GB/T 27910-2011 Financial services—Information security guidelines
GB/T 27910-2011 Financial services—Information security guidelines
Basic Information
Scope
This standard provides guidance for financial institutions in developing information security programs. The guide includes strategic discussions and structured legal and regulatory components of institutions and programs. The standard explores the considerations that should be taken into account when selecting and implementing security control measures, as well as the elements of managing information security risks in modern financial services institutions, and provides recommendations based on the institution's business environment, practices, and procedures. The standard also includes discussions on legal and regulatory compliance issues, which need to be considered during the design and implementation phases of the program.
This standard is intended as a reference for financial institutions when developing information security programs.