Valid

GB/T 47683-2026Industrial internet - Specification for hazard analysis and risk assessment (English PDF)

工业互联网 危险分析和风险评估规范

Open the GB/T 47683-2026 preview as PDF

Preview — first pages of GB/T 47683-2026 (full document: 37 pages)

This is a limited preview

Buy now to download the full PDF (37 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

May 25, 2026

Implementation date

December 1, 2026

Scope

GB/T 47683-2026 is the English-translated version of 工业互联网 危险分析和风险评估规范.

GB/T 47683-2026 is the Chinese national standard covering hazard analysis for an industrial internet installation - where the connection of plant to network creates hazards that neither the plant nor the network had alone, and how those are identified, analysed and rated. First edition, in force from 1 December 2026, published with GB/T 47698-2026 on the safety integrity of collaborative manufacturing platforms. It was issued on 25 May 2026 and takes effect on 1 December 2026, as a first edition. The document is under the responsibility of the China Machinery Industry Federation. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.

Document preview — GB/T 47683-2026

National Standard of the People's Republic of China

ICS
25.040
Classification
N 10

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 1 Scope
  • 5 General Rules
  • 6 General Requirements
  • 6.2 Personnel Requirements
  • 6.3 Management Requirements
  • 6.4 Procedure Requirements
  • 6.5 Documentation Requirements
  • 7 Determination of security objectives
  • 7.1 General Requirements
  • 7.2 Determine the applicable risk matrix
  • 7.3 Determine tolerable risks
  • 8 Risk Factor Identification and Analysis
  • 8.2 Identification and Analysis of Information Security Risk Factors
  • 9 Hazard Analysis and Risk Assessment of the Edge Layer
  • 9.2 Content and Requirements
  • 10 Network Layer Hazard Analysis and Risk Assessment
  • 10.2 Content and Requirements
  • 10.2.3 For each hazardous event identified in

1 Scope

GB/T 47683-2026 is the Chinese national standard covering hazard analysis for an industrial internet installation - where the connection of plant to network creates hazards that neither the plant nor the network had alone, and how those are identified, analysed and rated. First edition, in force from 1 December 2026, published with GB/T 47698-2026 on the safety integrity of collaborative manufacturing platforms. It was issued on 25 May 2026 and takes effect on 1 December 2026, as a first edition. The document is under the responsibility of the China Machinery Industry Federation. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.

Note. The above is only an example of a possibility. Users of this document need to develop a classification that meets user and regulatory requirements based on the specific implementation situation.

7.2.4 The consequences classification should include factors affecting the industrial internet, such as personal injury, economic loss, business continuity impact, and environmental impact. Impacts include asset and reputational damage. The severity of consequences must be graded based on national laws and regulations, national standards, industry standards, and company documents. Classification.

7.2.5 The risk matrix should combine the probability of an event occurring and the severity of its consequences.

5 General Rules

5.1 Scope of Analysis and Risk Assessment The scope of Industrial Internet hazard analysis and risk assessment is shown in Figure 1, and should cover the Industrial Internet edge layer, network layer, platform layer, and industrial core layers. The business application layer consists of four logical layers and various application combinations.

---The edge layer connects to different devices and systems through various communication methods, collects massive amounts of data, and utilizes edge computing devices to implement the underlying layer. Data is aggregated and processed, and integrated into the cloud platform.

Note. Typical examples of devices and systems accessing the edge layer include. manufacturing/production equipment, data acquisition equipment, industrial communication equipment, industrial control equipment, and industrial control systems. Control systems, human-computer interaction devices, etc.

---The network layer is the network infrastructure that supports the operation of industrial internet platforms. The platform layer provides general data analysis and management, industrial model development and management, and other services to support the industrial application layer in carrying out industrial... application.

---The industrial application layer provides industrial applications for different industries and scenarios.

5.2 Principles for Security Risk Analysis and Assessment at Each Level of the Industrial Internet Industrial control equipment and systems typically incorporate functional safety systems as risk mitigation measures. This is to address the information risks introduced by Industrial Internet technology. Information security threats necessitate the implementation of information security risk mitigation measures at all levels of the Industrial Internet to ensure the availability and integrity of facilities and systems at each level. And confidentiality. Functional safety and information security must be considered during the hazard analysis and risk assessment process at each layer of the Industrial Internet.

