A method and apparatus for screening cybersecurity compliance policy documents.

By utilizing historical inspection judgments and document similarity calculations in cybersecurity compliance checks, supporting documents are automatically matched, solving the problem of low efficiency in existing technologies, achieving fast and accurate document matching, improving inspection efficiency and reducing costs.

CN118839009BActive Publication Date: 2026-01-30BEIJING XIAOXINIU SOFTWARE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410881526.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-02
Publication Date
2026-01-30
Estimated Expiration
2044-07-02

AI Technical Summary

Technical Problem

In cybersecurity compliance checks, existing technologies are unable to quickly and accurately match supporting cybersecurity compliance policy documents, resulting in low inspection efficiency.

Method used

By obtaining the checklist items, judging the historical inspection situation, and using the legal and regulatory map and document database, the document similarity is calculated, and supporting documents that meet the requirements are automatically matched.

Benefits of technology

It enables the rapid and accurate matching of supporting documents for inspection items, improving the efficiency of cybersecurity compliance inspections and reducing costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118839009B_ABST
    Figure CN118839009B_ABST
Patent Text Reader

Abstract

This invention relates to a method, apparatus, electronic device, and medium for screening cybersecurity compliance policy documents, comprising: acquiring all inspection items in a checklist; determining whether each inspection item has been historically inspected; if an inspection item has been historically inspected, using the referenced documents from the historical inspection as the referenced documents for that inspection item; if an inspection item has not been historically inspected, acquiring the target laws and regulations involved in the inspection item; acquiring a first document set containing all the target laws and regulations in a document database; acquiring the target documents in the first document set; calculating the similarity between each target document and the inspection item; and using the similarity between each target document and the inspection item to obtain the referenced documents for each inspection item; completing the acquisition of referenced documents for all inspection items in the checklist; improving the efficiency of obtaining supporting documents and solving the deficiency in current cybersecurity compliance inspections where corresponding supporting documents cannot be accurately matched.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of security compliance, in particular to a screening method and device for network security compliance system documents, an electronic device and a medium. BACKGROUND

[0002] In the process of network security compliance construction, own security systems such as network security work general policy, information system daily operation rules, security management organization structure and post responsibilities, network security approval management system, personnel security management system are established according to the policies and regulations of the country, region and industry and according to the business types. Meanwhile, a large number of record documents such as security management system review and revision record table, security management system receiving and sending record table, external communication conference minutes, equipment change approval table and outsourcing service evaluation report are generated during the implementation of the own security systems. In the process of grade protection evaluation and network security compliance inspection by public security organs and the office of network security and information, the above security systems and record documents cannot be quickly and accurately used as evidence. SUMMARY

[0003] The application provides a screening method, device, electronic device and medium for network security compliance system documents, which can quickly match application documents cited by each check item in a check table as evidence.

[0004] The application is implemented by the following technical scheme, a screening method for network security compliance system documents, comprising:

[0005] All check items in a check table are obtained, and it is determined whether each check item has been historically checked. When a check item has been historically checked, the cited documents of the historical check are used as the cited documents of the check item.

[0006] When a check item has not been historically checked, target laws and regulations involved in the check item are obtained.

[0007] A first document set containing all target laws and regulations in a document database is obtained, target documents in the first document set are obtained, the similarity between each target document and the check item is calculated, and the cited documents of each check item are obtained by using the similarity between each target document and the check item.

[0008] The cited documents in all check items in the check table are completed.

[0009] Preferably, the method for obtaining the target documents in the first document set comprises classifying the documents in the first document set, and using the classified documents to match documents with the same category as the check item as the target documents.

[0010] Preferably, the method of calculating the similarity of each target document to the check item comprises:

[0011] Obtaining keywords in each target document; and calculating the similarity of each target document to the check item using the keywords and the check item.

[0012] Preferably, the method of obtaining keywords in the target document comprises:

[0013] Calculating the frequency of each word in the target document, and taking the word with high frequency as the keyword of the target document.

[0014] Or, clustering the sentences or paragraphs in the target document, merging the sentences or paragraphs in the same cluster after clustering, and screening the representative word in the cluster after merging as the keyword.

[0015] Preferably, when the similarity of each target document to the check item is greater than 80%, the target document is taken as the reference document of the check item.

[0016] A screening device for network security compliance system documents, comprising:

[0017] A judgment module for judging whether each check item in the check table has been historically checked.

