Valid

GB/T 43708-2025General rules for scientific data security requirements (English PDF)

科学数据安全要求通则

Open the GB/T 43708-2025 preview as PDF

Preview — first pages of GB/T 43708-2025 (full document: 16 pages)

This is a limited preview

Buy now to download the full PDF (16 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

January 24, 2025

Implementation date

January 24, 2025

Scope

GB/T 43708-2025 is the English-translated version of 科学数据安全要求通则.

GB/T 43708-2025 gives the general rules for the security of scientific data in China. Scientific data is an awkward asset to secure: its value depends on being shared, much of it is generated by institutions with no security function, and yet parts of it, genomic, geospatial, meteorological, health, are exactly the categories the Data Security Law treats as important data with cross-border transfer restrictions. The standard sets the security goals and basic principles and then the basic framework for scientific data security, working through the data lifecycle, the collection, transmission, storage, processing, sharing and disposal, and setting for each the security requirements, together with the classification and grading of the data, the identification of important data among it, the access control and identity management, the security of the platforms that hold it, the requirements on cross-border provision, the monitoring and incident response, and the responsibilities of the institutions involved. It took effect on 24 January 2025.

Document preview — GB/T 43708-2025

National Standard of the People's Republic of China

ICS
35.240.70
Classification
A40

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 1 Scope1
  • 2 Normative references1
  • 3 Terms and Definitions1
  • 4 General Principles3
  • 4.1 Security Goal3
  • 4.2 Basic Principles3
  • 5 Basic Framework for Scientific Data Security3
  • 5.1 Overview3
  • 5.2 Dimensions of the scientific data life cycle4
  • 5.3 Data Security Attribute Dimensions4
  • 6 Security requirements for the scientific data lifecycle6
  • 6.1 Safety requirements for scientific data collection and processing6
  • 6.2 Security requirements for scientific data storage and backup6
  • 6.3 Security requirements for scientific data transmission and exchange6
  • 6.4 Security requirements for open sharing of scientific data6
  • 6.5 Security requirements for scientific data usage services7
  • 6.6 Security requirements for safe handling of scientific data7
  • 7 Scientific Data Physical Security Requirements7
  • 7.1 Physical security requirements for computer systems7
  • 7.2 Safety requirements for scientific data recording media8
  • 7.3 Safety requirements for the storage environment of scientific data recording media8
  • 10 Reference12

Foreword

This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part

1.Structure and drafting rules for standardization documents" Drafting. Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents. This document was proposed by the Ministry of Science and Technology of the People's Republic of China. This document is under the jurisdiction of the National Science and Technology Platform Standardization Technical Committee (SAC/TC486). This document was drafted by: China National Institute of Standardization, Computer Network Information Center of the Chinese Academy of Sciences, China Network Security Review Technology and Certification Center, Fujian CITIC Network Security Information Technology Co., Ltd., National Marine Information Center, Beijing University of Aeronautics and Astronautics, National Science and Technology Infrastructure Platform Center, Shanxi Huazheng Innovation Technology Research Institute Co., Ltd., Zhongke Xingrui Technology (Beijing) Co., Ltd., Zhonglu High-tech Transportation Technology Group Co., Ltd., the First Institute of Oceanography of the Ministry of Natural Resources, Fujian Big Data Level

1 Development Co., Ltd., Guangzhou Internet of Things Research Institute, China Southern Power Grid Network Services Co., Ltd., Institute of Tibetan Plateau Research, Chinese Academy of Sciences. The main drafters of this document are. Wang Zhiqiang, Liao Fangyu, Yang Qinghai, Hu Lianglin, Gan Jiefu, Su Jing, Jin Huasong, Xu Kaicheng, Jiang Xiaoyi, Zhao Qiyang, Wang Yi, He Yuntao, Zhu Yanhua, Ye Ling, Qu Dong, Liu Dongmei, Song Zhuanling, Li Zhe, Chen Luxin, Gao Shang, Duan Jinghui, Zhao Lin, Liang Guoxia, Li Xin.

