GB/T 44774-2024Specifications of emergency response management for vehicle cybersecurity (English PDF)
汽车信息安全应急响应管理规范
Open the GB/T 44774-2024 preview as PDF
This is a limited preview
Buy now to download the full PDF (23 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
October 26, 2024
Implementation date
October 26, 2024
Scope
GB/T 44774-2024 is the English-translated version of 汽车信息安全应急响应管理规范.
GB/T 44774-2024 sets the management process for vehicle cybersecurity emergency response. A vulnerability in a car is unlike one in a server: the fleet is in the hands of the public, a fix must be delivered over the air or through workshops to vehicles that may be moving, and a mistaken patch can be as dangerous as the flaw. Chinese regulation now requires manufacturers to have this capability, and the standard describes what it consists of. It sets the overall architecture and then the phases: preparation, verification, response, remediation and post-incident handling, with the roles, decisions and records belonging to each, and informative annexes giving an example of the emergency response process with its associated documents and the grading of both the response and the incident. It took effect on 26 October 2024.
Document preview — GB/T 44774-2024
National Standard of the People's Republic of China
- ICS
- 43.020
- Classification
- T40
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- 1 Scope
- 2 Normative References
- 3 Terms and Definitions
- 4 Overall Architecture Diagram
- 5 Preparation Phase
- 5.2 Formulation of Emergency Response Plan
- 5.3 Establishment of Roles and Responsibilities
- 5.3.2 Establishment of the responsibilities of each functional group
- 6 Verification Phase
- 6.3 Incident Assessment
- 6.4 Incident Notification
- 7 Response Phase
- 7.2 Formulation of Response Scheme
- 8 Remediation Phase
- 8.2 Formulation of Remediation Scheme
- 8.3 Verification of Remediation scheme
- 8.4 Implementation of Remediation Scheme
- 9 Post-Incident Handling Phase
- 9.2 Post-incident Summary
- 9.3 Post-incident Assessment and Tracking
1 Scope
GB/T 44774-2024 sets the management process for vehicle cybersecurity emergency response. A vulnerability in a car is unlike one in a server: the fleet is in the hands of the public, a fix must be delivered over the air or through workshops to vehicles that may be moving, and a mistaken patch can be as dangerous as the flaw. Chinese regulation now requires manufacturers to have this capability, and the standard describes what it consists of. It sets the overall architecture and then the phases: preparation, verification, response, remediation and post-incident handling, with the roles, decisions and records belonging to each, and informative annexes giving an example of the emergency response process with its associated documents and the grading of both the response and the incident. It took effect on 26 October 2024.
This document establishes the management process for the emergency response for vehicle cybersecurity and describes the relevant management methods. This document applies to vehicle cybersecurity emergency response management conducted by relevant organizations, including all phases of preparation, verification, response, remediation and post-incident handling.
2 Normative References
This document does not have normative references.
3 Terms and Definitions
The following terms and definitions are applicable to this document.
3.1 vehicle cybersecurity A state in which a vehicle's electronic and electrical systems, assemblies and functions, so that its assets are protected from threats. [Source: GB/T 40861-2021, 3.1]
3.2 vehicle cybersecurity incident A single or multiple identified vehicle cybersecurity states in a vehicle that may compromise an organization's assets or operations. NOTE. a cybersecurity state indicates a potential cybersecurity breach or the occurrence of a certain control failure.
3.3 emergency response plan An organization's policies and procedures for maintaining or recovering business operations, including information system operations, in response to emergent / significant cybersecurity incidents. [Source: GB/T 24363-2009, 3.5]
3.4 emergency response for vehicle cybersecurity Preparatory work undertaken by organizations, such as vehicle manufacturers, suppliers and other stakeholders, to respond to emergent vehicle cybersecurity incidents; measures taken after the occurrence of an incident (excluding unrelated work and measures within the suppliers and other stakeholders); and post-incident assessment, tracking and summary.
3.5 stakeholder Individuals or organizations that may be affected or aware of potential impacts due to adverse consequences or unfavorable outcomes resulting from a violation of one or multiple cybersecurity attributes (such as confidentiality, integrity and availability, etc.) of one or a group of assets.
3.6 organization Individuals or collectivities with their own responsibilities, authority, and relationships to achieve their objectives. NOTE. the concept of organization includes, but is not limited to, sole proprietors, companies, legal persons, commercial firms, enterprises, institutions, partnerships, charities or academies, or any part or combination thereof, whether incorporated or unincorporated, public or private. [Source: GB/T 20984-2022, 3.1.3]
4 Overall Architecture Diagram
The overall architecture of each phase of this document is shown in Figure 1.A complete example of the emergency response process is shown in A.1 of Appendix A.
