Financial data security regulation and control management method and system

By adopting encryption technology, role access control, regular backup and multi-factor authentication in the transmission and storage of financial data, problems such as data leakage, overprivileged access and identity impersonation in the existing financial data security management have been solved, and the security and availability of financial data have been significantly improved.

CN119991046APending Publication Date: 2025-05-13JIAYOUZAN (SHANGHAI) INFORMATION TECH CO LTD

Patent Information

Application Number
CN202510432512.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing financial data security management and regulation methods have problems such as data leakage, overprivileged access, and identity impersonation, and cannot effectively prevent the security threat of financial data.

Method used

Data encryption and control, access rights control, backup and recovery control, identity verification control, approval optimization control, monitoring and audit control, etc. are adopted to ensure the security of financial data in the transmission and storage process, control access rights, and achieve high availability and security of data.

Benefits of technology

Through encrypted transmission and storage, role access control, regular backup and multi-factor authentication, the confidentiality, integrity and availability of financial data are significantly improved, the risks of data breaches and overright access are reduced, and the security of financial data regulation and management is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119991046A_ABST
    Figure CN119991046A_ABST
Patent Text Reader

Abstract

The invention discloses a financial data security regulation and control management method and system, and relates to the technical field of commercial financial management, and the method comprises the following steps: 1, data encryption regulation and control: employing an encryption protocol to carry out encryption transmission, and carrying out encryption storage; step 2, access permission regulation and control: distributing corresponding access permissions; step 3, backup and recovery regulation and control: making a backup, and performing a data recovery test; 4, authenticating the identity of the regulator, wherein a multi-factor identity authentication and digital certificate authentication mode is adopted; 5, approval optimization regulation and control: refining the approval authority, and introducing an approval risk assessment mechanism and an abnormity early warning mechanism; and step 6, monitoring and auditing regulation and control: monitoring access and operation of data, and regularly performing internal and external auditing. According to the method, transmission encryption and storage encryption are utilized, man-in-the-middle attack is effectively prevented, permissions are allocated according to responsibilities, unauthorized operation is avoided, the internal abuse risk is reduced, and the security of financial data regulation and control management is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of commercial financial management, and in particular to a financial data security control management method and system thereof. Background Art

[0002] With the acceleration of digital transformation of enterprises, the security management of financial data faces unprecedented challenges. Financial data involves the core business information of enterprises, including capital flow, transaction records, customer account information, etc. As the core asset of enterprises, the security of financial data is of vital importance. Once leaked or tampered with, it may lead to serious economic losses and reputation crisis.

[0003] In order to ensure the confidentiality, integrity and availability of financial data, existing financial data security management and control methods usually adopt a single password protection or basic permission control. However, existing enterprise servers, cloud or mobile storage devices may lead to data leakage due to physical loss or intrusion. Conventional storage encryption technology may not cover all sensitive data. Some enterprises use static permission allocation, which increases the risk of unauthorized access or misoperation by internal personnel. In addition, financial authentication that only relies on username + password is easily cracked by brute force or phishing attacks, and cannot effectively prevent identity theft, affecting the security of existing enterprise financial data control and management. Summary of the invention

[0004] The purpose of the present invention is to provide a financial data security control management method and system to solve the problems raised in the above background technology.

[0005] To achieve the above object, the present invention provides the following technical solution: a financial data security control management method, comprising the following steps: Step 1: Data encryption control: Encryption protocols are used for financial data transmission, and full disk encryption technology is used to encrypt and store financial data during the storage phase; Step 2: Access permission control: Based on role-based access control and the principle of least privilege, assign corresponding data access permissions to employees with different responsibilities; Step 3: Backup and recovery control: Develop a regular backup strategy, including daily incremental backup and weekly full backup, and perform data recovery tests regularly; Step 4: Controller identity verification: Use multi-factor identity verification and digital certificate authentication to verify the controller's identity. Step 5: Optimize and regulate approval: Establish clear approval processes and nodes, refine approval authority, and introduce approval risk assessment mechanism and abnormal warning mechanism; Step 6: Monitoring and audit control: Real-time monitoring of access to and operation of financial data, and regular internal and external audits.

