GB/T 45577-2025Data security technology — Risk assessment method for data security (English PDF)
数据安全技术 数据安全风险评估方法
Open the GB/T 45577-2025 preview as PDF
This is a limited preview
Buy now to download the full PDF (35 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
April 25, 2025
Implementation date
November 1, 2025
Scope
GB/T 45577-2025 is the English-translated version of 数据安全技术 数据安全风险评估方法.
GB/T 45577-2025 is the Chinese national standard covering assessing the risk to the data an organisation holds — the preparation and the assessment team, the survey of the data processor, its business systems, its data assets and its processing activities, the identification of risk across management, processing activities, technology and personal information protection, the analysis and rating that follows, and the residual risk left in the report once the recommended measures are assumed to be in place. The assessment is built on the data classification and grading of GB/T 43697-2024. First edition, in force from 1 November 2025. Issued on 25 April 2025, it has been in force since 1 November 2025.
Document preview — GB/T 45577-2025
National Standard of the People's Republic of China
- ICS
- 35.030
- Classification
- L 80
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- PrefaceIII
- 1 Scope1
- 2 Normative references1
- 3 Terms and Definitions1
- 4 Abbreviations2
- 5 General3
- 5.1 Overview3
- 5.2 Relationship between data security risk assessment elements3
- 5.3 Principles of Data Security Risk Assessment4
- 5.4 Applicable Situations for Data Security Risk Assessment5
- 5.5 Data Security Risk Assessment Implementation Process5
- 5.6 Data Security Risk Assessment Content Framework6
- 5.7 Data security risk assessment methods7
- 6 Data Security Risk Assessment Preparation7
- 6.1 Determine the evaluation objectives7
- 6.2 Determine the scope of the assessment8
- 6.3 Establishing an evaluation team8
- 6.4 Carry out preliminary preparations8
- 6.5 Develop an evaluation plan9
- 7 Information Research9
- 7.1 Data Processor Survey9
- 7.2 Business and Information System Research10
- 7.3 Data Asset Research10
- 7.4 Survey on data processing activities10
- 7.5 Safety protection measures research11
- 8 Risk Identification1111
- 8.1 General11
- 8.2 Analysis of the evaluation situation carried out12
- 8.3 Data Security Management12
- 8.4 Security of data processing activities1213
- 8.5 Data Security Technology13
- 8.6 Personal Information Protection1314
- 9 Risk Analysis and Assessment1414
- 9.1 General14
- 9.2 Data Security Risk Analysis14
- 9.3 Data Security Risk Assessment16
- 9.4 Create a data security risk list17
- 10 Evaluation Summary17
- 10.1 Preparation of assessment report17
- 10.2 Risk Management Recommendations18
- 10.3 Residual risk analysis18
- Appendix A (Normative) Data Security Risk Identification Content19
- A.1 Data Security Management19 A.2 Data processing activities24 A.3 Data security technology30
- A.4 Protection of Personal Information34 Appendix B (Informative) Typical Data Security Risk Types39
- Appendix C (Informative) Data Security Risk Analysis Reference41
- C.1 Data security risk analysis reference41
- C.2 Analysis of the likelihood of data security risks occurring Reference43
- Appendix D (Informative) Data Security Risk Quantitative Analysis and Evaluation Method45
- D.1 Quantitative analysis method of data security risk degree45
- D.2 Quantitative analysis method for the possibility of data security risks occurring45 D.3 Data security risk quantitative assessment method45
- Appendix E (Informative) Data Security Risk Assessment Report Template46
- References49
Foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1: Structure and drafting rules for standardization documents" Drafting.
Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.
This document was proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260).
This document was drafted by: China Electronics Technology Standardization Institute, National Information Technology Security Research Center, National Computer Network Emergency Response Team Technical Processing Coordination Center, National Industrial Information Security Development Research Center, Central Cyberspace Affairs Office Data and Technology Support Center, China Information Security Evaluation Center, National Information Center, Information Engineering Institute of Chinese Academy of Sciences, Third Research Institute of Ministry of Public Security, Beijing Municipal Government Information Security Center Center, China Cybersecurity Review Certification and Market Supervision Big Data Center, University of Science and Technology of China, Institute of Software, Chinese Academy of Sciences, Alibaba Cloud Computing Co., Ltd., Beijing Kuaishou Technology Co., Ltd., Ant Technology Group Co., Ltd., and Huawei Technologies Co., Ltd.
The main drafters of this document are: Yang Jianjun, Yao Xiangzhen, Zhang Yuguang, Hu Ying, Chen Qi, Yang Tao, Lin Xingchen, Chen Te, Lu Lei, Lin Zhiqiang, Jiang Songhao, Shangguan Xiaoli, Ren Yingjie, Zhu Xuefeng, Yan Hui, Li Min, Zhao Ran, Liu Xize, Li Ye, Chen Jing, Xu Feng, Wang Hui, Wang Defu, Du Jing, Ma Ying, Zhang Yan, Su Yanfang, Li Yuan, Cheng Yuqi, Zuo Xiaodong, Zhang Liwu, Song Jing, Sun Yong, Wang Xin, Bai Xiaoyuan, Shao Meng, Sudan, Li Haidong, Zhang Mingtian, Gao Chentao.
Data security technology Data security risk assessment method
1 Scope
This document describes the basic concepts, element relationships, and analysis principles of data security risk assessment, and provides practical examples for data security risk assessment.
Implementation process, assessment content, analysis and evaluation methods, etc.
This document is applicable to guiding data processors and third-party assessment agencies in conducting data security risk assessments, and can also be used by relevant regulatory authorities.
For reference when implementing data security review assessments.
2 Normative references
GB/T 25069-2022
GB/T 43697-2024
3 Terms and definitions
The terms and definitions defined in GB/T 25069-2022 and the following apply to this document.
3.1 data
Any recording of information by electronic or other means.
3.2 Data security
By taking necessary measures, we ensure that data is effectively protected and legally used, and that there are mechanisms to ensure continuous security. ability.
3.3
Activities such as data collection, storage, use, processing, transmission, provision, disclosure, and deletion.
3.4 rationality
Data processing activities must comply with laws, administrative regulations, and common sense in cybersecurity and data security, and must not harm national security or public order.
The common interests and the legitimate rights and interests of individuals and organizations.
3.5
Threats, vulnerabilities, problems, hidden dangers that may lead to events that endanger the confidentiality, integrity, availability and reasonableness of data processing Suffering, etc.
Note. In this document, “risk sources” are referred to as such, which include risk sources that may lead to data security incidents due to security threats exploiting vulnerabilities, as well as data processing activities.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 35 pages — is available in the English PDF.
Referenced standards
Normative references
Editions of GB/T 45577
| Edition | Title | Revision | Status |
|---|---|---|---|
| GB/T 45577-2025 | Data security technology - Risk assessment method for data security | current edition | Current |
This page sells the current edition, GB/T 45577-2025. Earlier editions are listed for reference only.
How to Buy GB/T 45577-2025
- 1Add to cart. Click the "Buy GB/T 45577-2025" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 25069-2022 — Information security techniques—Terminology
GB/T 43697-2024 — Data security technology - Rules for data classification and grading
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
Secure payment via Stripe
Payments accepted
GB/T 45577-2025
$635.00