[0018] A legal regulation obtaining module for obtaining the legal regulation in the check item which has not been historically checked in the judgment module.

[0019] A similarity calculating module for obtaining a first document set containing all target legal regulations in a document database, obtaining target documents in the first document set, and calculating the similarity of each target document to the check item.

[0020] A reference document determining module for taking the reference document of the check item with historical check obtained by the judgment module as the reference document of the check item.

[0021] The reference document of each check item is obtained using the similarity of each target document to the check item.

[0022] An electronic device, comprising:

[0023] One or more processors;

[0024] A storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement a screening method for network security compliance system documents.

[0025] A computer readable medium having stored thereon a computer program which, when executed by a processor, implements a method for screening network security compliance system documents.

[0026] The beneficial effects of the present application are:

[0027] By checking the mapping relationship between the check items in the check table and the supporting files, the corresponding reference documents in the document library can be automatically matched as supporting documents through the check items, the efficiency of obtaining supporting documents is improved, and the defect that corresponding supporting documents cannot be accurately matched during network security compliance checking is solved. BRIEF DESCRIPTION OF DRAWINGS

[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description only constitute some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor.

[0029] Figure 1 is a flow chart of a screening method for network security compliance system documents in the embodiment of the present application;

[0030] Figure 2 is a block diagram of a screening device for network security compliance system documents in the embodiment of the present application;

[0031] Figure 3 is a structural schematic diagram of a computer system of an electronic device in the embodiment. DETAILED DESCRIPTION

[0032] Example implementations will now be described more fully with reference to the accompanying drawings. Example implementations may, however, be implemented in many different forms and should not be construed as limited to the implementations set forth herein; rather, these implementations are provided so that this disclosure will be thorough and complete, and will fully convey the inventive aspects of example implementations to those skilled in the art. Like reference numerals may refer to like elements throughout the description of the figures.

[0033] Moreover, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of embodiments of the application. One skilled in the relevant art will recognize, however, that the techniques described herein can be practiced without one or more of the specific details, or with other methods, components, materials, and so forth. In other instances, well-known structures, systems, implementations, or operations are not shown or described in detail in order to avoid obscuring aspects of the application.

[0034] The block diagrams shown in the drawings are merely functional entities, and do not necessarily have to correspond to physically independent entities. That is, these functional entities can be implemented in software, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0035] The flowcharts shown in the drawings are merely exemplary illustrations, and do not necessarily include all contents and operations / steps, nor are they necessarily executed in the order described. For example, some operations / steps can be further divided, and some operations / steps can be combined or partially combined, so the actual execution order can be changed according to actual conditions.

[0036] The professional terms involved in the present embodiment are explained as follows:

[0037] Owner: An entity or organization that owns or operates a network system. This definition can cover various types of organizations, including government agencies, enterprises, research institutions, etc. These owners need to conduct self-inspections on their network systems or accept external network security inspections.

[0038] Network security system document: A complete set of network security management regulations and systems, including security management requirements for network equipment, security equipment, system software, application software, data, and personnel, etc. It aims to ensure the safe operation of the network system, prevent and reduce the occurrence of network security incidents, improve the level and ability of network security management, and establish and implement the network security system document in accordance with the requirements of national laws and regulations and standards, combined with the actual situation of the enterprise or organization, including but not limited to network topology, system architecture, application scenarios, personnel quality, etc.

[0039] System implementation record document: System implementation record document refers to the document that records and saves various activities and operations in the implementation process of the network security system. These records include but are not limited to: configuration and operation records of network security equipment such as firewalls, intrusion detection / prevention systems (IDS / IPS), etc.; access and use records of system, application software and data, such as permission assignment, password management, data backup and recovery, etc. Response and handling records of security incidents, such as security vulnerability scanning, incident response, recovery and reporting, etc. Records of network security training and education activities, such as training plans, training content, training personnel, etc.; records of network security checks and assessments, such as security checklists, risk assessment reports, etc.

[0040] Security compliance: refers to the behavior of an enterprise or organization in complying with legal regulations in network security management and implementing security measures, which requires network operators to fully comply with network security laws and regulations, system standards and related text specifications to avoid legal sanctions or regulatory penalties.

[0041] Security compliance check: refers to the establishment of network security compliance check indicators from the perspective of security compliance, finding some places that need to be optimized and corrected in enterprise network security, so as to promote the construction and operation of the whole security system.

