Safety management and control method based on informatization asset data standard specification

By formulating unified information asset data standards and building internal and external security work standards, the systematic, standardized and digital management of security work in information asset management has been achieved, and the problems of inconsistent security management standards, inefficient execution efficiency, and insufficient risk prevention and control capabilities have been solved, and the safety management efficiency and risk prevention and control capabilities have been improved.

CN120146596APending Publication Date: 2025-06-13上海市大数据中心
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510075403.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

In the management of information-based asset, the existing technology has problems such as inconsistent security management standards, low execution efficiency, and insufficient risk prevention and control capabilities.

Method used

Adopt security management and control methods based on information asset data standards and specifications, including formulating unified information asset data standards, building internal and external security work standards, and realizing digital management of security work.

Benefits of technology

The systematized, standardized and digital management of safety work has been realized, and the efficiency of safety management and risk prevention and control capabilities have been improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120146596A_ABST
    Figure CN120146596A_ABST
Patent Text Reader

Abstract

The invention discloses a security management and control method based on informatization asset data standard specifications, which comprises the following steps: S1) constructing standard metadata of informatization assets, establishing a main data standard, and keeping data formats and coding rules of assets of the same type consistent; setting a classification and grading framework of the informatization asset data, and defining a relationship and a hierarchical structure between the data; s2) formulating an OLA framework based on an informatization asset data standard, classifying and evaluating assets, and determining security risk levels of various assets; s3) comprehensively carding informatization assets, and analyzing security requirements and risk points of various assets to form an SLA framework; and S4) constructing a digital security execution index system based on the SLA framework and the OLA framework in combination with the informatization asset data field. The method can solve the problems of non-uniform security management standards, low execution efficiency, insufficient risk prevention and control capability and the like in informatization asset management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a data security control method, and particularly to a security control method based on information asset data standard specifications. Background Art

[0002] Today, with the rapid development of informatization, enterprises and organizations rely on a large number of information assets to support their business operations. However, with the expansion of the asset scale and the increase in complexity, how to effectively manage these assets and ensure their security has become a major challenge. Traditional security management methods often focus on after-the-fact response, lacking foresight and systematicness, and are difficult to cope with increasingly complex network threats and security risks.

[0003] Especially for organizations in the fields of government affairs, finance, transportation, and large groups, as well as security departments or information centers, the types of information assets they manage are numerous, the quantity is huge, the distribution is relatively wide, and the management difficulty is great. The changes in information system assets cannot be grasped in a timely manner, and the coverage and execution effectiveness of security work cannot be confirmed and identified.

[0004] Facing the management organizations of large information system assets, the adopted security management mode mainly focuses on after-the-fact response with traditional security management methods, lacking preventive and systematicness. Security incidents occur frequently, and security resources cannot be effectively utilized to protect against security risks.

[0005] Under the traditional security management mode, the security management institutions of the organization face various information systems, responsible departments, and teams, and the implemented security management standards are not unified. There is a lack of effective coordination between the organization and external service providers. As a result, the security service work is not implemented in place, and they are exhausted in dealing with security inspections and security compliance work. Summary of the Invention

[0006] The technical problem to be solved by the present invention is to provide a security control method based on information asset data standard specifications, which can solve the problems existing in information asset management, such as non-uniform security management standards, low execution efficiency, and insufficient risk prevention and control capabilities.

[0007] The technical solution adopted by the present invention to solve the above technical problems is to provide a security control method based on information-based asset data standard specifications, including the following steps: S1) Formulate a unified information-based asset data standard: construct standard metadata for information-based assets, establish a master data standard, and keep the data formats and coding rules of the same type of assets consistent; set a classification and grading framework for information-based asset data to clarify the relationships and hierarchical structures between data; S2) Construct an internal security work standard: formulate an OLA framework based on the information-based asset data standard, classify and evaluate assets, and determine the security risk levels of various assets; S3) Establish an external service provider security work standard: comprehensively sort out information-based assets, analyze the security requirements and risk points of various assets, and form an SLA framework; S4) Implement digital management of security work: based on the SLA framework and OLA framework, combined with the information-based asset data fields, construct a digital security execution index system.

[0008] Further, in step S1, the information-based asset data includes the types, quantities, and usage status of assets. The asset types include hardware, software, middleware, databases, and service devices. The constructed standard metadata includes asset names, types, numbers, responsible persons, locations, and life cycles.

[0009] Further, step S2 includes setting the specific responsibilities, cooperation methods, and response times of each department or team in security work to form an OLA agreement.

[0010] Further, step S3 includes setting specific requirements and standards for service providers in terms of service content, response time, and service quality to form an SLA agreement; during the execution of the SLA, further refine the service content in the SLA framework to form a specific work breakdown structure, clarify the specific tasks, responsible persons, and completion times of each work, and combine the SLA framework of external service providers with the internal security work OLA framework.

[0011] Further, the security execution indicators constructed in step S4 include the security risk levels, the number of security incidents, response times, and processing results of various assets.

