An enterprise supplier information security management method and system

By designing enterprise supplier information security management methods and systems, using API interfaces to collect data in real time and constructing scoring algorithms, it solves the problem that enterprises find it difficult for them to continuously evaluate supplier security capabilities, real-time monitoring and dynamic evaluation of supplier information security, and improves the management efficiency and overall security of supply chain information security.

CN119670129BActive Publication Date: 2025-05-27SHENZHEN JIANAN RUNXING SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510174272.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-27
Estimated Expiration
2045-02-18

AI Technical Summary

Technical Problem

Enterprises lack effective tools to continuously evaluate and monitor suppliers' security capabilities, resulting in the static assessment model being unable to detect potential security risks in a timely manner, increasing the threat to enterprise information security.

Method used

A method and system for information security management of enterprise suppliers is designed, including supplier information collection module, preliminary security analysis module, compliance and data protection analysis module, comprehensive analysis module and problem tracking and rectification suggestions module. Provider data is collected in real time through the API interface, scoring algorithms are constructed, comprehensive security scores are generated, and points deduction plan is implemented.

Benefits of technology

Real-time monitoring and dynamic assessment of supplier information security is realized, helping enterprises to identify and respond to security risks in a timely manner, and improving the management efficiency and overall security of supply chain information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119670129B_ABST
    Figure CN119670129B_ABST
Patent Text Reader

Abstract

The present invention discloses an enterprise supplier information security management method and system, which relates to the technical field of information security management. The system realizes automatic integration with the supplier system through the supplier information collection module, collects key data and logs in real time, and stores them in the database to ensure the timeliness and accuracy of the data, providing a basis for subsequent security analysis. The preliminary security analysis module and the compliance and data protection analysis module use the collected data, generate security scores through relevant security algorithms, and calculate the comprehensive security score Stot of the supplier through the comprehensive analysis module. After comparing and evaluating with the security threshold S, the security shortboards are identified and improvement suggestions are generated. Through the problem tracking and rectification suggestion module, the system monitors the improvement situation of the supplier in real time, outputs the improvement effectiveness score Eimp and the security capability improvement score, and automatically executes point deduction or further rectification prompts.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security management, and specifically provides an enterprise supplier information security management method and system. Background Art

[0002] Enterprise supplier information security management systems belong to the field of information security management, which aims to ensure the confidentiality, integrity, and availability of internal and external information of enterprises, especially in transactions and data processing related to the supply chain. As supply chain management plays an increasingly important role in global enterprise operations, the importance of information security in the supply chain has become increasingly prominent. In this specific field, suppliers share access rights to sensitive data or critical systems with enterprises, which makes the security of suppliers directly affect the overall security guarantee of enterprises. Therefore, the information security management of suppliers has become an important part of enterprise risk management.

[0003] A significant problem faced by enterprises at the present stage is the lack of effective tools to continuously evaluate and monitor the security capabilities of suppliers. Traditional supplier security assessments mostly stay at the preliminary review and static inspection before contract signing, lacking the monitoring of the dynamic performance of suppliers. With the increasing complexity of the supply chain and the growing dependence on suppliers, enterprises often lack real-time means to track the compliance, security incident response, data protection measures, etc. of suppliers. This static assessment mode not only makes it difficult for enterprises to discover potential security risks in a timely manner but also, due to ignoring the dynamics of supplier security management, leads to the accumulation of serious security hazards, further threatening the information security of enterprises. Summary of the Invention

[0004] Aiming at the deficiencies of the prior art, the present invention provides an enterprise supplier information security management method and system, which solves the problems mentioned in the background art.

[0005] To achieve the above objectives, the present invention is realized through the following technical solutions: including a supplier information collection module, a preliminary security analysis module, a compliance and data protection analysis module, a comprehensive analysis module, and a problem tracking and rectification suggestion module;

[0006] The supplier information collection module is used to set up API application program interfaces to integrate with the supplier side and supplier system logs, collect supplier information data and log data in real time, and build a database to store the collected supplier information data and log data in the database;

[0007] The preliminary security analysis module is used to build a response ability algorithm formula and a log management ability algorithm formula, extract the supplier information data and log data in the database, input them into the response ability algorithm formula and the log management ability algorithm formula, and output a response ability score Sres and a log management ability score Slog;

[0008] The compliance and data protection analysis module is used to construct the compliance deviation rate algorithm formula and the data processing security algorithm formula, and then extract the supplier information data and log data in the database, and input them into the compliance deviation rate algorithm formula and the data processing security algorithm formula for calculation to output the compliance score Scom and the data processing security score Sadt;

[0009] The comprehensive analysis module is used to comprehensively calculate the obtained response ability score Sres, log management ability score Slog, compliance score Scom and data processing security score Sadt, output the supplier comprehensive security score Stot, and preliminarily compare and evaluate the preset security threshold S with the obtained supplier comprehensive security score Stot, and generate evaluation results and improvement suggestions;

[0010] The problem tracking and rectification suggestion module is used to construct the improvement effectiveness algorithm formula, output the improvement effectiveness score Eimp, set a secondary evaluation, combine the improvement effectiveness score Eimp and the supplier comprehensive security score Stot, calculate and output the security ability improvement score Sfin, and conduct a secondary evaluation with the security threshold S, and execute the deduction plan according to the evaluation results.