[0042] Grade protection evaluation: refers to the protection of information systems according to importance level, including the protection of national important information, private information of legal persons and other organizations and citizens, and public information and the information systems storing, transmitting and processing these information. The information security products used in the information system are managed according to the level, and the information security events occurring in the information system are responded and disposed according to the level. In the grade protection evaluation, the inspection of technology and system is an important link. The technical inspection mainly includes the detection and evaluation of the security technical requirements of the hardware, software, network and data of the information system, such as the access control, encryption technology, firewall of the system; the system inspection mainly refers to the inspection and evaluation of the management rules and regulations of the information system, such as the information security management system, security audit system, emergency plan, etc.

[0043] Check item: the check item in the process of security compliance check or grade protection evaluation, the content usually includes project, key work, check and evaluation content, score and evaluation index, such as data security management (project), network data security management (key work), network data classification and grading management (check and evaluation content), 3 (score), 2 points for promoting the data classification and grading management of the local key industry according to the requirements of the superior, 1 point for establishing relevant account (evaluation index).

[0044] Check item set: the collection of check items of a check.

[0045] As shown in Figure 1 A screening method for network security compliance system documents, comprising:

[0046] All check items in the check table (check item set) are obtained, and it is judged whether each check item has been checked in history. Since the check items that have completed the historical check have referenced documents, when performing the second check, the documents referenced by the historical check of the check items can be directly used as the supporting documents of the current check.

[0047] Therefore, when it is judged that the check item has been checked in history, the referenced document of the historical check is used as the referenced document of the check item;

[0048] Since the check table involves the classification of policies and regulations (i.e., the basis for formulating), such as the protection evaluation of classified protection and the protection evaluation of key infrastructure, and the owner unit includes a complete set of network security system documents in the writing of network security system documents, which includes the requirement that the execution should comply with the requirements of national laws, regulations and standards, in view of this relationship, the embodiment is to match the evidence files in the check items by the relevance of laws and regulations. The embodiment is to match the graph established for the laws and regulations corresponding to each check item in the check table and the laws and regulations involved in the document.

[0049] Specifically, when the check item has not been checked historically, the target laws and regulations involved in the check item are obtained;

[0050] A first document set containing all target laws and regulations in the document database is obtained. The document database in the embodiment is a set of network security system documents completed by the owner unit, which contains all the network security system documents formulated by the owner unit. The network security system documents are entered into the database to form the document database. Since the laws and regulations involved in the check item are obtained, the laws and regulations are matched as target laws and regulations in the document database. Specifically, the words involved in the laws and regulations are calculated for similarity with the words in the documents in the database. The documents with high similarity, i.e., the similarity exceeding 80%, are considered as matching successful documents, and the first document set is obtained.

[0051] Since the first document set contains a set of documents that meet the requirements, further matching of corresponding documents is needed. After obtaining the first document set, the documents in the document set are classified. The classification method adopted in the embodiment includes constructing a network model and training the network model to complete the classification of the documents. Specifically,

[0052] Determine the corpus: First, a large number of check items and their types are labeled to construct a corpus for training and testing semantic analysis algorithms.

[0053] Data preprocessing: Preprocess the text data in the corpus, including word segmentation, removal of stop words, removal of special symbols, etc., to improve the accuracy of semantic analysis.

[0054] Feature extraction: Extract features from the preprocessed text data using bag-of-words model, TF-IDF, etc.

[0055] Train the model: Use the extracted features and labeled data to train a classification model, such as support vector machine (SVM), naive Bayes classifier or deep learning model, etc.

[0056] Model evaluation: Use the test dataset to evaluate the performance of the model, and use accuracy, recall, F1 score and other indicators to measure the performance of the model.

[0057] Using the trained model to classify the documents in the document set, and matching the documents classified with the same category as the check item as the target document.

[0058] Then calculate the similarity of each target document and the check item, when the similarity of each target document and the check item is greater than 80%, the target document is taken as the reference document of the check item, when calculating the similarity, the embodiment adopts the method of cosine similarity to calculate the similarity of the keywords of the target document and the check item, when the similarity is greater than 80%, the document is taken as the reference document of the check item.

[0059] In one embodiment, the method for obtaining the keywords of the target document includes:

[0060] By calculating the frequency of each word appearing in the target document, select the word with higher frequency as the keyword;

[0061] Or, the sentences or paragraphs in the target document are clustered and analyzed, the sentences or paragraphs in the same class are merged, and then the representative words in each class are selected as the keywords.