[0006] Preferably, the data encryption control in step 1 includes: S1.1, Transmission encryption: In the process of financial data transmission, the SSL / TLS protocol is used to encrypt and package the data for secure transmission of the transmission link; S1.2, Storage encryption: During the financial data storage stage, full disk encryption technology is used to encrypt the disk where the database is located, and only authorized keys are allowed to access it.

[0007] Preferably, the access rights control in step 2 includes: S2.1, Role-controlled access: Based on the RBAC model, according to the different responsibilities of the finance department employees, different data access rights are assigned to different roles in the finance department, including but not limited to the financial director, accountant, and cashier. The financial director views and approves all financial data reports, the accountant has the authority to handle daily account data entry and query, and the cashier is responsible for data operations related to fund collection and payment; S2.2. Least privilege control: When assigning specific permissions to employees, follow the principle of least privilege, and employees can only access financial data within their scope of responsibility.

[0008] Preferably, the backup and recovery control in step 3 includes: S3.1. Regular backup strategy: Develop a strict regular backup plan for financial data, formulate daily incremental backup and weekly full backup strategies, and store the backup data in an offsite data center; S3.2, Recovery test: Perform data recovery tests regularly to simulate data loss scenarios and verify the integrity and availability of backup data.

[0009] Preferably, the identity verification of the controller in step 4 includes: S4.1. Multi-factor authentication: When a controller accesses and operates the financial data room, a multi-factor authentication method is used to confirm the identity of the controller, combining passwords, SMS verification codes and biometric recognition technology; S4.2, Digital Certificate Authentication: Issue a digital certificate to the controller, which includes the controller's identity information and public key. The controller uses a medium including but not limited to a USB Key to store the digital certificate for login and sensitive operation security protection; S4.3, Behavior analysis engine: real-time monitoring of the controller's operating habits, abnormal behavior triggers secondary verification or authority downgrade.

[0010] Preferably, the approval optimization and regulation in step 5 includes: S5.1. Clarify the approval process and nodes: formulate a detailed financial data control approval process manual, specify the responsible person, approval content and approval time limit for each approval node; S5.2. Refine approval authority: Refine approval authority according to the importance and sensitivity level of financial data. General financial data query and regular report generation shall be approved by middle-level managers of the finance department. High-risk operations shall require multi-level approval from senior management and risk control team. S5.3. Introduce risk assessment mechanism: embed risk assessment process in the approval process, use professional financial risk assessment software to conduct risk quantitative assessment on each financial data control application. The assessment factors include but are not limited to the sensitivity of the data, possible security threats, and potential losses after data leakage. Generate a risk report based on the assessment results, and the approval personnel will assist in decision-making based on the risk report; S5.4. Establish an abnormal warning system: monitor and handle abnormal behaviors in the approval process in real time. Establish an approval abnormality warning system through real-time monitoring of approval process data. When abnormal situations occur, including but not limited to approval timeouts, frequent applications for high-risk data control, and approval process jumps, the system immediately sends a warning notification to relevant management personnel and relevant middle and senior management personnel.

[0011] Preferably, the approval optimization and regulation in step 5 further includes: S5.5, Emergency channel: preset exception rules, in the event of system failure, try out the emergency adjustment and approval channel, at least two groups of low, middle and senior management will conduct emergency approval processing of financial data, and the financial department, including but not limited to the financial director, accountant, and cashier will make approval records and attach audit instructions.

[0012] Preferably, the monitoring and auditing control in step 6 includes: S6.1. Real-time monitoring: Deploy real-time monitoring tools to detect abnormal access behaviors to and operations of financial data, conduct real-time monitoring, monitor abnormal access behaviors, and immediately issue an alarm to notify security management personnel once abnormal behaviors are found; S6.2. Regular Audits: Regularly audit financial data security control and management measures to review whether access rights are reasonably allocated, whether data encryption is effective, and whether backup and recovery processes are compliant. Conduct internal audits every quarter and invite external professional auditing agencies to conduct comprehensive audits every year to implement effective and compliant security measures.

