A method, apparatus and computing device for information security compliance assessment

By automating the invocation of application programming interfaces (APIs) for cloud resources through online assessment solutions, the problem of low efficiency in existing compliance assessments for information security protection has been solved, enabling efficient and accurate cloud resource assessments and security remediation.

CN115168860BActive Publication Date: 2026-04-03ALIBABA CLOUD COMPUTING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-06
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing compliance assessment methods mainly rely on manual operation, which is inefficient and makes it difficult to achieve timely and unified management and efficient coverage of cloud resources.

Method used

By automating the call to application programming interfaces (APIs) of cloud resources through online assessment solutions, the assessment process can be automated, assessment reports can be generated, and security remediation can be guided.

Benefits of technology

This improved the coverage and efficiency of compliance assessments, reduced labor costs, and ensured the accuracy and completeness of assessment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115168860B_ABST
    Figure CN115168860B_ABST
Patent Text Reader

Abstract

This specification discloses one or more embodiments of a method, apparatus, and computing device for information security compliance assessment. The method includes: generating an online assessment scheme for assessment projects created based on assessment tasks using a preset assessment scheme template; assessing the corresponding target cloud resources through the call interfaces of the target cloud resources arranged in the assessment project based on the online assessment scheme; obtaining the assessment results for each target cloud resource; and calculating and outputting an assessment report according to the weights assigned to each target cloud resource in the online assessment scheme. This integrates the information security compliance assessment process for cloud resources online, automating the combination and call of cloud resource application programming interfaces (APIs) by arranging assessment process tasks, thereby completing the automated assessment of information security compliance projects and improving the coverage and efficiency of information security compliance assessments for cloud resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the field of computer technology, and in particular to a method, apparatus and computing device for information security compliance assessment. Background Technology

[0002] Information security compliance refers to classifying and protecting information systems that store, transmit, and process important, proprietary, and public information according to their security levels; managing information security products used in information systems according to their security levels; and responding to and handling information security incidents that occur in information systems according to their security levels.

[0003] Currently, to ensure successful compliance assessment, compliance teams of enterprises and institutions typically spend a significant amount of time preparing for compliance certification. Based on this preparation, on-site certification is conducted through methods such as reviewing paper materials, conducting on-site interviews, and sampling to obtain evidence. Finally, risk management work is carried out based on the issues discovered during the certification process and the risks associated with obtaining their own qualifications, in order to maintain compliance standards.

[0004] However, most existing assessment methods are implemented manually, resulting in low assessment efficiency. Summary of the Invention

[0005] The purpose of one or more embodiments in this specification is to provide a method, apparatus, and computing device for information security compliance assessment, so as to realize online automatic information security compliance assessment of target users, reduce manual intervention, and improve assessment efficiency.

[0006] To solve the above-mentioned technical problems, one or more embodiments of this specification are implemented as follows:

[0007] Firstly, a compliance assessment method for information security protection is proposed, including:

[0008] Identify the target users and create assessment tasks based on the selected target cloud resources to be evaluated;

[0009] After completing the system survey based on the assessment project, an online assessment plan is generated for the assessment project created based on the assessment task by using a preset assessment plan template;

[0010] Based on the online evaluation scheme, the corresponding target cloud resources are evaluated through the call interface of the target cloud resources arranged in the evaluation project;

[0011] The evaluation results of each target cloud resource are obtained. According to the weight assigned to each target cloud resource in the online evaluation scheme, an evaluation report is calculated and output. The evaluation report is used to guide the target user to carry out security rectification of the target cloud resources to be evaluated.

[0012] Secondly, a compliance assessment device for information security protection is proposed, including:

[0013] The determination module is used to determine the assessment task created by the target user based on the selected target cloud resources to be assessed.

[0014] The generation module is used to generate online assessment schemes for assessment projects created based on assessment tasks after completing system surveys based on assessment projects, using preset assessment scheme templates.

[0015] The evaluation module is used to evaluate the corresponding target cloud resources based on the online evaluation scheme and through the call interface of the target cloud resources arranged in the evaluation project.

[0016] The output module is used to obtain the evaluation results of each target cloud resource, calculate and output an evaluation report according to the weight assigned to each target cloud resource in the online evaluation scheme, wherein the evaluation report is used to guide the target user to carry out security rectification of the target cloud resources to be evaluated.