[0062] Or, by calculating the TF (term frequency) and IDF (inverse document frequency) value of each word, the importance and rarity of each word in the article are considered comprehensively, and the word with higher score is selected as the keyword.

[0063] Or, use natural language processing technology to process the article, such as word segmentation, part-of-speech tagging, named entity recognition, etc., extract important entities, concepts and relationships, etc. Information, and then select representative words from these information as keywords.

[0064] After obtaining the reference documents of all check items in the check table, all reference documents are taken as the supporting documents of the check table, and the reference documents of all check items in the check table are completed, which can quickly and accurately match the supporting documents in the check table, improve the efficiency of the check, and reduce the cost.

[0065] As shown in Figure 2 The embodiment provides a screening device for network security compliance system document, which comprises:

[0066] The judgment module is used for judging whether each check item in the check table has been historically checked or not.

[0067] The legal regulation acquisition module is used for acquiring the legal regulations of the check items which have not been historically checked in the judgment module.

[0068] a similarity calculation module, configured to obtain a first document set containing all target legal regulations in a document database, obtain target documents in the first document set, and calculate similarity between each target document and an inspection item;

[0069] a referenced document determination module, configured to determine the documents referenced by the inspection item with historical inspection obtained in the judgment module as the referenced documents of the inspection item;

[0070] obtain the referenced documents of each inspection item by using the similarity between each target document and the inspection item.

[0071] Figure 3 A structural schematic diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application is shown.

[0072] It should be noted that the computer system 400 of the electronic device shown in the figure is only an example and should not bring any limitation to the functions and use range of the embodiments of the present application.

[0073] The computer system 400 includes a central processing unit (CPU) 401, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 402 or programs loaded from a storage portion 408 to a random access memory (RAM) 403, such as the network security compliance regulation document screening method used in the above embodiments. In the RAM 403, various programs and data required for system operation are also stored. The CPU 401, the ROM 402, and the RAM 403 are connected to each other through a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.

[0074] The following components are connected to the I / O interface 405: an input part 406 including a keyboard, a mouse, etc.; an output part 407 including a display such as a Cathode Ray Tube (CRT), a Liquid Crystal Display (LCD), etc., and a speaker, etc.; a storage part 408 including a hard disk, etc.; and a communication part 409 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication part 409 performs communication processing via a network such as the Internet. A drive 410 is also connected to the I / O interface 405 as necessary. A removable medium 411 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is attached to the drive 410 as necessary, so that a computer program read out therefrom is installed in the storage part 408 as necessary.

[0075] In particular, according to embodiments of the present application, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, embodiments of the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing a computer program for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via the communication part 409, and / or installed from the removable medium 411. When the computer program is executed by the central processing unit (CPU) 401, various functions defined in the system of the present application are executed.

[0076] It should be noted that the computer readable medium shown in the embodiments of the present application is used to implement the method for screening the network security compliance system document; the computer readable medium can be a computer readable signal medium or a computer readable storage medium or any combination of the two, and the computer readable storage medium can be, for example, but is not limited to, an electric, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination of the above. More specific examples of the computer readable storage medium can include, but are not limited to, an electric connection with one or more conductive wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (Compact Disc Read-Only Memory, CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer readable storage medium can be any tangible medium containing or storing a program that can be used or combined with an instruction execution system, device or apparatus. In the present application, the computer readable signal medium can include a data signal propagating in a baseband or as part of a carrier wave, which carries a computer readable computer program. Such a propagating data signal can take various forms, including but not limited to electromagnetic signals, optical signals or any suitable combination of the above. The computer readable signal medium can also be any computer readable medium other than the computer readable storage medium, which can send, propagate or transmit a program for use by or in combination with an instruction execution system, device or apparatus. The computer program contained in the computer readable medium can be transmitted by any suitable medium, including but not limited to wireless, wired, etc., or any suitable combination of the above.

[0077] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process, such that the instructions which execute on the computer, other programmable data processing apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0078] The units described in the embodiments of the present application can be implemented by software, or by hardware, or by a combination of software and hardware. The units described can be located in a single processor, or can be distributed over a plurality of processors.

[0079] According to an aspect of the present application, a computer program product or computer program is provided, which includes computer instructions. A processor of a computer device reads the computer instructions from a computer readable storage medium, and executes the computer instructions, so that the computer device performs the method provided in the various optional implementation manners.