[0013] The present invention also provides a financial data security control and management system, comprising: A data encryption control module, which uses an encryption protocol to encrypt the financial data during the data storage process and uses full disk encryption technology to encrypt the disk where the database is located during the financial data storage phase, allowing only authorized keys to access it; An access rights control module, which allocates corresponding data access rights to employees with different responsibilities based on role-based access control and the principle of least privilege; A backup and recovery control module, which formulates a regular backup strategy, stores the backup data in an off-site data center, and performs regular data recovery tests to verify the integrity and availability of the backup data; A controller identity authentication module, wherein the controller identity authentication module uses multi-factor identity authentication and digital certificate authentication to perform controller identity authentication; An approval optimization and control module, which establishes clear approval processes and nodes, refines approval authority, and introduces an approval risk assessment mechanism and an abnormal warning mechanism; The monitoring and audit control module monitors the access and operation of financial data in real time. Once abnormal behavior is found, an alarm is immediately issued to notify the security management personnel, and internal and external audits are conducted regularly.

[0014] Preferably, the approval optimization and control module includes: Approval process and node unit, used to formulate a detailed financial data control approval process manual, to define the responsible person, approval content and approval time limit for each approval node; Approval authority unit, which refines approval authority according to the importance and sensitivity level of financial data; The risk assessment mechanism unit uses professional financial risk assessment software to conduct risk quantitative assessment on each financial data control application; The abnormal warning unit monitors and handles abnormal behaviors in the approval process in real time, and establishes an approval abnormality warning system by real-time monitoring of approval process data; The emergency channel unit has preset exception rules and will try out the emergency regulation and approval channel when the system fails.

[0015] Technical effects and advantages of the present invention: The present invention uses transmission encryption and storage encryption to ensure that data cannot be decrypted even if it is intercepted during transmission, effectively preventing man-in-the-middle attacks. Even if the storage device is lost, the data cannot be illegally accessed. Permissions are allocated according to responsibilities to avoid unauthorized operations. Only the minimum permissions required for employees to complete their work are granted, reducing the risk of internal abuse and improving the security of enterprise financial data regulation and management. The present invention ensures disaster recovery capabilities, simulates data loss scenarios, verifies backup validity, and avoids backup invalidation issues through off-site multi-copy backup and regular recovery testing, daily incremental backup and weekly full backup are implemented simultaneously, and stored in facilities in different geographical locations; The present invention utilizes multiple identity authentication mechanisms, combined with passwords, SMS verification codes, and biometrics, to greatly improve identity authentication security, uses hardware media such as USB Key to store certificates to prevent certificates from being stolen, and simultaneously monitors abnormal operations to effectively prevent identity fraud.

[0016] The present invention uses quantitative analysis tools to assess data sensitivity and potential threats, assist in approval decisions, monitor approval anomalies in real time, promptly block high-risk operations, enable multi-level approval emergency processes in the event of system failures, ensure business continuity, detect abnormal access, and immediately alert the security team. At the same time, regular internal and external audits are conducted to ensure financial security and improve the confidentiality, integrity and availability of financial data. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 The figure is a flow chart of the steps of the method of the present invention.

[0018] Figure 2 This is a system structure framework diagram of the present invention.

[0019] Figure 3 This is a structural framework diagram of the approval optimization and control module of the system of the present invention. DETAILED DESCRIPTION

[0020] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0021] The present invention provides Figure 1-3 A financial data security control management method is shown, comprising the following steps: Step 1: Data encryption control: Encryption protocols are used for financial data transmission, and full disk encryption technology is used to encrypt and store financial data during the storage phase; Data encryption controls include: S1.1, Transmission encryption: In the process of financial data transmission, the SSL / TLS protocol is used to encrypt and package the data for secure transmission of the transmission link. For example, when the financial department interacts with the bank, the SSL encryption technology is used to encrypt sensitive data such as financial transfer instructions and account information into ciphertext for transmission. Even if the data is intercepted during the transmission process, hackers cannot directly obtain the plaintext information, thus ensuring the security of the data in the transmission link; S1.2. Storage encryption: During the financial data storage stage, full-disk encryption technology is used to encrypt the disk where the database is located, and only authorized keys are allowed to access it. Full-disk encryption technology can be BitLocker technology for Windows systems or FileVault technology for Mac systems. Taking the enterprise financial database as an example, the disk partition where the entire database file is located is encrypted. Only authorized keys can access and read data, preventing data leakage caused by loss or theft of storage devices.