[0017] Thirdly, a computing device is proposed, comprising:

[0018] Processor; and

[0019] A memory configured to store computer-executable instructions, which, when executed, cause the processor to perform the information security compliance assessment method described in the first aspect.

[0020] Fourthly, a computer-readable storage medium is proposed, which stores one or more programs that, when executed by a computing device including multiple applications, cause the computing device to perform the information security compliance assessment method described in the first aspect.

[0021] As can be seen from the technical solutions provided by one or more embodiments of this specification above, the online integration of the cloud resource compliance assessment process, by arranging the application programming interfaces (APIs) of cloud resources into assessment process tasks, automatically combines and calls the APIs of cloud resources to complete the automated assessment of the compliance assessment project, reducing manual intervention and improving the coverage and efficiency of cloud resource compliance assessment. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in one or more embodiments or prior art of this specification, the accompanying drawings used in the description of one or more embodiments or prior art will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a schematic diagram of the scenario architecture of a compliance assessment scheme for information security level protection provided in the embodiments of this specification.

[0024] Figure 2 This is a schematic diagram illustrating the steps of a compliance assessment method for information security protection provided in the embodiments of this specification.

[0025] Figure 3 This is a service module involved in the information security compliance solution provided in one embodiment of this specification.

[0026] Figure 4 This is a schematic diagram of the cloud resource information security compliance assessment process provided in one embodiment of this specification.

[0027] Figure 5 This is a schematic diagram of the structure of a compliance assessment device for information security protection provided in one embodiment of this specification.

[0028] Figure 6 This is a schematic diagram of the structure of an electronic device provided in one embodiment of this specification. Detailed Implementation

[0029] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described one or more embodiments are only some embodiments of this specification, and not all embodiments. All other embodiments obtained by those skilled in the art based on one or more embodiments of this specification without creative effort should fall within the protection scope of this document.

[0030] As mentioned in the background section, current compliance assessment systems for information security level protection (ISLP) typically include basic personnel management, assessment, and assessment report functions. Personnel management defines the responsibilities of personnel within the assessment system, managing staff such as assessment administrators, assessors, and assessment auditors. The assessment function manages the entire assessment process, encompassing several stages from the initial assessment to its completion: for example, research on the system to be assessed, assessment plan development, on-site assessment, analysis of security issues, and output of the assessment report.

[0031] However, these assessment management and processes are primarily offline. The compliance assessment items and corresponding assessment methods are relatively fixed, making them difficult to modify once released and online. Furthermore, updates and maintenance are not timely, hindering the timely unification of compliance assessment standards. The assessment process and methods for compliance assessment projects are determined manually by the assessment organization, making it difficult for users to assess the overall compliance status of their cloud systems and make corresponding rectifications before conducting compliance assessments. Moreover, the assessment methods are primarily manual, requiring assessors to manually log into the cloud resources to be assessed, execute fixed testing commands, and manually enter the results into the compliance assessment results. This results in high labor costs, and when the number of cloud resources to be assessed is large, sampling methods are often used, leading to significant errors in the assessment results due to limited coverage.

[0032] Therefore, this specification proposes a solution for performing compliance assessments on cloud resources. The main concept of the solution includes: integrating the compliance assessment process of cloud resources online; automating the combination and calling of application programming interfaces (APIs) of cloud resources by orchestrating assessment process tasks; completing the automated assessment of compliance assessment projects; and improving the coverage and efficiency of compliance assessments of cloud resources.

[0033] Reference Figure 1 The diagram illustrates a scenario architecture for a compliance assessment scheme provided in this specification. This assessment scheme can include a target user terminal 102 and an assessment server terminal 104. The target user terminal 102 is the object to be assessed. Based on the operations of target user a, the target user terminal 102 can apply for assessment services for one or more cloud resources currently accessible to it. The assessment server terminal 104 is the entity providing the assessment service to the target user terminal 102. The assessment server terminal 104 can be a cloud environment product like the target user terminal 102, or it can be a non-cloud product. The assessment user b is a third party providing the assessment service, assisting the assessment server terminal 104 in providing a more reasonable and accurate assessment scheme to the target user terminal 102, thereby achieving a more efficient assessment service. Before the evaluation begins, the evaluation server 104, with the assistance of the evaluation user b, can apply for access permissions from the target user terminal 102. This allows it to obtain real-time data of cloud resources based on the application programming interface of the cloud resources on the target user terminal 102, based on the pre-arranged evaluation items, and thus evaluate the cloud resources.

