GB/T 47324-2026 Cyber security protection requirements for internet of vehicles platform English, Anglais, Englisch, Inglés, えいご
This is a draft translation for reference among interesting stakeholders. The finalized translation (passing through draft translation, self-check, revision and verification) will be delivered upon being ordered.
ICS
CCS
National Standard of the People's Republic of China
GB/T 47324-2026
Cyber security protection requirements for internet of vehicles platform
车联网平台网络安全防护要求
Issue date: 2026-03-31 Implementation date: 2026-10-01
Issued by the General Administration of Quality Supervision, Inspection and Quarantine of the People's Republic of China
the Standardization Administration of the People's Republic of China
Contents
Foreword
1 Scope
2 Normative References
3 Terms and Definitions
4 Abbreviations
5 Security Protection Content
6 Level Ⅰ Security Protection Requirements
6.1 Physical Environment Security Requirements
6.2 Security Management Requirements
6.3 Security Technical Requirements
7 Level Ⅱ Security Protection Requirements
7.1 Physical Environment Security Requirements
7.2 Security Management Requirements
7.3 Security Technical Requirements
8 Level Ⅲ Security Protection Requirements
8.1 Physical Environment Security Requirements
8.2 Security Management Requirements
8.3 Security Technical Requirements
9 Level Ⅳ Security Protection Requirements
9.1 Physical Environment Security Requirements
9.2 Security Management Requirements
9.3 Security Technical Requirements
10 Level Ⅴ Security Protection Requirements
Cybersecurity protection requirements for internet of vehicles platforms
1 Scope
This document specifies the cybersecurity protection requirements for internet of vehicles platforms, including requirements for physical environment security, security management and security technology at Levels Ⅰ, Ⅱ, Ⅲ, Ⅳ and Ⅴ.
This document applies to intelligent and connected vehicle manufacturers, internet of vehicles platform operators, etc., for the implementation of graded cybersecurity protection of internet of vehicles platforms.
2 Normative References
The following documents are essential for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition (including any amendments) applies.
GB/T 22239 Information security technology — Baseline for classified protection of cybersecurity
GB/T 25069 Information security technology — Terminology
3 Terms and Definitions
For the purposes of this document, the terms and definitions given in GB/T 25069 and the following apply.
3.1 internet of vehicles
A complex network and related systems that, through newgeneration network communication technologies, achieve deep integration with the fields of automobiles, electronics, road transport, etc., realise allround connectivity and information exchange among vehicles, roads, people, platforms, etc., and promote vehicle driving safety, traffic efficiency services, and support the evolution of autonomous driving.
3.2 internet of vehicles platform
An information system or platform that provides services such as collection, storage, use, processing and provision for data generated during the operation of noncommercial motor vehicles (excluding special purpose vehicles) and related equipment data, as well as a system or platform that aggregates and uniformly manages the above data.
NOTE 1: Internet of vehicles platforms include systems or platforms that provide services and applications such as remote control, overtheair updates, infotainment, autonomous driving, intelligent cockpits, remote monitoring and diagnostic operations management, safety operations management, and data processing and analysis for vehicles.
NOTE 2: Motor vehicles are wheeled vehicles driven or towed by a power unit for the purpose of transporting persons or goods, or for performing special engineering operations. They do not include road trains, motorcycles, wheeled special purpose machinery, trailers, trolleybuses, trams, tractors or tractor transport units, nor do they include motorised wheelchairs for disabled persons or electric bicycles that have a power unit but whose maximum design speed, kerb mass, overall dimensions and other indicators comply with relevant national standards.
NOTE 3: Special purpose vehicles include vehicles for police, firefighting, ambulance, engineering rescue and other special transport or special operations, as well as vehicles for other special purposes.
3.3 security protection of internet of vehicles
The ability, through the adoption of necessary measures, to prevent attacks, intrusions, interference, destruction and illegal use of the internet of vehicles, as well as accidents, to keep the internet of vehicles in a stable and reliable operating state, and to ensure the integrity, confidentiality and availability of internet of vehicles data.
3.4 security protection classification of internet of vehicles
A characterisation of the importance level of the internet of vehicles network and related systems.
NOTE: The importance level is measured by the damage that would be caused to national security, social order, economic operation, public benefit, and internet of vehiclesrelated enterprises and users if the internet of vehicles network and related systems were to be compromised.
3.5 common middleware
A class of software that facilitates interaction between software components and provides connectivity between system software and application software.
NOTE: Mainly includes microservices middleware, message middleware and web services middleware, etc.
3.6 sensitive personal information
Personal information that, if leaked or used illegally, may lead to discrimination or serious harm to the personal or property safety of vehicle owners, drivers, passengers, people outside the vehicle, etc.