[0011] Preferably, the supplier information collection module includes a data collection unit and a data storage unit;

[0012] The data collection unit integrates with the supplier side and the supplier system log through the API application program interface provided by the supplier to collect the supplier information data and log data in real time;

[0013] The supplier information data includes the data processing security index DPP, the dependency index VDR of the upstream supplier, the compliance deviation rate CDP, the data encryption ability index Eenc, the data storage security ability index Esto and the external data risk coefficient Rext;

[0014] The log data includes the response time TTR of security events, the supplier log retention time SLR, the event recurrence probability IRP and the permission management ability index Eacc;

[0015] The data processing security index DPP is obtained by integrating an automated scanning tool to perform a security detection on the supplier system and verify the effectiveness of its security measures;

[0016] The dependency index VDR of the upstream supplier is collected after obtaining the dependency analysis of the supplier through a third-party supply chain risk management tool;

[0017] The compliance deviation rate CDP is collected by integrating a third-party compliance tool to automatically check the compliance of the supplier and calculate the deviation rate;

[0018] The data encryption capability metric Eenc obtains detailed information about encryption logs or encryption algorithms through the supplier's security management tool;

[0019] The data storage security capability metric Esto reads the supplier's data storage system logs to check whether data backup and redundancy mechanisms are adopted and whether the stored data is encrypted;

[0020] The external data risk factor Rext connects to the supplier's external data interface through the API to detect the security of its transmission and potential threats of external connections;

[0021] The response time of security incidents TTR is obtained through statistical analysis by the supplier based on its internal data to provide the average response time, especially the statistical data in a specific past period;

[0022] The supplier log retention time SLR is obtained by connecting to the API of the supplier log management system, and the system can automatically obtain the relevant configuration of the log retention time;

[0023] The incident recurrence probability IRP is obtained by automatically reading the supplier's historical event records in the supplier system and calculating the frequency of occurrence of similar events;

[0024] The privilege management capability metric Eacc deeply scans and verifies through the supplier's network access logs and privilege management policies to ensure that the user's privileges are correct and comply with the security policies;

[0025] The data storage unit is used to build a NoSQL database, and write ports and read ports are set. The collected supplier information data and log data are written into the storage tables in the database through the write ports. The storage tables include the supplier information table and the log retention table. The supplier information table is used to store supplier information data, and the log retention table is used to store log data. Then, the supplier information data and log data are extracted in real time through the read ports.

[0026] Preferably, the preliminary security analysis module includes a security incident response capability analysis unit and a log management capability analysis unit;

[0027] The security incident response capability analysis unit is used to build a response capability algorithm formula, and then extracts the response time TTR of security incidents in the log data through the read port of the database and inputs it into the response capability algorithm formula for calculation to output the response capability score Sres;

[0028] The response capability score Sres is obtained through the following response capability algorithm formula; ;

[0029] In the formula, represents an adjustment factor used to represent the impact of response time differences, Tideal represents the ideal response time required by the enterprise, and the specific value is set by the user. e represents the exponential function.

[0030] Preferably, the log management ability analysis unit is used to construct a log management ability algorithm formula, and then extracts the supplier log retention time SLR and the upstream supplier dependency index VDR from the supplier information data and log data through the write port of the database, and inputs them into the log management ability algorithm formula for calculation to output the log management ability score Slog.

[0031] The log management ability score Slog is calculated and obtained through the following log management ability algorithm formula; ;

[0032] In the formula, log represents the logarithmic function, represents the weight value of the upstream supplier dependency index, and its specific value is set by the user.

[0033] Preferably, the compliance and data protection analysis module includes a compliance deviation rate analysis unit and a data processing security analysis unit;

[0034] The compliance deviation rate analysis unit is used to construct a compliance deviation rate algorithm formula, and then extracts the compliance deviation rate CDP from the supplier information data through the write port of the database, and inputs it into the compliance deviation rate algorithm formula for calculation to output the compliance score Scom.

[0035] The compliance score Scom is calculated and obtained through the following compliance deviation rate algorithm formula; ;

[0036] In the formula, n represents the total number of compliance standards, wi represents the weight value of the i-th standard, and CDPi represents the compliance deviation rate CDP of the i-th standard.

[0037] Preferably, the data processing security analysis unit is used to construct a data processing security algorithm formula, extracts the supplier information data and log data through the write port of the database and inputs them into the data processing security algorithm formula for calculation to output the data processing security score Sadt.

[0038] The data processing security score Sadt is calculated and obtained through the following data processing security algorithm formula; ;

[0039] In the formula, a1, a2, and a3 respectively represent the weight values of the data encryption ability index Eenc, the permission management ability index Eacc, and the data storage security ability index Esto, and their specific values are set by the user to adjust the importance of each data processing link in the overall security. represents an adjustment parameter used to control the change rate of the data processing security algorithm formula. represents the external data risk coefficient, which reflects the data processing security risk when the supplier interacts with external systems. The larger the value, the higher the risk.

[0040] Preferably, the comprehensive analysis module includes a comprehensive analysis unit and a comprehensive evaluation unit.

[0041] The comprehensive analysis unit is used to comprehensively calculate the obtained response ability score Sres, log management ability score Slog, compliance score Scom, and data processing security score Sadt, and output the comprehensive security score Stot of the supplier through comprehensive calculation.

[0042] The comprehensive security score Stot of the supplier is calculated and obtained through the following algorithm formula. ;

[0043] In the formula, represents the supply chain dependence risk score, b1, b2, b3, and b4 respectively represent the preset weight values of the response ability score Sres, log management ability score Slog, compliance score Scom, and data processing security score Sadt, b5 represents the weight value of the supply chain dependence risk score, and its specific value is set by the user, and b1 + b2 + b3 + b4 + b5 = 1.

[0044] The comprehensive evaluation unit sets a security threshold S based on the ISO27001 standard in the field of enterprise information security, and then makes a preliminary comparison and evaluation with the obtained comprehensive security score Stot of the supplier, analyzes the result of the comprehensive security score of the supplier in the supplier information security management system, and generates an improvement prompt based on the evaluation result. The specific evaluation content is as follows.

[0045] When the comprehensive security score Stot of the supplier ≥ the security threshold S, it indicates that the comprehensive security ability of the supplier meets the security standards set by the enterprise. At this time, continue to perform real-time security monitoring.

[0046] When the comprehensive security score Stot of the supplier < the security threshold S, it indicates that the comprehensive security ability of the supplier does not meet the security standards set by the enterprise. At this time, a rectification prompt is generated to prompt the supplier to rectify according to the security management process.

[0047] Preferably, the problem tracking and rectification suggestion module includes an improvement effect analysis unit and a final analysis unit.

[0048] The improvement effect analysis unit is triggered when it is initially evaluated that the comprehensive security ability of the supplier does not meet the security standards set by the enterprise. By constructing an improvement effectiveness algorithm formula, it calculates and outputs the improvement effectiveness score Eimp.