Scientific data is a strategic and basic scientific and technological resource with the characteristics of fast dissemination, wide impact, and great potential for development and utilization. The Data Security Law of the People's Republic of China and the Personal Information Protection Law of the People's Republic of China have a significant impact on the country's scientific and technological progress and economic development. The Cybersecurity Law of the People's Republic of China is the basic law for the governance of my country's network data field, marking the country's support for a major network power and digital The institutional system for building a great power is more mature. The "Measures for the Administration of Scientific Data" clearly states that "the security management of scientific data throughout its life cycle should be strengthened." Management, formulate scientific data security protection measures; strengthen the authentication, authorization and other protection management of data downloads to prevent data from being used maliciously. "This document It is an important guarantee for effectively improving the information protection and compliance application capabilities in the field of scientific data, and can promote the data security capabilities of scientific data-related institutions. Strength improvement. This document is a basic scientific data security standard that comprehensively considers the security factors in the life cycle of scientific data and forms a comprehensive scientific data security standard. The life cycle dimension of the entire data process, as well as security based on confidentiality, availability, integrity, traceability, controllability and non-repudiation The requirements for attribute dimensions also unify the common terminology of scientific data security, see Appendix A. General Requirements for Scientific Data Security

1 Scope

GB/T 43708-2025 gives the general rules for the security of scientific data in China. Scientific data is an awkward asset to secure: its value depends on being shared, much of it is generated by institutions with no security function, and yet parts of it, genomic, geospatial, meteorological, health, are exactly the categories the Data Security Law treats as important data with cross-border transfer restrictions. The standard sets the security goals and basic principles and then the basic framework for scientific data security, working through the data lifecycle, the collection, transmission, storage, processing, sharing and disposal, and setting for each the security requirements, together with the classification and grading of the data, the identification of important data among it, the access control and identity management, the security of the platforms that hold it, the requirements on cross-border provision, the monitoring and incident response, and the responsibilities of the institutions involved. It took effect on 24 January 2025.

This document specifies the general requirements for scientific data security, including general principles, a basic framework for scientific data security, and scientific data life cycle security. scientific data security requirements, scientific data entity security requirements and scientific data security management requirements. This document applies to the collection, processing, storage, backup, transmission, exchange, open sharing, use services and safe disposal of scientific data. Data security throughout its life cycle.

2 Normative references

The contents of the following documents constitute the essential clauses of this document through normative references in this document. For referenced documents without a date, only the version corresponding to that date applies to this document; for referenced documents without a date, the latest version (including all amendments) applies to This document.

GB/T 9361-2011 Computer site safety requirements

GB/T 21052 Information security technology - Technical requirements for physical security of information systems

GB/T 34945 Information technology data traceability description model

GB/T 35274 Information security technology Big data service security capability requirements

GB/T 36092 Information technology backup storage backup technology application requirements

GB/T 37939 Information security technology Network storage security technical requirements

GB/T 37973 Information security technology Big data security management guide

GB/T 43705 Guidelines for the classification and grading of scientific data security

GB/T 43710 Scientific Data Security Audit Requirements GM/T 0054 Basic requirements for the application of cryptography in information systems

3 Terms and definitions

The following terms and definitions apply to this document.

3.1 scientific datascientificdata In the fields of natural sciences, engineering sciences, etc., the Records of original and derived information obtained by other means, or other data that can be used for scientific research activities.

3.2 Through management and technical measures, we will ensure the continuity of scientific data in the interests of national security, scientific and technological security, social public interests and the legitimate rights and interests of others. A state of being effectively protected and used in compliance with regulations. [Source: GB/T 37988-2019, 3.1, modified]

3.3 Scientific data is collected and processed, stored and backed up, transmitted and exchanged, shared, used and served, safely disposed, and finally reused.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 16 pages — is available in the English PDF.

Referenced standards

Similar standards

How to Buy GB/T 43708-2025

  1. 1Add to cart. Click the "Buy GB/T 43708-2025" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
16 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 43708-2025

$305.00

$260.00for partners