GB/T 37401-2019 PDF English
US$150.00 · In stock · Download in 9 secondsGB/T 37401-2019: Service assurance technical requirement for electronic commerce platform Delivery: 9 seconds. True-PDF full-copy in English & invoice will be downloaded + auto-delivered via email. See step-by-step procedureStatus: Valid
Standard ID | Contents [version] | USD | STEP2 | [PDF] delivery | Name of Chinese Standard | Status |
GB/T 37401-2019 | English | 150 |
Add to Cart
|
0-9 seconds. Auto-delivery
|
Service assurance technical requirement for electronic commerce platform
| Valid |
Excerpted PDFs (Download full copy in 9 seconds upon purchase)PDF Preview: GB/T 37401-2019
GB/T 37401-2019: Service assurance technical requirement for electronic commerce platform---This is an excerpt. Full copy of true-PDF in English version (including equations, symbols, images, flow-chart, tables, and figures etc.), auto-downloaded/delivered in 9 seconds, can be purchased online: https://www.ChineseStandard.net/PDF.aspx/GBT37401-2019
NATIONAL STANDARD OF THE
PEOPLE’S REPUBLIC OF CHINA
ICS 35.240.60
A 10
Service assurance technical requirement for
electronic commerce platform
ISSUED ON: MAY 10,2019
IMPLEMENTED ON: DECEMBER 1, 2019
Issued by: State Administration for Market Regulation of the People's
Republic of China;
Standardization Administration of the People's Republic of
China.
Table of Contents
Foreword ... 3
1 Scope ... 4
2 Normative references ... 4
3 Terms and definitions ... 5
4 Service assurance system of electronic commerce platform ... 5
5 Transaction process assurance ... 6
6 Fundamental guarantees ... 10
Bibliography ... 15
Foreword
This Standard was drafted in accordance with the rules given in GB/T 1.1-2009.
This Standard was proposed by and shall be under the jurisdiction of National
Technical Committee on Electronic Business Standardization (SAC/TC 83).
The drafting organizations of this Standard: China National Institute of Standardization,
Xiamen Zhicheng Standardization Service Co., Ltd., Haiquan Baishan Biotechnology
Co., Ltd., Chengdu DAQsoft Co., Ltd., CTCA Inspection (Quanzhou) Technical
Services Co., Ltd., Jinjiang Lvsheng Food Co., Ltd., China Jiliang University, Jiangsu
Institute of Quality and Standardization, Guangzhou Institute of Standardization,
Hanghzou Hanzheng Technical Services Co., Ltd., Shandong University of Technology,
Dongguan ARUN Inc., Xiamen Anne Corporation Limited, Anhui Institute of Quality and
Standardization.
The main drafters of this Standard: Cheng Yue, Sun Zhaoyang, Sui Yuan, Mao Haijun,
Li Jing, Wang Shuang, Wang Zhimin, Gao Ang, Zhu Hong, Xian Kuitong, Chen Yinlong,
Mao Xu, Lin Yun, Yang Xiaofeng, Zhang Ying, Liu He, Qiu Zhiping, Ding Yafang, Gong
Kunxiang, Cao Xinjiu, Liu Ying, Zhou Daohua, Hao Han, Ling Junjie, Lin Fengxi, Zhou
Ruqi.
Service assurance technical requirement for
electronic commerce platform
1 Scope
This Standard specifies the transaction process assurance and basic assurance
technical requirements for electronic commerce platform.
This Standard applies to the planning and implementation of the service assurance of
electronic commerce platform.
2 Normative references
The following referenced documents are indispensable for the application of this
document. For dated references, only the edition dated applies to this document. For
undated references, the latest edition of the referenced documents (including all
amendments) applies to this document.
GB/T 2887, General specification for computer field
GB/T 20270, Information security technology – Basis security techniques
requirement for network
GB/T 20281, Information security technology – Security technical requirements
and testing and evaluation approaches for firewall
GB/T 20988, Information security technology – Disaster recovery specifications
for information systems
GB/T 22080, Information technology – Security techniques – Information security
management systems – Requirements
GB/T 28827.1, Information technology service – Operations and maintenance –
Part 1: General requirements
GB/Z 28828, Information security technology – Guideline for personal information
protection within information system for public and commercial services
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply.
