GB/T 42447-2023Information security technology - Data security guidelines for telecom field (English PDF)
信息安全技术 电信领域数据安全指南
Open the GB/T 42447-2023 preview as PDF
This is a limited preview
Buy now to download the full PDF (15 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
March 17, 2023
Implementation date
October 1, 2023
Scope
GB/T 42447-2023 is the English-translated version of 信息安全技术 电信领域数据安全指南.
GB/T 42447-2023 covers how a telecom operator or any other telecom data processor protects the data it holds, from the principles down to the measures that attach to each stage of processing. Clause 6 states those principles, among them the rule that security is planned, built and operated in step with the platform carrying the data rather than bolted on once it runs. Clause 7 sets out the general measures — organizational responsibility first, then the management and technical controls that apply whatever is being done with the data — and clause 8 works through the processing activities themselves, from collection and storage onward through the data life cycle, each with the measures that belong to it. The terms are taken from GB/T 41479-2022, so the vocabulary lines up with the wider telecom data security framework. A carrier sees who contacts whom, from where and how often, for most of the population, and that record is valuable in the same measure that losing it is damaging; it is also scattered across signalling, billing, customer service and analytics, which is why the measures are organized by processing activity rather than by system. For carriers and telecom service providers, their platform vendors, and the auditors and regulators who review them.
Document preview — GB/T 42447-2023
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L80
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- Foreword3
- 1 Scope4
- 2 Normative references4
- 3 Terms and definitions4
- 4 Abbreviations5
- 5 General5
- 6 Security principles6
- 7 General security measures for telecom data6
- 8 Security measures for telecom data processing11
- Bibliography15
Foreword
This document was issued on 17 March 2023 by the State Administration for Market Regulation; Standardization Administration of the PRC and takes effect on 1 October 2023.
It is a GB/T standard: recommended rather than compulsory, but it is the text a Chinese reviewer applies when assessing a submission.
1 Scope
GB/T 42447-2023 covers how a telecom operator or any other telecom data processor protects the data it holds, from the principles down to the measures that attach to each stage of processing. Clause 6 states those principles, among them the rule that security is planned, built and operated in step with the platform carrying the data rather than bolted on once it runs. Clause 7 sets out the general measures — organizational responsibility first, then the management and technical controls that apply whatever is being done with the data — and clause 8 works through the processing activities themselves, from collection and storage onward through the data life cycle, each with the measures that belong to it. The terms are taken from GB/T 41479-2022, so the vocabulary lines up with the wider telecom data security framework. A carrier sees who contacts whom, from where and how often, for most of the population, and that record is valuable in the same measure that losing it is damaging; it is also scattered across signalling, billing, customer service and analytics, which is why the measures are organized by processing activity rather than by system. For carriers and telecom service providers, their platform vendors, and the auditors and regulators who review them.
This document provides security principles and general security measures for carrying
out data processing activities in the telecom field, as well as corresponding security
measures that should be taken during the implementation of data collection, storage,
use and processing, transmission, provision, disclosure, destruction, etc.
This document applies for guiding telecom data processors to carry out data security
protection work, and is also applies for guiding third-party organizations to carry out
telecom data security assessment work.
2 Normative references
The following referenced documents are indispensable for the application of this
document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
GB/T 41479-2022 Information security technology - Network data processing
security requirements
3 Terms and definitions
For the purpose of this document, the terms and definitions defined in GB/T 41479-
2022 and the following apply.
3.1
telecom data
Data generated and collected in the course of telecommunications filed business
operations.
NOTE 1: Such as user identity information, call data, location data, signaling data, base station
construction and operation and maintenance data, network optimization data, etc.
NOTE 2: Without causing confusion, “telecommunications field data” in this document is
referred to as “telecom data”.
3.2
NOTE 1: The identification rules for important data and core data refer to relevant national and
industry standards, and other data are general data. Since general data covers a wide range of
data, telecom data processors can refine and grade general data according to production and
operation needs.
NOTE 2: For links where general measures and enhancement measures are not distinguished,
general data, important data, and core data shall be protected with reference to the same
measures.
Remaining clauses in the full document
- 4 Abbreviations
- 5 General
- 6 Security principles
- 7 General security measures for telecom data
- 8 Security measures for telecom data processing
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 15 pages — is available in the English PDF.
Referenced standards
Normative references
Similar standards
How to Buy GB/T 42447-2023
- 1Add to cart. Click the "Buy GB/T 42447-2023" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 42447-2023
$185.00