GB/T 47698-2026Industrial internet - Specification for the safety integrity assessment of collaborative manufacturing platforms (English PDF)
工业互联网 协同制造平台安全完整性评估规范
Open the GB/T 47698-2026 preview as PDF
This is a limited preview
Buy now to download the full PDF (44 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
May 25, 2026
Implementation date
December 1, 2026
Scope
GB/T 47698-2026 is the English-translated version of 工业互联网 协同制造平台安全完整性评估规范.
GB/T 47698-2026 is the Chinese national standard covering how the safety integrity of a platform that coordinates manufacturing across sites and companies is assessed - the safety functions the platform performs, the integrity level each requires and the evidence that it achieves it. First edition, in force from 1 December 2026, the companion of GB/T 47683-2026. It was issued on 25 May 2026 and takes effect on 1 December 2026, as a first edition. The document is under the responsibility of the China Machinery Industry Federation. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.
Document preview — GB/T 47698-2026
National Standard of the People's Republic of China
- ICS
- 25.040
- Classification
- N 10
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- 6 Safety Criticality Assessment Process
- 7 Safety Criticality Classification
- 7.1 General Requirements
- 7.3 Safety Criticality Classification Process and Methods
- 7.4 Determination of Module Security Integrity Requirements
- 8 Safety Integrity Assessment Requirements
- 8.1 General Requirements
- 8.3 Systemic Security Integrity Assessment
- 9 Evaluation Procedures and Methods
- 9.2 Evaluation Methods
- 9.2.1 Inspection
- 9.2.2 Analysis
- 9.2.3 Testing
- 10 Assessment Report
6 Safety Criticality Assessment Process
7.3.3 All software related to the execution of security functions shall undergo security criticality assessments and comply with the following requirements.
a) For C1 level software components, it should be confirmed that a failure will not negatively impact C2 or C3 level software components (this needs to be included). This includes analyzing the protective measures for these components, such as verifying, through checks on specified ranges, that data will not be written to C2 or C3 levels. (In components), when a negative impact is expected, it should be classified as level C2;
b) For C2-level components, it is necessary to verify that the implementation of their functionality will not lead to C3-level security-critical impacts (e.g., data integrity). The sex diagnostic function may cause data corruption during diagnosis, and there is no way to recover it.
c) For C3 level components, it is necessary to analyze and confirm whether C2 level components (monitoring, diagnostic, etc.) exist to ensure their security. A complete and critical downgrade.
7.3.4 The safety criticality assessment should at least include a deviation analysis and assessment of the module's operation in terms of timing, data, and state transitions, and can be conducted using software. Methods such as HAZOP and FMEA were used to conduct keystone analysis. The parameters, lead words, meanings of lead words, and parameters were discussed. See Appendix A for examples of the meanings of conjunctions.
7.1 General Requirements
7.1.1 The expected functions to be performed by the collaborative manufacturing platform should be identified and clearly defined.
7.1.2 Based on the functions defined by the collaborative manufacturing platform, the platform should be divided into modules, and the specific unit modules included in each function should be clearly defined.
Note 1: A trade-off needs to be struck regarding the granularity of the functional module decomposition. If the granularity is too large, the coupling between security functions will be stronger, potentially leading to the corresponding modules only being able to... Achieve higher SIL targets. Note
2.The platform's internal functions, external interfaces, operating assumptions, and user manuals must be clearly described, and the collaborative manufacturing platform itself must be clearly listed. Specific items in the security integrity risk assessment include, for example, fault detection items in the platform's operating hardware environment, software self-test functions, and security input. Items such as security output items and cybersecurity threat items are described in documents such as architecture design and security requirements specifications.
7.1.3 The safety status, failure conditions, internal functions, external interfaces, operating assumptions, and usage conditions of all modules should be analyzed and determined. Items, etc.
7.1.4 Match all identified security functions of the collaborative manufacturing platform with the participating modules.
7.2 Safety Criticality Classification Criteria Each security function should be classified into security criticality levels for its respective functional module. Based on the mode of impact, security criticality can be categorized into... There are 3 levels, see Table 1.
7.3 Safety Criticality Classification Process and Methods
7.3.1 The safety criticality classification process is shown in Figure 5.
7.3.2 Safety criticality assessments should be conducted based on the hierarchical process shown in Figure
5.Hypothetical analysis assessment methods can be used, assuming deviations from the established criteria, and then analyzing the results. To assess whether it will lead to danger, the safety criticality assessment process is shown in Figure 6. Figure
7.4 Determination of Module Security Integrity Requirements
7.4.1 The SIL for each safety function should be determined according to Chapter 6, as well as the safety criticality of each module within the safety function, in accordance with the specifications in Table 2. Define the SIL requirements that each module should meet.