3.1
electronic commerce
Commercial activities which are carried out in the form of electronics.
NOTE: Economic activity subjects use modern information technology (including the Internet,
mobile network and other information networks) to carry out commercial activities with each
other, to fulfill electronization in part or in whole in the key commercial activities such as online
communication, signing, payment and so on, including goods trading, service trading,
intellectual property trading, etc.
[GB/T 31524-2015, Definition 3.1]
3.2
electronic commerce platform
The total of information network systems which provide match-making and related
services for two parties or multiple parties of a transaction in electronic commerce
activities.
[GB/T 31524-2015, Definition 3.2]
3.3
electronic commerce subject
The total of information network systems which provide match-making and related
services for two parties or multiple parties of a transaction in electronic commerce
activities.
[GB/T 32873-2016, Definition 3.2]
4 Service assurance system of electronic commerce
platform
4.1 The service assurance system of electronic commerce platform is as shown in
Figure 1.
Figure 1 – Service assurance system of electronic commerce platform
4.2 The service assurance system of electronic commerce platform shall include:
a) transaction process assurance: the service assurance of the whole transaction
process of electronic commerce, mainly covering the service assurance in the
links such as before transaction, in transaction and after transaction;
b) basic assurance: all kinds of basic service assurance provided based on
electronic commerce platform, covering security assurance, platform
environment, data management and operation and maintenance management.
5 Transaction process assurance
5.1 Before-transaction requirements
5.1.1 Subject identity authentication
Electronic commerce platform shall have the subject identity authentication function,
whose functional requirements shall at least include:
Transaction process assurance
Before transaction In transaction After transaction
Subject identity authentication
Product service assurance
Order handling
Order payment
Logistics distribution
After-sale service
Fundamental assurance
Security
assurance Platform environment Data management
Operation and
maintenance
management
a) data acquisition: supporting the functions such as online fill-out and uploading
corresponding documentary evidences, to fulfill the acquisition of subject’s real
information in the process of an electronic commerce transaction. The information
acquired shall include but not limited to:
1) subject registration information, including basic information, subject identity
information and so on;
2) license information, including the information of relevant administrative licenses
or selling authorization licenses which are necessary for selling goods or
providing services;
3) contact information, including the information of detailed address, contact
telephone, e-mail and so on.
b) Information authentication: providing the functions such as online inquiry,
background authentication, and examining the related transaction activity
information by means of digital signature, digital certificate, etc.
c) information announcement: by means of image insertion or web page linkage,
realizing the announcement of the qualification information such as license
information, registration information, in prominent positions.
5.1.2 Product service assurance
5.1.2.1 Product information description
Electronic commerce platform shall have the function of describing the information of
products sold clearly, including:
a) the function of product information modelling shall at least include:
1) general information module, supporting the function to describe the information
entities such as the basic information, corporate information, contact information
and so on of products sold, and the information elements such as product name,
brand, place of origin, corporate name, contact telephone, etc.;
2) special information module, supporting the function to describe the characteristic
information entities and information elements of products sold.
b) the function established by the product information description methods: supporting
the establishment of the related descriptive methods of basic attributes, data types
and formats, etc. of product information entities and information elements. For the
detailed descriptive methods, refer to the requirements in relevant national
standards such as GB/T 32670 and GB/T 33989.
5.1.2.2 Product quality assurance
Electronic commerce platform shall provide the function of online fill-out of
documentary information and uploading documentary documents related to product
quality assurance, and examine its compliance, legality and authenticity.
