GB/T 20274.4-2008 Information security technology—Evaluation framework for information systems security assurance—Part 4:Engineering assurance
GB/T 20274.4-2008 Information security technology—Evaluation framework for information systems security assurance—Part 4:Engineering assurance
Basic Information
Scope
This part of GB/T 20274 establishes a framework for ensuring the security of information systems and sets out guidelines and general principles for organizations to initiate, implement, maintain, evaluate, and improve information security projects. It defines and explains the security engineering capability levels that reflect an organization's ability to ensure information security, as well as the requirements for security engineering control categories that provide the content of information security project assurance for organizations. This part of GB/T 20274 is applicable to organizations that initiate, implement, maintain, evaluate, and improve information security projects, as well as all users, developers, and evaluators involved in information system security engineering work.