US$629.00 · In stock Delivery: <= 5 days. True-PDF full-copy in English will be manually translated and delivered via email. GB/T 29766-2021: Information security technology - Technical requirements and testing and evaluating approaches of website data recovery products Status: Valid GB/T 29766: Evolution and historical versions
Standard ID | Contents [version] | USD | STEP2 | [PDF] delivered in | Standard Title (Description) | Status | PDF |
GB/T 29766-2021 | English | 629 |
Add to Cart
|
5 days [Need to translate]
|
Information security technology - Technical requirements and testing and evaluating approaches of website data recovery products
| Valid |
GB/T 29766-2021
|
GB/T 29766-2013 | English | RFQ |
ASK
|
7 days [Need to translate]
|
Information security technology -- Technical requirements and testing and evaluating approaches of website data recovery products
| Obsolete |
GB/T 29766-2013
|
PDF Samples
Basic data Standard ID | GB/T 29766-2021 (GB/T29766-2021) | Description (Translated English) | | Sector / Industry | National Standard (Recommended) |
GB/T 29766-2021: Information security technology - Technical requirements and testing and evaluating approaches of website data recovery products ---This is a DRAFT version for illustration, not a final translation. Full copy of true-PDF in English version (including equations, symbols, images, flow-chart, tables, and figures etc.) will be manually/carefully translated upon your order.
Information security technology - Technical requirements and testing and evaluating approaches of website data recovery products
ICS 35.030
CCSL80
National Standards of People's Republic of China
Replace GB/T 29766-2013
Information security technology website data recovery products
Technical requirements and test evaluation methods
Released on 2021-10-11
2022-05-01 implementation
State Administration for Market Regulation
Issued by the National Standardization Management Committee
Table of contents
Foreword Ⅰ
1 Scope 1
2 Normative references 1
3 Terms and definitions 1
4 Abbreviations 2
5 Product description 2
6 Technical requirements 3
6.1 Safety function requirements 3
6.2 Self-safety requirements 6
6.3 Safety assurance requirements 7
7 Test and evaluation method 10
7.1 Test environment and tools 10
7.2 Safety function requirement test 10
7.3 Self-safety function test 19
7.4 Security assurance assessment method 22
Appendix A (Normative) Website Restoration Product Level Classification 28
Appendix B (Normative) Performance Parameters and Test 30
B.1 Performance Index 30
B.2 Performance Test 30
Foreword
This document is in accordance with the provisions of GB/T 1.1-2020 "Guidelines for Standardization Work Part 1.Structure and Drafting Rules of Standardization Documents"
Drafting.
This document replaces GB/T 29766-2013 "Technical Requirements and Test Evaluation Methods for Information Security Technology Website Data Recovery Products",
Compared with GB/T 29766-2013, in addition to structural adjustments and editorial changes, the main technical changes are as follows.
---Modified the "Terms and Definitions" chapter (see Chapter 3, Chapter 3 of the.2013 edition);
---Added the "abbreviations" chapter (see Chapter 4);
---Added the "Product Description" chapter (see Chapter 5);
---Added the requirement of "Website data tamper-proof" (see 6.1.2);
---Modified the "implementation of alarm events" requirements (see 6.1.3.1, 5.1.1.2.1 in the.2013 edition);
---Added the "alarm information" requirement (see 6.1.3.3);
---Modified the requirements of "Auditable Events" and "Audit Data Content" (see 6.1.8.1, 6.1.8.2, 5.1.1.9.1 and 5.1.1 of the.2013 edition.
9.2);
---Added the requirements of "Audit Data Storage" and "Audit Statement" (see 6.1.8.3, 6.1.8.6);
---Modified "Backup Data Protection" (see 6.1.9, 5.1.1.10 of the.2013 edition);
---Added "self-safety requirements" (see 6.2, 7.3);
---The requirement of "defense against known attacks" has been deleted (see 5.1.1.12 in the.2013 version);
---Modified the "safety assurance requirements" (see 6.3, 7.4, 5.1.2, 5.2.2 of the.2013 edition).
Please note that some of the contents of this document may involve patents. The issuing agency of this document is not responsible for identifying patents.
This document was proposed and managed by the National Information Security Standardization Technical Committee (SAC/TC260).
Drafting organizations of this document. China Accreditation Principal (Beijing) Technical Services Co., Ltd., China Cyber Security Review Technology and Certification Center, Ministry of Public Security
The Third Research Institute, the 15th Research Institute of China Electronics Technology Group Corporation, Shanghai Information Security Evaluation and Certification Center, Beijing Information Security Evaluation
Center, the First Research Institute of the Ministry of Public Security, Beijing Tianrongxin Network Security Technology Co., Ltd., Beijing Shenzhou NSFOCUS Technology Co., Ltd., Blue Shield Information Security
All Technology Co., Ltd., Xiamen Service Cloud Information Technology Co., Ltd., Hangzhou Anheng Information Technology Co., Ltd., Beijing Hillstone Network Information Technology
Technology Co., Ltd., Beijing Beixinyuan Software Co., Ltd., Institute of Information Engineering, Chinese Academy of Sciences.
The main drafters of this document. Buning, Gan Jiefu, Zhao Ting, Shen Yongbo, He Hai, Tian Xia, Wu Di, Dong Jingjing, Zhang Xiaoxiao, Zhang Junyan, Xu Tonghai,
Lei Xiaofeng, An Gaofeng, Liu Qiang, Pan Wenxin, Cheng Changgao, Han Yu, Li Yu, Liu Silong, Duan Jinghui, Kou Shilei, Liu Xing'an, Liu Yuling.
The previous releases of this document and the documents it replaced are as follows.
---In.2013, it was first published as GB/T 29766-2013;
---This is the first revision.
Information security technology website data recovery products
Technical requirements and test evaluation methods
1 Scope
This document specifies the safety function requirements, self-safety requirements, safety assurance requirements and test evaluation methods of website data recovery products.
This document is suitable for the development, production, testing and evaluation of website data recovery products.
2 Normative references
The content of the following documents constitutes an indispensable clause of this document through normative references in the text. Among them, dated quotations
Only the version corresponding to the date is applicable to this document; for undated reference documents, the latest version (including all amendments) is applicable to
This document.
GB/T 18336.1 Information Technology Security Technology Information Technology Security Assessment Criteria Part 1.Introduction and General Model
GB/T 25069 Information Security Technical Terms
3 Terms and definitions
The following terms and definitions defined in GB/T 18336.1 and GB/T 25069 apply to this document.
3.1
Website data recovery product websitedatarecoveryproduct
The software or combination of software and hardware that realizes the anti-tampering, backup and recovery of website data.
3.2
Staticwebsitedata
The data on the website server will not change due to the different access objects or download requests.
3.3
Dynamicwebsitedata
The data on the website server that can change according to the different access objects or download requests, can be used by the website server-side scripting language
Generated based on submission conditions or status.
3.4
Websitedata
Data related to the content posted on the website.
Note. Website data includes website static data, website dynamic data and website directory.
3.5
Websitedatarecovery
The process of timely restoration of website data that has suffered unauthorized changes.
3.6
Authorizedadministrator
Those who have the authority to use website data recovery product management functions.
......
|