[0034] Reference Figure 2The diagram illustrates the steps of a compliance assessment method for information security compliance (ISC) provided in this embodiment. This method is applied in an ISC compliance assessment system for cloud resources, and its execution entity can be an ISC compliance assessment device. This device can be a regular server or a cloud server, or other software modules capable of performing ISC compliance assessments. These software modules can be integrated into a regular server or a cloud server. The ISC compliance assessment method may include the following steps:

[0035] Step 202: Determine the assessment task created by the target user based on the selected target cloud resources to be assessed.

[0036] The target users here can be cloud users with evaluation needs, who utilize cloud resources provided by their cloud service provider to achieve their resource utilization goals. The evaluation task is created in response to the target user's selection on the platform interface, specifically targeting the selected cloud resource to be evaluated. Evaluation tasks can be created based on the target user's manual selection or in conjunction with the evaluation task options set in the service interface of the evaluation server.

[0037] Step 204: After completing the system survey based on the assessment project, generate an online assessment plan for the assessment project created based on the assessment task by using a preset assessment plan template.

[0038] There can be multiple preset assessment plan templates, managed by the template management module. This module also manages various report templates, log templates, and statistical report templates. Each template includes user-defined templates and system templates. System templates can be provided by the compliance management provider. Different assessment users can customize and edit these system templates online. The assessment plan and report generation during the assessment process will use the corresponding templates to generate online assessment plans and reports.

[0039] After identifying the assessment task created by the target user, the assessment task can be pushed to the assessment user. The assessment user accepts the assessment task and creates a corresponding information security compliance assessment project based on the assessment task, and conducts system research. Specifically, the information security compliance assessment project can be created by combining offline discussion and planning with online prediction. Then, the system research is completed by selecting user cloud resources in real time and importing offline device resources. Afterwards, an online assessment plan is generated by using a preset assessment plan template, and further adjustments to the assessment plan can be made according to the actual situation.

[0040] The assessment project dynamically configures assessment sub-items with different compliance levels. Each assessment sub-item corresponds to one or more cloud systems, and each cloud system contains at least one cloud resource. The cloud resources covered by the cloud-based compliance assessment project may include: physical data centers, network equipment, security equipment, servers or storage devices, terminals or field devices, system management software or platforms, service application systems or platforms, etc.

[0041] Step 206: Based on the online evaluation scheme, evaluate the corresponding target cloud resources through the call interface of the target cloud resources arranged in the evaluation project.

[0042] Optionally, in step 206, when evaluating the corresponding cloud resources based on the online evaluation scheme and through the calling interface of the target cloud resources arranged in the evaluation project, the target user may be requested to access the target cloud resources to be evaluated based on the online evaluation scheme. After the control permission is granted, the corresponding cloud resources are evaluated through the calling interface of the target cloud resources arranged in the evaluation project, based on the resource access control service provided by the cloud server where the target user is located.

[0043] Furthermore, when evaluating the corresponding cloud resources through the call interfaces of the target cloud resources arranged in the evaluation project, the call interfaces of the corresponding target cloud resources can be called sequentially according to the arrangement order of the target cloud resources in the evaluation project to obtain the real-time data of the target cloud resources, and the evaluation can be carried out based on the real-time data.

[0044] Step 208: Obtain the evaluation results of each target cloud resource, calculate and output an evaluation report according to the weight assigned to each target cloud resource in the online evaluation scheme, wherein the evaluation report is used to guide the target user to carry out security rectification of the target cloud resources to be evaluated.

[0045] The online assessment scheme allows for the setting of weights for each target cloud resource. These weights can be determined based on the resource's impact within the scheme or on historical experience. Furthermore, these weights can be adjusted as the assessment project changes, and the compliance level within the online assessment scheme can be dynamically configured, thus achieving flexible assessment.

