Valid

GB/T 37939-2026Cybersecurity technology - Technical requirements for network storage security (English PDF)

网络安全技术 网络存储安全技术要求

Open the GB/T 37939-2026 preview as PDF

Preview — first pages of GB/T 37939-2026 (full document: 51 pages)

This is a limited preview

Buy now to download the full PDF (51 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

May 25, 2026

Implementation date

December 1, 2026

Scope

GB/T 37939-2026 is the English-translated version of 网络安全技术 网络存储安全技术要求.

GB/T 37939-2026 is the Chinese national standard covering securing networked storage - the authentication and access control on the storage network, the encryption of data at rest and in transit, the isolation between tenants, the integrity and the secure erasure of media that leave the building. It replaces GB/T 37939-2019 and takes effect on 1 December 2026. It was issued on 25 May 2026 and takes effect on 1 December 2026, replacing GB/T 37939-2019. The document is under the responsibility of the Standardization Administration of China. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.

Document preview — GB/T 37939-2026

National Standard of the People's Republic of China

ICS
35.030
Classification
L 80
Replacing
GB/T 37939-2019

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 6.3 Access Security
  • 6.4 System Security
  • 6.4.1 Reliable equipment operation
  • 6.4.1.1 Level
  • 6.4.1.2 Level
  • 6.4.1.3 Level
  • 6.4.4 System Integrity Protection
  • 6.4.4.1 Level
  • 6.4.4.2 Level
  • 6.5 Data Security
  • 6.5.1 Data Integrity
  • 6.5.1.1 Integrity of stored data 6.5.1.1.1 Level
  • 6.5.1.2 Integrity of Transmitted Data 6.5.1.2.1 Level
  • 6.5.2 Data Confidentiality
  • 6.5.2.1 Data Confidentiality 6.5.2.1.1 Level
  • 6.5.3 Data Availability
  • 6.6 Management Security
  • 6.6.1 Identity Management
  • 6.6.1.1 Identity Management 6.6.1.1.1 Level
  • 6.6.1.2 Account Security Management 6.6.1.2.1 Level
  • 6.6.2 Identity Authentication
  • 6.6.2.1 Authentication Mechanism Management 6.6.2.1.1 Level
  • 6.6.2.2 Password Security Management 6.6.2.2.1 Level

Foreword

GB/T 37939-2026 | Cybersecurity technology - Technical requirements for network storage security

GB/T 37939-2026 English version. Cybersecurity technology - Technical requirements for network storage security ICS

80 National Standards of the People's Republic of China Replaces GB/T 37939-2019 Network security technology and network storage security requirements Published on 2026-05-

25 Implemented on December 1, 2026 State Administration for Market Regulation The State Administration for Standardization issued a statement.

1.Scope This document specifies the security function requirements and security assurance requirements for network storage. This document applies to the design, development, testing, and evaluation of network storage.

4.Abbreviations The following abbreviations apply to this document. CER. Certificate CPU. Central Processing Unit DER. Distinguished Encoding Rules JKS. Java Keystore PEM. Privacy Enhanced Mail PKCS Requirements in areas such as security management. See Appendix A for a description of the security function requirements for each level of network storage. If no specific level of requirements is specified in this chapter, it means that Level 1, Level 2, and Level 3 all must comply with the requirements of this chapter; if there are explicit requirements... If a specific level of security function requirements is specified in a relevant chapter or clause, then that specific level must comply with the requirements of that chapter or clause. See the corresponding chapters or clauses for different levels of security function requirements. Table B.1 in Appendix B.

6.2 General Requirements It should comply with the requirements of Chapter 5 of GB 42250-2022 regarding identification and authentication, self-access control, self-security auditing, communication security, and support. It supports requirements regarding system security, product upgrades, user information security, and passwords.

6.3 Access Security

6.3.1 Access Authentication Applications accessing network storage should be authenticated and meet the following requirements.

a) Provide a unique identifier for the application and associate the identifier with all auditable events associated with it;

b) Authentication information should not be stored in plaintext, and authentication data should not be accessed or tampered with without authorization;

c) There is no access method that can bypass the authentication mechanism.

