The basis of classification is the "Information System Security Level Protection Classification Guide" you mentioned. The principle of grading is "self-grading", because I know best how much impact the system will have after being destroyed. After determining the grade, draft a "grading report", which can be found in Baidu Library.
Step 2: Prepare filing materials.
The materials needed for filing are mainly information security level protection filing forms, which can be found in Baidu Library. Each system should fill in a filing form, and the secondary system only needs to fill in Table 1, Table 2 and Table 3 of the filing form; Table 1, Table 2, Table 3 and Table 4 are required for the three-level system.
Step 3: Grade evaluation
The secondary system can be put on record without rating; The three-level system requires a qualified evaluation agency to conduct an evaluation and issue an evaluation report, which is one of the filing materials (clearly stated in Table 4 of the filing form) for filing.
Step 4: Submit the filing materials.
Print and seal the Record Form of Information Security Level Protection in duplicate, and submit it together with the electronic version to the network supervision detachment of the local public security bureau at or above the prefecture level (now called the network security detachment). After the approval, the information security protection filing certificate will be issued to you, and the filing work is over.