[0049] The improved effectiveness score Eimp is obtained by calculating through the following improved effectiveness algorithm formula; ;;

[0050] In the formula, S total-new represents the latest comprehensive security score of the supplier, and S total-old represents the previous comprehensive security score of the supplier, and time improvement represents the rectification time.

[0051] Preferably, the final analysis unit includes a supplier final score analysis unit and a secondary evaluation unit;

[0052] The final score analysis unit is used to monitor the information security changes of the supplier in real time, construct the supplier final score formula, and calculate and output the security capability improvement score Sfin for the supplier's information security every 24 hours in combination with the improved effectiveness score Eimp; ;

[0053] In the formula, represents the preset weight value of the improvement effect, represents the deduction coefficient of the newly discovered security risk, and new-risks represents the score of the newly discovered security risk, which is detected by the system through the security assessment of the supplier, especially through automated tools or the audit process;

[0054] The secondary evaluation unit is used to conduct a secondary evaluation based on the obtained security capability improvement score Sfin and the security threshold S, analyze the security capability and rectification performance of the improved supplier, and generate a corresponding deduction mechanism. The specific evaluation content is as follows;

[0055] When the security capability improvement score Sfin ≥ the security threshold S, it indicates that the security capability and rectification performance of the supplier are normal. At this time, the cooperation is continued, and monitoring and re-evaluation are carried out every 24 hours;

[0056] When the security capability improvement score Sfin < the security threshold S, it indicates that the security capability and rectification performance of the supplier are abnormal. At this time, a deduction mechanism is generated and rectification is prompted again;

[0057] The deduction mechanism is as follows:

[0058] When the security capability improvement score Sfin < 10% of the security threshold S, 2 points are deducted at this time;

[0059] When the security capability improvement score Sfin < 30% of the security threshold S, 5 points are deducted at this time;

[0060] When the security capability improvement score Sfin < 80% of the security threshold S, 15 points are deducted at this time;

[0061] When the safety capability improvement score Sfin < 100% of the safety threshold S, the remaining score is deducted at this time, and the cooperation with the supplier is automatically terminated;

[0062] The initial score of the supplier is set to 20 points. When the score is deducted to zero, the cooperation with the supplier is automatically terminated.

[0063] An enterprise supplier information security management method includes the following steps:

[0064] S1. Set up an API application interface to integrate with the supplier side and the supplier system logs, collect supplier information data and log data in real time, and build a database to store the collected supplier information data and log data in the database;

[0065] S2. By constructing a response capability algorithm formula and a log management capability algorithm formula, and extracting the supplier information data and log data in the database, input them into the response capability algorithm formula and the log management capability algorithm formula, and output the response capability score Sres and the log management capability score Slog;

[0066] S3. By constructing a compliance deviation rate algorithm formula and a data processing security algorithm formula, then extracting the supplier information data and log data in the database, input them into the compliance deviation rate algorithm formula and the data processing security algorithm formula for calculation, and output the compliance score Scom and the data processing security score Sadt;

[0067] S4. Perform a comprehensive calculation on the obtained response capability score Sres, log management capability score Slog, compliance score Scom, and data processing security score Sadt, output the supplier comprehensive security score Stot, and preliminarily compare and evaluate the preset safety threshold S with the obtained supplier comprehensive security score Stot, and generate an evaluation result and improvement suggestions;

[0068] S5. Construct an improvement effectiveness algorithm formula to output the improvement effectiveness score Eimp, and set a secondary evaluation. Combine the improvement effectiveness score Eimp and the supplier comprehensive security score Stot, perform a calculation to output the safety capability improvement score Sfin, and perform a secondary evaluation with the safety threshold S. Execute a deduction mechanism based on the evaluation result.

[0069] The present invention provides an enterprise supplier information security management method and system. It has the following beneficial effects:

[0070] (1) The system integrates with the logs of the supplier system by setting up API interfaces, enabling real-time collection of supplier information data and log data, and storing these data in a database. This integration method greatly improves the automation level of supplier data collection and solves the drawbacks of traditional data collection methods that rely on manual labor and have strong lag. Enterprises can accurately understand the security performance of suppliers through key data collected automatically (such as data processing security index DPP, upstream supplier dependence index VDR, security incident response time TTR, log retention time SLR, etc.), reducing the risk of information distortion or omission. This real-time data collection and storage mechanism ensures that enterprises can monitor the security status of suppliers at any time, enhancing the overall control ability of supply chain information security.

[0071] (2) Through a series of algorithm formulas, the system can comprehensively analyze the security performance of suppliers. Based on the supplier's response ability score Sres, log management ability score Slog, compliance score Scom, and data processing security score Sadt, the system can conduct a comprehensive evaluation and generate the supplier's comprehensive security score Stot. By setting a security threshold S, the system can automatically compare the security scores of suppliers, detect whether there are security hazards, and give corresponding improvement suggestions. This mechanism can not only help enterprises conduct a comprehensive and accurate security assessment of suppliers but also ensure that suppliers continuously meet the security standards set by enterprises, enhancing the overall security of the supply chain.

