Method for generating information asset portrait based on informatization asset data

Through the collection, preprocessing, correlation modeling and image construction methods of information asset data, a comprehensive information asset portrait of information system is generated, which solves the problem of difficulty in integrating and analyzing information asset management in the existing technology, and achieves efficient security protection and risk management.

CN120146550APending Publication Date: 2025-06-13上海市大数据中心
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510076352.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

It is difficult for existing technology to fully integrate information asset data, in-depth analysis and generate intuitive asset portraits, making it difficult for security teams to identify key assets, evaluate risk exposures and formulate effective security strategies.

Method used

Through methods of asset data collection and integration, preprocessing and cleaning, correlation modeling and information asset portrait construction, a comprehensive information asset portrait portrait of information system is generated. This method includes using API interface, operation and maintenance management platform, AI-assisted identification and other technical means to build Bayesian networks and Six Sigma algorithms, and perform data classification and compliance evaluation.

Benefits of technology

It has achieved the generation of comprehensive information system information asset portraits, improved the pertinence and efficiency of security protection, and reduced security risks and management costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120146550A_ABST
    Figure CN120146550A_ABST
Patent Text Reader

Abstract

The invention discloses a method for generating an information asset portrait based on informatization asset data, and the method comprises the steps: S1, asset data collection and integration: collecting recorded fragmented asset data from an organization or various informatization systems in real time or at regular intervals, and uniformly forming a pre-informatization asset data summary sheet; s2, asset data preprocessing and cleaning: preprocessing and cleaning the collected data, and removing repeated, wrong or invalid data; s3, association modeling of asset data: forming association of data, people and assets through data modeling, and associating fingerprint information, management information and control information of the assets; and S4, information asset portrait construction: applying big data processing and data classification and grading, introducing a convergence analysis algorithm, and constructing a presentation data set or a data label required by the information asset portrait. The comprehensive information asset portrait of the information system is generated, the pertinence and efficiency of safety protection are improved, and the safety risk and the management cost are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for generating an asset portrait, and particularly to a method for generating an information asset portrait based on informatization asset data. Background Art

[0002] In the current era of accelerating digital transformation, enterprises and organizations are increasingly relying on networks and data to drive business operations, decision-making, and service provision. With the rapid growth and complexity of informatization assets (including hardware devices, software systems, data resources, network devices, security protection information, compliance execution, system usage, etc.), effectively managing and protecting these assets has become a huge challenge. Traditional network security and data protection methods often focus on static rule settings and post-event responses, and are difficult to adapt to the dynamically changing threat environment and growing compliance requirements.

[0003] Under the compliance work and protection requirements of network and data security, although there are already some asset management and risk assessment tools, most of them focus on single-dimensional information collection, such as hardware inventory, software version tracking, or network security vulnerability scanning, lacking the ability to comprehensively integrate various types of informatization asset data, conduct in-depth analysis, and generate intuitive portraits. This makes it difficult for security teams to quickly and accurately identify key assets, assess risk exposures, and formulate effective network security and data protection strategies accordingly. Especially in industries with rapid digital and informatization development such as government, finance, and transportation, in the face of the management of large-scale, dispersed, and constantly changing information systems, traditional security management is difficult to fully and comprehensively cover these information system assets, resulting in the occurrence of security accidents and incidents.

[0004] In the current industry, there is generally no reference standard for the implementation of security work, the goals of security work implementation cannot be focused, and the management level within the organization has doubts about the results and benefits of security work. There is a lack of necessary combination and promotion between security work and operation and maintenance work. The implementation requirements of security work cannot cover and be implemented in each team or department of the organization. Relevant responsible persons lack sufficient understanding of the implementation of regulations and standards. The existence of compliance risks and security risks is in a normal state and cannot be connected with the organization's security work to avoid or narrow the risk scope.

[0005] Therefore, it is urgently necessary to solve the key problem in current informatization asset management that cannot be associated with the organization's security work management and display the work results: that is, to solve how security teams or the organization's security departments can efficiently integrate various types of informatization asset network and data security work data. Summary of the Invention

[0006] The technical problem to be solved by the present invention is to provide a method for generating an information asset portrait based on informatization asset data, which can generate an information asset portrait of a comprehensive information system, improve the pertinence and efficiency of security protection, and reduce security risks and management costs.

