Path:
Home >
GB/T >
Page206 > GB/T 31500-2024
Price & Delivery
US$509.00 · In stock · Download in 9 secondsGB/T 31500-2024: Cybersecurity technology - Security specification of data recovery service for storage media
Delivery: 9 seconds. True-PDF full-copy in English & invoice will be downloaded + auto-delivered via email. See
step-by-step procedureStatus: Valid
GB/T 31500: Historical versions
| Std ID | Version | USD | Buy | Deliver [PDF] in | Title (Description) |
| GB/T 31500-2024 | English | 509 |
Add to Cart
|
4 days [Need to translate]
|
Cybersecurity technology - Security specification of data recovery service for storage media
|
| GB/T 31500-2015 | English | 209 |
Add to Cart
|
3 days [Need to translate]
|
Information security technology -- Requirement of data recovery service for storage media
|
Click to Preview a similar PDF
Basic data
| Standard ID | GB/T 31500-2024 (GB/T31500-2024) |
| Description (Translated English) | Cybersecurity technology - Security specification of data recovery service for storage media |
| Sector / Industry | National Standard (Recommended) |
| Classification of Chinese Standard | L80 |
| Classification of International Standard | 35.030 |
| Word Count Estimation | 25,239 |
| Date of Issue | 2024-10-26 |
| Date of Implementation | 2025-05-01 |
| Older Standard (superseded by this standard) | GB/T 31500-2015 |
| Issuing agency(ies) | State Administration for Market Regulation, China National Standardization Administration |
GB/T 31500-2024: Cybersecurity technology - Security specification of data recovery service for storage media
---This is an excerpt. Full copy of true-PDF in English version (including equations, symbols, images, flow-chart, tables, and figures etc.), auto-downloaded/delivered in 9 seconds, can be purchased online: https://www.ChineseStandard.net/PDF.aspx/GBT31500-2024
ICS 35.030
CCSL80
National Standard of the People's Republic of China
Replaces GB/T 31500-2015
Network security technology storage media data recovery service
Safety regulations
storagemedia
Released on October 26, 2024
Implementation on May 1, 2025
State Administration for Market Regulation
The National Standardization Administration issued
Table of Contents
Preface III
1 Scope 1
2 Normative references 1
3 Terms and Definitions 1
4 Principle 2
5 General Requirements 3
6 Safety Management Requirements 3
6.1 Institution 3
6.2 Personnel 3
6.3 Environment 4
6.4 Quality Control 5
6.5 Security Audit 6
7 Security Implementation Requirements 6
7.1 Overview 6
7.2 Media Reception 6
7.3 Media Detection 7
7.4 Data Recovery 7
7.5 Data Delivery 8
7.6 Data Destruction 8
8 Safety Management Evaluation Methods 8
8.1 Organization 8
8.2 Personnel 9
8.3 Environment 10
8.4 Quality Control 13
8.5 Security Audit 14
9 Safety Implementation Evaluation Methods 15
9.1 Media Reception 15
9.2 Media Detection 15
9.3 Data Recovery 16
9.4 Data Delivery 16
9.5 Data Destruction 17
Appendix A (Normative) Basic Configuration Requirements for Software and Hardware Tools for Data Recovery Services 18
Appendix B (Informative) Data Recovery Service Agreement Template 19
Reference 20
Preface
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for standardization work Part 1.Structure and drafting rules for standardization documents"
Drafting.
This document replaces GB/T 31500-2015 "Information Security Technology Storage Media Data Recovery Service Requirements" and GB/T 31500-
Compared with.2015, in addition to structural adjustments and editorial changes, the main technical changes are as follows.
a) The scope of application of the document has been changed (see Chapter 1, Chapter 1 of the.2015 edition);
b) Added terms and definitions such as “logical failure”, “mirror data”, and “data recovery service”, and changed the terms and definitions of “storage media”.
righteousness (see Chapter 3);
c) The relevant requirements of the “confidentiality principle” have been changed, and the “compliance principle” and “grading principle” clauses have been added (see Chapter 4,.2015 Edition).