[0072] (3) By constructing an improved effectiveness algorithm formula, the system can conduct continuous secondary evaluation based on the supplier's comprehensive security score and improvement effect score. When the security ability of the supplier is initially evaluated as insufficient, the system will automatically generate rectification suggestions and quantitatively evaluate the effectiveness of rectification Eimp. The system calculates the rectification time of the supplier and the improvement of security ability, generates a security ability improvement score SfinS, and conducts a secondary comparison and evaluation with the security threshold S. If the rectification effect of the supplier is not good, the system will automatically execute a deduction mechanism, and finally decide whether to continue to cooperate with the supplier based on the scoring results. Through this automated problem tracking and improvement evaluation, enterprises can effectively track the progress of suppliers' rectification, significantly improve the rectification efficiency of suppliers, and reduce the long-term security risks of enterprises to suppliers. Description of the Drawings

[0073] Figure 1 It is a schematic diagram of the process of an enterprise supplier information security management system of the present invention;

[0074] Figure 2 It is a schematic diagram of the steps of an enterprise supplier information security management method of the present invention. Detailed Embodiments

[0075] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0076] Embodiment 1

[0077] Please refer to Figure 1 , the present invention provides an enterprise supplier information security management system. To achieve the above objectives, the present invention is realized through the following technical solutions: including a supplier information collection module, a preliminary security analysis module, a compliance and data protection analysis module, a comprehensive analysis module, and a problem tracking and rectification suggestion module;

[0078] The supplier information collection module is used to set up API application program interfaces to integrate with the supplier side and the supplier system logs, collect supplier information data and log data in real time, and build a database to store the collected supplier information data and log data in the database;

[0079] The preliminary security analysis module is used to build a response ability algorithm formula and a log management ability algorithm formula, extract the supplier information data and log data in the database, input them into the response ability algorithm formula and the log management ability algorithm formula, and output a response ability score Sres and a log management ability score Slog;

[0080] The compliance and data protection analysis module is used to build a compliance deviation rate algorithm formula and a data processing security algorithm formula, then extract the supplier information data and log data in the database, input them into the compliance deviation rate algorithm formula and the data processing security algorithm formula for calculation, and output a compliance score Scom and a data processing security score Sadt;

[0081] The comprehensive analysis module is used to comprehensively calculate the obtained response ability score Sres, log management ability score Slog, compliance score Scom, and data processing security score Sadt, output a supplier comprehensive security score Stot, preset a security threshold S, and conduct a preliminary comparison and evaluation with the obtained supplier comprehensive security score Stot, and generate an evaluation result and improvement suggestions;

[0082] The problem tracking and rectification suggestion module is used to build an improvement effectiveness algorithm formula, output an improvement effectiveness score Eimp, set a secondary evaluation, combine the improvement effectiveness score Eimp and the supplier comprehensive security score Stot, calculate and output a security ability improvement score Sfin, conduct a secondary evaluation with the security threshold S, and execute a deduction plan according to the evaluation result.

[0083] In this embodiment, through the supplier information collection module, the system can be automatically integrated with the supplier side and the supplier system log, collect the key data and log data of the supplier in real time, and store them in the database. This real-time data collection method effectively solves the problems of data lag and incomplete information in traditional supplier management methods. Enterprises can obtain the latest information of suppliers without relying on manual processes. This improvement not only improves the efficiency of information collection, but also ensures the timeliness and accuracy of data, thus providing a reliable data basis for subsequent security analysis and evaluation. The preliminary security analysis module and the compliance and data protection analysis module use the information data and log data of the supplier, and output a series of security scores respectively through response capabilities, log management, compliance deviation rate and data processing security algorithms. These scores are comprehensively calculated by the comprehensive analysis module to generate the comprehensive security score Stot of the supplier, and compared and evaluated with the preset security threshold S. Compared with the current single-dimensional security assessment method, the system can comprehensively analyze and evaluate the security status of the supplier, accurately identify the security weaknesses of the supplier and generate improvement suggestions to ensure that the supplier continuously meets the standards in multiple key security dimensions. Through the problem tracking and rectification suggestion module, the system can effectively track and improve the security deficiencies of the supplier. This module constructs an improvement effectiveness algorithm formula, monitors the security improvement of the supplier in real time, outputs the improvement effectiveness score Eimp, and calculates the security capability improvement score Sfin in the secondary evaluation. This evaluation result can be used to judge whether the improvement of the supplier meets the expectations, and implement the corresponding deduction plan or further rectification prompts. Compared with the traditional manual monitoring and manual evaluation methods, the automated tracking and evaluation mechanism greatly improves the rectification efficiency of the supplier, ensuring the continuity and effectiveness of the supplier security management in the supply chain.

[0084] Embodiment 2

[0085] This embodiment is an explanatory description based on Embodiment 1. Please refer to Figure 1 , specifically: The supplier information collection module includes a data collection unit and a data storage unit;

[0086] The data collection unit is integrated with the supplier side and the supplier system log by using the API application program interface provided by the supplier, and collects the supplier information data and log data in real time;

[0087] The supplier information data includes data processing security index DPP, upstream supplier dependence index VDR, compliance deviation rate CDP, data encryption ability index Eenc, data storage security ability index Esto and external data risk coefficient Rext;

[0088] The log data includes the Time to Respond (TTR) for security incidents, the Supplier Log Retention (SLR) time, the Incident Recurrence Probability (IRP), and the Entitlement Management Capability (Eacc) metric;

[0089] The Data Processing Security (DPP) metric is obtained by integrating an automated scanning tool to perform security detection on the supplier's system and verifying the effectiveness of its security measures;

[0090] The Vendor Dependency Ratio (VDR) of upstream suppliers is collected after obtaining the dependency analysis of suppliers through a third-party supply chain risk management tool;

[0091] The Compliance Deviation Percentage (CDP) is collected by integrating a third-party compliance tool to automatically check the compliance of suppliers and calculating the deviation percentage;

[0092] The Encryption Capability (Eenc) metric obtains detailed information about encryption logs or encryption algorithms through the supplier's security management tool;

[0093] The Data Storage Security (Esto) metric reads the logs of the supplier's data storage system to check whether it has adopted data backup and redundancy mechanisms and whether the stored data is encrypted;

[0094] The External Data Risk Factor (Rext) connects to the external data interface of the supplier through an API to detect the security of its transmission and potential threats of external connections;

[0095] The Time to Respond (TTR) for security incidents is obtained through statistical analysis by the supplier providing the average response time based on its internal data, especially the statistical data within a specific past time period;

[0096] The Supplier Log Retention (SLR) time is obtained by connecting to the API of the supplier's log management system, and the system can automatically obtain the relevant configuration of the log retention time;

[0097] The Incident Recurrence Probability (IRP) is obtained by automatically reading the supplier's historical event records in the supplier's system and calculating the frequency of similar events;

[0098] The Entitlement Management Capability (Eacc) metric conducts in-depth scanning and verification through the supplier's network access logs and entitlement management policies to ensure that users' entitlements are correct and compliant with security policies;

[0099] The data storage unit is used to build a NoSQL database and set write ports and read ports. Through the write ports, the collected supplier information data and log data are written into the storage tables in the database. The storage tables include the supplier information table and the log retention table. The supplier information table is used to store supplier information data, and the log retention table is used to store log data. Then, the supplier information data and log data are extracted in real-time through the read ports.

