2025-12-5 10.1.6.65
Code of China Chinese Classification Professional Classification ICS Classification Latest News Value-added Services

Position: Chinese Standard in English/JR/T 0071-2012
JR/T 0071-2012   Implementation Guidance for Financial Industry Information System Safety Level Protection (English Version)
Standard No.: JR/T 0071-2012 Status:superseded remind me the status change

Email:

Target Language:English File Format:PDF
Word Count: 60000 words Translation Price(USD):150.0 remind me the price change

Email:

Implemented on:2012-7-6 Delivery: via email in 1 business day

→ → →

,2020-11-11,2012-7-6,14113818190123BD33B1530A01A20
Standard No.: JR/T 0071-2012
English Name: Implementation Guidance for Financial Industry Information System Safety Level Protection
Chinese Name: 金融行业信息系统信息安全等级保护实施指引
Professional Classification: JR    Professional Standard - Finance
Source Content Issued by: China People's Bank
Issued on: 2012-7-6
Implemented on: 2012-7-6
Status: superseded
Superseded by:JR/T 0071.2-2020 Implementation guidelines for classified protection of cybersecurity of financial industry—Part 2:Basic requirements
JR/T 0071.1-2020 Implementation guidelines for classified protection of cybersecurity of financial industry—Part 1:Fundamentals and vocabulary
Superseded on:2020-11-11
Target Language: English
File Format: PDF
Word Count: 60000 words
Translation Price(USD): 150.0
Delivery: via email in 1 business day
1 Scope According to the national standards "Baseline for Classified Protection of Information System Security " and "Technical Requirements of Security Design for Information System Classified Protection" and allowing for the characteristics of financial industry and requirements for information systems security development, this standard has designed the information security system structure in divisions and has specified the application systems depending on the system level, so as to guarantee industrialized and concretized national requirements for classified protection and to improve the protection level of information security for the important networks and information systems of our industry. This standard is applicable to the use by the departments of financial institution (including its affiliates), e.g. system planning and development (service and technology), application development, system operation, security management, system use, internal supervision and audit. It may be served as the basis for the supervision, inspection and guidance for information security functions. With the supplementing and enrichment of the contents, this standard provides guidance for the practice of classified protection. 2 Normative References The following referenced documents are indispensable for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies. GB/T 22239-2008 Baseline for Classified Protection of Information System Security GB/T 25069 Information Security Technology - Glossary JR/T 0003-2001 Security Specification for the Interoperable Services of Bank Card JR/T 0013-2004 Specification on the Interconnection Security between Star Networks of Financial Industry JR/T 0011-2004 Systematic Specification of Centralized Bank Data Center JR/T 0023-2004 Specification on Information Technology Management of Securities Company JR/T 0026-2006 Specification for Protection against Lightning of Banking Computer Information System JR/T 0044-2008 Management Specification of Information System Disaster Recovery for Banks JR/T 0055.4-2009 Technical Specifications on Bankcard Interoperability – Part 4: Data Secure Transmission Control PBC Doc. [2002] No. 260 Guidance of the People's Bank of China on Reinforcing Bank Data Concentration Security YIN KE JI [2006] No. 73 Guidance of the People's Bank of China on the Secure Configuration of Information System YIN BAN Doc. [2006] No. 154 Guidance of the People's Bank of China on IT Emergency Plan YIN BAN Doc. [2006] No. 9 Guidance of the People's Bank of China on the Normalization of Computer Room PBC Doc. [2010] No. 276 Administrative Rules of the People's Bank of China on Computer System Information Security PBC Doc. [2010] No. 276 Administrative Rules of the People's Bank of China on Computer System Information Security CBRC Doc. [2008] No. 50 Administrative Regulations on the Commissioning and Modification of Important Information Systems of Banking