7.4.2 The premise for meeting the requirements of Table 2 is that different modules have sufficient independence. If the independence between two or more modules is difficult to achieve... If valid proof is obtained, then all associated modules should meet the highest SIL requirement.
7.4.3 In accordance with the requirements of GB/T 20438.1-2017, GB/T 20438.2-2017, and GB/T 20438.3-2017, determine the module's... Its security and integrity requirements include the security-related performance requirements of the module and execution time limits.
8.1 General Requirements
8.1.1 An evaluation should be conducted on all modules assigned SIL requirements to confirm that each module has correctly implemented its component safety functions. Yes, and it meets the corresponding safety and integrity requirements.
8.1.2 In accordance with the requirements of GB/T 20438.2-2017, the security-related modules of the collaborative manufacturing platform should be inspected from at least the following aspects. Security integrity capability assessment. hardware security integrity, system security integrity, behavior when a fault is detected, and secure data communication.
8.1.3 It should be assessed whether the platform has implemented sufficient information security protection measures, including.
a) Information security protection designs were developed based on typical industrial or sectoral requirements; Note
1.Such as the requirements of graded protection, and the requirements of industrial control information security standards such as GB/T 42456.
b) It should be analyzed whether the failure of different information security attacks may have a negative impact on security functions, and it should be determined whether all security functions have been adequately protected. Appropriate protection; Note
2.Consider using appropriate threat/vulnerability analysis methods.
c) It should be analyzed whether the designed information security protection measures themselves may have unacceptable negative impacts on the execution of security functions.
8.2 Hardware Security Integrity Assessment Conduct hardware security integrity assessments in accordance with the requirements of sections
7.4.5 of GB/T 20438.2-2017.
Note. During the hardware security integrity assessment, it is necessary to consider that the collaborative manufacturing platform hardware may be a computer server, and the detection of its random failures is also important. Control may need to rely more on software.
8.3 Systemic Security Integrity Assessment
8.3.1 Conduct system security and integrity testing in accordance with the requirements of
7.4.7 of GB/T 20438.2-2017 and GB/T 20438.3-2017. Sexual assessment.
8.3.2 Based on compliance with 8.3.1, the following points should be emphasized in the design of collaborative manufacturing platform software.
a) Has the software code been tested and proven to comply with the relevant security coding standards? For any code that does not comply with the standards, sufficient [security measures should be taken]? Explain the rationale behind it.
b) In addition to the security function code, does the software itself have sufficient security mechanisms in place, such as defensive programming, code processing, etc. Program sequence monitoring, etc.; the ability of these security mechanisms to control software errors and random hardware failures should be analyzed and evaluated. Whether it is sufficient, for example, whether the corresponding diagnostic coverage has been achieved.
c) Design independence between different SIL modules or between security- and non-security-related modules; analysis of the impact of low-SIL modules on high-SIL modules. Do security-related modules, and non-security-related modules, have any unacceptable negative impacts on security-related modules?
8.3.3 Based on compliance with 8.3.1, the following points should be emphasized in the evaluation of collaborative manufacturing platform software verification.
a) Have software failure analyses been conducted on SIL2, SIL3, and SIL4 modules to demonstrate their effectiveness against reasonably foreseeable errors? Protective measures for each part;
b) Has the software code undergone sufficient testing, including static and dynamic testing? Does the dynamic testing meet the requirements? Test coverage as specified in GB/T 20438.3-2017;
c) Whether the tools involved in software development have undergone sufficient applicability verification.
8.4 Evaluation of behavior when a fault is detected
8.4.1 Conduct an assessment of the behavior when a fault is detected in accordance with section
7.4.8 of GB/T 20438.2-2017.
8.4.2 Assessments should be conducted on a per-function basis for each safety feature of the collaborative manufacturing platform to confirm its performance under various fault detection conditions. The block state, output status, action or duration, and additional constraints meet the requirements.
9 Evaluation Procedures and Methods
9.1 Evaluation Procedure The evaluation procedure should be determined first. This process may vary depending on factors such as its size, nature, and complexity. A typical evaluation... The estimation procedure is shown in Figure 7. Figure
9.2.1 Inspection
9.2.1.1 Inspection is the foundation for assessing the security integrity of an industrial internet collaborative manufacturing platform. Inspection activities are conducted to confirm whether it complies with [the requirements of the platform]. Relevant standards, design requirements, and safety specifications, including document review, configuration review, and on-site inspection.
9.2.1.2 Document review should include the following activities.
a) Check whether the platform architecture design, security function specifications, hardware/software technical documents, interface definitions, etc., are complete and clearly defined. SIL requirements and safety measure design;
b) Review network security management documents, emergency plans, change management processes, personnel training records, etc., to confirm the compliance of the security management mechanism. Sex and effectiveness;
c) Verify previous assessment reports, incident analysis reports, and the implementation of corrective measures to confirm that historical issues have been closed-loop resolved.