[0046] Optionally, after determining the assessment task and before completing the system survey based on the assessment project, a predictive assessment operation can be performed on the cloud resources to be assessed based on the predictive assessment request of the target user. Specifically, an online pre-assessment plan can be generated based on the assessment project created based on the assessment task, and based on the online pre-assessment plan, the corresponding target cloud resources can be predicted and assessed through the call interface of the target cloud resources arranged in the assessment project to obtain the predictive assessment result. The predictive assessment result is used to guide the target user to carry out security rectification of the target cloud resources to be assessed. In fact, before the assessment of the target cloud resources by the evaluation user, a predictive assessment can be conducted in advance. This predictive assessment process is similar to the formal assessment process. It involves granting access permissions to the compliance assessment device, allowing it to access the cloud service provider's network where the target cloud resources reside. This establishes a connection with the application level interface of the target cloud resources. Based on the defined assessment task, a predictive assessment plan can be created, and real-time data can be obtained from the corresponding API of the target cloud resources for predictive assessment, ultimately yielding the predictive assessment result. Based on the predictive assessment result, if any target cloud resources require rectification, timely rectification can be carried out to ensure compliance with the set compliance level. This provides multiple rectification opportunities for subsequent formal assessments, improving both assessment and rectification efficiency.

[0047] Another feasible solution is to output at least one piece of intermediate data generated during the assessment process, based on the rectification needs of the target user or the assessment user, after outputting the assessment report. This intermediate data is used to assist the target user in carrying out security rectification of the target cloud resources under assessment. Therefore, this supports the import and export of multiple data types throughout the entire compliance assessment process, comprehensively covering compliance assessment data and ensuring the reliability and completeness of the assessment data.

[0048] Furthermore, after the evaluation report is output, it can also be stored in the evaluation account corresponding to the target user, so that the historical evaluation report can be referenced when conducting the next evaluation, thus enabling continuous tracking and supervision.

[0049] Therefore, by orchestrating application programming interface (API) tasks for cloud resources, standardized and unified cloud-based automated compliance assessment items are formed. By combining and calling the APIs of the compliance assessment items corresponding to the cloud resources used by the cloud system, real-time compliance assessment results of cloud resources can be obtained, forming standardized and unified compliance assessment results. This can quickly cover cloud systems and improve the coverage rate of cloud-based compliance assessments.

[0050] Reference Figure 3As shown in the embodiments of this specification, the compliance assessment scheme provides services such as assessment service personnel role management, access control, template management, project management, assessment mechanism, log service, and reporting service. These can be obtained according to the above functional divisions. Figure 3 The module unit shown.

[0051] The role management module can directly integrate with the cloud service provider's resource access control service, using a cloud account and sub-account management model. This eliminates the need for a separate personnel management system. Depending on the actual evaluation process, in addition to the main account provided by the cloud service provider (corresponding to the target user) acting as the system administrator, multiple sub-accounts can be created and assigned corresponding role permissions to serve as responsible personnel for different stages of the evaluation mechanism. In the embodiments described in this specification, this can be simply set up as two roles: a main account corresponding to the target user and a sub-account corresponding to the test user. The main account and sub-accounts can trigger corresponding operations through their respective account pages, such as creating an evaluation plan, calling the corresponding interface of cloud resources, and executing the evaluation plan.

[0052] The access control module can implement role-based access control policies at the operation interface level. The roles in the cloud-based information security assessment process are divided into: system administrator, template administrator, assessor, project manager, project administrator, and reviewer. In fact, except for the system administrator, the other roles can be implemented by the assessment user. That is, in the embodiment of this specification, the assessment user is responsible for template management, assessment, project management, and review operations.

[0053] The template management module includes templates for compliance assessment plans and reports. Each template contains both custom templates for assessment organizations and system templates. The system templates are provided by the authoritative compliance management body, and different assessment organizations can customize and edit them online. The plan and report compilation in the assessment mechanism will generate online assessment plans and reports based on the corresponding templates. The online assessment plan can include one or more compliance assessment indicators of a set level, and assessment operations will be performed on the content of the online assessment plan based on these indicators.

[0054] Project management refers to responding to the selection or creation operation of the assessment user, creating corresponding compliance assessment projects based on the compliance assessment tasks submitted by the target user on the cloud, and managing the assessment tasks through projects. One assessment project can correspond to multiple cloud systems, and one cloud system can correspond to multiple cloud resources.