5 Preparation Phase
5.1 Overview Organize and complete the preparation and revision of emergency response plans during this phase, including formulating emergency response plans, establishing roles and responsibilities, completing training, drills, management and updates of emergency response plans, formulating cybersecurity incident classification and grading specifications, and formulating and distributing cybersecurity emergency response operation manuals. Furthermore, a coordination and cooperation mechanism with relevant external organizations is established during this phase. NOTE. the cybersecurity emergency response operation manuals are independently formulated by the organization to guide specific technical operations within and outside the organization during the emergency response process.
5.2 Formulation of Emergency Response Plan
5.2.1 The emergency response plan shall clearly specify at least the following contents.
a) Roles and responsibilities;
b) Emergency response process;
c) Timelines for each process in the verification phase, response phase, remediation phase, and post-incident handling phase. In accordance with different emergency response levels, formulate different timelines. For the classification of emergency response levels, see B.1 in Appendix B;
d) Other relevant forms and attachments, etc.
5.2.2 The emergency response plan shall be based on the organization's specific circumstances and business characteristics and shall be operable.
5.2.3 When formulating emergency response plans, participants shall adhere to the following principles.
a) Confidentiality. emergency response information shall not be provided or disclosed to unauthorized individuals, entities or process.
b) Standardization. when formulating emergency response plans, adhere to the organization's relevant cybersecurity management system.
c) Minimum impact. the emergency response plan covers the minimum set of tasks required to complete the objective of emergency response.
5.3 Establishment of Roles and Responsibilities
5.3.1 Role division The organization shall establish a cybersecurity emergency response operating mechanism in conjunction with its daily organizational structure and clearly define its responsibilities. The requirements are as follows:
a) If one person assumes multiple responsibilities, or if multiple people assume a single responsibility, the emergency response plan document shall clearly define the mapping relationships between personnel and responsibilities. The order of personnel replacement for a single responsibility shall also be clearly defined.
b) The emergency response operating mechanism shall be composed of management, business, technical, and administrative support personnel, etc. Based on their roles, it can be divided into five functional groups. the emergency response leadership group, the emergency response expert group, the emergency response implementation group, the emergency response technical support group, and the emergency response daily operation group. Personnel shall be assigned to these groups based on their skills and knowledge. Personnel assigned to these groups should be responsible for the same or similar tasks in their daily work. Among these five functional groups, the organization shall at least set up emergency response leadership group, emergency response implementation group (incorporating the responsibilities of the expert group), and emergency response daily operation group (incorporating the responsibilities of the technical support group). In accordance with its own business characteristics and organizational structure, the organization may set up other groups (with self-defined names), but the relevant responsibilities shall be complete.
c) The organization may hire external experts with corresponding qualifications to assist with the emergency response or entrust an external institution with corresponding qualifications to undertake part of the work of the implementation group and the daily operation group. When hiring external experts or delegating tasks to external institutions, relevant agreements (such as confidentiality agreements, service level agreements and service continuity agreements) shall be signed with them.
d) Each functional group for emergency response shall clearly define its internal division of labor and responsibilities, and each group shall have a person in charge of overall coordination.
5.3.2 Establishment of the responsibilities of each functional group
5.3.2.1 Emergency response leadership group The emergency response leadership group serves as the leading body for cybersecurity emergency response and shall be led by a member of the organization's top management. The leadership team is responsible for leading and making decisions on major matters of cybersecurity emergency response. The requirements are as follows:
a) Establish emergency response expert group, emergency response implementation group, emergency response technical support group and emergency response daily operation group, and take charge of the overall management of the emergency response process;
b) Provide commitment and support for emergency response, including issuing official documentation and providing necessary resources (including personnel, financial resources and materials), etc.;
c) Approve the emergency response plan and documentation for each phase;
d) Approve and supervise the implementation of the emergency response plan;
e) Take charge of the notification of the occurrence of vehicle cybersecurity incidents
6 Verification Phase
6.1 Overview Based on the emergency response plan formulated by the organization and the vehicle cybersecurity incident classification and grading specifications, the emergency response daily operation group shall execute the vehicle cybersecurity incident confirmation and assessment processes, and the emergency response leadership group shall execute the incident reporting process.
6.2 Incident Confirmation After receiving intelligence regarding vehicle cybersecurity incident, the incident confirmation process shall be immediately initiated, with the following requirements.
a) Investigate and confirm the source of the intelligence of the vehicle cybersecurity incident, including but not limited to. 1) Security warning incidents found by the emergency response daily operation group; 2) Industry security warning intelligence received from authoritative industry platforms; 3) Security issues reported by customers or security researchers through the external incident collection channels established by the organization.
b) Record the elements of the incident and intelligence integrity check and identity verification results.
c) Conduct a preliminary judgment of the relevance of the incident-related assets to the vehicle manufacturers, suppliers and other stakeholders.
d) Record and document the incident confirmation results in detail.
