GB/T 34942-2025Cybersecurity technology — The assessment method for security capability of cloud computing service (English PDF)
网络安全技术 云计算服务安全能力评估方法
Open the GB/T 34942-2025 preview as PDF
This is a limited preview
Buy now to download the full PDF (121 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
August 1, 2025
Implementation date
February 1, 2026
Scope
GB/T 34942-2025 is the English-translated version of 网络安全技术 云计算服务安全能力评估方法.
GB/T 34942-2025 is the Chinese national standard covering how an assessor checks what a cloud provider claims — the evidence to be collected and the assessment process, then the method for each domain: system development and supply chain, communication protection and the security of system, network and storage virtualisation, access control and API security, data protection, configuration and maintenance, emergency response, audit, continuous monitoring, personnel, and physical security, with the scores rolled into one overall judgement. The data protection chapter and the assessment by capability level are new. Issued on 1 August 2025, it has been in force since 1 February 2026, replacing GB/T 34942-2017.
Document preview — GB/T 34942-2025
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L 80
- Replacing
- GB/T 34942-2017
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- PrefaceVII
- IntroductionVIII
- 1 Scope1
- 2 Normative references1
- 3 Terms and Definitions1
- 4 Abbreviations2
- 5 Overview2
- 5.1 Evaluation Principles2
- 5.2 Assessment Content3
- 5.3 Evaluating the evidence3
- 5.4 Evaluation Implementation Process3
- 5.5 Comprehensive Assessment5
- 6 System Development and Supply Chain Security Assessment Methods6
- 6.1 Resource Allocation6
- 6.2 System Lifecycle6
- 6.3 Procurement Process7
- 6.4 System Documentation9
- 6.5 Criticality Analysis10
- 6.6 External Services10
- 6.7 Developer Security Architecture12
- 6.8 Development Process, Standards and Tools13
- 6.9 Development Process Configuration Management15
- 6.10 Developer Security Testing and Assessment16
- 6.11 Training provided by developers20
- 6.12 Component Authenticity20
- 6.13 Unsupported System Components21
- 6.14 Supply Chain Protection22
- 7 System and Communication Protection Assessment Methods25
- 7.1 Boundary Protection25
- 7.2 Transmission confidentiality and integrity protection28
- 7.3 Network Interruption29
- 7.4 Trusted Path30
- 7.5 Password Usage and Management31
- 7.6 Device Access Protection31
- 7.7 Mobile Code33
- 7.8 Session Authentication34
- 7.9 Malicious Code Protection35
- 7.10 Memory Protection37
- 7.11 System Virtualization Security37
- 7.12 Network Virtualization Security40
- 7.13 Storage Virtualization Security41
- 7.14 Communication protection of security management functions43
- 8 Access Control Assessment Methods45
- 8.1 User identification and authentication45
- 8.2 Identifier Management46
- 8.3 Authentication Credential Management47
- 8.4 Authentication Credentials Feedback49
- 8.5 Cryptographic Module Authentication49
- 8.6 Account Management50
- 8.7 Enforcement of Access Control51
- 8.8 Information Flow Control52
- 8.9 Least Privilege54
- 8.10 Unsuccessful Login Attempts55
- 8.11 System Usage Notice56
- 8.12 Previous Visit Notice56
- 8.13 Concurrent Session Control57
- 8.14 Session Lock57
- 8.15 Actions to be taken if marking and identification are not carried out58
- 8.16 Security Attributes58
- 8.17 Remote Access59
- 8.18 Wireless Access60
- 8.19 Use of external information systems61
- 8.20 Publicly accessible content63
- 8.21 Global WAN (Web) Access Security63
- 8.22 API Access Security64
- 9 Data Protection Assessment Methodology65
- 9.1 General Data Security65
- 9.2 Media Access and Use66
- 9.3 Residual Information Protection69
- 9.4 Data Usage Protection70
- 9.5 Data Sharing Protection70
- 9.6 Data Migration Protection71
- 10 Configuration Management Assessment Methods72
- 10.1 Configuration Management Plan72
- 10.2 Baseline Configuration73
- 10.3 Change Control75
- 10.4 Configuration Parameters78
- 10.5 Principle of Minimum Functionality79
- 10.6 Information System Component List80
- 11 Maintenance Management Assessment Methods82
- 11.1 Controlled Maintenance82
- 11.2 Maintenance Tools84
- 11.3 Remote Maintenance85
- 11.4 Maintenance Personnel86
- 11.5 Timely Maintenance88
- 11.6 Bug Fixes88
- 11.7 Safety Function Verification89
- 11.8 Software and Firmware Integrity90
- 12 Emergency Response Assessment Methods91
- 12.1 Incident Handling Plan91
- 12.2 Event Handling93
- 12.3 Incident Report94
- 12.4 Event Handling Support95
- 12.5 Security Alert96
- 12.6 Error Handling97
- 12.7 Emergency Response Plan98
- 12.8 Emergency Response Training100
- 12.9 Emergency Drills101
- 12.10 Information System Backup102
- 12.11 Supporting Customers' Business Continuity Plans104
