Home Cart Quotation About-Us
www.ChineseStandard.net
SEARCH

GA/T 1138-2014 English PDF

US$739.00 · In stock
Delivery: <= 4 days. True-PDF full-copy in English will be manually translated and delivered via email.
GA/T 1138-2014: Information security technology. Security technical requirements for access control products of host resources
Standard IDUSDBUY PDFLead-DaysStandard Title (Description)Status
GA/T 1138-2014739 Add to Cart 4 days Information security technology. Security technical requirements for access control products of host resources

Similar standards

GB/T 37230   GA/T 1059   GB 13954   GA/T 1137   GA/T 1139   GA/T 1136   

Basic data

Standard ID: GA/T 1138-2014 (GA/T1138-2014)
Description (Translated English): Information security technology. Security technical requirements for access control products of host resources
Sector / Industry: Public Security (Police) Industry Standard (Recommended)
Classification of Chinese Standard: A90
Classification of International Standard: 35.240
Word Count Estimation: 21,234
Quoted Standard: GB 17859-1999; GB/T 18336.1-2008; GB/T 18336.2-2008; GB/T 18336.3-2008; GB/T 25069-2010
Regulation (derived from): Notice on Publication of Public Safety Industry Standard (Year of 2014); Industry Standard Record Announcement No. 4 of 2015 (No. 184)
Issuing agency(ies): Ministry of Public Security
Summary: This standard specifies the security function requirements, security assurance requirements and classification requirements for host resource access control products. This standard is applicable to the design, development and testing of host resource acce

GA/T 1138-2014: Information security technology. Security technical requirements for access control products of host resources


---This is a DRAFT version for illustration, not a final translation. Full copy of true-PDF in English version (including equations, symbols, images, flow-chart, tables, and figures etc.) will be manually/carefully translated upon your order.
Information security technology.Security technical requirements for access control products of host resources ICS 35.240 A90 People's Republic of China Public Security Industry Standards Information Security Technology Host resource access control product safety technical requirements Issued on. 2014-03-10 2014-03-10 implementation People's Republic of China Ministry of Public Security

Table of Contents

Introduction Ⅲ Introduction Ⅳ 1 Scope 1 2 Normative references 1 3 Terms and definitions 4 Host Resource Access Control Product Description 1 5 2 Security Environment 5.1 Hypothesis 2 5.2 Threat 2 5.3 3 Organization for Security Policy 6 security objectives 3 6.1 Product Safety Objective 3 6.2 Objective 4 Environmental Safety 7 Security functional requirements 4 7.1 Access Control host resources covered 4 7.2 Host Resource Management 4 7.3 access control policy 4 7.4 Access Control 4 7.5 Access restrictions capacity of 50,000 7.6 access control policy issued under 5 7.7 access control policy can not bypass 5 7.8 User Authentication Management 5 7.9 Security Management 6 7.10 self-protection function 6 7.11 Remote Transport Security 7 7.12 audit function 7 8 7 Security assurance requirements 8.1 Configuration Management 7 8.2 Delivery and Operation 8 8.3 Development 8 8.4 guidance document 10 10 8.5 Life Cycle Support 8.6 Test 11 8.7 Vulnerability assessment 12 9 basic principles of technical requirements 12 9.1 Security functional requirements Fundamentals 12 9.2 Security assurance requirements 14 Fundamentals 10 Classification of claim 14 10.1 Overview 14 10.2 Classification of security functional requirements 14 10.3 Classification of security assurance requirements 15

Foreword

This standard was drafted in accordance with GB/T 1.1-2009 given rules. Please note that some of the content of this document may involve patents. Release mechanism of the present document does not assume responsibility for the identification of these patents. This standard was proposed by the Ministry of Public Security Network Security Protection Agency. This standard is under the jurisdiction of the Ministry of Public Security Information System Standardization Technical Committee. This standard was drafted. Ministry of Public Security of Computer Information System Security Product Quality Supervision and Inspection Center, Zhejiang Wansai Software Technology Co., Secretary, Ministry of Public Security the third Institute. The main drafters of this standard. a good song, Shen Liang, Yu excellent, Hu Weina, Gu Jian, Gu Wei, Zhang smiled, Zhao Yongliang.

Introduction

This standard is described in detail with the host resource access control product safety environment-related assumptions, threats and organizational security policy defines the primary Machine Resource Access Control security purposes and product support environment through the basic principles of argumentation security functional requirements and be able to trace the products covered Security purposes, for security purposes can be traced back cover and secure environment-related assumptions, threats and organizational security policies. The standard base-level reference to GB/T 18336.3-2008 prescribed level EAL2 security assurance requirements, and enhance the level at EAL4 level Security assurance requirements based on the vulnerability analysis requires upgrade to an attacker can withstand moderate attack potential attack. This standard only gives the host resource access control products should meet the technical requirements of safety, but the host with resource access control products Body technical methods and methods is not required. Information Security Technology Host resource access control product safety technical requirements

1 Scope

This standard specifies the host resource access control products security functional requirements, security assurance requirements and grading requirements. This standard applies to access host resources to design, develop and test control products.

2 Normative references

The following documents for the application of this document is essential. For dated references, only the dated version suitable for use herein Member. For undated references, the latest edition (including any amendments) applies to this document. GB 17859-1999 computer information system security protection classification criterion GB/T 18336-2008 (all parts), Information technology - Security techniques - Information Technology Security Evaluation Guidelines GB/T 25069-2010 Information security technology terms

3 Terms and Definitions

GB 17859-1999, terms and definitions GB/T 18336-2008 (all parts) and GB/T 25069-2010 defined apply This document.

4 Host Resource Access Control Product Description

Host resource access control products for controlled host, unified distribution logon rights and access to resources of a host of users, thus ensuring User control policy to permit the controlled host resources (including system access, files and folders, peripheral interface based on pre-defined access, Applications, processes, etc.) to access in order to protect the host resources from unauthorized access and use. Host resource access control products are generally by the server and the client management console consists of three parts, sent by the server access control policy Slightly to the client. Its assets are protected host resources, in addition to a host of important data resource access control product itself and its interior is also subject to Protection of assets. FIG. 1 is a host resource access control products a typical operating environment.
......
Image     

Tips & Frequently Asked Questions:

Question 1: How long will the true-PDF of GA/T 1138-2014_English be delivered?

Answer: Upon your order, we will start to translate GA/T 1138-2014_English as soon as possible, and keep you informed of the progress. The lead time is typically 2 ~ 4 working days. The lengthier the document the longer the lead time.

Question 2: Can I share the purchased PDF of GA/T 1138-2014_English with my colleagues?

Answer: Yes. The purchased PDF of GA/T 1138-2014_English will be deemed to be sold to your employer/organization who actually pays for it, including your colleagues and your employer's intranet.

Question 3: Does the price include tax/VAT?

Answer: Yes. Our tax invoice, downloaded/delivered in 9 seconds, includes all tax/VAT and complies with 100+ countries' tax regulations (tax exempted in 100+ countries) -- See Avoidance of Double Taxation Agreements (DTAs): List of DTAs signed between Singapore and 100+ countries

Question 4: Do you accept my currency other than USD?

Answer: Yes. If you need your currency to be printed on the invoice, please write an email to Sales@ChineseStandard.net. In 2 working-hours, we will create a special link for you to pay in any currencies. Otherwise, follow the normal steps: Add to Cart -- Checkout -- Select your currency to pay.