6.3 Incident Assessment
6.3.1 Upon confirmation of a vehicle cybersecurity incident, the incident assessment process shall be immediately initiated. The requirements for the process and related documents are as follows:
a) Preliminarily determine the type, level and emergency response level of the vehicle cybersecurity incident and form a preliminary assessment conclusion. This should be comprehensively considered from multiple perspectives, including personnel safety, economy and property, vehicle functions and performance, privacy and regulations, and social impact. This judgment shall include aspects, such as incident relevance, scope of impact and worst-case scenarios, etc.
b) Review the preliminary assessment conclusions and submit relevant documents to the emergency response expert group for review, thereby, forming a vehicle cybersecurity incident assessment and review form (see A.2 for an example).
c) During the execution of the incident assessment process, data security and information confidentiality-related work shall satisfy the demand for traceability.
6.3.2 The vehicle cybersecurity incident assessment and review form shall include at least.
a) The focus of each expert involved in the incident assessment process;
b) Relevant information obtained, including impact and hazard, etc.;
c) The information processing and logical inference process;
d) The final assessment and review conclusion, including the type, level and emergency response level of the vehicle cybersecurity incident.
6.3.3 If the incident assessment process requires the introduction of personnel outside the emergency response group, the information of the introduced personnel recorded on the vehicle cybersecurity incident assessment and review form shall include at least.
a) Position and responsibilities within the organization;
b) Reason for introduction into the incident;
c) Incident information obtained during the work.
6.4 Incident Notification
6.4.1 After the incident assessment is completed, the incident notification process shall be immediately initiated. The requirements for the process and related documents are as follows:
a) Incident notification shall be easy to record and process-traceable, and the scope of information dissemination shall be controllable. It can be conducted through telephone conferences, on-site and online conferences, etc.
b) The incident notification conference shall form a vehicle cybersecurity incident record form (see example A.3) and archive it. If the conclusion is that an emergency response is not necessary, then, the current emergency response shall be terminated. If the conclusion is that an emergency response is necessary, the emergency response leadership group shall provide final approval and notify it to all members of the emergency response functional groups.
6.4.2 Minutes shall be generated for the incident notification conference. The minutes shall include at least the following contents.
a) Participants;
b) Details of the information and intelligence presented at the conference;
c) Assessment records;
d) The process of discussions among members of the emergency response functional groups and other personnel on the relevant information;
e) Conference resolutions;
f) Any remaining issues to be clarified or resolved.
7 Response Phase
7.1 Overview Based on the emergency response operation manuals formulated by the organization and other relevant documents, the emergency response implementation group shall execute the processes of formulating, developing and implementing a vehicle cybersecurity incident response plan. NOTE. the work during the response phase is generally time-sensitive and can control the impact of the vehicle cybersecurity incident within a relatively short period of time.
7.2 Formulation of Response Scheme
7.2.1 After the verification phase is completed, if the emergency response process needs to be initiated, the existing emergency handling scheme shall be reviewed and assessed first. If a fully applicable response scheme exists, then, it shall be implemented accordingly. If a partially applicable response scheme exists, then, the response scheme formulation process shall be initiated based on that scheme. If no fully or partially applicable emergency handling scheme exists, then, the response scheme formulation process shall be immediately initiated. The response scheme shall satisfy the following requirements.
a) Formulate in accordance with the type, level and emergency response level of the vehicle cybersecurity incident;
b) Analyze the emergency response demands and their corresponding response scheme, clearly define the response targets. If the vulnerability involves a component, the scheme shall be broken down to the component level;
c) Record and remediate the vehicle cybersecurity vulnerability, and ensure the confidentiality of the response scheme;
d) Record in the vehicle cybersecurity incident summary report (see example in A.4).
7.2.2 If the vulnerability causing the cybersecurity incident cannot be addressed and remediated in the existing relevant products, it shall be proposed by the emergency response implementation group, and assessed and reviewed by the emergency response expert group. In subsequent models;
d) After the implementation of the scheme, an emergency handling report shall be completed and archived (see A.5 for an example). The report shall at least include the incident classification, incident level, response time, implementation effect and remediation recommendations. For situations where response and remediation are not feasible for existing relevant products, the impact shall be described based on the incident level;
e) The emergency handling report shall be submitted to the emergency response expert group and the emergency response leadership group for review and approval;
f) If a product recall is required, it shall be handled in accordance with relevant requirements;
g) The organization shall enter the remediation phase when the impact of the current vehicle cybersecurity incident has been contained.