NOTE: Includes vehicle trajectory, audio, video, images and biometric features, etc.
4 Abbreviations
The following abbreviations apply to this document.
CPU: Central Processing Unit
DTC: Diagnostic Trouble Code
FTP: File Transfer Protocol
HTTP: HyperText Transfer Protocol
HTTPS: Hypertext Transfer Protocol Secure
IP: Internet Protocol
OTA: OvertheAir
POP3: Post Office Protocol – Version 3
SMTP: Simple Mail Transfer Protocol
SSL: Secure Socket Layer
TLS: Transport Layer Security
VIN: Vehicle Identification Number
5 Security Protection Content
Enterprises related to internet of vehicles platforms shall determine the cybersecurity protection level of their internet of vehicles platforms and adopt security protection measures to ensure the cybersecurity of the platform. In terms of security protection content, the security protection of internet of vehicles platforms is divided into three parts: physical environment security requirements, security management requirements and security technical requirements.
Physical environment security requirements include physical location selection, physical access control, theft and damage prevention, lightning protection, fire protection, water and moisture protection, electrostatic protection, temperature and humidity control, dust protection, power supply, and electromagnetic protection.
Security management requirements include security management systems, security management organisations and personnel, platform security construction management, and platform security operation and maintenance management.
Security technical requirements include infrastructure security protection and application service security protection. Infrastructure security protection includes computing environment security protection requirements, communication network security protection requirements, area boundary security protection requirements, security management centre requirements, virtualisation security protection requirements, container security protection requirements, common middleware security protection requirements, and general interface security protection requirements. Application service security protection requirements include general requirements, update service requirements, remote control requirements, remote monitoring requirements, remote diagnosis requirements, and charging management and monitoring requirements.
6 Level Ⅰ Security Protection Requirements
6.1 Physical environment security requirements
6.1.1 Physical location selection
Physical location selection requirements include the following:
a) Requirements for the basic selection conditions of the computer room site shall comply with the provisions of Level Ⅱ in GB/T 22239;
b) The computer room shall be located away from areas prone to geological disasters, such as mudslides and landslides;
c) The loadbearing capacity of the computer room shall meet the building requirements of the computer room.
Standard
GB/T 47324-2026 Cyber security protection requirements for internet of vehicles platform (English)
Standard No.
GB/T 47324-2026
Status
to be valid
Language
English
File Format
PDF
Word Count
22000 words
Translation Price(USD)
660.0
Implemented on
2026-10-1
Delivery
via email in 1~8 business day
Detail of GB/T 47324-2026
Standard No.
GB/T 47324-2026
English Name
Cyber security protection requirements for internet of vehicles platform
GB/T 47324-2026 Cyber security protection requirements for internet of vehicles platform English, Anglais, Englisch, Inglés, えいご
This is a draft translation for reference among interesting stakeholders. The finalized translation (passing through draft translation, self-check, revision and verification) will be delivered upon being ordered.
ICS
CCS
National Standard of the People's Republic of China
GB/T 47324-2026
Cyber security protection requirements for internet of vehicles platform
车联网平台网络安全防护要求
Issue date: 2026-03-31 Implementation date: 2026-10-01
Issued by the General Administration of Quality Supervision, Inspection and Quarantine of the People's Republic of China
the Standardization Administration of the People's Republic of China
Contents
Foreword
1 Scope
2 Normative References
3 Terms and Definitions
4 Abbreviations
5 Security Protection Content
6 Level Ⅰ Security Protection Requirements
6.1 Physical Environment Security Requirements
6.2 Security Management Requirements
6.3 Security Technical Requirements
7 Level Ⅱ Security Protection Requirements
7.1 Physical Environment Security Requirements
7.2 Security Management Requirements
7.3 Security Technical Requirements
8 Level Ⅲ Security Protection Requirements
8.1 Physical Environment Security Requirements
8.2 Security Management Requirements
8.3 Security Technical Requirements
9 Level Ⅳ Security Protection Requirements
9.1 Physical Environment Security Requirements
9.2 Security Management Requirements
9.3 Security Technical Requirements
10 Level Ⅴ Security Protection Requirements
Cybersecurity protection requirements for internet of vehicles platforms
1 Scope
This document specifies the cybersecurity protection requirements for internet of vehicles platforms, including requirements for physical environment security, security management and security technology at Levels Ⅰ, Ⅱ, Ⅲ, Ⅳ and Ⅴ.
This document applies to intelligent and connected vehicle manufacturers, internet of vehicles platform operators, etc., for the implementation of graded cybersecurity protection of internet of vehicles platforms.
2 Normative References
The following documents are essential for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition (including any amendments) applies.
GB/T 22239 Information security technology — Baseline for classified protection of cybersecurity
GB/T 25069 Information security technology — Terminology
3 Terms and Definitions
For the purposes of this document, the terms and definitions given in GB/T 25069 and the following apply.