[0055] The evaluation mechanism is the core evaluation process for compliance assessment, mainly comprising five evaluation stages: system investigation, solution preparation, on-site evaluation, security issue analysis, and report editing, as well as compliance assessment project management. Through cloud-based compliance assessment projects, application programming interface (API) data provided and maintained by cloud resource providers (target users) is converted into real-time detection data. This integrates the automated data capture capabilities of underlying cloud products, covering multi-level compliance assessment indicators. It can dynamically configure and adjust the evaluation process, weights, and comprehensive score calculation methods for different levels of compliance assessment items, and calculate the comprehensive score of the system under evaluation in real time after the automated evaluation results are updated, generating an evaluation report. Furthermore, the cloud-based compliance assessment process orchestration allows for more flexible configuration and combination of compliance assessment items with pre-process dependencies. Although false alarms or errors may occur due to process dependencies, these errors are not significant or have a small impact on the entire evaluation process due to the large number of assessment items, thus avoiding a single API blocking the execution of the entire assessment item. The acquisition of cloud resources and the application programming interfaces (APIs) provided by cloud resource providers both require integration with the cloud service provider's resource access control service. Therefore, data security can be ensured by obtaining temporary authorization from the target user to access the target user's cloud service provider's API.

[0056] In addition, the log and reporting service provides historical assessment data reports on compliance with information security standards, as well as execution logs for assessment items, to continuously monitor the cloud system. This log and reporting service can be continuously linked with the previous log and reporting service each time an assessment operation is triggered; that is, the logs and reports of the (n+1)th assessment will be linked with the logs and reports of the nth assessment.

[0057] Reference Figure 4 The diagram shown is a complete flowchart of the cloud resource information security compliance assessment process. In the actual assessment scheme, the entity executing this assessment operation can be an assessment server running in the cloud environment, which can perform... Figure 2 The evaluation method shown is applicable and can perform the corresponding functions.

[0058] Before the assessment begins, the target user can log in to the web client interface (main account) and select the cloud resources to be assessed through the assessment interface provided by the assessment server. This can be done by inputting or selecting known cloud resource items. The client interface will generate an assessment task based on the selection and send it back to the assessment server. Simultaneously, the assessment user can also log in to the web client interface (sub-account) and receive assessment tasks through the assessment interface provided by the sub-account on the assessment server. In this case, the assessment user can manually create or the assessment server can automatically create compliance assessment projects. During creation, the interfaces corresponding to the cloud resources can be automatically arranged according to the assessment requirements for dynamic adjustment. Afterwards, the assessment user can complete the system survey offline by selecting the target user's cloud resources in real time and importing offline device resources. Next, the assessment user triggers the assessment server to generate an online assessment plan using the assessment plan template. Further adjustments to the assessment plan can be made based on the actual situation; for example, after automatically generating the online assessment plan, manual fine-tuning can be performed. Once the online assessment plan is finalized, the pre-arranged cloud-based compliance assessment projects will automatically assess the target user's cloud resources according to the online assessment plan. It will call the corresponding cloud resource application programming interfaces to obtain standardized assessment results, and then render and display these results, forming a composite assessment result containing compliance assessment item knowledge base information. Based on the assessment results, users will rectify non-compliant security issues according to the knowledge base and user feedback. Finally, an online assessment report can be generated using an assessment report template, and further adjustments can be made based on actual circumstances. Ultimately, a comprehensive assessment report containing complete assessment process data will be generated, ensuring the reliability and completeness of the compliance assessment data.

[0059] Therefore, the above technical solution can form standardized cloud-based automated compliance assessment items through the task orchestration of application programming interfaces (APIs) for cloud resources. By combining and calling the APIs of the compliance assessment items corresponding to the cloud resources used by the cloud system, real-time compliance assessment results of cloud resources can be obtained, forming standardized compliance assessment results. This can quickly cover the cloud system, improve the coverage of cloud-based compliance assessment, reduce labor costs, and improve the efficiency of compliance assessment.

[0060] Reference Figure 5 The diagram shown is a structural schematic of the information security compliance assessment device provided in the embodiments of this specification. It should be understood that the information security compliance assessment device can be a cloud software module deployed based on cloud resources, or a regular software module deployed on non-cloud resources. The device 500 may include:

[0061] Module 502 is used to determine the assessment task created by the target user based on the selected target cloud resource to be assessed.

