Book Description
This Standard specifies the requirements for classified protection of information system of financial industry, including unit-evaluation requirements for security evaluation of second-level information system, third-level information system and fourth-level information system and overall evaluation system of information system, etc. Based on the classification of information system of financial industry, fifth-level system does not exist, while first-level system is not required to file at public security agency, and it is not the key point of evaluation. This Standard omits specific content requirements for unit-evaluation of first-level information system and fifth-level information system.