---The risk analysis and risk assessment of the edge layer comprehensively considers the risk reduction capabilities of functional safety measures and information security measures, as well as information security measures. The impact of safety measures on functional safety measures;

---In hazard analysis and risk assessment at the network layer, platform layer, and industrial application layer, information security measures should be considered to reduce the occurrence of hazardous events. Potential preventative capabilities, and the reliability and availability of equipment at each level, which could lead to hazardous events; the impact of hazardous events. When impacting field devices and control systems connected to the edge layer, attention should be paid to the ability of functional safety and other measures to mitigate the severity of the consequences.

6 General Requirements

6.1 Timing of Assessment Hazard analysis and risk assessment should be conducted at the following points.

---At least one hazard analysis and risk assessment should be conducted during the design phase.

---During the operational phase, hazard analysis and risk assessment should be conducted regularly. In the event of a major hazard incident in the same field, targeted hazard assessments should be implemented. Risk analysis and risk assessment. Note

1.The time interval is determined according to the specific circumstances, generally 3 to 5 years.

---A hazard analysis and risk assessment should be conducted after any major changes occur. Hazard analysis and risk assessment should be conducted during the disposal phase. Note

2.During the disposal phase, it is necessary to ensure that sensitive data is completely eliminated and that the risks of other related devices still in use are controllable.

6.2 Personnel Requirements

6.2.1 Members of the hazard analysis and risk assessment working group should be independent (as opposed to project design and operation), either from the project design personnel or the project team. Other relevant personnel in the group should cooperate with the analysis team in hazard analysis and risk assessment activities.

6.2.2 The working group members should include personnel with relevant experience in the Industrial Internet and knowledge of relevant laws and regulations to ensure the effectiveness of hazard analysis and risk assessment. The reasonableness and credibility of the risk assessment results.

6.2.3 The working group shall include personnel who have participated in functional safety and information security technology training and have the corresponding knowledge and experience.

Note. Regarding functional safety, personnel need to understand GB/T 20438 (all parts) [process industries also need to understand GB/T 21109 (all parts)] and obtain industry certification. Authoritative functional safety certification; in terms of information security, personnel need to understand GB/T 20986, GB/T 35673, and other standards for information security and industrial control system information security. Comply with relevant standards and obtain training certificates.

6.2.4 The working group should include at least one person with a relevant professional background in the industrial system to be evaluated (such as industrial control equipment, process flow, etc.). The term of service shall not be less than 3 years.

6.3 Management Requirements

6.3.1 The organization responsible for hazard analysis and risk assessment shall establish a hazard analysis and risk assessment working group and clearly define the responsibilities and independence of each member. Require.

Note. The organizers include the designers, builders, and users of the industrial system.

6.3.2 Personnel performing hazard analysis and risk assessment shall meet the requirements of 6.2.

6.3.3 The working group shall prepare a hazard analysis and risk assessment plan, which shall include the following contents.

---The objects and scope of hazard analysis and risk assessment.

Note. The scope of the assessment object, applicable laws, regulations, and standards must be clearly defined in the plan. The definition of the scope of work may also be related to the input data (such as design specifications). The level of detail (as in books, device drawings, etc.) is related to this.

---Activities required to be performed at each stage of hazard analysis and risk assessment.

---Personnel, departments, organizations, or other entities involved in hazard analysis and risk assessment activities.

---Resources needed to complete hazard analysis and risk assessment activities.

---Proposed tools and record sheets.

---The outputs that should be obtained after completing hazard analysis and risk assessment activities.

---Identification of potential personnel risks, business impact risks, and data leakage risks during the hazard analysis and risk assessment process. control.

---Schedule planning.

6.3.4 The hazard analysis and risk assessment plan shall be approved by the assessment organization before the hazard analysis and risk assessment are carried out.

6.4 Procedure Requirements

6.4.1 The preliminary preparations for conducting industrial internet hazard analysis and risk assessment should include the following.

---Establish a hazard analysis and risk assessment working group, with personnel meeting the requirements of 6.2.

---Develop a hazard analysis and risk assessment work plan that meets the requirements of 6.3.3.