Chapter 4 of);
d) Added general requirements (see Chapter 5);
e) The requirements for practitioners have been changed, further divided into two categories, and the clauses have been refined accordingly (see 6.1,.2015 edition).
5.1);
f) Changed the requirements for practitioners, further divided the requirements into two categories, and detailed the clauses accordingly (see 6.2,.2015 edition)
5.2);
g) Changed the relevant requirements of "Environment" and detailed the relevant provisions of service places, facilities and equipment, and storage media (see 6.3,.2015
Versions 5.3, 5.4, 7.3, and 7.4);
h) Added "quality control" requirements (see 6.4);
i) Added "Safety Audit" requirements (see 6.5);
j) Changed the relevant requirements of “Security Implementation Requirements” and changed “Service Process Requirements” to “Security Implementation Requirements” (see Chapter 7,.2015
Chapter 6 of the.2001 edition);
k) Added "Safety Management Evaluation Method" to describe the evaluation method of safety management requirements in Chapter 6 (see Chapter 8);
l) Added "Safety Implementation Evaluation Method" to describe the evaluation method for the safety implementation requirements in Chapter 7 (see Chapter 9);
m) Added Normative Appendix A (see Appendix A).
Please note that some of the contents of this document may involve patents. The issuing organization of this document does not assume the responsibility for identifying patents.
This document is proposed and coordinated by the National Cybersecurity Standardization Technical Committee (SAC/TC260).
This document was drafted by. National Information Center, Lenovo (Beijing) Co., Ltd., Institute of Information Engineering, Chinese Academy of Sciences, Forensic Science
Research Institute, China Electronics Technology Standardization Institute, China Electronics Great Wall Internet System Application Co., Ltd., Beijing Yuanbao Technology Co., Ltd., Yunlingxin
Information Technology (Tianjin) Co., Ltd.
The main drafters of this document are. Wang Xiaoqiang, Wang Jiahui, Wei Lian, Zhang Yu, Zhu Xuefeng, Li Ruxin, Feng Weimiao, Guo Hong, Min Jinghua, Gao Yanan,
Li Ran, Zhao Xiaole, Wang Xiaozhen, Liang Lulu, Mi Baoxin, Liu Yiran, Wang Qingde, Yang Shaoliang, Li Yan, Zhao Zhen, Jia Chenggang, and Liu Jun.
The previous versions of this document and the documents it replaces are as follows.
---First published in.2015 as GB/T 31500-2015;
---This is the first revision.
Network security technology storage media data recovery service
Safety regulations
1 Scope
This document establishes the security principles of storage media data recovery services, stipulates security management requirements and security implementation requirements, and describes the requirements for
Evaluation methods for meeting safety management requirements and safety implementation requirements.
This document is intended to guide storage media data recovery service agencies in the implementation and management of data recovery services that do not involve state secrets.
Self-evaluation and third-party supervision and review of data recovery service agencies for storage and storage media, as well as procurement of data recovery services by storage service users
evaluation.
2 Normative references
The contents of the following documents constitute the essential clauses of this document through normative references in this document.
For referenced documents without a date, only the version corresponding to that date applies to this document; for referenced documents without a date, the latest version (including all amendments) applies to
This document.
GB/T 25069-2022 Information Security Technical Terminology
GB/T 42446-2023 Information security technology - General requirements for the competence of network security practitioners
GB 50073 Cleanroom Design Specifications
GB 50174 Data Center Design Specification
3 Terms and Definitions
The terms and definitions defined in GB/T 25069-2022 and the following apply to this document.
3.1
electronic data
Objective data formed by electronic technology such as computer application and communication, used to represent text, graphic symbols, multimedia, etc.
information.
Note. Electronic data includes static data and dynamic data stored, processed or transmitted in electronic form.
3.2
storage medium storagemedium
Storage Media
Various media or devices that carry electronic data (3.1), including but not limited to computer hard disks, tapes, floppy disks, CDs, various forms of storage media,
Memory cards, memory chips, etc.
[Source. GB/T 25069-2022, 3.94, modified]
3.3
data recovery
Regenerate (restore) lost or damaged electronic data in storage media (3.2) through specialized computer software and hardware technology
(3.1) process.
...