This document specifies the cyber resilience evaluation criteria, and gives the evaluation indicator system and evaluation method of cyber resilience.
This document is applicable to the self-evaluation of cyber resilience of organizations, the third-party evaluation of cyber resilience of cybersecurity service organizations. It also applicable to the design, construction, and improvement of cyber resilience of organizations.
2 Normative references
The following documents contain requirements which, through reference in this text, constitute provisions of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies.
GB/T 20988-2007 Information security technology - Disaster recovery specifications for information systems
GB/T 25069-2022 Information security techniques - Terminology
GB/T 30146-2023 Security and resilience - Business continuity management systems - Requirements
GB/T 43269-2023 Information security techniques - Assessment criteria for cybersecurity emergency capability
3 Terms and definitions
For the purposes of this document, the terms and definitions given in GB/T 25069-2022 and the following apply.
3.1
cyber resilience
when the cyber has adverse conditions, pressure, attacks, or lost components, it shall have the ability to prevent, withstand, recover, and adapt to maintain the stability of system function and structure, achieve orderly and effective response to major cybersecurity events, and ensure the stable operation of critical business
Note: The term "network" in this document refers to such system consisting of computer or other information terminals and relevant equipment that are used for collection, storage, transmission, exchange and processing of information in accordance with certain rules and procedures.
3.2
critical business
business that may seriously affect the cybersecurity and stability of the organizations or customers and cause significant losses when suffered to a cybersecurity incident.
3.3
survivability
ability of the system to perform basic business functions and complete critical businesses in the event of attack, failure, fault, or interruption
Note: Failure refers to when a system or component loses its design purpose or function and, although operational, does not produce the correct result. Fault refers to a condition in which a system or device cannot perform a specified function. Basic business functions refer to the basic functional units that make up the business functions, such as processes, threads, or algorithm modules.