weihua, Yao Yinan, Zhang Zhilei, Li Fuqin, Liao Baicheng, Zhang Yong, Li Dequan, Hua Chang, An Jincheng, Guo Wei, Bai Xinlu, Li Yan, Liu Zhanfeng, Yang Yong, Zhao Yong, Liang Guiqian, Li Deqing, Ma Jin, Jia Nan, Liu Bo, Ma Wei, Liu Haijie, Chai Siyue, Zhang Shenghua, Zhang Lei, Zhou Runsong, Guo Ying, Ma Xiangliang, Li Shijing and Zhang Tao. The previous versions of this document and the documents it replaces are as follows:

---GB/T 30278-2013;

---GB/T 35283-2017;

---This is the first revision.

The core configuration specification of government computer terminals is to ensure the computer security of government departments and reduce the risk of system security problems caused by improper configuration. To reduce the risk of full vulnerabilities, establish a security baseline for government computers, and guide the deployment of security configuration baselines in government office environments. This document is based on the three-level security requirements of GB/T 22239-2019 "Basic Requirements for Information Security Technology Network Security Level Protection" The full configuration baseline takes the seven types of software commonly used on government computers as the core configuration scope of this document, and proposes Security configuration requirements, guide software vendors and security vendors to formulate core configuration baselines according to requirements, and guide government departments to complete computer security verification. When users refer to this document to protect government terminal data, they should follow the classification and grading standards of government terminal data. GB/T 30278-2013 has been issued and implemented for more than ten years. The concept of government computer terminal security baseline has received more and more attention, and both the government office environment and computer technology have changed. First, as computer technology changes, the government office environment presents a variety of software of the same type and complex security configuration. Secondly, with the advancement of computer hardware and software technology, the widespread use of biometric technology and trusted computing technology has made computing In view of this, it is necessary to revise and improve GB/T 30278 and GB/T 35283 in a timely manner to continuously adapt to the government environment. new changes in the environment and new requirements for security baselines. Cybersecurity Technology Core Configuration Specifications for Government Computer Terminals

1 Scope

GB/T 30278-2024 specifies the core security configuration for the computers used in Chinese government work. It is the Chinese equivalent of a government security baseline: rather than describing objectives, it states the actual settings a terminal must carry, which makes it directly usable by the administrators who have to deploy them and directly informative to anyone who wants to know how a Chinese government endpoint is hardened. It gives an overview of the core configuration approach, then the configuration requirements in detail, for the BIOS, for the operating system, for office software, for the browser, for the email client and for the other components that make up a working terminal, covering account and password policy, audit, access control, network services, removable media, patching and the security functions that must be enabled or disabled. It then covers the implementation and management of the configuration, its verification and the handling of deviations. The 2024 edition brings the baseline up to date with current operating systems and domestic software. It takes effect on 1 June 2025.

This document defines the core configuration objects and configuration scope of government computer terminals, and stipulates configuration requirements, automated deployment and monitoring requirements. It provides a method to verify the configuration requirements and the automated deployment and monitoring requirements. This document applies to the core configuration technology implementation and testing and verification of government computer terminals.

2 Normative references

The contents of the following documents constitute the essential terms of this article through normative references in this article. For referenced documents without a date, only the version corresponding to that date applies to this document; for referenced documents without a date, the latest version (including all amendments) applies to This document.

GB/T 22239-2019 Information security technology - Basic requirements for cybersecurity level protection

GB/T 25069-2022 Information Security Technical Terminology

GB/T 25100-2010 Dublin Core Metadata Element Set for Information and Documentation

GB/T 25647-2010 E-government terminology

GB/T 40692-2021 Definition and scope of government information system

3 Terms and definitions

GB/T 22239-2019, GB/T 25069-2022, GB/T 25647-2010 and GB/T 40692-2021 and The following terms and definitions apply to this document.

3.1 Computer terminals that support government departments in carrying out their business operations.

Note. Such as desktop computers, laptops, and virtual desktops.

3.2 Core configuration coreconfiguration The process of setting parameters for core configuration items (3.3).

Note. By limiting or disabling functions with potential security risks or loopholes through core configuration, and enabling or strengthening security protection functions, the computer can be strengthened to resist security risks. ability.

3.3 Key parameter configuration items that affect the security of government computer terminal systems or software.

Note. Core configuration item types include switch items, enumeration items, interval items, and compound items.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 36 pages — is available in the English PDF.

Referenced standards

Similar standards

GB 38031-2025|GB/T 30278|GB/T 30278-2013|GB/T30278-2024|GB/T 35283-2017|GB/T 1.1-2020|GB/T 35283|GB/T 22239-2019

How to Buy GB/T 30278-2024

  1. 1Add to cart. Click the "Buy GB/T 30278-2024" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
36 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 30278-2024

$635.00

$540.00for partners