GB/T35274 Big Data Service Security Capability Evaluation and Certification
Big data service security capability evaluation and certification is a system aimed at comprehensively evaluating the data security service capabilities of enterprises engaged in data security related fields. This certification is based on the national standard GB/T 35274-2023 Information Security Technology Big Data Service Security Capability Requirements of the People's Republic of China. The standard specifies the requirements for the security capabilities of big data service providers, including the security capabilities of big data organization and management, big data processing, and big data service security risk management.
Big data organization management security capability: Develop big data security strategies and regulations in accordance with information security management system requirements, and develop data security management systems from the perspective of big data service organization and personnel security management, as well as data asset and system asset management required for big data services, to meet the requirements of big data service organization management security compliance and data security risk control.
Big data processing security capability: For data processing activities such as data collection, storage, use, processing, transmission, provision, disclosure, and destruction, data protection measures are taken from the big data platform and big data application business and technical levels to meet the data protection requirements related to data processing activities in big data services.
Big data service security risk management capability: In accordance with the security protection requirements of the data business flow process and data processing activities in big data services, the big data service security risk management capability is established from six aspects: risk identification, security protection, security monitoring, security inspection, security response, and security recovery. Risk response measures are taken to ensure that big data services and their data assets are always effectively protected and legally utilized, ensuring the sustainability of big data services provided by big data system operators.
Big data service providers, based on the importance of protected data assets and system assets, as well as the potential harm caused by the destruction of big data systems, combined with their own big data service business, big data service goals, and the software and hardware facilities, big data platforms, and big data application functions that support big data services, refer to this document for the construction and evaluation of big data organizational management security capabilities, big data processing security capabilities, and big data service security risk management capabilities (for important data and core data processing activities, data security risk management capabilities need to be built and evaluated in accordance with relevant laws and regulations and management systems formulated by competent authorities), to meet the requirements of data processing activity compliance, data service continuity, and data service risk controllability in big data services.