[0022] Step 2: Access permission control: Based on role-based access control and the principle of least privilege, assign corresponding data access permissions to employees with different responsibilities; Access rights control includes: S2.1, Role-controlled access: Based on the RBAC model, according to the different responsibilities of the finance department employees, different data access permissions are assigned to different roles in the finance department, including but not limited to the financial director, accountant, and cashier. The financial director views and approves all financial data reports, the accountant has the authority to handle daily account data entry and query, and the cashier is responsible for data operations related to fund collection and payment. In this way, employees are restricted to access only financial data related to their work, reducing the risk of data leakage; S2.2. Least privilege control: When assigning specific permissions to employees, follow the principle of least privilege to ensure that employees can only access financial data within their scope of responsibility while completing their work tasks. For example, ordinary accountants only have data read and write permissions within the scope of their accounts, and have no access to other departments or sensitive financial data (such as senior management salary data). They have the minimum necessary permissions to reduce data security incidents caused by internal personnel's misoperation or malicious behavior.

[0023] Step 3: Backup and recovery control: Develop a regular backup strategy, including daily incremental backup and weekly full backup, and perform data recovery tests regularly; Backup and recovery control includes: S3.1. Regular backup strategy: Develop a strict regular backup plan for financial data, formulate daily incremental backup and weekly full backup strategies, and store the backup data in an off-site data center to prevent data loss due to local natural disasters or major accidents; for example, a multinational company backs up its global financial data daily incrementally to data centers located in different continents, and also stores weekly full backups in secure off-site storage facilities; S3.2. Recovery test: Perform data recovery tests regularly, simulate data loss scenarios, verify the integrity and availability of backup data, and perform recovery tests at least once a month to ensure that when data recovery is actually needed, financial data can be quickly and accurately restored to a normal state. Through recovery testing, problems that may exist in the backup process, such as incomplete backup data and cumbersome recovery processes, can be discovered in a timely manner, and optimization can be carried out based on existing problems.

[0024] Step 4: Controller identity verification: Use multi-factor identity verification and digital certificate authentication to verify the controller's identity. Regulator identity verification includes: S4.1. Multi-factor authentication: When accessing and operating the financial data room, the controller uses multi-factor authentication, combining passwords, SMS verification codes and biometric identification technology to confirm identity. For example, in addition to entering the traditional user name and password, it is also necessary to verify through mobile phone SMS verification code or biometric identification technology such as fingerprint recognition. When the financial director logs into the financial system to review important data, the system first requires the user name and password, and then sends a verification code to the bound mobile phone. At the same time, if the device supports it, fingerprint recognition is also required. Only when all three verification methods are passed can the system be successfully logged in to operate; S4.2, Digital certificate authentication: Issue a digital certificate to the controller, which includes the controller's identity information and public key. The controller uses a medium including but not limited to a USB key to store the digital certificate for login and security of sensitive operations. The digital certificate uses encryption technology and has high security, effectively preventing identity fraud. For example, on the internal financial data sharing platform of an enterprise, only the controller who uses digital certificate authentication can access and download sensitive financial statements; S4.3, Behavior Analysis Engine: Real-time monitoring of the operating habits of regulators. Abnormal behaviors trigger secondary verification or authority downgrade based on the regulator's usual control habits. For example, the financial reconciliation data in the company system is opened for review before funds are input.

