Valid

GB/Z 24294.1-2018Information security technology - Guide of implementation for internet-based e-government information security - Part 1: General (English PDF)

信息安全技术 基于互联网电子政务信息安全实施指南 第1部分:总则

Open the GB/Z 24294.1-2018 preview as PDF

Preview — first pages of GB/Z 24294.1-2018 (full document: 23 pages)

This is a limited preview

Buy now to download the full PDF (23 pages)

Issued by

State Administration for Market Regulation; Standardization Administration of China

Level / Type

National · Recommended

Issue date

March 15, 2018

Implementation date

March 15, 2018

Scope

GB/Z 24294.1-2018 is the English-translated version of 信息安全技术 基于互联网电子政务信息安全实施指南 第1部分:总则.

This part of GB/Z 24294 gives the reference model for the information security of internet-based e-government, builds the technical system for the information security of internet-based e-government, and gives guidance recommendations on the principles of implementation of the system, the framework of implementation, the key technologies of implementation and risk assessment. It provides a specification for building an information security assurance architecture for internet-based e-government and for establishing an information security system for internet-based e-government. This part applies to organizations that have no dedicated e-government extranet line and no leased communication network line and that carry out the construction of information security for e-government not involving state secrets on the basis of the internet; it provides a management and technical reference for managers, engineering and technical personnel and suppliers of information security products in the construction of information security. Where state secrets are involved, or where the information stored, processed or transmitted may involve state secrets once aggregated, the national secrecy provisions and standards are to be followed.

Document preview — GB/Z 24294.1-2018

National Standard of the People's Republic of China

ICS
35.040
Classification
L80

Issued by: State Administration for Market Regulation; Standardization Administration of China

Contents

  • 1 Scope1
  • 2 Normative references1
  • 3 Terms and Definitions1
  • 4 Abbreviations2
  • 5 Internet-based e-government information security reference model2
  • 5.1 Safety Reference Model2
  • 5.2 Security Policy3
  • 5.3 Identifying security requirements4
  • 5.4 Safety Design4
  • 5.5 Security Implementation4
  • 5.6 Security Assessment5
  • 6 Based on the Internet e-government information security technology system5
  • 6.1 Safety Technology System5
  • 6.2 Public Key Infrastructure6
  • 6.3 Security Interconnection and Access Control, Border Protection6
  • 6.4 Regional Security6
  • 6.5 Terminal Security6
  • 6.6 Application Security6
  • 6.7 Security Management6
  • 6.8 Security Services6
  • 7 Implementation Principles of the System6
  • 7.1 On-demand protection principle6
  • 7.2 Principle of Minimization of Permissions7
  • 7.3 Information Classification Protection Principle7
  • 7.4 System Domain Control Principle7
  • 8 System Implementation Architecture7
  • 8.1 System Implementation Architecture in Data Centralized Mode7
  • 8.2 System Implementation Architecture in Data Distribution Storage Mode8
  • 8.3 System Implementation Architecture in Mobile Office Mode11
  • 9 Key aspects of system implementation13
  • 9.1 System Domain Control13
  • 9.2 Unified Certification Authorization13
  • 9.3 Access Control and Secure Exchange14
  • 9.4 Terminal Security Protection14
  • 10 System Risk Assessment14
  • 10.1 Customer Interview14
  • 10.2 Document Information Verification14
  • 10.3 Analysis of Construction Plan14
  • 10.4 Programme Implementation Verification15
  • 10.5 Tool Detection15
  • 16 Appendix B (informative appendix) Example of information classification protection based on Internet e-government system in a city19

Foreword

GB /Z 24294 "Information Security Technology Based on Internet E-Government Information Security Implementation Guide" is divided into the following sections.

--- Part 1. General;

--- Part 2. Access Control and Security Exchange;

--- Part 3. Identity authentication and authorization management;

--- Part 4. Terminal security protection. This part is the first part of GB /Z 24294. This part is drafted in accordance with the rules given in GB/T 1.1-2009. This part replaces GB /Z 24294-2009 "Internet-based e-government information security implementation guide." With GB /Z 24294- Compared to.2009, the main technical changes are as follows:

--- Added a reference model based on Internet e-government information security;

--- A new revision to the Internet-based e-government information security technology system;

--- New recommendations for the implementation of the Internet-based e-government implementation framework;

--- New recommendations for access control and secure exchange;

--- New recommendations for the new application model of Internet e-government mobile terminals;

--- New additions to the specific application of information classification protection;

--- New recommendations for identity authentication and authorization management for trust system construction. Please note that some of the contents of this document may involve patents. The issuing organization of this document is not responsible for identifying these patents. This part is proposed and managed by the National Information Security Standardization Technical Committee (SAC/TC260). This section drafted by: PLA Information Engineering University, China Electronics Technology Standardization Institute, Beijing Tianrongxin Technology Co., Ltd., Zheng State Xinda Jiean Information Technology Co., Ltd. The main drafters of this section. Chen Xingyuan, Du Xuehui, Sun Wei, Cao Lifeng, Zhang Dongyu, Ren Zhiyu, Xia Chuntao, He Jun, Jing Hongli, Shangguan Xiaoli. The previous versions of the standards replaced by this section are.