[0007] The technical solution adopted by the present invention to solve the above technical problem is to provide a method for generating an information asset portrait based on informatization asset data, including the following steps: S1. Asset data collection and integration: Real-time or regular collection of fragmented asset data recorded from within the organization or various informatization systems, and uniformly forming a pre-informatization asset data summary table; S2. Asset data preprocessing and cleaning: Preprocessing and cleaning the collected data to remove duplicate, incorrect or invalid data; S3. Correlation modeling of asset data: Forming the correlation of data, people, and assets through data modeling, and associating fingerprint information, management information, and control information of assets; S4. Information asset portrait construction: Using big data processing and data classification and grading, introducing a convergence analysis algorithm, and constructing a presentation data set or data label required for the information asset portrait.

[0008] Further, in step S1, the asset data is collected by using the API interface of the asset management platform, the operation and maintenance management platform, the license data collection method, and the manual summary method, and the asset data includes the physical location, IP address, operating system, middleware, database, software version, open port, network connection, data flow situation, security protection ability, and compliance work execution situation of the asset.

[0009] Further, in step S2, an automated recognition program is formed through a screening script and AI-assisted recognition, and recognition and preprocessing are performed during the data extraction and push process.

[0010] Further, in step S2, the relevant field data information of the informatization assets is classified and graded for storage according to different importance levels, and different permissions and policies are used for protection.

[0011] Further, in step S3, work data, workflow data, work results, compliance requirements, and execution requirements are all digitized, data indicators and execution standards are defined, and a Bayesian network is constructed to convert threat scenarios into a series of interrelated random variables. Each node in the Bayesian network represents a random variable, the connection lines between the nodes represent the dependence relationship between the variables, and the weights on the connection lines represent conditional probabilities.

[0012] Further, step S3 also includes incorporating the six sigma algorithm to form an index-level assessment of security work in combination with the actual business path and the relevance of security work execution.

[0013] Further, in step S4, an information asset portrait is presented by establishing a data dashboard and / or a data visualization platform; the asset portrait includes a security importance rating of the asset, a security risk level, a compliance status, key data security indicators, a static display of security protection capabilities, the implementation status of security work, and a security work implementation guidance module.

[0014] Further, it also includes automatically generating optimization suggestions for network and data security work implementation through a matching algorithm and a compliance evaluation algorithm based on the information asset portrait, and automatically adjusting the data interaction and information filling modes according to the actual changes in asset data.

[0015] Further, it also includes establishing a closed-loop monitoring mechanism, continuously optimizing the processes of data collection, processing, and portrait construction through a feedback mechanism, continuously tracking changes in asset status and security risks, repairing, improving, and expanding the ledger forms of informatization asset data, and timely adjusting the information asset portrait, data presentation, and work result display.

[0016] The present invention has the following beneficial effects compared with the prior art: The method for generating an information asset portrait based on informatization asset data provided by the present invention can generate an information asset portrait of a comprehensive information system, improve the pertinence and efficiency of security protection, and reduce security risks and management costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 is a flowchart for generating an information asset portrait based on informatization asset data of the present invention; Figure 2 is a business relationship diagram formed based on informatization asset data of the present invention; Figure 3 is a business relationship logic diagram established based on informatization asset data of the present invention; Figure 4 is a radar chart of informatization asset security protection capabilities based on the sigma level of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] The present invention will be further described below with reference to the drawings and embodiments.

[0019] Figure 1 is a flowchart for generating an information asset portrait based on informatization asset data of the present invention.

[0020] Please refer to Figure 1 , the method for generating an information asset portrait based on informatization asset data provided by the present invention includes: S1. Asset data collection and integration The service team / management team uses the API interface of the asset management platform, the operation and maintenance management platform, the licensed data collection method, the manual summary method, etc. to collect the recorded fragmented asset data from the organization or various information systems in real time or regularly. Considering that the real business scenario cannot fully realize the automatic collection and entry of information asset data, the existence of manual methods can make up for the difficulty of not being able to obtain some data in technical and management scenarios. After all the data is entered, a unified summary table of pre-informatization asset data is formed.

[0021] The data summary table of pre-informatization assets includes but is not limited to the physical location of the assets, IP address, operating system, middleware, database, software version, open ports, network connection, data flow, security protection capabilities, compliance work execution, etc. Each dimension contains the corresponding necessary data fields and filled-in data content.

