GB/T 28448-2012 Information security technology—Testing and evaluation requirement for classified protection of information system
GB/T 28448-2012 Information security technology—Testing and evaluation requirement for classified protection of information system
Basic Information
Scope
This standard specifies the requirements for testing and evaluating whether the implemented information systems comply with GB/T 22239-2008, including the requirements for testing and evaluating first-level, second-level, third-level, and fourth-level information systems. This standard omits the requirements for evaluating fifth-level information systems.
This standard applies to information security assessment service institutions, the competent departments of information systems, and operational and user units conducting security testing and evaluation of the security level protection status of information systems. Information security regulatory departments may refer to and use this standard when conducting supervision and inspection of information security level protection in accordance with the law.