[0080] As another aspect, the present application also provides a computer readable medium, which can be included in the electronic device described in the above embodiments, or can exist separately without being assembled into the electronic device. The computer readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to implement the method described in the above embodiments.

[0081] It should be noted that although several modules or units for performing actions are mentioned in the above detailed description, the division into such modules or units is not mandatory. In fact, according to the embodiments of the present application, features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, features and functions of one module or unit described above can be further split into a plurality of modules or units.

[0082] Through the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, touch terminal, or network device, etc.) to execute the method according to the embodiments of this application.

[0083] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the embodiments disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein.

[0084] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A method for screening of network security compliance regime documents, characterized in that, The method comprises the following steps: acquiring all the check items in the check list, judging whether each check item has been historically checked, and taking the reference documents of the historical check as the reference documents of the check item when the check item has been historically checked; when the check item has not been historically checked, acquiring the target legal regulations involved in the check item; acquiring a first document set containing all the target legal regulations in the document database, acquiring the target documents in the first document set, calculating the similarity between each target document and the check item, and obtaining the reference documents of each check item by using the similarity between each target document and the check item; completing the reference documents in all the check items in the check list; wherein the method for acquiring the target documents in the first document set comprises classifying the documents in the first document set and matching the documents of the same category as the check item as the target documents; the method for classifying the documents in the first document set comprises: determining a corpus: a large number of check items and their types are first labeled to construct a corpus for training and testing the semantic analysis algorithm; data preprocessing: the text data in the corpus is preprocessed, including word segmentation, stop word removal, and special symbol removal; feature extraction: features are extracted from the preprocessed text data using a bag-of-words model or a TF-IDF method; training a model: a classification model is trained using the extracted features and labeled data, which is one of a support vector machine (SVM), a naive Bayes classifier, or a deep learning model; model evaluation: the performance of the model is evaluated using a test data set; the trained model is used to classify the documents in a document set, and the classified documents of the same category as the check item are matched as the target documents.

2. The method for screening of network security compliance regime documents as claimed in claim 1 wherein, The method for calculating the similarity between each target document and the check item comprises: acquiring the keywords in each target document; and obtaining the similarity between each target document and the check item by using each check item and the keywords.

3. The method for screening of network security compliance regime documents as claimed in claim 2 wherein, The method for acquiring the keywords in the target document comprises: calculating the frequency of each word in the target document, and taking the words with high frequency as the keywords of the target document; or, clustering the sentences or paragraphs in the target document, merging the sentences or paragraphs of the same category after clustering, and screening the representative words in the merged category as the keywords.

4. The method for screening of network security compliance regime documents as claimed in claim 1 wherein, When the similarity between each target document and the check item is greater than 80%, the target document is taken as the reference document of the check item.

5. A screening device for network security compliance program documents, characterized by, The method comprises the following steps: a judgment module for judging whether each check item in the check list has been historically checked; a legal regulation acquisition module for acquiring the legal regulations in the check items that have not been historically checked by the judgment module; a similarity calculation module for acquiring a first document set containing all the target legal regulations in the document database, acquiring the target documents in the first document set, and calculating the similarity between each target document and the check item; a reference document determination module for taking the reference documents of the check items with historical checks obtained by the judgment module as the reference documents of the check items; the reference documents of each check item obtained by using the similarity between each target document and the check item; and The method for obtaining the target document in the first document set comprises classifying the documents in the first document set, and matching the classified documents to obtain the documents of the same category as the inspection item as the target document. The method for classifying the documents in the first document set comprises: Determine the corpus: first, a large number of inspection items and the types to which they belong are labeled to construct a corpus for training and testing the semantic analysis algorithm; Data preprocessing: the text data in the corpus is preprocessed, including word segmentation, stop word removal and special symbol removal; Feature extraction: features are extracted from the preprocessed text data, and a bag-of-words model or a TF-IDF method is used to extract text features; Train the model: use the extracted features and label data to train a classification model, which is one of support vector machine (SVM), naive Bayes classifier or deep learning model; Model evaluation: use the test data set to evaluate the performance of the model; Classify the documents in a document set using the trained model, and match the classified documents to obtain the documents of the same category as the inspection item as the target document.

6. An electronic device, comprising: It comprises: One or more processors; Storage device for storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the screening method for network security compliance system document according to any one of claims 1 to 4.

7. A computer readable medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to implement the screening method for network security compliance system document according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Legal provision citation information extraction system

    CN112069307A