5.2 In-transaction requirements
5.2.1 Order handling
Electronic commerce platform shall provide the related function module of order
handling such as order placing service, order management, etc., whose requirements
shall include but not limited to:
a) the requirements of order placing service function module include:
1) providing specific transaction rules and convenient order placing processes,
preferably supporting the functions such as one-key order placing;
2) providing the guidance of the whole process of order placing by means of page
reminder, etc.;
3) having the functions such as order confirmation, payment method description
and selection, etc. at the key links of the order placing service process;
4) describing the quantity of goods selected, expected delivery time, delivery place,
distribution method, order amount details, invoice information, discounting
details, which are shown by means of independent pages before confirming
order;
5) providing the order detail notification function by means of text message, platform
short message, related social communication software, e-mail, etc., to realize
the confirmation of ordering and payment;
6) electronic commerce platform can support the distribution method selection
function;
7) preferably providing multiple order placing methods, including but not limited to
computer end, mobile phone end, etc.
b) the requirements for the order management function module include:
1) supporting the acquisition of information related to payment, delivery, receiving,
etc. and realizing the function of order detail tracking;
2) being able to carry out historical order inquiry by setting the conditions such as
time and keywords.
5.2.2 Order payment
Electronic commerce platform shall ensure the safety and convenience of order
payment, its requirements including but not limited to:
a) it shall provide multiple optional payment methods and payment means through all
kinds of interfaces;
b) it shall support the access to the payment processes, payment reminders, payment
instructions, etc. through the technologies such as image insertion and web page
linkage;
c) it shall support the notification function with the methods such as SMS and E-mail
at the same time when the payment is completed;
d) it shall preferably support the real-time verification function for the on-line payment
processes;
5.3 After-transaction requirements
5.3.1 Logistics distribution
Electronic commerce platform shall provide service guarantee for the logistics
distribution of the products sold, its requirements including but not limited to:
a) it shall support the information display function of the whole distribution process of
the goods sold in the order page, the content of information including but not limited
to delivery information, transportation information, dispatching information,
receiving information, etc.;
b) it shall provide the consumers the evaluation function module of logistics distribution
services;
c) for those electronic commerce platforms which provide self-operated logistics
distribution services, the requirements for them include:
1) the message notification function, which supports sending relevant information,
such as delivery, transportation, dispatching, receiving, etc., by means of the
technologies, such as E-mail, SMS and telephone;
2) the receiving confirmation function module, which preferably provide a receiving
confirmation function combining the on-line and off-line ways.
5.3.2 After-sale services
5.3.2.1 Goods return or replacement service
Electronic commerce platform shall have the goods return or replacement service, its
requirements including but not limited to:
a) it shall, in accordance with the instructions for goods return and replacement, clarify
the form of returning goods and payment, the time and address of goods handover,
the identity of deliveryman, the appearance of goods, the inspection requirements
of goods, the extra expenses, etc.;
b) it shall provide package for the transportation of returned or replaced goods;
c) it preferably uses electronic documents to record the appearance and performance
of the returned or replaced goods received;
d) it preferably uses electronic documents to keep all kinds of records of the process
of goods return or replacement.
5.3.2.2 Dispute handling service
Electronic commerce platform shall provide the dispute handling service, its
requirements including but not limited to:
a) it shall, using the technologies such as image insertion and web page linkage,
publish, at notable locations on the page of electronic commerce platform, the
information such as the dispute handling rules, dispute handling channels and
detailed processes;
b) it shall, by means of the information technologies such as SMS, platform SMS,
associated social software and E-mail to feedback the dispute complaint information,
guarantee that it will confirm the receiving of the dispute complaint information to
the consumers within a guaranteed time, and feedback the handling results on a
timely basis to the consumers.
6 Fundamental guarantees
6.1 Security guarantee
6.1.1 Information security
The information security guarantee of electronic commerce platform shall be as
specified in GB/T 22080, the specific requirements at least including:
a) it shall filter out the contents not conforming to the rules, such as videos, images
and words;
b) it shall clarify the transactional information protection principles at notable locations
of the website, the content including but not limited to consumer information,
information access channels, information protection methods, information use
purposes, information use ranges, etc.;
c) it shall allow the consumers to set limits and authorize the use right and use range
of their personal information;
d) it preferably provides the details whether personal information is protected, where
the protection of the consumers’ personal information shall be as specified in GB/Z
28828;
e) electronic commerce platform shall follow their information protection principles in
the service processes including payment and distribution;
f) the consumers’ information stored by electronic commerce platform shall be
processed by encryption. It shall only be used in the transactional process occurring
on the electronic commerce platform, and shall be as specified in relevant laws and
regulations such as the Cybersecurity Law of the People's Republic of China and
the Provisions on Protecting the Personal Information of Telecommunications and
Internet Users;
g) the relevant interfaces of electronic commerce platform shall provide the functions
form the consumers to change, delete, cancel, etc. their personal information.