- 12.12 Telecommunication Services105
- 13 Audit Assessment Methods106
- 13.1 Auditable Events106
- 13.2 Audit Record Contents107
- 13.3 Audit Record Storage Capacity107
- 13.4 Response to Audit Process Failure108
- 13.5 Audit review, analysis and reporting109
- 13.6 Audit Processing and Report Generation111
- 13.7 Timestamp112
- 13.8 Audit Information Protection113
- 13.9 Non-repudiation114
- 13.10 Audit Record Retention115
- 14 Risk Assessment and Continuous Monitoring Assessment Methodology116
- 14.1 Risk Assessment116
- 14.2 Vulnerability Scanning117
- 14.3 Continuous Monitoring118
- 14.4 Information System Monitoring120
- 14.5 Spam Monitoring122
- 15 Security Organization and Personnel123
- 15.1 Security Policies and Procedures123
- 15.2 Security Organization124
- 15.3 Job Risks and Responsibilities125
- 15.4 Personnel Screening126
- 15.5 Staff Resignation126
- 15.6 Personnel Transfer128
- 15.7 Third-party personnel safety128
- 15.8 Personnel Punishment129
- 15.9 Safety Training130
- 16 Physical and Environmental Security Assessment Methods131
- 16.1 Physical Facilities and Equipment Site Selection131
- 16.2 Physical and Environmental Planning132
- 16.3 Physical Environment Access Authorization134
- 16.4 Physical Environment Access Control135
- 16.5 Output Device Access Control137
- 16.6 Physical Access Monitoring137
- 16.7 Visitor Access Records138
- 16.8 Equipment Transport and Removal139
- Appendix A (Informative) Common Cloud Computing Service Vulnerabilities141
- A.1 Overview141
- A.2 System Development and Supply Chain Security141
- A.3 System and Communication Protection142
- A.4 Access Control143
- A.5 Data Protection145
- A.6 Configuration Management147
- A.7 Maintenance Management149
- A.8 Emergency Response150
- A.9 Audit151
- A.10 Risk Assessment and Continuous Monitoring Assessment Methodology152
- A.11 Security Organization and Personnel154
- A.12 Physical and Environmental Security155
- Appendix B (Informative) Description of Single Safety Requirements Assessment156
- Reference157
Foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting.
This document replaces GB/T 34942-2017 "Information Security Technology Cloud Computing Service Security Capability Assessment Method" and is in line with GB/T Compared with 34942-2017, in addition to structural adjustments and editorial changes, the main technical changes are as follows.
a) The applicable limits of the scope have been changed (see Chapter 1, Chapter 1 of the 2017 edition);
b) Added assessment requirements for different capability levels and comprehensive assessment requirements (see 5.2 and 5.5);
c) The specific assessment methods have been changed (see Chapters 6 to 8, 10 to 14, and Chapters 5 to 14 of the 2017 edition);
d) Added data protection assessment method (see Chapter 9).
Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.
This document is proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260).
This document was drafted by: China Electronics Technology Standardization Institute, China Cybersecurity Review and Certification and Market Supervision Big Data Center, National Information Technology Security Research Center, China Information Security Evaluation Center, China Academy of Information and Communications Technology, University of Science and Technology of China, Sichuan University China University of Posts and Telecommunications, China National Cyberspace Administration of China, China Great Wall Internet System Application Co., Ltd., State Information Center, National Industrial Information Security Development Research Institute Research Center, National Computer Network Emergency Response Technology Coordination Center, the 15th Research Institute of China Electronics Technology Group Corporation, and the Software Research Institute of the Chinese Academy of Sciences.
Institute of Information Engineering, Chinese Academy of Sciences, Hangzhou Anheng Information Technology Co., Ltd., Beijing University of Aeronautics and Astronautics, Beijing Institute of Technology University of Posts and Telecommunications, Chongqing University of Electronic Science and Technology, Xidian University, Beijing University of Chemical Technology, Renmin University of China, Communication University of China, Tsinghua University, Shanghai Municipal Information Security Evaluation and Certification Center, the 30th Research Institute of China Electronics Technology Group Corporation, the Archives Information Center of Chongqing Municipal Market Supervision Administration, Mongolia Digital Economy Security Technology Co., Ltd., China Mobile Communications Co., Ltd. Research Institute, Huawei Cloud Computing Technology Co., Ltd., Alibaba Cloud Computing Co., Ltd., Tianyi Cloud Technology Co., Ltd., and AsiaInfo Technologies (Chengdu) Co., Ltd.