[0025] Step 5: Optimize and regulate approval: Establish clear approval processes and nodes, refine approval authority, and introduce approval risk assessment mechanism and abnormal warning mechanism; Approval optimization and regulation include: S5.1. Clarify the approval process and nodes: Develop a detailed financial data control approval process manual, and define the responsible person, approval content, and approval time limit for each approval node. For example, when financial data needs to be modified or major data queries are required, the data applicant must first fill out a detailed application form, stating the reason for the application, data scope, expected time of use, and other information, and submit it to the direct supervisor for preliminary review. The direct supervisor reviews the rationality and necessity of the application. If approved, it will be submitted to the financial manager for business compliance review. The financial manager must complete the review within 1 working day to check whether the data control complies with financial systems and business processes. Finally, the financial director will conduct the final approval and check data control applications involving large amounts or high sensitivity. The financial director must complete the approval within 2 working days. The entire approval process is circulated through the online approval system to ensure that the process is transparent and traceable; S5.2. Refine approval authority: Refine approval authority according to the importance and sensitivity level of financial data. The query of general financial data and the generation of regular reports shall be approved by the middle-level management of the financial department. For example, the query of daily sales financial reports shall be approved by the financial director. High-risk operations shall require multi-level approval from senior management and risk control team. High-risk operations include the modification of financial data related to the company's core financial indicators and strategic decisions, the viewing of large-amount fund transaction data, etc., to prevent key financial information from being improperly obtained and used. S5.3. Introduce risk assessment mechanism: embed risk assessment process in the approval process, use professional financial risk assessment software to conduct risk quantitative assessment on each financial data control application. The assessment factors include but are not limited to the sensitivity of the data, possible security threats, and potential losses after data leakage. Generate a risk report based on the assessment results, and the reviewer will assist in decision-making based on the risk report. For example, when a data control application involves a large amount of sensitive financial information of customers, the risk assessment software will analyze factors such as data volume, information sensitivity, and current network security situation, and assess that the application has a high risk. After receiving the risk report, the reviewer may require the applicant to provide additional security measures, such as strengthening the data encryption level, shortening the data usage time, etc., and will only approve the application when the risk is controllable; S5.4. Establish an abnormal warning system: Real-time monitoring and handling of abnormal behaviors in the approval process. By real-time monitoring of approval process data, an approval abnormality warning system is established. When abnormal situations occur, including but not limited to approval timeouts, frequent applications for high-risk data control, and approval process jumps, the system immediately issues a warning notification to relevant managers and relevant middle and senior management personnel. For example, if an employee submits multiple sensitive financial data query applications in a short period of time, and the interval between each application is extremely short, the system automatically determines it as abnormal behavior and issues a warning. After receiving the warning, the manager will intervene in the investigation in a timely manner. If it is found that the employee made an operational error, the manager can be trained and guided. If there is a potential security risk, such as the employee's account being stolen, measures such as freezing the account, changing the password, and strengthening security protection will be taken immediately to ensure the safety and normal operation of the financial data approval process; S5.5, Emergency Channel: Preset exception rules, in the event of system failure, try out the emergency regulation and approval channel, at least two groups of low, middle and senior management will conduct emergency approval of financial data, and the finance department, including but not limited to the financial director, accountant, and cashier will make approval records and attach audit notes to ensure that the company's financial funds can be regulated and approved normally when the company's financial system fails.

[0026] Step 6: Monitoring and audit control: Real-time monitoring of access to and operation of financial data, and regular internal and external audits; Monitoring and auditing controls include: S6.1. Real-time monitoring: Deploy real-time monitoring tools to detect abnormal access behaviors to and operations of financial data, conduct real-time monitoring, monitor abnormal access behaviors, and immediately issue an alarm to notify security managers once abnormal behaviors are found, monitor abnormal access behaviors, such as downloading a large amount of financial data in a short period of time, too many failed login attempts, etc. Once abnormal behaviors are found, immediately issue an alarm to notify security managers; for example, through network traffic monitoring tools, real-time analysis of data traffic in the financial network area, when it is found that a certain employee account suddenly initiates a large number of data download requests during non-working hours, the system automatically triggers an alarm, and the security team can intervene in the investigation in time; S6.2. Regular Audits: Regularly audit the financial data security control and management measures to review whether the access rights are reasonably allocated, whether the data encryption is effective, and whether the backup and recovery processes are compliant. Conduct internal audits every quarter and invite external professional auditing agencies to conduct comprehensive audits every year to implement effective and compliant security measures. Through audits, potential data security vulnerabilities and management defects are discovered, and rectification is carried out in a timely manner to continuously improve the financial data security control and management system.

[0027] The present invention also provides a financial data security control and management system, including a data encryption control module, an access authority control module, a backup and recovery control module, a controller identity authentication module, an approval optimization control module and a monitoring and auditing control module. The data encryption control module adopts an encryption protocol to perform encrypted transmission during the financial data transmission process, and uses full disk encryption technology to encrypt the disk where the database is located during the financial data storage stage, and only allows authorized keys to access. The access authority control module allocates corresponding data access rights to employees with different responsibilities based on role access control and the principle of minimum authority. The backup and recovery control module formulates a regular backup strategy, stores the backup data in an off-site data center, and regularly performs data recovery tests to verify the integrity and availability of the backup data. The controller identity authentication module adopts multi-factor identity authentication and digital certificate authentication to perform controller identity authentication. The approval optimization control module refines the approval authority by establishing clear approval processes and nodes, and introduces an approval risk assessment mechanism and an abnormal early warning mechanism. The monitoring and auditing control module monitors the access and operation of financial data in real time. Once abnormal behavior is found, an alarm is immediately issued to notify the security management personnel, and internal and external audits are performed regularly.