[0062] The generation module 504 is used to generate an online assessment plan for the assessment project created based on the assessment task after the system survey based on the assessment project is completed, by using a preset assessment plan template.

[0063] The evaluation module 506 is used to evaluate the corresponding target cloud resources based on the online evaluation scheme and through the call interface of the target cloud resources arranged in the evaluation project.

[0064] The output module 508 is used to obtain the evaluation results of each target cloud resource, calculate and output an evaluation report according to the weight assigned to each target cloud resource in the online evaluation scheme, wherein the evaluation report is used to guide the target user to carry out security rectification of the target cloud resources to be evaluated.

[0065] Optionally, as an embodiment, when the evaluation module evaluates the corresponding cloud resources based on the online evaluation scheme and through the calling interface of the target cloud resources arranged in the evaluation project, it is specifically used to: apply to the target user for access control permissions to evaluate the target cloud resources to be evaluated based on the online evaluation scheme; after being granted the control permissions, evaluate the corresponding cloud resources through the calling interface of the target cloud resources arranged in the evaluation project based on the resource access control service provided by the cloud server where the target user is located.

[0066] In one specific implementation of the embodiments of this specification, when the evaluation module evaluates the corresponding cloud resources through the calling interface of the target cloud resources arranged in the evaluation project, it is specifically used to: sequentially call the calling interface of the corresponding target cloud resources according to the arrangement order of the target cloud resources in the evaluation project to obtain the real-time data of the target cloud resources, and perform evaluation based on the real-time data.

[0067] In another specific implementation of the embodiments of this specification, it further includes: a prediction evaluation module; the prediction evaluation module is used to generate an online pre-evaluation scheme based on the evaluation project created based on the evaluation task after the determination module determines the evaluation task and before the system survey is completed based on the evaluation project, and based on the online pre-evaluation scheme, to perform prediction evaluation on the corresponding target cloud resources through the calling interface of the target cloud resources arranged in the evaluation project, and obtain the prediction evaluation result, the prediction evaluation result being used to guide the target user to carry out security rectification of the target cloud resources to be evaluated.

[0068] In another specific implementation of the embodiments of this specification, after outputting the evaluation report, the output module is further configured to output at least one piece of intermediate data generated during the evaluation process based on the rectification needs of the target user or the evaluation user, wherein the intermediate data is used to assist and guide the target user in carrying out security rectification of the target cloud resources to be evaluated.

[0069] In another specific implementation of the embodiments of this specification, a storage module is further included, which is used to store the evaluation report under the evaluation account corresponding to the target user after the evaluation report is output.

[0070] In another specific implementation of the embodiments of this specification, the evaluation project is dynamically configured with evaluation sub-items of different compliance levels, each evaluation sub-item corresponds to one or more cloud systems, and each cloud system contains at least one cloud resource.

[0071] The above technical solution can form standardized automated cloud-based compliance assessment items through the task orchestration of application programming interfaces (APIs) for cloud resources. It can combine and call the APIs of the corresponding compliance assessment items for cloud resources used by the cloud system to obtain real-time compliance assessment results for cloud resources, form standardized compliance assessment results, quickly cover cloud systems, improve the coverage of cloud-based compliance assessment, reduce labor costs, and improve the efficiency of compliance assessment.

[0072] Figure 6 This is a schematic diagram of the structure of a computing device according to one embodiment of this specification. Please refer to it. Figure 6 At the hardware level, the electronic device includes a processor, and optionally also an internal bus, a network interface, and memory. The memory may include main memory, such as high-speed random-access memory (RAM), or non-volatile memory, such as at least one disk drive. Of course, the electronic device may also include hardware required for other services.

[0073] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 6The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.

[0074] Memory is used to store programs. Specifically, programs may include program code, which includes computer operation instructions. Memory may include main memory and non-volatile memory, and provides instructions and data to the processor.

