China: Chinese National Network Security Standardization Technical Committee Secretariat opened consultation on national standard on network security technical authentication and authorisation focused on attribute-based access control model and management specification

Description

Chinese National Network Security Standardization Technical Committee Secretariat opened consultation on national standard on network security technical authentication and authorisation focused on attribute-based access control model and management specification

On 27 August 2025, the Chinese National Network Security Standardisation Technical Committee Secretariat (TC260) opened a consultation on the national standard on network security technical authentication and authorisation, focused on the attribute-based access control model and management specification, until 26 October 2025. The standard applies to organisations and cybersecurity product and service providers, and provides a reference for evaluators and regulators. The standard sets out obligations on attribute, policy, and engine management and requires natural language and digital policy expression with conflict resolution through metapolicies. The standard also mandates audits and maintenance of attribute-based access control engines, and introduces test methods for attributes, policies, and engines. It also outlines cryptographic safeguards for system integrity and confidentiality.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
software provider: other software
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2025-08-27
in consultation

On 27 August 2025, the Chinese National Network Security Standardisation Technical Committee Secret…

2025-10-26
processing consultation

On 26 October 2025, the Chinese National Network Security Standardisation Technical Committee Secre…