Abstract:Taking China Disease Control and Prevention Information System for example, the paper introduces the target and definition of information security hierarchy protection, concretely elaborates the main contents from the following aspects: information system status investigation, risk evaluation, overall planning and design, level assessment, etc.