3.1 internet of vehicles
A complex network and related systems that, through newgeneration network communication technologies, achieve deep integration with the fields of automobiles, electronics, road transport, etc., realise allround connectivity and information exchange among vehicles, roads, people, platforms, etc., and promote vehicle driving safety, traffic efficiency services, and support the evolution of autonomous driving.
3.2 internet of vehicles platform
An information system or platform that provides services such as collection, storage, use, processing and provision for data generated during the operation of noncommercial motor vehicles (excluding special purpose vehicles) and related equipment data, as well as a system or platform that aggregates and uniformly manages the above data.
NOTE 1: Internet of vehicles platforms include systems or platforms that provide services and applications such as remote control, overtheair updates, infotainment, autonomous driving, intelligent cockpits, remote monitoring and diagnostic operations management, safety operations management, and data processing and analysis for vehicles.
NOTE 2: Motor vehicles are wheeled vehicles driven or towed by a power unit for the purpose of transporting persons or goods, or for performing special engineering operations. They do not include road trains, motorcycles, wheeled special purpose machinery, trailers, trolleybuses, trams, tractors or tractor transport units, nor do they include motorised wheelchairs for disabled persons or electric bicycles that have a power unit but whose maximum design speed, kerb mass, overall dimensions and other indicators comply with relevant national standards.
NOTE 3: Special purpose vehicles include vehicles for police, firefighting, ambulance, engineering rescue and other special transport or special operations, as well as vehicles for other special purposes.
3.3 security protection of internet of vehicles
The ability, through the adoption of necessary measures, to prevent attacks, intrusions, interference, destruction and illegal use of the internet of vehicles, as well as accidents, to keep the internet of vehicles in a stable and reliable operating state, and to ensure the integrity, confidentiality and availability of internet of vehicles data.
3.4 security protection classification of internet of vehicles
A characterisation of the importance level of the internet of vehicles network and related systems.
NOTE: The importance level is measured by the damage that would be caused to national security, social order, economic operation, public benefit, and internet of vehiclesrelated enterprises and users if the internet of vehicles network and related systems were to be compromised.
3.5 common middleware
A class of software that facilitates interaction between software components and provides connectivity between system software and application software.
NOTE: Mainly includes microservices middleware, message middleware and web services middleware, etc.
3.6 sensitive personal information
Personal information that, if leaked or used illegally, may lead to discrimination or serious harm to the personal or property safety of vehicle owners, drivers, passengers, people outside the vehicle, etc.
NOTE: Includes vehicle trajectory, audio, video, images and biometric features, etc.
4 Abbreviations
The following abbreviations apply to this document.
CPU: Central Processing Unit
DTC: Diagnostic Trouble Code
FTP: File Transfer Protocol
HTTP: HyperText Transfer Protocol
HTTPS: Hypertext Transfer Protocol Secure
IP: Internet Protocol
OTA: OvertheAir
POP3: Post Office Protocol – Version 3
SMTP: Simple Mail Transfer Protocol
SSL: Secure Socket Layer
TLS: Transport Layer Security
VIN: Vehicle Identification Number
5 Security Protection Content
Enterprises related to internet of vehicles platforms shall determine the cybersecurity protection level of their internet of vehicles platforms and adopt security protection measures to ensure the cybersecurity of the platform. In terms of security protection content, the security protection of internet of vehicles platforms is divided into three parts: physical environment security requirements, security management requirements and security technical requirements.
Physical environment security requirements include physical location selection, physical access control, theft and damage prevention, lightning protection, fire protection, water and moisture protection, electrostatic protection, temperature and humidity control, dust protection, power supply, and electromagnetic protection.
Security management requirements include security management systems, security management organisations and personnel, platform security construction management, and platform security operation and maintenance management.
Security technical requirements include infrastructure security protection and application service security protection. Infrastructure security protection includes computing environment security protection requirements, communication network security protection requirements, area boundary security protection requirements, security management centre requirements, virtualisation security protection requirements, container security protection requirements, common middleware security protection requirements, and general interface security protection requirements. Application service security protection requirements include general requirements, update service requirements, remote control requirements, remote monitoring requirements, remote diagnosis requirements, and charging management and monitoring requirements.
6 Level Ⅰ Security Protection Requirements
6.1 Physical environment security requirements
6.1.1 Physical location selection
Physical location selection requirements include the following:
a) Requirements for the basic selection conditions of the computer room site shall comply with the provisions of Level Ⅱ in GB/T 22239;
b) The computer room shall be located away from areas prone to geological disasters, such as mudslides and landslides;
c) The loadbearing capacity of the computer room shall meet the building requirements of the computer room.