[0075] The processor reads the corresponding computer program from non-volatile memory into main memory and then runs it, forming a compliance assessment device at the logical level. The processor executes the program stored in memory and specifically performs the following operations:

[0076] The process involves identifying assessment tasks created by target users based on selected target cloud resources to be assessed; after completing system research based on the assessment projects, generating online assessment schemes for the assessment projects created based on the assessment tasks using a preset assessment scheme template; evaluating the corresponding target cloud resources through the call interfaces of the target cloud resources arranged in the assessment projects based on the online assessment scheme; obtaining the assessment results for each target cloud resource; calculating and outputting an assessment report according to the weights assigned to each target cloud resource in the online assessment scheme; wherein the assessment report is used to guide the target users in carrying out security rectification of the target cloud resources to be assessed.

[0077] The above is as described in this instruction manual. Figure 2The methods performed by the apparatus disclosed in the illustrated embodiments can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in one or more embodiments of this specification. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in one or more embodiments of this specification can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0078] The electronic device can also perform Figure 2 The method, and implement the corresponding device in Figure 2 The functions of the embodiments shown are not described in detail here.

[0079] Of course, in addition to the software implementation, the electronic devices in the embodiments of this specification do not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0080] This specification also provides an embodiment of a computer-readable storage medium that stores one or more programs, the programs including instructions that, when executed by a portable electronic device including multiple applications, enable the portable electronic device to perform... Figure 2 The method of the illustrated embodiment is specifically used to perform the following method:

[0081] The process involves identifying assessment tasks created by target users based on selected target cloud resources to be assessed; after completing system research based on the assessment projects, generating online assessment schemes for the assessment projects created based on the assessment tasks using a preset assessment scheme template; evaluating the corresponding target cloud resources through the call interfaces of the target cloud resources arranged in the assessment projects based on the online assessment scheme; obtaining the assessment results for each target cloud resource; calculating and outputting an assessment report according to the weights assigned to each target cloud resource in the online assessment scheme; wherein the assessment report is used to guide the target users in carrying out security rectification of the target cloud resources to be assessed.

[0082] In summary, the above description is merely a preferred embodiment of this specification and is not intended to limit the scope of protection of this specification. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of protection of this specification.

[0083] The systems, apparatuses, modules, or units described in one or more of the above embodiments may be implemented by a computer chip or entity, or by a product having a certain function. A typical implementation device is a computer. Specifically, a computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.

[0084] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0085] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0086] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

[0087] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

Claims

1. A method for assessing compliance with information security standards, comprising: Identify the target users and create assessment tasks based on the selected target cloud resources to be evaluated; After completing the system survey based on the assessment project, an online assessment plan is generated for the assessment project created based on the assessment task by using a preset assessment plan template; Based on the online assessment scheme, real-time data of the target cloud resources is obtained by calling the application programming interface corresponding to the information security compliance assessment item of the target cloud resources arranged in the assessment project, and the information security compliance assessment item is assessed on the target cloud resources according to the real-time data. Obtain the evaluation results, calculate and output the evaluation report according to the weights allocated in the online evaluation scheme, wherein the evaluation report is used to guide the target user to carry out security rectification of the target cloud resources to be evaluated.

2. The information security compliance assessment method as described in claim 1, based on the online assessment scheme, obtains real-time data of the target cloud resources by calling the application programming interface corresponding to the information security compliance assessment item of the target cloud resources arranged in the assessment project, and assesses the target cloud resources for the information security compliance assessment item based on the real-time data, including: Based on the online evaluation scheme, request control permissions from the target user to perform access evaluation of the target cloud resources to be evaluated; After the control permissions are granted, based on the resource access control service provided by the cloud server where the target user is located, the real-time data of the target cloud resources is obtained by calling the application programming interface corresponding to the compliance assessment item of the target cloud resources arranged in the assessment project, and the compliance assessment item of the target cloud resources is assessed based on the real-time data.

3. The information security compliance assessment method as described in claim 2, wherein real-time data of the target cloud resources is obtained by calling the application programming interface corresponding to the information security compliance assessment item of the target cloud resources arranged in the assessment project, including: By sequentially calling the application programming interfaces (APIs) of the target cloud resources corresponding to the compliance assessment items in the evaluation project according to the arrangement order of the target cloud resources, the real-time data of the target cloud resources is obtained.

4. The information security compliance assessment method as described in any one of claims 1-3, after determining the assessment task and before completing the system survey based on the assessment project, the method further includes: Based on the assessment project created by the assessment task, an online pre-assessment plan is generated. Based on the online pre-assessment plan, the corresponding target cloud resources are predicted and assessed through the call interface of the target cloud resources arranged in the assessment project to obtain the prediction assessment result. The prediction assessment result is used to guide the target user to carry out security rectification of the target cloud resources to be assessed.