6.1.2 Network fundamental security
The network fundamental security of electronic commerce platform shall be as
specified in GB/T 20270.
6.1.3 Interface security
The interface of electronic commerce platform shall include the marking-accounting
interface, the product purchase-sell-stock circulation interface, the subject identity
authentication interface, the logistics distribution interface, the payment service
provider interface; their openness shall be as specified in the security requirements for
relevant interfaces.
6.2 Platform environmental requirements
The requirements for the environment of electronic commerce platform shall include
but not limited to:
a) the design of the machine rooms shall be as specified in GB/T 2887;
b) the operating systems and databases shall meet the requirements for the operation
of electronic commerce platform;
c) the backup software shall ensure the completeness of the backup data. it shall
support multiple backup methods such as increment, differential, on-line, off-line,
etc. as well as multiple checking methods such as byte parity and fast tape scanning.
It shall have the management capability of the backup media;
d) it shall use relatively mature network and system monitoring equipment and software,
carry out real-time inspection, monitoring, alarming and blocking of the commonly
operations of the network and system, and protect from the network attacks;
e) the fire wall shall have good performance, convenient configuration and complete
management and condition monitoring means, as specified in GB/T 20281;
f) it shall have anti-virus software which features low footprint, easily deployment and
management, and strong virus protection.
6.3 Data management requirements
The requirements for the data management of electronic commerce platform shall
include but not limited to:
a) it shall, in accordance with the data storage protection requirements, select a
corresponding encryption method to protect the data stored by the platform;
b) it shall test the completeness of the significant business and management data by
means of the deployment of a detection system, etc., and take necessary recovery
measures when completeness errors are detected;
c) it shall, in accordance with relevant laws, regulations and standards to handle and
protect the sensitive information, e.g. the data involving personal privacy, etc.;
d) it shall carry out the data backup work regularly, the specific methods including but
not limited to:
1) it shall make backups by means of full backup, incremental backup or differential
backup;
2) it shall determine the backup cycle in accordance with the flow and significance
of the business and management data;
3) the data backup content shall include but not limited to the basic information of a
page, the personal information of the consumers, the transactional information,
and the business and management information.
e) for data recovery, it shall be as specified in GB/T 20988.
6.4 Requirements for operation, maintenance and management
6.4.1 Management mechanism construction
Electronic commerce platform shall establish a management mechanism for the
operation and maintenance of the platform, including but not limited to:
a) it shall establish a related mechanism to provide the comprehensive management
of operation and maintenance for the objects, including electronic commerce
platform, application system, services, resources, etc., and the specific measures
shall be as specified in GB/T 28827.1;
b) it supports using the technologies, such as telephone, SMS, platform SMS,
associated social communication software and E-mail, and establish an
informationalized receiving mechanism of the relevant requests and records for the
users of electronic commerce platform;
c) it shall classify the services requested by the users of the platform in terms of the
whole process links and fundamental guarantee of transactions, and establish a
classified handling mechanism;
d) the supervision service handles the process of relevant matters, and establish a
corresponding supervisory handling mechanism;
e) it shall support using the technologies, such as telephone, SMS, platform SMS,
associated social communication software and E-mail, call back to know about the
handling and implementation of the requests received, and establish a call-back
feedback mechanism;
f) it shall use the methods, such as reporting, alarming, statistical analysis and tracing
of complaints, and establish a complaint management mechanism;
g) it shall clarify the requirements for the management and technology in terms of
operating procedures, emergency response, routine maintenance, custody of
software and hardware files, information privacy, access management, etc., and
establish a security mechanism;
h) electronic commerce service providers shall provide an evaluation system to
evaluate the quality of services.