6.3.2 Access Control The design should be based on access control security policies to implement policy-controlled access control functions and meet the following requirements.

a) The scope of access control policies includes the subjects, objects, and operations between them related to resource access;

b) The content and operation permissions accessed to resources do not exceed the preset scope and comply with the principle of least privilege;

c) The networks connecting the server and storage, as well as the management network, should be isolated from each other and unable to access each other;

d) It has log auditing functionality;

e) If multi-protocol access is available, set up a unified access control policy.

6.4.1.1 Level

1 Safety Function Requirements It should have functions such as redundancy of management modules, power modules, and control modules, and provide fault tolerance and fault recovery capabilities.

6.4.1.2 Level

2 Safety Function Requirements It should meet the following requirements.

a) Centralized storage devices feature redundancy in management modules, power modules, and control modules, and provide fault tolerance and disaster recovery capabilities. Recovery ability;

b) It has the function of memory detection and error correction;

c) It has the function of detecting hard disks and solid-state drives.

6.4.1.3 Level

3 Safety Function Requirements It should meet the following requirements.

a) Centralized storage devices feature redundancy in management modules, power modules, and control modules, and provide fault tolerance and disaster recovery capabilities. Recovery ability;

b) It has the function of memory detection and error correction;

c) It has the function of detecting hard disks and solid-state drives;

d) It has the function of detecting CPU anomalies.

6.4.2 Equipment operating status monitoring It should have the function of automatically detecting the working status of the equipment, including but not limited to detecting hardware failures, network interruptions, network connection errors, and quota limitations. It includes functions such as quantity warning and business anomaly warning, and issues alarms for detected abnormal equipment status.

6.4.3 Software and Software Operation Security The system software and its operating environment should not contain vulnerabilities that are known to be classified as high-risk or medium-risk.

6.4.4.1 Level

2 Safety Function Requirements System integrity protection functions should be provided, meeting the following requirements.

a) The software installation package is protected for integrity;

b) It has the function of verifying the integrity of firmware during firmware upgrades and installations.

6.4.4.2 Level

3 Safety Function Requirements System integrity protection functions should be provided, meeting the following requirements.

a) The software installation package is protected for integrity;

b) It has the function of verifying firmware integrity during firmware upgrades and installations;

c) Digitally sign the software package.

6.4.5 Safety reinforcement Level 2 and Level 3 should have safety reinforcement functions and meet the following requirements.

a) The operating system, database, and file system should be hardened for security.

b) Disable unnecessary system services, default shares, and ports;

c) It has the function to disable insecure access protocols, and this function is disabled by default;

d) You cannot log in remotely using the root account directly.

6.4.6 Web Security Level 2 and Level 3 should provide web security features and meet the following requirements.

a) For each request that requires authorized access, verify whether the user's session ID is valid and whether the user is authorized to perform this operation;

b) It has the function of content verification for all data from untrusted data sources, and rejects any data that fails the verification;

c) If the data output to the client comes from an untrusted data source, then the data is encoded or escaped accordingly;

d) When uploading files via the web, a whitelist should be used on the server side to classify the file types uploaded to the web content directory. Line restrictions;

6.5.1.1 Integrity of stored data 6.5.1.1.1 Level

1 Safety Function Requirements It should have the capability to detect data integrity errors during storage and provide necessary recovery measures. 6.5.1.1.2 Level

2 Safety Function Requirements Data integrity protection during storage processes should meet the following requirements.

a) It has the function of detecting data integrity errors during storage and provides automatic recovery in the presence of redundant data;

b) It has the function of automatically detecting data integrity errors and providing automatic recovery function in the case of redundant data;

c) The file storage device has a file system-level security snapshot function;

d) It has WORM functionality. 6.5.1.1.3 Level

3 Safety Function Requirements Data integrity protection during storage processes should meet the following requirements.

a) It has the function of detecting data integrity errors during storage and provides automatic recovery in the presence of redundant data;

b) It has the function of automatically detecting data integrity errors and providing automatic recovery function in the case of redundant data;

c) It has the function of recovering accidentally deleted logical units/file systems;

d) The file storage device has a file system-level security snapshot function;

e) It has WORM functionality.