[0100] In this embodiment, through the data collection unit and data storage unit in the supplier information collection module, the system can be integrated with the supplier system through the API interface provided by the supplier to achieve real-time collection and storage of supplier information data and log data. By collecting key information including data processing security metrics DPP, upstream supplier dependency metrics VDR, compliance deviation rate CDP, data encryption ability Eenc, data storage security ability Esto, and external data risk factor Rext, etc., this module comprehensively covers multiple core dimensions of supplier security. At the same time, the system can automatically obtain the supplier's security incident response time TTR, log retention time SLR, incident recurrence probability IRP, and permission management ability Eacc, thereby providing accurate data support for the security assessment of the supplier. By constructing a NoSQL database to store and manage these data, the system realizes efficient data storage and fast calling, ensuring real-time performance and data integrity. Compared with the traditional manual data collection and analysis method, this system significantly improves the automation and accuracy of information collection, and solves the problems of data lag and incompleteness.

[0101] Embodiment 3

[0102] This embodiment is an explanatory description based on Embodiment 2. Please refer to Figure 1 , specifically: The preliminary security analysis module includes a security incident response ability analysis unit and a log management ability analysis unit;

[0103] The security incident response ability analysis unit is used to construct a response ability algorithm formula, and then extract the response time TTR of security incidents in the log data through the write port of the database, and input it into the response ability algorithm formula for calculation to output the response ability score Sres;

[0104] The response ability score Sres is calculated and obtained through the following response ability algorithm formula; ;

[0105] In the formula, represents the adjustment factor, which is used to represent the impact of response time differences. Tideal represents the ideal response time required by the enterprise, and the specific value is set by the user. e represents the exponential function.

[0106] The log management ability analysis unit is used to construct a log management ability algorithm formula, and then extract the supplier log retention time SLR and the upstream supplier dependency metric VDR in the supplier information data and log data through the write port of the database, and input them into the log management ability algorithm formula for calculation to output the log management ability score Slog;

[0107] The log management ability score Slog is calculated through the following log management ability algorithm formula; ;

[0108] In the formula, log represents the logarithmic function, represents the weight value of the dependence index of the upstream supplier, and its specific value is set by the user.

[0109] In this embodiment, the method realizes the preliminary evaluation of the supplier's security performance by constructing the algorithm formulas for response ability and log management ability respectively. In the security incident response ability analysis unit, the system extracts the response time TTR in the log data and combines it with the ideal response time Tideal set by the enterprise to calculate the response ability score Sres of the supplier. This evaluation method enables the enterprise to quickly quantify the reaction speed of the supplier in security incidents and ensure that the supplier can respond in a timely manner when facing security threats. The log management ability analysis unit extracts the log retention time SLR and the upstream supplier dependence index VDR of the supplier, and uses the logarithmic function and weight adjustment to calculate the log management ability score Slog to evaluate the performance of the supplier in log management and dependence risk. Compared with the traditional method that relies on manual evaluation and static review, the system realizes the automated and quantitative security evaluation of suppliers through algorithm formulas, greatly improving the accuracy and efficiency of the evaluation.

[0110] Embodiment 4

[0111] This embodiment is an explanatory description based on Embodiment 2. Please refer to Figure 1 , specifically: The compliance and data protection analysis module includes a compliance deviation rate analysis unit and a data processing security analysis unit;

[0112] The compliance deviation rate analysis unit is used to construct a compliance deviation rate algorithm formula, and then extracts the compliance deviation rate CDP in the supplier information data through the write port of the database and inputs it into the compliance deviation rate algorithm formula for calculation to output the compliance score Scom;

[0113] The compliance score Scom is calculated through the following compliance deviation rate algorithm formula; ;

[0114] In the formula, n represents the total number of compliance standards, wi represents the weight value of the i-th standard, and CDPi represents the compliance deviation rate CDP of the i-th standard.

[0115] The data processing security analysis unit is used to construct a data processing security algorithm formula, extracts the supplier information data and log data through the write port of the database and inputs them into the data processing security algorithm formula for calculation to output the data processing security score Sadt;

[0116] The data processing security score Sadt is calculated through the following data processing security algorithm formula; ;

[0117] In the formula, a1, a2, and a3 respectively represent the weight values of the data encryption ability index Eenc, the permission management ability index Eacc, and the data storage security ability index Esto. Their specific values are set by the user to adjust the importance of each data processing link in the overall security. represents a regulation parameter used to control the change rate of the data processing security algorithm formula. represents the external data risk coefficient, which reflects the data processing security risk when the supplier interacts with external systems. The larger the value, the higher the risk.

[0118] In this embodiment, the system constructs a compliance deviation rate algorithm through the compliance deviation rate analysis unit, which can perform weighted analysis on multiple compliance standards through the supplier's compliance deviation rate CDP to calculate the compliance score Scom, thereby evaluating the deviation degree of the supplier from regulations and industry standards. The data processing security analysis unit then uses the supplier's data encryption ability Eenc, permission management ability Eacc, and data storage security ability Esto, combined with the external data risk coefficient, to calculate the data processing security score Sadt to evaluate the security of the supplier in key links such as data encryption, permission control, and data storage. This module automatically evaluates the supplier's compliance and data processing security through algorithms, not only improving the efficiency and accuracy of the evaluation, but also dynamically reflecting the supplier's performance in compliance and data security. This improvement enables enterprises to quickly identify the compliance defects and data security risks of suppliers, ensure that suppliers always maintain compliance in a changing legal and security environment, and improve the overall information security level of the supply chain.