5. The information security compliance assessment method as described in any one of claims 1-3, after outputting the assessment report, the method further includes: Based on the rectification needs of the target user or the evaluation user, at least one piece of intermediate data generated during the evaluation process is output, wherein the intermediate data is used to assist and guide the target user in carrying out security rectification of the target cloud resources to be evaluated.

6. The information security compliance assessment method as described in any one of claims 1-3, further comprising, after outputting the assessment report: The evaluation report is stored under the evaluation account corresponding to the target user.

7. The information security compliance assessment method as described in claim 1, wherein the assessment project is dynamically configured with assessment sub-items of different information security compliance levels, each assessment sub-item corresponds to one or more cloud systems, and each cloud system contains at least one cloud resource.

8. A compliance assessment device for information security level protection, comprising: The determination module is used to determine the assessment task created by the target user based on the selected target cloud resources to be assessed. The generation module is used to generate online assessment schemes for assessment projects created based on assessment tasks after completing system surveys based on assessment projects, using preset assessment scheme templates. The evaluation module is used to obtain real-time data of the target cloud resources by calling the application programming interface corresponding to the information security compliance evaluation item arranged in the evaluation project, based on the online evaluation scheme, and to evaluate the target cloud resources according to the information security compliance evaluation item based on the real-time data. The output module is used to obtain the evaluation results, calculate and output the evaluation report according to the weights allocated in the online evaluation scheme, wherein the evaluation report is used to guide the target user to carry out security rectification of the target cloud resources to be evaluated.

9. The information security compliance assessment device as described in claim 8, wherein the assessment module, based on the online assessment scheme, obtains real-time data of the target cloud resource by calling the application programming interface corresponding to the information security compliance assessment item arranged in the assessment project, and assesses the target cloud resource for the information security compliance assessment item based on the real-time data, is specifically used for: Based on the online evaluation scheme, request control permissions from the target user to perform access evaluation of the target cloud resources to be evaluated; After the control permissions are granted, based on the resource access control service provided by the cloud server where the target user is located, the real-time data of the target cloud resources is obtained by calling the application programming interface corresponding to the compliance assessment item of the target cloud resources arranged in the assessment project, and the compliance assessment item of the target cloud resources is assessed based on the real-time data.

10. The information security compliance assessment device as described in claim 9, wherein the assessment module obtains real-time data of the target cloud resources by calling the application programming interface corresponding to the information security compliance assessment item arranged in the assessment project, specifically for: By sequentially calling the application programming interfaces (APIs) of the target cloud resources corresponding to the compliance assessment items in the evaluation project according to the arrangement order of the target cloud resources, the real-time data of the target cloud resources is obtained.

11. The information security compliance assessment device as described in any one of claims 8-10, further comprising: Prediction and evaluation module; The prediction and evaluation module is used to generate an online pre-evaluation scheme based on the evaluation project created based on the evaluation task after the determination module determines the evaluation task and before the system survey is completed based on the evaluation project. Based on the online pre-evaluation scheme, the module performs a prediction evaluation on the corresponding target cloud resources through the call interface of the target cloud resources arranged in the evaluation project to obtain the prediction evaluation result. The prediction evaluation result is used to guide the target user to carry out security rectification of the target cloud resources to be evaluated.

12. The information security compliance assessment device as described in any one of claims 8-10, wherein after outputting the assessment report, the output module is further configured to: Based on the rectification needs of the target users or evaluation users, output at least one intermediate data point generated during the evaluation process, where... The intermediate data is used to assist and guide the target user in carrying out security rectification of the target cloud resources being evaluated.

13. A computing device, comprising: processor; as well as A memory configured to store computer-executable instructions, which, when executed, cause the processor to perform any one of the information security compliance assessment methods described in 1-7.

14. A computer-readable storage medium storing one or more programs, which, when executed by a computing device including a plurality of applications, cause the computing device to perform the information security compliance assessment method described in any one of 1-7.

Citation Information

Patent Citations

  • Safety evaluation method and device based on cloud service

    CN112217836A

  • Evaluation method and device, electronic equipment and readable storage medium

    CN113065793A