GB/T 28453-2012 Information security technology—Information system security management assessment requirements
GB/T 28453-2012 Information security technology—Information system security management assessment requirements
Basic Information
Scope
This standard, based on the requirements for hierarchical security management of information systems specified in GB/T 20269—2006, stipulates the principles and models, organizations and activities, methods and implementation for conducting security management assessments of information systems at different stages of their life cycle. It also sets out the requirements for security management assessments of information systems at levels 1 to 5 of the information security level protection system.
This standard applies to the security management assessments and self-assessments conducted by relevant organizations (departments) on information systems implementing security level protection, as well as the management of assessments by both assessors and those being assessed.