[0022] The integration of information asset data needs to be connected to national standards, industry standards, and the relevant requirements of superiors or regions to form the necessary information asset fields and data aggregation standards. The aggregated asset data forms internal circulation and metadata standards. Data standardization is the basis for asset profiling and subsequent data sorting, cleaning, and expansion.

[0023] S2. Asset data preprocessing and cleaning Pre-process and clean the collected data to remove duplicate, erroneous or invalid data, ensure data accuracy and consistency, and form uniqueness. At the same time, in accordance with the relevant requirements of the Data Security Law, implement data classification and grading standards, and in accordance with the classification and grading requirements of the organization, classify and grade the relevant field data information of information assets according to different importance, store and manage them. Rely on the storage and protection capabilities of asset management, and use different permissions and strategies for protection.

[0024] The process of data preprocessing, that is, the process of data cleaning, is that the security team uses data thinking to analyze and identify errors in asset and security work data, and to correct the non-compliant data field information. For example, "Apache" is a standard intermediate component, but "Apache 1.12" also belongs to it, and needs to be separated into "Apache" and "1.12" and stored in component information and component version information respectively. This process is an adjustment and optimization process that requires the use of screening scripts, AI-assisted recognition, and the formation of an automated recognition program to perform recognition and preprocessing during data extraction and push.

[0025] The rules for data cleaning are a process of continuous improvement and dynamic adjustment. It requires the establishment of cleaning standards and implementation of management methods through internal or external service providers of the organization, with clear business scenarios and business fields.

[0026] S3. Relevance Modeling of Asset Data For the collected informatization asset data, establish the relevance among data, people, and assets. Identify the person in charge, development unit, operation and maintenance unit, and management information of each information system, and associate the fingerprint information, management information, and control information of the assets. Archive the preprocessed and cleaned data as the standard data of informatization assets.

[0027] The innovative thinking of relevance modeling is to establish the relevance between security work and informatization asset data through data modeling. Digitalize work data, workflow data, work results, compliance requirements, execution requirements, etc., define data indicators and execution standard data indicators, and combine them through necessary algorithms to digitally present security work and security management dimensions. The relevance modeling between informatization asset data and security work adopts the data model thinking to open up the execution perspective of security work.

[0028] For example, in the organization's annual performance appraisal, there are quantitative requirements for the necessary security work to be completed by the information systems responsible for a certain department. For example, the vulnerability scan needs to be carried out 2 times for each system, penetration testing once, risk assessment once, and data security risk assessment once, and the annual equal protection and confidentiality assessment work needs to be completed. Based on the information asset portrait, include the necessary data fields and filling specifications presented by these work contents. Data modeling depends on industry analysis, extracts key data information, forms a necessary data business model, and continuously improves this data business model. Similar field relationships and business relationship diagrams are as Figure 2 shown.

[0029] Relevance Modeling and Algorithm for Informatization Asset Security (Based on Bayesian Network Algorithm and Threat Modeling Probability Analysis)

[0030] P(c / x) represents the conditional probability of c given x.

[0031] P(x / c) represents the conditional probability of x given c.

[0032] P(c) and P(x) represent the marginal probabilities of c and x respectively

[0033] Among them, P(A|B) represents the probability that event A occurs under the condition that event B occurs.

[0034] In a Bayesian network, each node represents a random variable (event), the connection lines between nodes represent the dependence relationship between variables, and the weights on the connection lines represent conditional probabilities.

[0035] By constructing a Bayesian network, complex threat scenarios can be transformed into a series of interrelated random variables, and probability inference can be carried out using Bayes' theorem.

[0036] In actual security work, the results will deviate due to different business paths and execution methods. When building the relevance model of information assets, fully consider the relationships between fields, introduce appropriate algorithms and field weights. Establish a Figure 3 business relationship logic diagram as shown to standardize and define the relevance modeling of information asset data: When building the relevance model of information assets, based on the organization's performance appraisal requirements, combined with the actual business path and the relevance of security work execution, incorporate the Six Sigma algorithm. Based on the practice of Six Sigma, it can be used to analyze and improve various processes, including security work analysis, quantify the quality, stability, and capabilities of the process, and thus determine what measures need to be taken to reduce defects, improve efficiency, and ensure security. Conduct an exponential evaluation of the security process data formation process, and the algorithm and formula are as follows: Cp = (Upper Specification Limit - Lower Specification Limit) / (6 × Standard Deviation) Cpk = min[(Upper Specification Limit - Process Mean) / (3 × Standard Deviation), (Process Mean - Lower Specification Limit) / (3 × Standard Deviation)] Cp measures the ratio of the process width to the specification width, while Cpk takes into account the central position of the process and provides a more comprehensive evaluation of process capabilities.