---Data collection and meeting preparation, hazard analysis and risk assessment input data should include, but are not limited to. - The system's operating environment; - Business strategy and management system; - Main business functions and requirements; - Network structure and network environment, including internal and external connections; - Main hardware and software; - System and data sensitivity; - Asset list; - Network security management procedures; - Emergency response plan for cybersecurity incidents; - Design documents related to industrial control equipment and systems accessed at the edge layer, including at least design requirements and descriptions, and flowcharts (process diagrams). In industrial applications, this typically involves piping and instrumentation diagrams; for programmable electronic systems, it's usually a data flow diagram. (Engineering data sheets, layout) Drawings, utility specifications, operation and maintenance requirements; - Collection of accident and incident case studies; - Previous assessment reports and historical accident and incident analysis reports of the assessed entity; - Other relevant documents.

6.4.2 Conduct industrial internet hazard analysis and risk assessment according to Figure 2.

6.4.3 Records and Tools Hazard analysis and risk assessment records should preferably be in the form of record sheets. Industrial Internet companies can use digital and intelligent methods to achieve hazard analysis and risk assessment. Recording and rating risk analysis and assessments, establishing a historical database, and leveraging big data and other methods to determine risk frequency and severity. Value correction. Industrial internet companies with the necessary resources can develop real-time dynamic hazard analysis and risk assessment tools for information security intrusion detection and on-site... Real-time monitoring of key risk factors such as instrument and equipment failures, personnel movement, and fire and gas monitoring, combined with hazard analysis and risk assessment algorithms, achieves... Real-time hazard analysis, risk assessment, and control.

6.5 Documentation Requirements

6.5.1 All hazard analysis and risk assessment activities should be documented.

6.5.2 Documents should be clearly structured, accurately expressed, unambiguous, interpretable, and traceable.

6.5.3 Hazard analysis and risk assessment reports should include. project background, basis for analysis and assessment, purpose of analysis and assessment, scope of analysis and assessment, and content. Content, analysis and evaluation methods, analysis and evaluation process, analysis and evaluation conclusions and recommendations, hazard analysis and risk assessment worksheets, analysis and evaluation tools The necessary data used and analyzed, such as analysis drawings, sources of evaluation criteria, and analysis and evaluation assumptions and their sources.

7.1 General Requirements

7.1.1 When conducting hazard analysis and risk assessment for the edge layer, network layer, platform layer, and industrial application layer of the Industrial Internet, the first step should be to determine... Set safety goals.

7.1.2 Determining security objectives typically involves identifying the applicable risk matrix and tolerable risks.

Note. When the residual risk is less than or equal to the tolerable risk, it indicates that the risk has reached an acceptable level, and no additional risk reduction measures are needed; residual risk... When the risk exceeds the tolerable level, it indicates that the risk has not been reduced to an acceptable level, and risk reduction measures need to be increased until the residual risk is less than or equal to the tolerable level. risk.

7.2 Determine the applicable risk matrix

7.2.1 The risk analysis and risk assessment of each level of the Industrial Internet should assess its risk level according to the applicable risk matrix, and be carried out in a timely manner. Corresponding records. The risk level assessment process includes initial hazard analysis and risk assessment, and residual hazard analysis and risk assessment.

7.2.2 The risk matrix has two main parameters. the probability of an event occurring and the severity of its consequences.

7.2.3 The probability of an event occurring should be classified according to industry experience, industry standards, and company documents. Example. See Table 1. Table

1.Event Probability Ranking (Example) Probability grading frequency range (F) description 1.F<=10^-5 has no international precedent. 2.10^-4 >= F > 10^-5 This is unlikely to occur in reality (there is no precedent for this in the domestic industry). 3.10^-3 >= F > 10^-4 is not expected to occur, but it may happen under special circumstances (there have been precedents in the domestic industry). 4 10^-2>=F >10^-3 This is unlikely to happen within the lifecycle of a specific analytical object, but there are multiple similar platforms/systems. At that time, it may occur on one of the platforms/systems. 5.10^-1 >= F > 10^-2 indicates that the event is likely to occur at least once during the lifecycle of the analyzed object (and is expected to occur). 6.F >10-

7.3 Determine tolerable risks

7.3.1 Tolerable risks should comply with national laws, regulations, standards, and the company's tolerable risk guidelines.

Note. Tolerable risk is the goal of safety work. From an engineering application perspective, there is no absolute safety or "zero risk"; any safety project needs to first define [the appropriate risk level]. Define a relative or acceptable risk target. One principle that can be referenced for tolerable risk is ALARP.