6.5.1.2 Integrity of Transmitted Data 6.5.1.2.1 Level

2 Safety Function Requirements It provides integrity protection for data transmitted within network storage and has the function of detecting data integrity errors during transmission. 6.5.1.2.2 Level

3 Safety Function Requirements To provide integrity protection for data transmitted between different components and parts within network storage, the following requirements must be met.

a) It has the function of detecting data integrity errors during transmission;

b) When a data integrity error is detected, perform the necessary data recovery operations.

6.5.1.3 Processing Data Integrity Level 2 and Level 3 should have the function of protecting the integrity of the data being processed.

6.5.2.1 Data Confidentiality 6.5.2.1.1 Level

1 Safety Function Requirements System management data should not be exposed to the public and should be stored in a non-plaintext format, meeting the following requirements.

a) Sensitive information such as system passwords must be stored locally without being in plain text and must be encrypted for protection;

b) Do not expose sensitive information such as system passwords, keys, and session identifiers in URLs, logs, error messages, or debugging information. 6.5.2.1.2 Level

2 Safety Function Requirements Data confidentiality should be protected in accordance with the following requirements.

a) It has the function of transparent encryption and decryption of data storage.

b) When transmitting data between untrusted networks, use a secure transmission channel or transmit data after encryption.

c) System management data is not exposed externally, is stored in a non-plaintext format, and meets the following requirements. 1) Sensitive information such as system passwords should not be stored in plain text locally; they must be encrypted and protected. 2) Do not expose sensitive information such as system passwords, keys, and session identifiers in URLs, logs, error messages, or debugging information.

d) Access to sensitive data should have authentication, authorization, or encryption mechanisms.

e) It has the function of encrypting the stored data. 6.5.2.1.3 Level

3 Safety Function Requirements Data confidentiality should be protected in accordance with the following requirements.

a) It has the function of transparent encryption and decryption for data to be written to disk.

b) It has encryption functionality during data transmission.

c) System management data should not be exposed externally and should be stored in a non-plaintext format, meeting the following requirements. 1) Sensitive information such as system passwords should not be stored in plain text locally; they must be encrypted and protected. 2) Do not expose sensitive information such as system passwords, keys, and session identifiers in URLs, logs, error messages, or debugging information.

d) Access to sensitive data must have authentication, authorization, or encryption mechanisms.

6.5.3 Data Availability

6.5.3.1 Backup and Restore 6.5.3.1.1 Level 1 safety function requirements. It should have the function of data backup and recovery, and meet the following requirements.

a) It has the function of manually backing up and restoring data;

b) It has the function of performing full backup and backup recovery of data;

c) It has the function of asynchronous backup and backup recovery of data;

d) It has the function of local backup and backup recovery of data;

e) It has snapshot-based data backup and recovery functions. 6.5.3.1.2 Level 2 and Level 3 safety function requirements It should have the function of data backup and recovery, and meet the following requirements.

a) It has the function of manually backing up and restoring data;

b) It has the function of performing full backup and backup recovery of data;

c) It has the function of asynchronous backup and backup recovery of data;

d) It has the function of local backup and backup recovery of data;

e) It has snapshot-based data backup and recovery capabilities;

f) It has the function of automatic data backup and recovery;

g) It has the function of incremental backup and backup recovery of data;

h) It has the function of synchronous backup and backup recovery of data;

6.6.1.1 Identity Management 6.6.1.1.1 Level

1 Safety Function Requirements The device should provide a user identification function, giving each user a unique identity. 6.6.1.1.2 Level

2 Safety Function Requirements The device user identification function should be provided, and should meet the following requirements.

a) Provide each user with a unique identifier;

b) Unauthorized users cannot access or manage user identity information. 6.6.1.1.3 Level

3 Safety Function Requirements The device user identification function should be provided, and should meet the following requirements.

a) Provide each user with a unique identifier;

b) Unauthorized users cannot access or manage user identity information;

c) Associate the user's identity with all auditable events for that user.