[0028] Among them, the approval optimization and control module includes: Approval process and node unit, used to formulate a detailed financial data control approval process manual, to define the responsible person, approval content and approval time limit for each approval node; Approval authority unit, which refines approval authority according to the importance and sensitivity level of financial data; The risk assessment mechanism unit uses professional financial risk assessment software to conduct risk quantitative assessment on each financial data control application; The abnormal warning unit monitors and handles abnormal behaviors in the approval process in real time, and establishes an approval abnormality warning system by real-time monitoring of approval process data; The emergency channel unit has preset exception rules and will try out the emergency regulation and approval channel when the system fails.

[0029] Finally, it should be noted that the above is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, it is still possible for those skilled in the art to modify the technical solutions described in the aforementioned embodiments or to make equivalent substitutions for some of the technical features therein. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A financial data security control management method, characterized in that: The following steps are involved: Step 1: Data encryption control: Encryption protocols are used for financial data transmission, and full disk encryption technology is used to encrypt and store financial data during the storage phase; Step 2: Access permission control: Based on role-based access control and the principle of least privilege, assign corresponding data access permissions to employees with different responsibilities; Step 3: Backup and recovery control: Develop a regular backup strategy, including daily incremental backup and weekly full backup, and perform data recovery tests regularly; Step 4: Controller identity verification: Use multi-factor identity verification and digital certificate authentication to verify the controller's identity. Step 5: Optimize and regulate approval: Establish clear approval processes and nodes, refine approval authority, and introduce approval risk assessment mechanism and abnormal warning mechanism; Step 6: Monitoring and audit control: Real-time monitoring of access to and operation of financial data, and regular internal and external audits.

2. A financial data security control management method according to claim 1, characterized in that: The data encryption control in step 1 includes: S1.1, Transmission encryption: In the process of financial data transmission, the SSL / TLS protocol is used to encrypt and package the data for secure transmission of the transmission link; S1.2, Storage encryption: During the financial data storage stage, full disk encryption technology is used to encrypt the disk where the database is located, and only authorized keys are allowed to access it.

3. A financial data security control management method according to claim 1, characterized in that: The access permission control in step 2 includes: S2.1, Role-controlled access: Based on the RBAC model, according to the different responsibilities of the finance department employees, different data access rights are assigned to different roles in the finance department, including but not limited to the financial director, accountant, and cashier. The financial director views and approves all financial data reports, the accountant has the authority to handle daily account data entry and query, and the cashier is responsible for data operations related to fund collection and payment; S2.

2. Least privilege control: When assigning specific permissions to employees, follow the principle of least privilege, and employees can only access financial data within their scope of responsibility.

4. A financial data security control management method according to claim 1, characterized in that: The backup and recovery control in step 3 includes: S3.

1. Regular backup strategy: Develop a strict regular backup plan for financial data, formulate daily incremental backup and weekly full backup strategies, and store the backup data in an offsite data center; S3.2, Recovery test: Perform data recovery tests regularly to simulate data loss scenarios and verify the integrity and availability of backup data.

5. A financial data security control management method according to claim 1, characterized in that: The identity verification of the controller in step 4 includes: S4.

1. Multi-factor authentication: When a controller accesses and operates the financial data room, a multi-factor authentication method is used to confirm the identity of the controller, combining passwords, SMS verification codes and biometric recognition technology; S4.2, Digital Certificate Authentication: Issue a digital certificate to the controller, which includes the controller's identity information and public key. The controller uses a medium including but not limited to a USB Key to store the digital certificate for login and sensitive operation security protection; S4.3, Behavior analysis engine: real-time monitoring of the controller's operating habits, abnormal behavior triggers secondary verification or authority downgrade.

6. A financial data security control management method according to claim 1, characterized in that: The approval optimization and regulation in step 5 includes: S5.