9.2.1.3 The configuration check should include the following activities.
a) Check whether the equipment selection, network architecture, and security configuration of software components (such as operating systems and industrial control software) meet the design requirements. Please check whether there are any high-risk vulnerabilities, unauthorized hardware access, or software modifications.
b) Whether network security equipment meets the requirements for isolation, protection, and auditing; whether communication protocols have enabled data encryption, identity authentication, and integrity checks. Security mechanisms such as integrity checks.
9.2.1.4 On-site inspections should include the following activities.
a) Conduct on-site inspections to verify that the installation and wiring of industrial control equipment comply with safety regulations, and that environmental conditions (such as temperature, humidity, and power supply stability) are adequate. Meets equipment operating requirements;
b) Check the operation logs and maintenance records to confirm whether the personnel's operation procedures are standardized and whether there is any risk of unauthorized access or misoperation.
9.2.2 Analysis
9.2.2.1 Analysis is a systematic approach to identify potential hazards, assess risk levels, and verify the effectiveness of safety measures; it is essential for platform security. A necessary basis for integrity assessment.
9.2.2.2 The analysis should include the following activities.
a) Use methods such as HAZOP and FMEA to perform risk and failure mode analysis to identify hazardous events (such as data tampering, communication interruption). The transmission routes and scope of impact of [various pathogens], etc., should be analyzed, and their probability of occurrence and severity of consequences should be assessed.
b) Based on the safety criticality classification results, analyze the direct impact of the failure of C3-level modules on the overall safety function, and the impact of the failure of C2-level modules... Risk of failure when the block is combined with other components;
c) Calculate the average failure probability of each module and verify whether it meets the target SIL level;
d) Analyze the impact of network attacks (such as denial-of-service attacks, malicious code injection, etc.) on functional safety, and evaluate information security protection measures. Whether to avoid negative impacts on functional safety.
9.2.3 Testing
9.2.3.1 If on-site testing of the collaborative manufacturing platform is required, the environmental conditions specified in
5.2.2 should be analyzed in detail before conducting on-site testing. Environmental constraints were considered to confirm that the action would not affect the normal production process.
9.2.3.2 Tests may include the following types.
a) Functional testing. Verify the compliance of safety-related functions with normal/abnormal operating conditions;
b) Penetration testing. Simulating network attacks to verify the effectiveness of the information security protection system;
c) Fault insertion test. Verify that it meets the corresponding fault detection capabilities and behavioral guidelines after a fault is detected;
d) Stress testing. Evaluate system stability under high load conditions;
e) Recovery test. Verify the system's ability to enter a safe state after a failure occurs.
10 Assessment Report
10.1 Reporting Requirements All Industrial Internet Collaborative Manufacturing (SIL) assessment activities should be documented. These documents should be clearly structured, accurately worded, and unambiguous. The requirements for the resulting evaluation report include.
a) The assessment report should cover the entire assessment process, ensuring transparency and traceability;
b) The assessment report is released after being reviewed, approved, and signed by the relevant stakeholders;
c) If any changes or additions are needed after the assessment report is issued, a supplementary report should be submitted, and the title of the original report should be indicated in the supplementary report. The supplementary report, including its numbering, follows the same requirements as the original report.
10.2 Report Format The assessment report should include a cover page, assessment purpose, assessment scope, assessment basis, assessment methods, assessment plan, system assets, original records, and pending details. The assessment items, assessment conclusions and recommendations, qualifications of the organization and personnel, signatures of the assessors, appendices, etc. The relevant content should meet the following requirements.
a) Cover. Indicate the report title, unified number, evaluation agency, and publication date.
b) Scope of Assessment. Describe the system being assessed, including the overall architecture of the collaborative manufacturing platform, the composition of each module, and their interrelationships. System, etc.
c) Evaluation methods. including procedures and standards.
d) Assessment Plan. Describe the assessment project, including the risk reduction measures undertaken by the collaborative manufacturing platform based on the overall risk assessment. Seeking, SIL objectives, etc.
e) Original Records. Detailed records of measurement and testing, including descriptions of observed faults, may be provided using appropriate tables, pictures, drawings, or other formats. Photo captions include the process and results of software testing and fault insertion testing, with supplementary materials provided as necessary.
f) Items to be evaluated. Record any inconsistencies with the evaluation plan, including adding or removing evaluation items, and explain the reasons.
g) Evaluation Conclusions and Recommendations. Provide an explanation of whether the system meets the evaluation requirements, including the achievements of each module of the collaborative manufacturing platform. SIL, restrictions on security applications, etc.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 44 pages — is available in the English PDF.
How to Buy GB/T 47698-2026
- 1Add to cart. Click the "Buy GB/T 47698-2026" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 47698-2026
$365.00