Valid

GB/Z 24294.4-2017Information security technology - Guide of implementation for Internet-based e-government information security - Part 4: Defense for terminal security (English PDF)

信息安全技术 基于互联网电子政务信息安全实施指南 第4部分:终端安全防护

Open the GB/Z 24294.4-2017 preview as PDF

Preview — first pages of GB/Z 24294.4-2017 (full document: 20 pages)

This is a limited preview

Buy now to download the full PDF (20 pages)

Issued by

State Administration for Market Regulation; Standardization Administration of China

Level / Type

National · Recommended

Issue date

May 12, 2017

Implementation date

May 12, 2017

Scope

GB/Z 24294.4-2017 is the English-translated version of 信息安全技术 基于互联网电子政务信息安全实施指南 第4部分:终端安全防护.

GB/Z 24294.4-2017 is the Chinese national standard on information security technology - guide of implementation for internet-based e-government information security - part 4: defense for terminal security, in the field of information technology. The /Z suffix marks it as a guiding technical document: it does not prescribe requirements that can be certified against, but sets out the technique, the method or the state of the art that the standards bodies recommend following. It was issued on 12 May 2017 by the State Administration for Market Regulation; Standardization Administration of China. As a guiding technical document it carries no separate date of entry into force: it applies from publication. Classification: ICS 35.040, CCS L80. This page is published from the official record of the standard held by the Chinese standards administration: the identification, the dates, the classification and the issuing body are taken from there. The clause text, the tables and the numeric limits are in the document itself, which is delivered complete in English translation.

Document preview — GB/Z 24294.4-2017

National Standard of the People's Republic of China

ICS
35.040
Classification
L80

Issued by: State Administration for Market Regulation; Standardization Administration of China

Contents

  • 1 Scope
  • 2 Normative references
  • 3 Terms and definitions
  • 4 Abbreviations
  • 5 Terminal Security Features and Implementation Principles

Foreword

GB /Z 24294 "Information Security Technology Internet-based e-government information security implementation guidelines" is divided into four parts.

--- Part 1. General principles;

--- Part 2. Access control and security exchange;

--- Part 3. Identity and authorization management;

--- Part 4. Terminal Security. This section GB /Z 24294 Part 4. This section drafted in accordance with GB/T 1.1-2009 given rules. Part of this section instead of GB /Z 24294-2009 "Information Security Technology Internet-based e-government information security implementation guidelines." Compared with GB /Z 24294-2009, the main technical changes are as follows:

--- Added vulnerabilities and major threats to Internet-based e-government terminals;

--- Supplement clearly defined based on the Internet e-government terminal security features and implementation principles;

--- Complement the division based on Internet e-government terminal security protection of the main application mode;

--- Supplementary specification based on the Internet e-government terminal in three application modes of security requirements. This part of the National Information Security Standardization Technical Committee (SAC/TC260) and focal point. This part of the drafting unit. People's Liberation Army Information Engineering University, China Electronics Standardization Institute, Beijing Tian Rong Xin Technology Co., Ltd. Zheng Dazhou Great Information Technology Co., Ltd. The main drafters of this section. Chen Xingyuan, Du Xuehui, Sun Yi, Xia Chuntao, Cao Li-feng, Zhang Dongwei, Ren Zhiyu, Luo Feng surplus, Shangguan Xiao Li, Dong Guohua. This part replaces the standards previously issued as.

--- GB /Z 24294-2009.

The Internet has become an important information infrastructure, making active use of the Internet for the construction of e-government in our country, which can not only improve efficiency and expand Service coverage, but also save resources and reduce costs. The use of open Internet to carry out e-government construction, computer terminals in the e-government To undertake and participate in the government information processing, storage and transmission and other important work, facing malicious code, cyber attacks, information leakage and Identity fraud and other security threats and risks. In order to promote the Internet in our e-government applications, guidance based on the Internet e-government terminal Security work, specially formulated in this section. This section is mainly applicable to organizations that do not have e-government extranet lines or do not have leased communications network special line conditions, to carry out non-involved State secrets e-government construction, when the construction needs, according to security strategy and e-government network security docking. Information Security Technology Internet-based e-government information security implementation guidelines Part 4. Terminal Security

1 Scope

GB/Z 24294.4-2017 is the Chinese national standard on information security technology - guide of implementation for internet-based e-government information security - part 4: defense for terminal security, in the field of information technology. The /Z suffix marks it as a guiding technical document: it does not prescribe requirements that can be certified against, but sets out the technique, the method or the state of the art that the standards bodies recommend following. It was issued on 12 May 2017 by the State Administration for Market Regulation; Standardization Administration of China. As a guiding technical document it carries no separate date of entry into force: it applies from publication. Classification: ICS 35.040, CCS L80. This page is published from the official record of the standard held by the Chinese standards administration: the identification, the dates, the classification and the issuing body are taken from there. The clause text, the tables and the numeric limits are in the document itself, which is delivered complete in English translation.

This part of GB /Z 24294 in accordance with the terminal security strategy, a clear Internet-based e-government terminal security technology Claim. This section applies to no e-government outside the green line or not leased communication network dedicated line organization, based on the Internet Do not involve the state secrets of e-government information security construction, for managers, engineers and technicians, information security products provider information Safety Management provides a management and technical reference. Where state secrets are involved or state secrets may be involved after the gathering of information stored, processed and transmitted, In accordance with national security regulations and standards.

2 Normative references

The following documents for the application of this document is essential. For dated references, only the dated version applies to this article Pieces. For undated references, the latest edition (including all amendments) applies to this document. Information technology - Computerized terminal computer core configuration specifications

3 Terms and definitions

The following terms and definitions apply to this document.

3.1 Safe government terminal terminalforsecuregovernmentaffairs Meet the government office security protection technology requirements, to carry out government office and business applications of computer terminals and handheld terminals.

4 Abbreviations

The following abbreviations apply to this document. FTP File Transfer Protocol (FileTransferProtocol) IIS Internet Information Services (InternetInformationServices) IP Internet Protocol (InternetProtocol) WWW WorldWideWeb

5 Terminal Security Features and Implementation Principles

5.1 Safety Vulnerability As a basic unit of work based on the Internet e-government system, the computer terminal undertakes and participates in the processing, processing and storage of government information Storage and transmission and other important work, the main security threats and vulnerabilities include.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 20 pages — is available in the English PDF.

Similar standards

Editions of GB/Z 24294.4

EditionTitleRevisionStatus
GB/Z 24294.4-2017Information security technology - Guide of implementation for Internet-based e-government information security - Part 4: Defense for terminal securitycurrent editionCurrent
GB/Z 24294-2009Information security technology-Guide of implementation for internet-based E-government information securitymerged into this editionSuperseded

This page sells the current edition, GB/Z 24294.4-2017. Earlier editions are listed for reference only.

How to Buy GB/Z 24294.4-2017

  1. 1Add to cart. Click the "Buy GB/Z 24294.4-2017" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
20 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/Z 24294.4-2017

$210.00

$180.00for partners