---GB /Z 24294-2009.

The Internet has become an important information infrastructure, and actively using the Internet to build e-government in China can improve efficiency and expand The coverage of the service can save resources and reduce costs. Using the open Internet to carry out e-government construction, facing computer viruses and networks Security threats and risks such as network attacks, information leakage, and identity spoofing. In order to promote the application of the Internet in China's e-government, the guidance is based on mutual This guideline technical document is specially formulated for the security of networked e-government information. The e-government information security implementation guideline standard based on the Internet e-government information security implementation guide general rules, access Control and security exchange, identity authentication and authorization management, terminal security protection. Implementation of e-government information security based on the Internet The general guideline is based on the overview of Internet e-government information security construction, which can guide government departments to establish e-government information based on the Internet. Security system, build Internet e-government information security technology system; access control and security exchange, identity authentication and authorization management Three specifications for terminal security protection, from the Internet e-government security interconnection and access control, government office and government service security, politics The three key implementation points of terminal security protection are to standardize the construction of Internet-based electronic information security systems. Information security technology Internet e-government information security implementation guide Part 1. General

1 Scope

This part of GB/Z 24294 gives the reference model for the information security of internet-based e-government, builds the technical system for the information security of internet-based e-government, and gives guidance recommendations on the principles of implementation of the system, the framework of implementation, the key technologies of implementation and risk assessment. It provides a specification for building an information security assurance architecture for internet-based e-government and for establishing an information security system for internet-based e-government. This part applies to organizations that have no dedicated e-government extranet line and no leased communication network line and that carry out the construction of information security for e-government not involving state secrets on the basis of the internet; it provides a management and technical reference for managers, engineering and technical personnel and suppliers of information security products in the construction of information security. Where state secrets are involved, or where the information stored, processed or transmitted may involve state secrets once aggregated, the national secrecy provisions and standards are to be followed.

This part of GB /Z 24294 gives an e-government based on Internet e-government information security reference model. The information security technology system provides guidance on the implementation principles, implementation framework, implementation of key technologies and risk assessment of the system. Structure It is based on the Internet e-government information security assurance framework and the establishment of an e-government information security system based on the Internet. This section applies to organizations that do not have an e-government extranet or a leased communication network. Information security construction of e-government that does not involve state secrets, and information for managers, engineers, and information security product providers Safety construction provides management and technical reference. Involving state secrets, or may involve state secrets after the collection, processing, and transmission of information, Implemented in accordance with national secrecy regulations and standards.

2 Normative references

The following documents are indispensable for the application of this document. For dated references, only dated versions apply to this article. Pieces. For undated references, the latest edition (including all amendments) applies to this document.

GB/T 20984-2007 Information Security Technology Information Security Risk Assessment Specification

GB/T 30278-2013 Information Security Technology Government Computer Terminal Core Configuration Specification

GB/T 31167-2014 Information Security Technology Cloud Computing Service Security Guide

3 Terms and definitions

The following terms and definitions apply to this document.

3.1 Internal data processing domain insidedataprocessingdomain The administrative office system and its data domain that are only open to government officials.

3.2 Security administration network platform networkplatformforsecuregovernmentaffairs Through the use of commercial cryptography and VPN technology, reasonable configuration of different types of VPN products, based entirely on the Internet, to achieve The low-cost, scalable e-government network built by the municipal/county/township and other party and government departments.

3.3 Security government office platform officeplatformforsecuregovernmentaffairs Security technology such as data domain storage, unified identity authentication, unified authorization management, and information classification protection, and e-government office applications The system is combined to make electronic electronic documents, such as finalization, issuance, stamping, sending, receiving, printing and archiving. In the government office system, the identity is credible, the behavior is controllable, and the system can be managed, creating a safe and controllable Internet e-government office platform.

3.4 Public data processing domain publicdataprocessingdomain The public service system open to the public and the domain in which it is located.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 23 pages — is available in the English PDF.

Referenced standards

Similar standards

Editions of GB/Z 24294.1

EditionTitleRevisionStatus
GB/Z 24294.1-2018Information security technology - Guide of implementation for internet-based e-government information security - Part 1: Generalcurrent editionCurrent
GB/Z 24294-2009Information security technology-Guide of implementation for internet-based E-government information securitymerged into this editionSuperseded

This page sells the current edition, GB/Z 24294.1-2018. Earlier editions are listed for reference only.

How to Buy GB/Z 24294.1-2018

  1. 1Add to cart. Click the "Buy GB/Z 24294.1-2018" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
23 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/Z 24294.1-2018

$420.00

$355.00for partners