[0037] Sigma Level: Different sigma levels correspond to different DPMO ranges, thus reflecting the quality level of the process. For example, a 6-sigma level usually means a DPMO lower than 3.4, indicating that the process is very stable and of high quality. Improvement Rate or Lift: Improvement Rate = (Number of Defects before Improvement - Number of Defects after Improvement) / Number of Defects before Improvement × 100%; This formula is used to quantify the reduction in the defect rate or nonconforming rate by improvement measures; The sigma level can effectively measure the current completion coefficient of information assets in security work under the requirements of security business execution and interface with performance appraisal to form index-level assessment. Figure 4 It is a radar chart of the security protection capabilities of information assets based on the sigma level.

[0038] S4. Construction of Information Asset Portrait Based on the pre-processed data, big data processing, data classification and grading, and the introduction of convergence analysis algorithms and other technical means are used to construct the presentation data integration or data labels required for information asset portraits. Information asset portraits are presented by establishing data dashboards and data visualization platforms. The portraits include modules such as asset security importance ratings, security risk levels, compliance status, key data security indicators, static display of security protection capabilities, security work execution status, and security work execution guidelines. The main goal of presenting information asset portraits is to provide necessary decision-making assistance for the execution of security work. The decision-making assistance provided can be associated with the business management platform and the internal digital platform of the organization to create a business closed loop. On the basis of the continuous improvement of information assets, the display dimensions of information asset portrait data are gradually extended. Assist organizations to continuously improve the execution of security work and drive security-related teams and personnel to improve their ability to execute security work.

[0039] S5. Security strategy formulation and optimization Based on the information asset portrait, the matching algorithm and compliance evaluation algorithm are used to automatically generate optimization suggestions for network and data security work execution. These strategies should be customized for different types of assets and different security risk levels to improve the pertinence and effectiveness of the strategies. At the same time, as the asset status and security risks change, the security work guidelines will automatically adjust the data interaction and information reporting mode according to the actual asset data changes.

[0040] S6. Continuous monitoring and feedback Establish a closed-loop monitoring mechanism, continuously track changes in asset status and security risks, repair, improve, and expand the ledger forms of information asset data, and timely adjust the information asset portrait and data presentation and work results display. At the same time, continuously optimize the process of data collection, processing, and portrait construction through the feedback mechanism to improve the accuracy and reliability of the system.

[0041] The present invention is a security management model that combines security work data through data thinking, data dimensions, big data models, and business data modeling capabilities, digitizes security business and work data, and matches the digital entry and development of the organization. Compared with the traditional security thinking of establishing a security operation center, establishing a log response center and other technical thinking, the technical solution of the present invention is a lighter and more intuitive way. The person in charge of the organization can directly see the gap between the work execution effect and the achievement of the goal, and effectively allocate resources and manpower. The present invention is a more intensive, efficient, and valuable implementation idea and solution. For organizations and enterprises, dataization and digitization is a process that can ensure that the invested assets and funds are quantified and precipitated, reduce the cost of ownership, and change the investment into a means and process of value capital.

[0042] Specifically, the present invention has the following outstanding essential features: 1. Dynamically integrate information asset data from multiple points and dimensions The innovation realizes the dynamic integration of multi-dimensional data of information assets. In traditional security work, during the implementation of the work of "taking inventory" of assets, the summary and collection are carried out from the perspective of event-based security management, relying on the identification dimensions of security products and protection systems. However, the present invention conducts a full-scale summary of information asset data from the perspectives of data, big data, and data mining, and not from a single asset perspective, but from the perspective of information systems to summarize the corresponding asset ledger information. This includes the physical location of the information system, the IP addresses of all servers and devices, the operating system, middleware, database, software component versions, open ports, running ports, network connections, data flow conditions, security protection capabilities, security work execution data, data security work data, security management information, security compliance work conditions, etc., providing a comprehensive and accurate data basis for information asset profiling.