[0119] Embodiment 5

[0120] This embodiment is an explanatory description based on Embodiment 3. Please refer to Figure 1 , specifically: The comprehensive analysis module includes a comprehensive analysis unit and a comprehensive evaluation unit;

[0121] The comprehensive analysis unit is used to comprehensively calculate the obtained response ability score Sres, log management ability score Slog, compliance score Scom, and data processing security score Sadt, and output the supplier comprehensive security score Stot through comprehensive calculation;

[0122] The supplier comprehensive security score Stot is calculated through the following algorithm formula; ;

[0123] Where, represents the supply chain dependence risk score, b1, b2, b3, and b4 respectively represent the preset weight values of the response ability score Sres, the log management ability score Slog, the compliance score Scom, and the data processing security score Sadt, b5 represents the weight value of the supply chain dependence risk score, and its specific value is set by the user, and b1 + b2 + b3 + b4 + b5 = 1;

[0124] The comprehensive evaluation unit sets the security threshold S based on the ISO27001 standard in the field of enterprise information security, and then makes a preliminary comparison and evaluation with the obtained comprehensive security score Stot of the supplier, analyzes the result of the comprehensive security score of the supplier in the supplier information security management system, and generates an improvement prompt according to the evaluation result. The specific evaluation content is as follows;

[0125] When the comprehensive security score Stot of the supplier ≥ the security threshold S, it means that the comprehensive security ability of the supplier meets the security standards set by the enterprise, and at this time, the real-time security monitoring continues;

[0126] When the comprehensive security score Stot of the supplier < the security threshold S, it means that the comprehensive security ability of the supplier does not meet the security standards set by the enterprise, and at this time, a rectification prompt is generated to prompt the supplier to rectify according to the security management process.

[0127] In this embodiment, the system combines the response ability score Sres, the log management ability score Slog, the compliance score Scom, and the data processing security score Sadt with the supply chain dependence risk score through the comprehensive analysis unit for weighted calculation to generate the comprehensive security score Stot of the supplier, so as to reflect the overall security status of the supplier. Then, the comprehensive evaluation unit compares the comprehensive security score Stot of the supplier with the preset security threshold S based on industry standards such as ISO27001, automatically judges whether the security ability of the supplier meets the requirements of the enterprise, and provides improvement suggestions. This module realizes the automation, quantification, and dynamicization of supplier security management, and significantly improves the accuracy and efficiency of evaluation.

[0128] Embodiment 6

[0129] This embodiment is an explanatory description carried out in Embodiment 5, please refer to Figure 1 , specifically: The problem tracking and rectification suggestion module includes an improvement effect analysis unit and a final analysis unit;

[0130] The improvement effect analysis unit is triggered when it is initially evaluated that the comprehensive security ability of the supplier does not meet the security standards set by the enterprise, and calculates and outputs the improvement effectiveness score Eimp by constructing an improvement effectiveness algorithm formula;

[0131] The improved effectiveness score Eimp is obtained by calculating through the following improved effectiveness algorithm formula; ;

[0132] In the formula, S total-new represents the latest comprehensive security score of the supplier, and S total-old represents the previous comprehensive security score of the supplier, and time improvement represents the rectification time.

[0133] The final analysis unit includes a supplier final score analysis unit and a secondary evaluation unit;

[0134] The final score analysis unit is used to monitor the information security changes of the supplier in real time, construct a supplier final score formula, and calculate and output the security capability improvement score Sfin for the supplier's information security every 24 hours in combination with the improved effectiveness score Eimp; ;

[0135] In the formula, represents the preset weight value of the improvement effect, represents the deduction coefficient of newly discovered security risks, and new-risks represents the score of newly discovered security risks, which are new problems detected by the system through the security assessment of the supplier, especially through automated tools or the audit process;

[0136] The secondary evaluation unit is used to conduct a secondary evaluation based on the obtained security capability improvement score Sfin and the security threshold S, analyze the security capability and rectification performance of the improved supplier, and generate a corresponding deduction mechanism. The specific evaluation content is as follows;

[0137] When the security capability improvement score Sfin ≥ the security threshold S, it means that the security capability and rectification performance of the supplier are normal. At this time, the cooperation is continued, and monitoring and re-evaluation are carried out every 24 hours;

[0138] When the security capability improvement score Sfin < the security threshold S, it means that the security capability and rectification performance of the supplier are abnormal. At this time, a deduction mechanism is generated and rectification is prompted again;

[0139] The deduction mechanism is as follows:

[0140] When the security capability improvement score Sfin < 10% of the security threshold S, 2 points are deducted at this time;

[0141] When the security capability improvement score Sfin < 30% of the security threshold S, 5 points are deducted at this time;

[0142] When the security capability improvement score Sfin < 80% of the security threshold S, 15 points are deducted at this time;

[0143] When the safety capability improvement score Sfin < 100% of the safety threshold S, the remaining score is deducted at this time, and the cooperation with the supplier is automatically terminated.

[0144] The initial score of the supplier is set to 20 points. When the score is fully deducted, the cooperation with the supplier is automatically terminated.

[0145] In this embodiment, the system uses the improvement effectiveness algorithm formula through the improvement effect analysis unit, and based on the latest comprehensive safety score S of the supplier before and after rectification total-new and the previous comprehensive safety score S of the supplier total-old , combined with the rectification time, calculates the improvement effectiveness score Eimp. This process helps the enterprise quantify the actual effect of the supplier's rectification and provides a specific improvement evaluation. The final analysis unit then monitors and evaluates the safety status of the supplier every 24 hours, combines the newly discovered safety risks, calculates the safety capability improvement score Sfin, and makes a secondary comparison with the safety threshold S. This module automatically triggers the score deduction mechanism to ensure that the supplier continuously improves and remains compliant with the enterprise's safety standards. This module realizes dynamic monitoring and automated feedback, improves the accuracy of problem tracking and rectification efficiency, and reduces manual intervention. Through the automated scoring and score deduction mechanism, the enterprise can quickly discover the potential risks of the supplier, take measures in a timely manner, and ensure the continuous optimization and efficient operation of the supply chain security management

