GB17859-1999
Classified criteria for security protection of computer information system
计算机信息系统 安全保护等级划分准则
GB 17859-1999 is a current mandatory Chinese national standard for Classified criteria for security protection of computer information system. It appears in the Electronics compliance cluster with a product safety focus and has an implementation date of Jan 1, 2001.
Applicability depends on product scope, certification route, competent authority notices and transition rules. Requst for the translation or verify source before using this record in a compliance decision.
Compliance overview
Scope and applicability
This standard applies to the classification of security protection technical capabilities for computer information systems in China. It provides a framework for evaluating the security architecture of IT infrastructure, software platforms, and network systems. It does not cover specific security product performance parameters but focuses on system-level security protection capabilities. System integrators and IT infrastructure providers operating in the Chinese market must adhere to these classified security requirements.
Technical requirements
GB 17859-1999 defines five distinct levels of security protection capabilities for computer information systems, ranging from Level 1 (User自主保护级) to Level 5 (Access验证保护级). Each level builds upon the previous one, requiring more stringent security policies and access control mechanisms. The standard specifies requirements for the Trusted Computing Base (TCB), which must implement both discretionary and mandatory access controls. It also outlines the specifications for identity authentication, data integrity, and audit mechanisms to ensure users are accountable for their actions. For higher levels (Level 4 and Level 5), the standard introduces advanced requirements such as covert channel analysis, trusted path, and trusted recovery. These advanced levels require the system to possess high penetration resistance and employ formalized security policy models.
Testing methods
The evaluation procedures involve verifying that the TCB correctly implements the required security mechanisms, such as discretionary and mandatory access controls. Testing includes reviewing audit trail records to confirm that security events are accurately captured. For Level 4 and Level 5, assessments require thorough covert channel analysis to identify and measure any unauthorized communication paths, as well as verifying the integrity of trusted paths during user authentication.
FAQs
What products are regulated under GB 17859-1999?
It applies to computer information systems deployed in China, providing a framework to evaluate system-level security protection capabilities rather than targeting individual hardware products.
Does GB 17859-1999 reference any international standards?
Yes, the standard was developed by referencing the U.S. Trusted Computer System Evaluation Criteria (DoD 5200.28-STD) and the Trusted Network Interpretation (NCSC-TG-005).
What are the five security levels defined in GB 17859-1999?
The five levels are User自主保护级, System审计保护级, Security标记保护级, Structured保护级, and Access验证保护级, with progressively increasing security requirements.
The summary above provides a high-level overview of GB 17859-1999. To ensure complete compliance for your products entering the Chinese market, a precise and professional translation of the full technical specifications is essential. Purchase our high-quality English translation of GB 17859-1999 today to access all detailed parameters, definitions, and evaluation procedures.
Applicability hints
- Type
- Foundational
- CCS
- L09
- ICS
- 35.020
- Competent department
- Office of the Central Cyberspace Affairs Commission
- Technical committee
- Office of the Central Cyberspace Affairs Commission