[0043] Dynamically integrating information asset data from multiple points and dimensions is a continuous deepening work in the organization's construction of information assets and the implementation of the work of "taking inventory" of assets. Traditional asset summaries only summarize basic fields such as IP, MAC, location, asset number, etc. It is difficult for a single organizational department or team to summarize other dimension data of assets and disassemble the security work execution data and associate it with the information asset data dimension. It is the implementation of big data thinking and business modeling thinking in security work. In terms of data integrity, accuracy, and comprehensiveness, the scope is much larger and broader than traditional data summaries. Without organizational guidance and a standard data model, it is difficult to summarize the necessary information asset data dimensions. The digitization of security work needs to be based on this ability.

[0044] 2. Intelligent and automated construction of asset profiles Using big data processing, statistics, and data analysis algorithms, automatically analyze the asset network and data security work result data and execution data to construct accurate and dynamic information asset profiles. The profiles not only reflect the basic attributes of the assets but also include key indicators such as security risk levels, compliance status, data sensitivity, security work execution conditions, the security status of the assets, dynamic security risks, and security work guidelines combined with the current asset status. This process is the informatization and digitization of physical work. It is necessary to summarize all security work execution data through statistics, and also require data analysis algorithms, summary algorithms, gap analysis algorithms, etc. to statistically calculate and form quantitative and summary result data.

[0045] 3. Automatic generation and guided execution of network and data security improvement and optimization strategies Based on the information asset portrait, combined with the requirements of informatization asset data filling and performance data, it can automatically generate capabilities such as network and data security work execution data, optimization suggestions, and filling of optimization docking measures, and dynamically adjust and display according to the changes in asset status and security risks. This greatly improves the efficiency and accuracy of the organization's formulation of information system security protection strategies, and provides decision-making assistance for the execution and management of the organization's security work.

[0046] 4. Closed-loop monitoring and improvement based on internal asset data Establish a closed-loop monitoring mechanism to continuously track the changes in asset status, security risks, and the status of security work, and continuously optimize the security status, security execution, connected security work, and execution capabilities of the system through a feedback mechanism. Record the status data and result data within a certain time range to form stage asset portrait data and the asset portrait of the current security work status. Continuously expand the coverage of informatization asset data and the connection surface of security work according to the necessity of information system security work and security protection.

[0047] In summary, the method for generating an information asset portrait based on informatization asset data provided by the present invention has the following beneficial effects: 1. Improve the execution efficiency of network and data security work Through the data presentation of the information portrait, the pertinence, coverage, and accuracy of the execution of network and data protection work are significantly improved, and the execution cost (manpower and technology) of security work is reduced. Personnel in different positions and departments no longer need to understand security work from the dry legal regulations, and do not need to rely on the service capabilities and execution capabilities of service units. The digital presentation is the main driving force for security work towards digital development. Through data visualization, the security person in charge can intuitively understand and promote the execution of security work.

[0048] The summary of the results of traditional security work generally relies on reports. The reports are large in length, rich in content, and insufficient in data fineness. The audit and analysis cycle of security work is long, and the evaluation criteria rely on the professionalism of personnel. Through the asset portrait, the quantification and evaluation of security work are formed in a digital manner during the process data collection, effectively reducing the skill requirements of the internal security team of the organization and the human resource cost. For the materials that originally required three people to review, now only one person is needed to confirm the authenticity or integrity of the data and judge the submitted data.

[0049] 2. Enhance the risk identification and management capabilities of information systems Comprehensive and accurate information asset data aggregation capabilities drive the summarization and definition of security work through data, and build automated and standardized risk identification through algorithms. Through data, an information asset profile is formed to help the security team discover potential security threats and compliance risks faster, more standardly, and more authoritatively, improving the accuracy and pertinence of risk identification. It solves the problems of the original security risk definition and identification relying on manual and manual methods, and reduces the misjudgment of the organization's security risks and the cost of execution work by referring to relevant national standards such as GB / T30279-2020 Information Security Technology - Network Security Vulnerability Classification and Grading Guidelines.

[0050] 3. Optimize security work and human resource allocation Based on the aggregated information data presented in the asset profile, it can assist the organization in clarifying the importance and risk level of current information assets, reasonably allocating and optimizing the input resources for the security team, compliance security, and security protection capacity building, achieving the optimal allocation and utilization of resources. It provides a necessary basis for the auxiliary decision-making of security work.

