CN Quality Check
Standards Comparison Tool
EXECUTIVE SUMMARY
This report covers GB/T 22081-2024 (网络安全技术 信息安全控制, Cybersecurity technology — Information security controls), the current Chinese national standard for information security control implementation, which supersedes GB/T 22081-2016. The standard is an IDT adoption of ISO/IEC 27002:2022, with full structural and technical alignment. The single most important procurement implication: any contract citing GB/T 22081-2016 must be updated to GB/T 22081-2024, as the 2016 edition is obsolete and no longer reflects current control requirements.
APPLICABLE CHINESE STANDARDS
| Standard No. | Title (Chinese) | Scope | Mandatory/Recommended | Status |
|---|---|---|---|---|
| GB/T 22081-2024 | 网络安全技术 信息安全控制 (Cybersecurity technology — Information security controls) | Code of practice for information security controls | Recommended (GB/T) | Current |
| GB/T 22081-2016 | 信息技术 安全技术 信息安全管理实用规则 (Information technology — Security techniques — Code of practice for information security controls) | Superseded edition adopting ISO/IEC 27002:2013 | Recommended (GB/T) | Superseded |
| GB/T 22080-2016 | 信息技术 安全技术 信息安全管理体系 要求 (Information technology — Security techniques — Information security management systems — Requirements) | ISMS requirements (IDT ISO/IEC 27001:2013) | Recommended (GB/T) | Current |
| GB/T 25069-2022 | 信息安全技术 术语 (Information security technology — Terminology) | Common terminology | Recommended (GB/T) | Current |
STANDARD TIER CLASSIFICATION
| Standard | Tier | Description |
|---|---|---|
| GB/T 22081-2024 | TIER 1 — Product/Technical Specification | Defines information security control objectives and controls |
| ISO/IEC 27002:2022 | TIER 1 — Product/Technical Specification | Same function — code of practice for controls |
| GB/T 22080-2016 | TIER 1 — Product/Technical Specification | ISMS requirements standard (companion) |
FLAG: No tier mismatch — both GB/T 22081-2024 and ISO/IEC 27002:2022 are TIER 1 technical specification standards. Valid comparison.
SCOPE BREAKDOWN
Information Security Controls (信息安全控制)
Chinese standard: GB/T 22081-2024: 网络安全技术 信息安全控制 (Cybersecurity technology — Information security controls)
International equivalent: ISO/IEC 27002:2022 — Information security, cybersecurity and privacy protection — Information security controls — 2022 edition
Equivalence: IDT
Standard tier match: Both TIER 1 — valid comparison
| Parameter | Chinese Standard Value (Clause) | International Value (Clause) | Deviation | Mutual Recognition | Procurement Impact |
|---|---|---|---|---|---|
| Control count | 93 controls (GB/T 22081-2024 §5–8) | 93 controls (ISO/IEC 27002:2022 §5–8) | Identical | 直接互认 (Direct mutual recognition) | LOW |
| Control domains | 4 domains: organisational, people, physical, technological (GB/T 22081-2024 §5–8) | 4 domains: organisational, people, physical, technological (ISO/IEC 27002:2022 §5–8) | Identical | 直接互认 (Direct mutual recognition) | LOW |
| Control attributes | 5 attributes: control type, cybersecurity properties, operational capabilities, security domains (GB/T 22081-2024 Annex A) | 5 attributes: control type, cybersecurity properties, operational capabilities, security domains (ISO/IEC 27002:2022 Annex A) | Identical | 直接互认 (Direct mutual recognition) | LOW |
| Structure | Clauses 5–8, Annex A (GB/T 22081-2024) | Clauses 5–8, Annex A (ISO/IEC 27002:2022) | Identical | 直接互认 (Direct mutual recognition) | LOW |
KEY DIFFERENCES SUMMARY
- Edition currency — GB/T 22081-2024 aligns with ISO/IEC 27002:2022; the 2016 edition (ISO/IEC 27002:2013) is obsolete. Deviation: full structural change (114→93 controls). Verdict: 直接互认 (Direct mutual recognition). Impact: HIGH.
- Control structure — 14 clauses (2013) → 4 domains (2022). Deviation: complete reorganisation. Verdict: 直接互认 (Direct mutual recognition). Impact: MEDIUM.
- Control attributes — New attribute framework introduced in 2022 edition. Deviation: N/A (new feature). Verdict: 直接互认 (Direct mutual recognition). Impact: LOW.
REGULATORY LINKAGE TABLE (法规联动)
| Compliance Scenario | Chinese Regulatory Basis | International Regulatory Basis |
|---|---|---|
| Mandatory product certification | N/A — GB/T 22081 is recommended, not mandatory | ISO/IEC 27001 certification (accredited) |
| Engineering acceptance inspection | N/A for product standard comparison | N/A |
| Import/export compliance | N/A — no customs requirement | N/A |
| Designer/engineer obligation | N/A for product standard comparison | N/A |
AUDIT FLAG RESOLUTION
- ✅ RESOLVED: Edition status — GB/T 22081-2024 is CURRENT (现行) per std.samr.gov.cn. GB/T 22081-2016 is superseded. No supersession note required for 2024 edition.
- ✅ RESOLVED: Equivalence — GB/T 22081-2024 is IDT adoption of ISO/IEC 27002:2022, confirmed by identical control count (93) and domain structure (4).
- ✅ FALSE POSITIVE: GB/T 22081-2016 — flagged as potentially current, but usage as reference is invalid; must cite 2024 edition.
PROCUREMENT VERDICT
- Update all contracts referencing GB/T 22081-2016 to GB/T 22081-2024.
- Verify supplier ISMS aligns with ISO/IEC 27002:2022 control set (93 controls).
- Request supplier's control implementation mapping to GB/T 22081-2024 Annex A.
- Confirm GB/T 22080-2016 (ISMS requirements) compliance for certification purposes.
- Check if supplier holds ISO/IEC 27001:2022 certification — direct evidence of alignment.
- For Chinese market compliance, ensure documentation references GB/T 22081-2024, not the international number alone.
REFERENCE DOCUMENT CHECKLIST (配套调阅清单)
- GB/T 22081-2024 §5–8 — Verify control count and domain structure
- GB/T 22081-2024 Annex A — Verify control attributes table
- ISO/IEC 27002:2022 §5–8 — Cross-check control numbering against Chinese edition
FIELD INSPECTION CHECKLIST
- Verify supplier's documented control implementation matches 93-control structure.
- Check that ISMS documentation references GB/T 22081-2024, not 2016 edition.
- Confirm internal audit scope covers all 4 control domains.
- Verify control attribute mapping (type, properties, capabilities) in supplier's risk assessment.
- Check training materials reference updated control numbering.
CONFIDENCE RATING
🟢 HIGH CONFIDENCE — data verified across two independent AI sources and official Chinese standards registry (std.samr.gov.cn); all numeric values have clause references; edition status confirmed authoritative.
Technical comparison report — CN Quality Check Standards Tool. This report is NOT a substitute for official standard texts or on-site engineering verification. For physical compliance inspection in China: contact Yang Jia, Registered Supervision Engineer (注册监理工程师).
Need on-site compliance verification in China?
This report is an AI-assisted technical reference. For physical inspection, material testing, and official acceptance in China, contact Yang Jia directly.
Request an Inspection →