As an important part of the series of standards for cybersecurity situation awareness, this standard, together with standards such as vulnerability assessment and threat assessment, constitutes a complete technical system. Its core lies in establishing multi-dimensional data collection specifications to provide high-quality data input for subsequent situation analysis.
| Data type | Collected content | Typical collection objects | Technical implementation |
|---|---|---|---|
| Log data | System log/network log/security log | Firewall, IDS/IPS, Server | Syslog/Kafka/Agent |
| Traffic data | Five-tuple information/protocol content/file sample | Network mirror port/traffic probe | NetFlow/deep packet inspection |
| Asset data | Hardware configuration/software version/topology relationship | IT asset management system | Active detection/passive monitoring |
The standard requires support for both active (SFTP/SSH) and passive (Syslog/Kafka) collection methods:
Special provisions for industrial Internet scenarios:
Implementation case of a smart manufacturing enterprise: Through
Compared with related standards such as YD/T 2388-2022, this document clarifies for the first time:
| Phase | Key Tasks | Meeting Requirements |
|---|---|---|
| Pilot Period | Core Network Traffic Collection + Key Equipment Logs | Meet clause 6.1(a)(b) |
| Promotion period | Full asset discovery + industrial protocol support | Meet clause 9.3/10.2 |

Copyright ©2026 All Rights Reserved
Update:
Tue, 02 Jun 2026 16:54:06 +0000