7.3.2 For each category of consequences and its severity level, a corresponding tolerable risk frequency should be defined. Example. Tolerable risks of personal injury consequences are shown in Table 4; tolerable risks of economic loss consequences are shown in Table 5; tolerable risks of business continuity impact consequences are shown in Table 5. See Table 6.

7.3.3 Tolerable risk depends on many factors, such as the severity of the injury, the number of people exposed to the hazard, and the ratio of one to multiple people exposed to the hazard. The frequency and duration of exposure. For a specific application, the composition of tolerable risk must consider the following set of determinants.

---International and national standards;

---National and local policies and regulations;

---Corporate policies, system documents, and standards;

---Investment in relevant parties such as community organizations, local judicial authorities, and insurance companies with good engineering practices.

8 Risk Factor Identification and Analysis

8.1 Identification and Analysis of Traditional Risk Factors in Industrial Sites The process for identifying and analyzing traditional risk factors in industrial sites shall be performed in accordance with GB/T 35320.(This refers to the identification and analysis of traditional risk factors in industrial sites.) include.

---Identification and probability analysis of human error hazards;

---Equipment malfunction hazard identification and probability analysis;

---Identification and probability analysis of external impact hazards;

---Identification of hazardous events caused by traditional risk factors in industrial sites and analysis of their probability of occurrence and scope of impact.

Note. In process industries, traditional risk factors mainly refer to process safety risks; in discrete industries, traditional risk factors mainly refer to safety risks in the manufacturing process.

8.2 Identification and Analysis of Information Security Risk Factors

8.2.1 The process of identifying and analyzing information security risk factors shall be performed in accordance with GB/T 20984 and GB/T 20986.Information security risk factor identification... Differentiation and analysis include.

---Asset identification;

---Security threat identification and probability analysis;

---Vulnerability identification and severity analysis;

---Information security risk identification and analysis of its likelihood and scope of impact.

8.2.2 Security threats to industrial systems generally include. information leakage, malicious tampering (such as malicious modification of control commands), unauthorized access, and identity theft. Impersonation, denial, denial of service, unauthorized escalation of privileges, virus infection, unauthorized physical access, disaster, power outage, etc.

8.2.3 Edge-layer security threats should be identified, including.

---The risk of terminal "zombification" or control logic tampering caused by terminal intrusion; Note

1.Typical examples of this type of threat include terminal hosts being infected with bots, leading to the "zombie" phenomenon of the terminal, and being implanted with logic bombs.

---Industrial control networks are interconnected, and security threats and attacks on the upper-level management network may penetrate and extend to the control network; Note

2.The difficulties in implementing security protection for industrial control systems include. the stringent requirements of industrial control systems for real-time performance and reliability, which make traditional... IT information security technologies are difficult to apply directly to industrial sites; to meet real-time and reliability requirements, industrial control equipment generally does not use, or rarely does. Security measures are in place; physical isolation has become the only security barrier for most industrial control equipment. The "interconnectivity" of the Industrial Internet enables industrial control... The control system and equipment were exposed to external public networks, which compromised the security of physical isolation.

---Security vulnerabilities caused by the failure to update the software and hardware of industrial control systems and equipment in a timely manner; Note

3.Industrial control systems and equipment generally operate for decades and are rarely upgraded in terms of software and hardware due to various factors, making it difficult to eliminate security vulnerabilities in a timely manner.

---The lack of effective control measures for remote maintenance of industrial control systems may lead to the leakage or destruction of production data;

9 Hazard Analysis and Risk Assessment of the Edge Layer

9.1 Objects The objects of edge layer hazard analysis and risk assessment include, but are not limited to.

---Controlled equipment (such as compressors, storage tanks, etc.);

---Processes (such as pressurization, catalysis, etc.);

---Industrial control systems (such as PLC, SIS, RTU, DCS, HMI);

---Industrial control network infrastructure (such as switches and routers);

---Other edge devices (such as edge data servers and edge computing nodes).

9.2 Content and Requirements

9.2.1 All potentially hazardous events and their causes that may pose risks at the industrial internet edge layer should be identified (including human error, equipment failure, network...). (Network failures, network security threats, etc.), and the analysis should be conducted after excluding the effects of industrial process safety protection measures and information security protection facilities. The likelihood of hazardous events occurring. Risk analysis and assessment at the industrial internet edge layer should include the following.