Financial Institutions CBRC [2009] No. 19 Guidance on the Information Technology Risk Management for Commercial Banks YIN JIAN BAN Doc. [2009] No. 437 Guidance on Emergency Handling for Cross-industry Information System of Banking and Securities YIN JIAN BAN Doc. [2010] No. 112 Guidance on the Supervision of Commercial Bank Data Center SAC Doc. [2006] Guidance on the Security Management Technology of Centralized Transaction for Securities Companies CFA Doc. [2009] Guidance on the Online Futures Information System Technology for Futures Companies SAC Doc. [2009] No. 154 Guidance on the Information Technology for Securities Business Departments CIRC Decree [2003] No. 3 Regulations on Major Emergency Handling for Insurance Industry 3 Terms and Definitions For the purpose of this standard, the terms and definitions specified in GB/T 25069 and those given below apply. 3.1 Sensitive data It refers to the data which, once revealed, possibly cause damage to the user or financial institution, including but not limited to: a) sensitive data of user, e.g. user password and secret key; b) sensitive data of system, e.g. system secret key and key system management data; c) other sensitive business data required to be kept secret;
Foreword i Introduction ii 1 Scope 2 Normative References 3 Terms and Definitions 4 Guide Preparation Policy 5 Information Security Assurance Framework 6 Protection Requirements Appendix A (Informative) Implementation Measures for Classified Protection Appendix B (Informative) Selection of Security Requirements of Financial Industry and the Use Instructions Bibliography
Referred in JR/T 0071-2012:
* GB/T 22239-2008 Ionformation secuiryt technology - Baseline for classified protection of information system security
* GB/T 25069-2010 Information security technology—Glossary
* JR/T 0003-2001 Security Specification for the Interoperable Services of Bank Card
* JR/T 0013-2004
* JR/T 0011-2004 Systematic specification of centralized bank data center
* JR/T 0023-2004 The criterion of IT management for securities companies
* JR/T 0026-2006 Specification for protection against lightning of banking computer information system
* JR/T 0044-2008 Management Specification of Information System Disaster Recovery for Banks
* JR/T 0055.4-2009 Technical specifications on bankcard interoperability—Part 4:Data secure transmission control
JR/T 0071-2012 is referred in:
*JR/T 0166-2018 Financial application specification of cloud computing technology - Technical architecture
Code of China
Standard
JR/T 0071-2012  Implementation Guidance for Financial Industry Information System Safety Level Protection (English Version)
Standard No.JR/T 0071-2012
Statussuperseded
LanguageEnglish
File FormatPDF
Word Count60000 words
Price(USD)150.0
Implemented on2012-7-6
Deliveryvia email in 1 business day
Detail of JR/T 0071-2012
Standard No.
JR/T 0071-2012
English Name
Implementation Guidance for Financial Industry Information System Safety Level Protection
Chinese Name
金融行业信息系统信息安全等级保护实施指引
Chinese Classification
Professional Classification
JR
ICS Classification
Issued by
China People's Bank
Issued on
2012-7-6
Implemented on
2012-7-6
Status
superseded
Superseded by
JR/T 0071.2-2020 Implementation guidelines for classified protection of cybersecurity of financial industry—Part 2:Basic requirements
JR/T 0071.1-2020 Implementation guidelines for classified protection of cybersecurity of financial industry—Part 1:Fundamentals and vocabulary
Superseded on
2020-11-11
Abolished on
Superseding
Language
English
File Format
PDF
Word Count
60000 words
Price(USD)
150.0
Keywords
JR/T 0071-2012, JR 0071-2012, JRT 0071-2012, JR/T0071-2012, JR/T 0071, JR/T0071, JR0071-2012, JR 0071, JR0071, JRT0071-2012, JRT 0071, JRT0071
Introduction of JR/T 0071-2012