8 Remediation Phase
8.1 Overview Based on the emergency response plan formulated by the organization and other relevant documents, the emergency response implementation group shall execute the processes of formulating, verifying and implementing a vehicle cybersecurity incident remediation scheme.
8.2 Formulation of Remediation Scheme
8.2.1 The emergency response implementation group shall formulate a remediation scheme for the affected vehicle model or component. The remediation scheme shall clarify how to eliminate the corresponding cybersecurity vulnerabilities associated with the current vehicle cybersecurity incident.
8.2.2 The remediation scheme formulation process shall satisfy the following principles.
a) Analyze and formulate a remediation scheme based on the development process of the affected vehicle model or component and the conclusions from the response phase;
b) Formulate the remediation scheme based on past common or similar incidents;
c) Cover all vehicle models or components affected by the vehicle cybersecurity incident;
d) Implement access control for confidential information of individuals or organizations affected by the vehicle cybersecurity incident.
8.2.3 The emergency response implementation group shall balance the time required to formulate the remediation scheme with the time required to fully test the formulated remediation scheme.
8.2.4 If the remediation scheme is not formulated within the timeframe specified in the emergency response plan, the emergency response leadership group shall approve the use of a temporary scheme as a mitigation measure and expedite the formulation of the remediation scheme.
8.3 Verification of Remediation scheme
8.3.1 The remediation scheme verification process shall satisfy the following principles.
a) Ensure that the remediation scheme has been verified on all supported vehicle models or components;
b) Ensure that the remediation scheme can correctly function on the affected vehicle models or components;
c) Ensure that the remediation scheme does not impact the quality of other components;
d) Ensure that the remediation scheme does not affect the operation of existing functions of the affected vehicle models or components;
e) Ensure that the implementation of the remediation scheme will not introduce new cybersecurity incidents;
f) Determine the priority for the implementation of the remediation scheme and conduct verification.
8.3.2 After successful verification of the remediation scheme, it shall be submitted to the emergency response expert group for review and, upon approval, submitted to the emergency response leadership group for approval and initiation of implementation.
8.3.3 If the verification of the remediation scheme fails, the emergency response technical support group shall assist in formulating a new remediation scheme or iterating on the existing scheme.
8.4 Implementation of Remediation Scheme
8.4.1 The emergency response implementation group shall implement the remediation scheme based on the priority of the vehicle cybersecurity incident. For vehicle cybersecurity incidents of the same level, the remediation scheme may be simultaneously implemented step-by-step (for example, a three-step approach. first, select 10% for remediation; second, select 30% for remediation; and third, complete the remediation).
8.4.2 During the implementation of the remediation scheme, the emergency response leadership group shall be promptly informed of the remediation progress of the vehicle cybersecurity incident.
8.4.3 Once the vehicle model vulnerability issues caused by the vehicle cybersecurity incident have been completely eliminated or the effectiveness of the remediation scheme has been recognized by vehicle users, the implementation of the remediation scheme is complete and the post-incident handling phase can begin.
9 Post-Incident Handling Phase
9.1 Overview After the emergency response is completed, the emergency response implementation group shall formulate a vehicle cybersecurity incident summary report and implement the summary process after the remediation phase. The emergency response daily operation group shall execute the assessment and tracking processes after the remediation phase.
9.2 Post-incident Summary
9.2.1 The vehicle cybersecurity incident summary report shall include the following contents.
a) Description, incident level, and responsibility judgment of the vehicle cybersecurity incident,;
b) Content and lessons learned from the vehicle cybersecurity incident handling phase;
c) Content related to the remediation phase, including the impact of the vehicle cybersecurity incident, root cause analysis, remediation scheme, and other relevant records and deliverables from each phase. These deliverables may be attached to the vehicle cybersecurity incident summary report.
9.2.2 The vehicle cybersecurity incident summary report shall be formulated by the emergency response implementation group, submitted to the emergency response expert group for review, and approved by the emergency response leadership group.
9.2.3 If regulatory authorities require reporting or filing, such reporting or filing shall be made in accordance with relevant requirements and after approval by the emergency response leadership group.
9.3 Post-incident Assessment and Tracking
9.3.1 Based on the status of emergency response, the daily emergency response operation group shall formulate subsequent continuous monitoring and incident tracking requirements in accordance with the vehicle cybersecurity incident summary report.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 23 pages — is available in the English PDF.
Similar standards
How to Buy GB/T 44774-2024
- 1Add to cart. Click the "Buy GB/T 44774-2024" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 44774-2024
$365.00