1. Clarify the approval process and nodes: formulate a detailed financial data control approval process manual, specify the responsible person, approval content and approval time limit for each approval node; S5.

2. Refine approval authority: Refine approval authority according to the importance and sensitivity level of financial data. General financial data query and regular report generation shall be approved by middle-level managers of the finance department. High-risk operations shall require multi-level approval from senior management and risk control team. S5.

3. Introduce risk assessment mechanism: embed risk assessment process in the approval process, use professional financial risk assessment software to conduct risk quantitative assessment on each financial data control application. The assessment factors include but are not limited to the sensitivity of the data, possible security threats, and potential losses after data leakage. Generate a risk report based on the assessment results, and the approval personnel will assist in decision-making based on the risk report; S5.

4. Establish an abnormal warning system: monitor and handle abnormal behaviors in the approval process in real time. Establish an approval abnormality warning system through real-time monitoring of approval process data. When abnormal situations occur, including but not limited to approval timeouts, frequent applications for high-risk data control, and approval process jumps, the system immediately sends a warning notification to relevant management personnel and relevant middle and senior management personnel.

7. A financial data security control management method according to claim 6, characterized in that: The approval optimization and control in step 5 also includes: S5.5, Emergency channel: preset exception rules, in the event of system failure, try out the emergency adjustment and approval channel, at least two groups of low, middle and senior management will conduct emergency approval processing of financial data, and the financial department, including but not limited to the financial director, accountant, and cashier will make approval records and attach audit instructions.

8. A financial data security control management method according to claim 1, characterized in that: The monitoring and auditing control in step 6 includes: S6.

1. Real-time monitoring: Deploy real-time monitoring tools to detect abnormal access behaviors to and operations of financial data, conduct real-time monitoring, monitor abnormal access behaviors, and immediately issue an alarm to notify security management personnel once abnormal behaviors are found; S6.

2. Regular Audits: Regularly audit financial data security control and management measures to review whether access rights are reasonably allocated, whether data encryption is effective, and whether backup and recovery processes are compliant. Conduct internal audits every quarter and invite external professional auditing agencies to conduct comprehensive audits every year to implement effective and compliant security measures.

9. A financial data security control and management system according to any one of claims 1 to 8, characterized in that: include: A data encryption control module, which uses an encryption protocol to encrypt the financial data during the data storage process and uses full disk encryption technology to encrypt the disk where the database is located during the financial data storage phase, allowing only authorized keys to access it; An access rights control module, which allocates corresponding data access rights to employees with different responsibilities based on role-based access control and the principle of least privilege; A backup and recovery control module, which formulates a regular backup strategy, stores the backup data in an off-site data center, and performs regular data recovery tests to verify the integrity and availability of the backup data; A controller identity authentication module, wherein the controller identity authentication module uses multi-factor identity authentication and digital certificate authentication to perform controller identity authentication; An approval optimization and control module, which establishes clear approval processes and nodes, refines approval authority, and introduces an approval risk assessment mechanism and an abnormal warning mechanism; The monitoring and audit control module monitors the access and operation of financial data in real time. Once abnormal behavior is found, an alarm is immediately issued to notify the security management personnel, and internal and external audits are conducted regularly.

10. A financial data security control and management system according to claim 9, characterized in that: The approval optimization and control module includes: Approval process and node unit, used to formulate a detailed financial data control approval process manual, to define the responsible person, approval content and approval time limit for each approval node; Approval authority unit, which refines approval authority according to the importance and sensitivity level of financial data; The risk assessment mechanism unit uses professional financial risk assessment software to conduct risk quantitative assessment on each financial data control application; The abnormal warning unit monitors and handles abnormal behaviors in the approval process in real time, and establishes an approval abnormality warning system by real-time monitoring of approval process data; The emergency channel unit has preset exception rules and will try out the emergency regulation and approval channel when the system fails.

Citation Information

Patent Citations

  • BIM (Building Information Modeling) data security protection system based on encryption and role authority control

    CN119358004A

  • Enterprise service management cloud storage system

    CN119561955A

Cited By

  • Office vulnerability analysis method and system based on big data

    CN120217394A

  • A method and system for analyzing office vulnerabilities based on big data

    CN120217394B