1 Scope According to the national standards "Baseline for Classified Protection of Information System Security " and "Technical Requirements of Security Design for Information System Classified Protection" and allowing for the characteristics of financial industry and requirements for information systems security development, this standard has designed the information security system structure in divisions and has specified the application systems depending on the system level, so as to guarantee industrialized and concretized national requirements for classified protection and to improve the protection level of information security for the important networks and information systems of our industry. This standard is applicable to the use by the departments of financial institution (including its affiliates), e.g. system planning and development (service and technology), application development, system operation, security management, system use, internal supervision and audit. It may be served as the basis for the supervision, inspection and guidance for information security functions. With the supplementing and enrichment of the contents, this standard provides guidance for the practice of classified protection. 2 Normative References The following referenced documents are indispensable for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies. GB/T 22239-2008 Baseline for Classified Protection of Information System Security GB/T 25069 Information Security Technology - Glossary JR/T 0003-2001 Security Specification for the Interoperable Services of Bank Card JR/T 0013-2004 Specification on the Interconnection Security between Star Networks of Financial Industry JR/T 0011-2004 Systematic Specification of Centralized Bank Data Center JR/T 0023-2004 Specification on Information Technology Management of Securities Company JR/T 0026-2006 Specification for Protection against Lightning of Banking Computer Information System JR/T 0044-2008 Management Specification of Information System Disaster Recovery for Banks JR/T 0055.4-2009 Technical Specifications on Bankcard Interoperability – Part 4: Data Secure Transmission Control PBC Doc. [2002] No. 260 Guidance of the People's Bank of China on Reinforcing Bank Data Concentration Security YIN KE JI [2006] No. 73 Guidance of the People's Bank of China on the Secure Configuration of Information System YIN BAN Doc. [2006] No. 154 Guidance of the People's Bank of China on IT Emergency Plan YIN BAN Doc. [2006] No. 9 Guidance of the People's Bank of China on the Normalization of Computer Room PBC Doc. [2010] No. 276 Administrative Rules of the People's Bank of China on Computer System Information Security PBC Doc. [2010] No. 276 Administrative Rules of the People's Bank of China on Computer System Information Security CBRC Doc. [2008] No. 50 Administrative Regulations on the Commissioning and Modification of Important Information Systems of Banking Financial Institutions CBRC [2009] No. 19 Guidance on the Information Technology Risk Management for Commercial Banks YIN JIAN BAN Doc. [2009] No. 437 Guidance on Emergency Handling for Cross-industry Information System of Banking and Securities YIN JIAN BAN Doc. [2010] No. 112 Guidance on the Supervision of Commercial Bank Data Center SAC Doc. [2006] Guidance on the Security Management Technology of Centralized Transaction for Securities Companies CFA Doc. [2009] Guidance on the Online Futures Information System Technology for Futures Companies SAC Doc. [2009] No. 154 Guidance on the Information Technology for Securities Business Departments CIRC Decree [2003] No. 3 Regulations on Major Emergency Handling for Insurance Industry 3 Terms and Definitions For the purpose of this standard, the terms and definitions specified in GB/T 25069 and those given below apply. 3.1 Sensitive data It refers to the data which, once revealed, possibly cause damage to the user or financial institution, including but not limited to: a) sensitive data of user, e.g. user password and secret key; b) sensitive data of system, e.g. system secret key and key system management data; c) other sensitive business data required to be kept secret;
Contents of JR/T 0071-2012
Foreword i Introduction ii 1 Scope 2 Normative References 3 Terms and Definitions 4 Guide Preparation Policy 5 Information Security Assurance Framework 6 Protection Requirements Appendix A (Informative) Implementation Measures for Classified Protection Appendix B (Informative) Selection of Security Requirements of Financial Industry and the Use Instructions Bibliography
About Us   |    Contact Us   |    Terms of Service   |    Privacy   |    Cancellation & Refund Policy   |    Payment
Tel: +86-10-8572 5655 | Fax: +86-10-8581 9515 | Email: coc@codeofchina.com | QQ: 672269886
Copyright: Beijing COC Tech Co., Ltd. 2008-2040
 
 
Keywords:
JR/T 0071-2012, JR 0071-2012, JRT 0071-2012, JR/T0071-2012, JR/T 0071, JR/T0071, JR0071-2012, JR 0071, JR0071, JRT0071-2012, JRT 0071, JRT0071