6.6.1.2 Account Security Management 6.6.1.2.1 Level

1 Safety Function Requirements It should meet the following requirements.

a) Accounts in the system are unique;

b) No undisclosed accounts are reserved; all accounts can be managed by the system, and all accounts and management operations are provided in the information. illustrate. 6.6.1.2.2 Level 2 and Level 3 safety function requirements It should meet the following requirements.

a) Accounts in the system are unique;

b) No undisclosed accounts are reserved; all accounts are manageable by the system, and all accounts and management operations are provided in the information. illustrate;

c) If the product has its own database and multiple default accounts exist, disable or delete unused accounts; if deletion or disabling is not possible, in the product... The product information prompts users to change the default account password and update it regularly.

6.6.1.3 Account Permission Management It should meet the following requirements.

a) Adopt a role-based account access control model;

b) Account authorization should be based on the principle of least privilege;

c) Accounts in the system cannot modify their own permissions.

6.6.2.1 Authentication Mechanism Management 6.6.2.1.1 Level

1 Safety Function Requirements It should meet the following requirements.

a) Before a user performs an operation on network storage, the user making the operation request must be authenticated;

b) The final authentication and authorization process for users shall be carried out on the server side according to the principle of authentication first and then execution. 6.6.2.1.2 Level

2 Safety Function Requirements It should meet the following requirements.

a) Before a user performs an operation on network storage, the user making the operation request must be authenticated;

b) The final authentication and authorization process for users is performed on the server side according to the principle of authentication before execution;

c) After a user's consecutive authentication failures reach a set number, measures will be taken to prevent the user from making further requests;

d) If a user's operation times out and the connection is terminated, authentication will be performed again upon reconnection;

e) It has the function of storing user authentication information in non-plaintext, and the authentication data cannot be viewed or modified without authorization. 6.6.2.1.3 Level

3 Safety Function Requirements It should meet the following requirements.

a) Before a user performs an operation on network storage, the user making the operation request must be authenticated;

b) The final authentication and authorization process for users is performed on the server side according to the principle of authentication before execution;

c) After a user's consecutive authentication failures reach a set number, measures will be taken to prevent the user from making further requests;

d) If a user's operation times out and the connection is terminated, authentication will be performed again upon reconnection;

6.6.2.2 Password Security Management 6.6.2.2.1 Level

1 Safety Function Requirements It should meet the following requirements.

a) When managing the device for the first time, do not use the default password; force a change to the default password or set a new password.

b) It has the function of setting the password lifespan.

c) When a user enters a password, the password is not displayed in plain text.

d) At the management level, the system provides a function to check password complexity. If the set password does not meet the complexity requirements, setting it is not allowed. Successfully complete the setup and provide a reasonable prompt. For passwords automatically generated by the system, use a secure random number generator.

e) The password complexity meets the following requirements. 1) The password must be at least 8 characters long; 2) The password must contain a combination of at least two characters; 3) The password cannot be the same as the account name or the account name reversed.

f) Third-party and open-source software used in the product does not use default passwords.

g) There are no passwords that users cannot modify. For the default factory-set account/password or the encryption key used for transmission, [the system provides...]. Modify the mechanism to remind users to make changes and update regularly, and warn of risks.

h) The password input field provided cannot be copied.

i) The password in the operation interface is not displayed in plain text.

j) Set access permissions for the password file. Users without access permissions cannot read or copy passwords or other data.

k) When a user changes their password, force verification of the current password. 6.6.2.2.2 Level

2 Safety Function Requirements It should meet the following requirements.

a) At the management level, the system provides a function to check password complexity. If the set password does not meet the complexity requirements, it will not be set. If the setup fails, a message will be displayed indicating that the setup was unsuccessful. For passwords automatically generated by the system, a secure random number will be used to generate them.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 51 pages — is available in the English PDF.

Referenced standards

Editions of GB/T 37939

EditionTitleRevisionStatus
GB/T 37939-2026Cybersecurity technology - Technical requirements for network storage securitycurrent editionCurrent
GB/T 37939-2019Cybersecurity technology - Technical requirements for network storage securityprevious editionIn force until 1 December 2026

This page sells the current edition, GB/T 37939-2026. Earlier editions are listed for reference only.

How to Buy GB/T 37939-2026

  1. 1Add to cart. Click the "Buy GB/T 37939-2026" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
51 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 37939-2026

$410.00

$350.00for partners