6.4.2 Personnel requirements
Electronic commerce platform shall establish a corresponding operation, maintenance
and management mechanism; provide staff in terms of technology, services,
management, etc., the number of personnel as required by the actual business
requirements; the requirements shall include but not limited to:
a) they shall abide by the national laws and regulations as well as all the rules and
regulations and professional ethics required for their posts;
b) they shall have the security secrecy consciousness and have the emergency
response capabilities;
c) they shall master the professional knowledge required for their posts.
6.4.3 Requirements for posts and training
Electronic commerce platform shall clarify the responsibilities of all posts, and provide
training for relevant staff at different posts. The specific requirements include but not
limited to:
a) it shall establish the posts such as after-sale service, operation and maintenance
management, and security and secrecy, which are responsible for the guarantee of
the overall operation of the services of electronic commerce platform;
b) it shall, in accordance with the details of different posts, organize relevant staff to
participate in pre-job and on-job training in order to meet the requirements for the
post skills and qualities;
c) the newly-recruited and temporary employees shall take up their work after they
pass the training.
Bibliography
[1] GB/T 31524-2015, Specification of operations and technology for electronic
commerce platform
[2] GB/T 32670-2016, Information description of product for electronic commerce
transaction – Clothing
[3] GB/T 32873-2016, Specification for basic information of electronic commerce
subject
[4] GB/T 33989-2017, Information description of product for electronic commerce
transaction – Tourism service
[5] Information description of product for electronic commerce transaction--Tourism
service (Order No. 53 of the President of the People’s Republic of China)
[6] Provisions on Protecting the Personal Information of Telecommunications and
Internet Users (Order No. 24 of the Ministry of Industry and Information Technology
of the People’s Republic of China)
__________ END __________
...... Source: Above contents are excerpted from the full-copy PDF -- translated/reviewed by: www.ChineseStandard.net / Wayne Zheng et al.
Tips & Frequently Asked QuestionsQuestion 1: How long will the true-PDF of English version of GB/T 37401-2019 be delivered?Answer: The full copy PDF of English version of GB/T 37401-2019 can be downloaded in 9 seconds, and it will also be emailed to you in 9 seconds (double mechanisms to ensure the delivery reliably), with PDF-invoice. Question 2: Can I share the purchased PDF of GB/T 37401-2019_English with my colleagues?Answer: Yes. The purchased PDF of GB/T 37401-2019_English will be deemed to be sold to your employer/organization who actually paid for it, including your colleagues and your employer's intranet. Question 3: Does the price include tax/VAT?Answer: Yes. Our tax invoice, downloaded/delivered in 9 seconds, includes all tax/VAT and complies with 100+ countries' tax regulations (tax exempted in 100+ countries) -- See Avoidance of Double Taxation Agreements (DTAs): List of DTAs signed between Singapore and 100+ countriesQuestion 4: Do you accept my currency other than USD?Answer: Yes. www.ChineseStandard.us -- GB/T 37401-2019 -- Click this link and select your country/currency to pay, the exact amount in your currency will be printed on the invoice. Full PDF will also be downloaded/emailed in 9 seconds.
How to buy and download a true PDF of English version of GB/T 37401-2019?A step-by-step guide to download PDF of GB/T 37401-2019_EnglishStep 1: Visit website https://www.ChineseStandard.net (Pay in USD), or https://www.ChineseStandard.us (Pay in any currencies such as Euro, KRW, JPY, AUD). Step 2: Search keyword "GB/T 37401-2019". Step 3: Click "Add to Cart". If multiple PDFs are required, repeat steps 2 and 3 to add up to 12 PDFs to cart. Step 4: Select payment option (Via payment agents Stripe or PayPal). Step 5: Customize Tax Invoice -- Fill up your email etc. Step 6: Click "Checkout". Step 7: Make payment by credit card, PayPal, Google Pay etc. After the payment is completed and in 9 seconds, you will receive 2 emails attached with the purchased PDFs and PDF-invoice, respectively. Step 8: Optional -- Go to download PDF. Step 9: Optional -- Click Open/Download PDF to download PDFs and invoice. See screenshots for above steps: Steps 1~3 Steps 4~6 Step 7 Step 8 Step 9
|