[0146] Embodiment 7

[0147] Please refer to Figure 1 and Figure 2 , an enterprise supplier information security management method, including the following steps:

[0148] S1. Set up API application interfaces to integrate with the supplier side and the supplier system logs, collect supplier information data and log data in real time, and build a database to store the collected supplier information data and log data in the database;

[0149] S2. By constructing a response capability algorithm formula and a log management capability algorithm formula, and extracting the supplier information data and log data in the database, input them into the response capability algorithm formula and the log management capability algorithm formula, and output the response capability score Sres and the log management capability score Slog;

[0150] S3. By constructing a compliance deviation rate algorithm formula and a data processing security algorithm formula, then extracting the supplier information data and log data in the database, input them into the compliance deviation rate algorithm formula and the data processing security algorithm formula for calculation, and output the compliance score Scom and the data processing security score Sadt;

[0151] S4. Comprehensively calculate the obtained response ability score Sres, log management ability score Slog, compliance score Scom, and data processing security score Sadt, output the comprehensive security score Stot of the supplier, and preliminarily compare and evaluate the preset security threshold S with the obtained comprehensive security score Stot of the supplier, and generate an evaluation result and improvement suggestions;

[0152] S5. Construct an improvement effectiveness algorithm formula, output the improvement effectiveness score Eimp, set a secondary evaluation, combine the improvement effectiveness score Eimp and the comprehensive security score Stot of the supplier, calculate and output the security ability improvement score Sfin, and conduct a secondary evaluation with the security threshold S, and implement a deduction mechanism according to the evaluation result.

[0153] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. An enterprise supplier information security management system, characterized by: It includes supplier information collection module, preliminary security analysis module, compliance and data protection analysis module, comprehensive analysis module and problem tracking and rectification suggestion module; The supplier information collection module is used to set up an API application program interface to integrate with the supplier end and the supplier system log, collect supplier information data and log data in real time, and build a database to store the collected supplier information data and log data in the database; The supplier information data includes the data processing security index DPP, the upstream supplier dependency index VDR, the compliance deviation rate CDP, the data encryption capability index Eenc, the data storage security capability index Esto and the external data risk factor Rext; The log data includes the response time TTR of security incidents, the supplier log retention time SLR, the event recurrence probability IRP and the authority management capability index Eacc The preliminary security analysis module is used to construct a response capability algorithm formula and a log management capability algorithm formula, and extract supplier information data and log data from the database, input them into the response capability algorithm formula and the log management capability algorithm formula, and output a response capability score Sres and a log management capability score Slog; The compliance and data protection analysis module is used to construct a compliance deviation rate algorithm formula and a data processing security algorithm formula, and then extract supplier information data and log data from the database, input them into the compliance deviation rate algorithm formula and the data processing security algorithm formula to calculate and output the compliance score Scom and the data processing security score Sadt; The compliance and data protection analysis module includes a compliance deviation rate analysis unit and a data processing security analysis unit; The compliance deviation rate analysis unit is used to construct a compliance deviation rate algorithm formula, and then extract the compliance deviation rate CDP in the supplier information data through the write port of the database, input it into the compliance deviation rate algorithm formula, and calculate and output the compliance score Scom; The compliance score Scom is calculated and obtained by the following compliance deviation rate algorithm formula; In the formula, n represents the total number of compliance standards, wi represents the weight value of the i-th standard, and CDPi represents the compliance deviation rate CDP of the i-th standard; The data processing security analysis unit is used to construct a data processing security algorithm formula, extract supplier information data and log data through the write port of the database and input them into the data processing security algorithm formula to calculate and output a data processing security score Sadt; The data processing safety score Sadt is calculated and obtained by the following data processing safety algorithm formula; In the formula, a1, a2 and a3 represent the weight values ​​of the data encryption capability index Eenc, the authority management capability index Eacc and the data storage security capability index Esto respectively, and their specific values ​​are set by the user. γ represents the adjustment parameter used to control the change rate of the data processing security algorithm formula, ρ represents the external data risk coefficient, and e represents the exponential function. The comprehensive analysis module is used to comprehensively calculate the obtained response capability score Sres, log management capability score Slog, compliance score Scom and data processing security score Sadt, output the supplier comprehensive security score Stot, and perform preliminary comparative evaluation with the preset security threshold S and the obtained supplier comprehensive security score Stot, and generate evaluation results and improvement suggestions; The problem tracking and rectification suggestion module is used to construct an improvement effectiveness algorithm formula, output the improvement effectiveness score Eimp, and set a secondary evaluation. Combine the improvement effectiveness score Eimp and the supplier's comprehensive safety score Stot to calculate and output the safety capability improvement score Sfin, and perform a secondary evaluation with the safety threshold S, and execute the deduction plan based on the evaluation results.

2. The enterprise supplier information security management system according to claim 1, characterized in that: The supplier information acquisition module includes a data acquisition unit and a data storage unit; The data collection unit integrates with the supplier end and the supplier system log by using the API application program interface provided by the supplier to collect supplier information data and log data in real time; The data storage unit is used to build a NoSQL database, and set a write port and a write port. The collected supplier information data and log data are written into a storage table in the database through the write port. The storage table includes a supplier information table and a log retention table. The supplier information table is used to store supplier information data, and the log retention table is used to store log data. The supplier information data and log data are then extracted in real time through the write port.

3. The enterprise supplier information security management system according to claim 2 is characterized by: The preliminary security analysis module includes a security incident response capability analysis unit and a log management capability analysis unit; The security incident response capability analysis unit is used to construct a response capability algorithm formula, and then extract the response time TTR of the security incident in the log data through the write port of the database, input it into the response capability algorithm formula, and calculate and output the response capability score Sres; The responsiveness score Sres is calculated and obtained by the following responsiveness algorithm formula; Where α is the adjustment factor, which is used to represent the impact of response time differences, T ideal It represents the ideal response time required by the enterprise. The specific value is set by the user. e represents an exponential function.