The main drafters of this document are: Yang Jianjun, Wang Huili, Jia Dawen, He Yanzhe, Wu Yang, Hu Huaming, Lu Xia, Zhang Lina, Liu Jialiang, Zhang Jianjun, Li Jingchun, Zuo Xiaodong, Chen Xingshu, Min Jinghua, Zhou Yachao, Shi Dawei, Chen Yonggang, Zhang Liwu, Yang Chen, Fang Yong, Cao Ling, Zhang Mingtian, Wu Bin, Ma Qingdong, Qu Ping, Zhang Dongju, Ji Lei, Li Yanwei, Huo Shanshan, Wu Qianhong, Yang Zhen, Huang Yonghong, Ma Wenping, Xi Ning, Yang Li, Pei Qingqi, Wang Mingyan, Qin Bo, Yang Yang, Ge Xiaonan, Yan Min, Jiang Zhengtao, Li Na, Cai Yuyuan, Liu Yan, Ge Zhenpeng, Fan Xiaohui, Xiao Min, Han Xuefeng, Li Lianlei, Gao Qiang, Xu Yu, Jin Song, Zhang Ling, Li Fengfeng, Fang Qiang, Si Boyang, and Liao Shuangxiao.
The previous versions of this document and the documents it replaces are as follows.
— First published in 2017 as GB/T 34942-2017;
— This is the first revision.
Introduction
GB/T 31168-2023 "Information Security Technology Cloud Computing Service Security Capability Requirements" puts forward the requirements for cloud service providers to ensure the security of cloud computing environment.
The security capabilities that should be possessed to ensure the security of customer information and business in a cloud computing environment. This standard divides the cloud computing service security capability requirements into general requirements, enhanced requirements, and Strong requirements and advanced requirements, enhanced requirements and advanced requirements are the supplement and reinforcement of the lower level requirements.
Cloud service providers should have appropriate security capabilities depending on the sensitivity and business importance.
This document is the supporting evaluation standard of GB/T 31168-2023, corresponding to Chapter 6 to Chapter 16 of GB/T 31168-2023 This document also provides the corresponding evaluation methods from Chapter 6 to Chapter 16.
Provide guidance for the security capability assessment of computing services. Third-party assessment agencies can develop corresponding security assessment plans, using multiple methods such as interviews, inspections, and tests.
This document can also provide a reference for cloud service providers to conduct self-assessments. Cybersecurity Technology Cloud computing service security capability assessment method
1 Scope
This document establishes the principles and implementation process for conducting assessments based on GB/T 31168-2023 and describes the specific safety requirements for each Methods for conducting assessments.
This document is suitable for third-party assessment agencies to assess the security capabilities of cloud service providers when providing cloud computing services.
It provides a reference for service providers when conducting self-assessment.
2 Normative references
GB/T 20984-2022
GB/T 25069-2022
GB/T 31167-2023
GB/T 31168-2023
GB/T 35273
GB/T 37972
GB 50174
3 Terms and Definitions
The terms and definitions defined in GB/T 25069-2022, GB/T 31167-2023 and GB/T 31168-2023 and the following terms and definitions apply In this document.
3.1 cloud computing
A model that provides access to scalable and flexible physical or virtual resource pools over the network and enables on-demand self-service acquisition and management.
Note. Examples of resources include servers, operating systems, networks, software, applications, and storage devices.
[Source. GB/T 31168-2023, 3.1]
3.2 [Source. GB/T 31168-2023, 3.2]
The ability to provide one or more resources using cloud computing (3.1) using defined interfaces.
3.3 cloud service provider
A party providing cloud computing services (3.2).
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 121 pages — is available in the English PDF.
Referenced standards
Normative references
- GB/T 20984-2022Information security technology—Risk assessment method for information security
- GB/T 25069-2022Information security techniques—Terminology
- GB/T 31167-2023Information security technology—Security guidance for cloud computing services
- GB/T 31168-2023Information security technology—Security capability requirements for cloud computing services
- GB/T 35273Information security technology—Personal information security specification
- GB/T 37972Information security technology—Operation supervision framework of cloud computing service
GB 50174
How to Buy GB/T 34942-2025
- 1Add to cart. Click the "Buy GB/T 34942-2025" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 20984-2022 — Information security technology—Risk assessment method for information security
GB/T 25069-2022 — Information security techniques—Terminology
GB/T 31167-2023 — Information security technology—Security guidance for cloud computing services
Secure payment via Stripe
Payments accepted
GB/T 34942-2025
$2,180.00