---Regarding new technologies and methods used in the edge layer of the Industrial Internet, their potential impact can be assessed from dimensions such as technology maturity and personnel capabilities. Analyze new dangers/threats;

--- Potential new dangers/threats arising from artificial intelligence (e.g., data poisoning, algorithmic errors, strategy errors, computing power collapse, etc.), and contingency plans. Are there dedicated measures to switch to traditional control methods, and are they directly applied to safety function loops?

---New dangers/threats that may arise from network connectivity (e.g., connection loss, authentication failure, data transmission errors, synchronization errors, unauthorized access) (Is there a specific measure to prevent and control potential faults such as malicious duplication or unauthorized access?)

--- Potential new dangers/threats associated with remote access (e.g., remote access tampering, unauthorized access, identity spoofing, access delays, Trojan horse planting) (e.g., access control), are there specific measures to cut off or block remote access, or switch to backup local functions?

---Due to inherent security design flaws in industrial control equipment, its access control mechanism is weak, resulting in a reduction in overall system security;

---Vulnerabilities exist in the network protocols and application software used by industrial control equipment;

---The industrial control network system has design and configuration flaws; Incomplete link-layer security policy configurations and simplistic protection mechanisms in industrial control network equipment and network switching devices can lead to intrusions through the network. To launch malicious attacks such as MAC flooding attacks and ARP spoofing;

---Security of external interfaces. Inadequate authentication and authorization policies for external communication can lead to unauthorized access, data leakage, and system instability. The system was maliciously controlled;

---Physical security at the edge layer. Damage to equipment caused by inadequate physical access control, intrusion prevention measures, or improper management of the device's operating environment. Bad, data breaches, and system outages;

---Supply chain security. Equipment, software, or services provided by suppliers may have backdoors or be compromised, creating entry points for attacks and compromised information. Information leak.

9.2.2 For dangerous incidents caused by information security incidents, the threat level should be calculated based on the frequency of information security threats and their vulnerabilities. The probability of information security incidents occurring due to vulnerabilities and the probability of dangerous incidents arising from such incidents are considered, and a comprehensive calculation is performed. Calculate the probability of a dangerous event occurring.

Note. Vulnerabilities can also be categorized by their impact level, with different levels representing the extent of damage to assets caused by exploited vulnerabilities. Vulnerability Examples of sexual influence levels are as follows:

1.If threatened and exploited, the damage to assets will be negligible;

10 Network Layer Hazard Analysis and Risk Assessment

10.1 Objects The objects of network layer hazard analysis and risk assessment include, but are not limited to.

---Failures or erroneous behaviors of network layer facilities, systems, storage, networks, etc.;

---Failures or errors caused by external attacks or unauthorized human intervention to network layer facilities, systems, storage, networks, etc. Behavior;

---The interaction of data flow and control flow between the network layer and other layers may introduce complex security risks (such as interface protocol vulnerabilities, etc.). (Data tampering, etc.)

10.2 Content and Requirements

10.2.1 Based on security threat identification, all potentially dangerous events that could lead to network layer risks and their causes should be identified, and industrial processes should be excluded from consideration. Under the influence of process security protection measures and information security protection facilities, the probability of dangerous events occurring is analyzed.

10.2.2 The effectiveness of industrial process safety protection measures and information security protection facilities should be excluded, and potential inherent vulnerabilities of network layer facilities should be identified. Analyze the likelihood of failures, erroneous behaviors, and unintended human intervention.

10.2.3 For each hazardous event identified in

10.2.1 and 10.2.2, its consequences on edge layer access devices/industrial control systems should be analyzed. The impact should be analyzed. When assessing the consequences, the role of information security protection facilities and industrial process safety measures should be excluded, and a comprehensive analysis of the events from their inception to their aftermath should be conducted. By analyzing the event chain during the occurrence of the event, the severity level of the final consequence can be determined.

10.2.4 The original risk of each hazardous event should be determined based on the risk matrix.

10.2.5 Relevant information should be determined...

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 37 pages — is available in the English PDF.

How to Buy GB/T 47683-2026

  1. 1Add to cart. Click the "Buy GB/T 47683-2026" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
37 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 47683-2026

$305.00

$260.00for partners