[0051] 4. Enhance the network and data security compliance management and execution capabilities The information asset profile can assist the security department or team in automatically forming compliance management strategies that meet the requirements of relevant laws and regulations based on the current security work needs and compliance work responses of the organization. Through methods such as interactive filling, asset data execution workflows, and result data summarization work, it guides the development and execution of security work through the asset profile, reducing the difficulty and cost of compliance management. It provides standardized and measurable security work execution management capabilities, presenting the execution process and reference standards for execution to relevant personnel in a digital manner, reducing the execution difficulty and aligning costs.

[0052] 5. Enhance the decision-making support capabilities for security work Relying on data visualization capabilities, the information asset profile provides decision-making support for the organization's management and implementation teams based on network and data security, helping them formulate network security and data protection strategies more scientifically. It provides decision-making assistance and standardized reference basis for the development of the organization's security work. It provides a digital perspective on the necessity and urgency of the execution of security work.

[0053] Although the present invention has been disclosed above with preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications and improvements without departing from the spirit and scope of the present invention. Therefore, the protection scope of the present invention shall be defined by the claims.

Claims

1. A method for generating an information asset portrait based on information asset data, characterized in that: The steps include: S1. Asset data collection and integration: collect the recorded fragmented asset data from the organization or various information systems in real time or regularly, and unify them into a pre-informatization asset data summary table; S2. Asset data preprocessing and cleaning: Preprocess and clean the collected data to remove duplicate, erroneous or invalid data; S3.Asset data correlation modeling: Through data modeling, the correlation between data, people and assets is formed, and the fingerprint information, management information and control information of assets are associated; S4. Information asset portrait construction: Use big data processing, data classification and grading, introduce convergence analysis algorithms, and construct the presentation data sets or data labels required for information asset portraits.

2. The method for generating an information asset portrait based on information asset data according to claim 1, characterized in that: The step S1 collects asset data using the API interface of the asset management platform, the operation and maintenance management platform, the licensed data collection method and the manual summary method. The asset data includes the physical location, IP address, operating system, middleware, database, software version, open port, network connection, data flow, security protection capability and compliance work execution of the asset.

3. The method for generating an information asset portrait based on information asset data according to claim 1, characterized in that: The step S2 forms an automated recognition program through screening scripts and AI-assisted recognition, and performs recognition and preprocessing during data extraction and push.

4. The method for generating an information asset portrait based on information asset data according to claim 1, characterized in that: The step S2 classifies and stores the relevant field data information of the information assets according to different importance, and uses different permissions and strategies to protect them.

5. The method for generating an information asset portrait based on information asset data according to claim 1, characterized in that: The step S3 digitizes the work data, workflow data, work results, compliance requirements, and execution requirements, defines data indicators and execution standards, and transforms the threat scenario into a series of interrelated random variables by constructing a Bayesian network. Each node in the Bayesian network represents a random variable, the lines between the nodes represent the dependency between the variables, and the weights on the lines represent the conditional probability.

6. The method for generating an information asset portrait based on information asset data according to claim 3, characterized in that: The step S3 also includes combining the actual business path and the relevance of the security work execution, and incorporating the Six Sigma algorithm to form an indicator-level assessment of the security work.

7. The method for generating an information asset portrait based on information asset data according to claim 1, characterized in that: The step S4 presents an information asset portrait by establishing a data dashboard and / or a data visualization platform; the asset portrait includes the asset's security importance rating, security risk level, compliance status, data security key indicators, static display of security protection capabilities, security work execution status, and a security work execution guidance module.

8. The method for generating an information asset portrait based on information asset data according to claim 1, characterized in that: It also includes automatically generating optimization suggestions for network and data security work execution based on information asset portraits through matching algorithms and compliance evaluation algorithms, and automatically adjusting data interaction and information reporting modes based on actual changes in asset data.

9. The method for generating an information asset portrait based on information asset data according to claim 1, characterized in that: It also includes establishing a closed-loop monitoring mechanism, continuously optimizing the process of data collection, processing and portrait construction through a feedback mechanism, continuously tracking changes in asset status and security risks, repairing, improving and expanding the ledger forms of information asset data, and timely adjusting information asset portraits, data presentation and work results display.