4. The enterprise supplier information security management system according to claim 3 is characterized by: The log management capability analysis unit is used to construct a log management capability algorithm formula, and then extract the supplier log retention time SLR and the upstream supplier dependency index VDR in the supplier information data and log data through the write port of the database, input them into the log management capability algorithm formula, and calculate and output the log management capability score Slog; The log management capability score Slog is calculated by the following log management capability algorithm formula: In the formula, log represents the logarithmic function, β represents the weight value of the upstream supplier's dependency index, and its specific value is set by the user.

5. The enterprise supplier information security management system according to claim 1, characterized in that: The comprehensive analysis module includes a comprehensive analysis unit and a comprehensive evaluation unit; The comprehensive analysis unit is used to comprehensively calculate the acquired response capability score Sres, log management capability score Slog, compliance score Scom and data processing security score Sadt, and perform comprehensive calculation to output the supplier comprehensive security score Stot; The supplier comprehensive safety score Stot is calculated by the following algorithm formula; In the formula, represents the supply chain dependency risk score, b1, b2, b3 and b4 represent the preset weight values ​​of the response capability score Sres, the log management capability score Slog, the compliance score Scom and the data processing security score Sadt respectively, b5 represents the weight value of the supply chain dependency risk score, and its specific value is set by the user, and b1+b2+b3+b4+b5=1; The comprehensive evaluation unit performs a preliminary comparative evaluation with the obtained supplier comprehensive security score Stot through the set security threshold S, analyzes the results of the supplier comprehensive security score in the supplier information security management system, and generates improvement tips based on the evaluation results. The specific evaluation contents are as follows; When the supplier's comprehensive security score Stot ≥ security threshold S, it means that the supplier's comprehensive security capabilities meet the security standards set by the enterprise, and real-time security monitoring will continue; When the supplier's comprehensive safety score Stot is less than the safety threshold S, it means that the supplier's comprehensive safety capabilities do not meet the safety standards set by the enterprise. At this time, a rectification prompt is generated to prompt the supplier to make rectifications in accordance with the safety management process.

6. The enterprise supplier information security management system according to claim 1, characterized in that: The problem tracking and rectification suggestion module includes an improvement effect analysis unit and a final analysis unit; The improvement effect analysis unit is used to be triggered when the supplier's comprehensive security capability is preliminarily evaluated to be not in compliance with the security standards set by the enterprise, and to calculate and output the improvement effectiveness score Eimp by constructing an improvement effectiveness algorithm formula; The improved effectiveness score Eimp is calculated and obtained by the following improved effectiveness algorithm formula; In the formula, S total-new Indicates the supplier’s latest comprehensive security score, S total-old Indicates the supplier's last comprehensive security score, time improvement Indicates the rectification time.

7. The enterprise supplier information security management system according to claim 6, characterized in that: The final analysis unit includes a supplier final scoring analysis unit and a secondary evaluation unit; The final scoring analysis unit is used to monitor the supplier information security changes in real time, and to construct a final scoring formula for the supplier, and to calculate the supplier information security and output the security capability improvement score Sfin in combination with the improvement effectiveness score Eimp every 24 hours; Sfin=S toal-new +θ·Eimp-ε·new-risks; In the formula, θ represents the preset weight value of the improvement effect, ε represents the deduction coefficient of the newly discovered safety risk, and new-risks represents the score of the newly discovered safety risk; The secondary evaluation unit is used to perform a secondary evaluation based on the obtained security capability improvement score Sfin and the security threshold S, analyze the security capability and rectification performance of the improved supplier, and generate a corresponding deduction mechanism. The specific evaluation contents are as follows; When the security capability improvement score Sfin ≥ the security threshold S, it means that the supplier's security capability and rectification performance are normal. In this case, cooperation should continue and monitoring and re-evaluation should be carried out every 24 hours. When the safety capability improvement score Sfin is less than the safety threshold S, it means that the supplier's safety capability and rectification performance are abnormal. At this time, a deduction mechanism is generated and rectification is prompted again; The deduction mechanism is as follows: When the safety capability improvement score Sfin is less than 10% of the safety threshold S, 2 points will be deducted; When the safety capability improvement score Sfin is less than 30% of the safety threshold S, 5 points will be deducted; When the safety capability improvement score Sfin is less than 80% of the safety threshold S, 15 points will be deducted; When the safety capability improvement score Sfin is less than 100% of the safety threshold S, the remaining score will be deducted and the supplier cooperation will be automatically terminated; The initial score of the supplier is set at 20 points, and the supplier cooperation will be automatically terminated after the score is deducted.

8. An enterprise supplier information security management method, applied to the enterprise supplier information security management system according to any one of claims 1 to 7, characterized in that: The following steps are involved: S1. Set up an API application program interface to integrate with the supplier side and the supplier system log, collect supplier information data and log data in real time, and build a database to store the collected supplier information data and log data in the database; S2. By constructing a response capability algorithm formula and a log management capability algorithm formula, extracting supplier information data and log data from the database, inputting them into the response capability algorithm formula and the log management capability algorithm formula, and outputting a response capability score Sres and a log management capability score Slog; S3. By constructing a compliance deviation rate algorithm formula and a data processing security algorithm formula, extracting supplier information data and log data from the database, and inputting them into the compliance deviation rate algorithm formula and the data processing security algorithm formula to calculate and output the compliance score Scom and the data processing security score Sadt; S4. Comprehensively calculate the response capability score Sres, log management capability score Slog, compliance score Scom and data processing security score Sadt, output the supplier comprehensive security score Stot, and perform preliminary comparative evaluation with the preset security threshold S and the obtained supplier comprehensive security score Stot, and generate evaluation results and improvement suggestions; S5. Construct the improvement effectiveness algorithm formula, output the improvement effectiveness score Eimp, and set up a secondary evaluation. Combine the improvement effectiveness score Eimp and the supplier's comprehensive safety score Stot to calculate the output safety capability improvement score Sfin, and conduct a secondary evaluation with the safety threshold S. Implement the deduction mechanism based on the evaluation results.

Citation Information

Patent Citations

  • Power information system supply chain security risk static analysis method and system

    CN118427828A

  • Data management method and system based on public resource transaction

    CN118627097A