[0012] The present invention has the following beneficial effects compared with the prior art: The security control method based on information-based asset data standard specifications provided by the present invention can realize the systematic, standardized, and digital management of security work, and improve the security management efficiency and risk prevention and control capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 is the security control flow chart of the present invention based on information-based asset data standard specifications; Figure 2 is the schematic diagram of the corresponding relationship between the SLA and OLA frameworks of the present invention; Figure 3 This is a schematic diagram for the implementation of security control based on the information-based asset data standard specification of the present invention. Detailed implementation manners

[0014] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.

[0015] Figure 1 This is a flowchart of security control based on the information-based asset data standard specification of the invention.

[0016] Please refer to Figure 1 , the security control method based on the information-based asset data standard specification provided by the present invention includes the following processes: S1. Formulate a unified information-based asset data standard It is necessary to build a normalized and continuous execution method to conduct a comprehensive investigation of the information-based assets within the organization, including multiple aspects such as hardware, software, middleware, databases, service devices, etc., to understand the existing asset types, quantities, usage conditions, etc. Based on the investigation results, define the basic metadata of the asset data, such as asset name, type, number, responsible person, location, life cycle, etc. Build the standard metadata of the information-based assets. On this basis, establish the master data standard to ensure the consistency of the data formats, coding rules, etc. of the same type of assets, and reduce data redundancy and errors. By combining the industry characteristics, organizational characteristics, and business characteristics of the organization, based on the data standard, specify the classification and grading framework of the information-based asset data. On this architecture, design the information-based asset data model to clarify the relationships and hierarchical structures between the data, which is convenient for data storage, query, and analysis. Promote the formulated data standard within the organization and train the relevant personnel of the organization to ensure that everyone can understand and follow the standard.

[0017] S2. Build an internal security work standard (OLA framework) The OLA (Operational Level Agreement) framework refers to the agreement on the responsibilities and obligations of security work between various departments or teams within the organization, which clarifies their respective responsibilities and cooperation methods in security work. Through the OLA framework, clarify the specific responsibilities of each department or team in security work, and avoid the phenomenon of shifting responsibilities due to unclear responsibilities. Promote communication and cooperation between various departments or teams, form a joint force, and jointly improve the organization's security protection ability. Through clear division of responsibilities and cooperation mechanisms, improve work efficiency and ensure the effective implementation of security work.

[0018] Develop an OLA framework based on information technology asset data standards. Classify and evaluate assets according to the information technology asset data standards to determine the security risk levels of various types of assets. Divide security work responsibilities based on the risk levels of assets and the actual situations of each department or team. Define the responsible persons for each position. Clearly define the specific responsibilities, collaboration methods, response times, etc. of each department or team in security work to form an OLA agreement. Continuously improve and publicize it to form a normalized security work. In daily security work, ensure that each department or team fulfills its security responsibilities according to the requirements of the agreement through the OLA framework, promptly discover and handle security risks, and ensure the security of information technology assets.

[0019] S3. Establish security work standards for external service providers (SLA framework capabilities) The SLA (Service Level Agreement) framework refers to the agreement between an organization and an external service provider regarding the quality and level of security services, clearly defining the specific requirements and standards for the service provider in security work. Through the SLA framework, clarify the specific requirements and standards for the service provider in security work to ensure service quality and level. The organization can regulate and evaluate the behavior of the service provider based on the SLA framework, preventing security risks caused by improper operations of the service provider. Provide a basis for the organization to conduct assessments and evaluations of the service provider internally to ensure that the service provider can provide security services according to the requirements of the agreement.

[0020] Based on the inventory of information technology assets, form an SLA framework. It is necessary to comprehensively inventory information technology assets, analyze the security requirements and risk points of various types of assets. Define the specific service contents that the service provider needs to provide according to the security requirements and risk points of the assets. Clearly define the specific requirements and standards for the service provider in terms of service contents, response times, service quality, etc. to form an SLA agreement. Sign an SLA agreement with the service provider based on a contract or service agreement and monitor its implementation to ensure that the service provider can provide security services according to the requirements of the agreement.

[0021] During the implementation of the SLA, further refine the service contents in the SLA framework to form a specific work breakdown structure (WBS), clearly defining the specific tasks, responsible persons, completion times, etc. for each piece of work. At the same time, organize the security management department to combine the SLA framework of external service providers with the internal security work OLA framework to ensure seamless connection and coordinated operation of internal and external security work, such as Figure 2 shown.

[0022] S4. Achieve digital management of security work Based on the SLA (Service Level Agreement) framework and the OLA (Operational Level Agreement) framework, combined with the data fields of information assets, the security management department of the organization has constructed a digital security execution indicator system. These indicators comprehensively cover key elements such as the security risk levels of various assets, the number of security incidents, response times, and handling results. To ensure the timeliness and accuracy of data, the security management department of the organization has seamlessly connected the digital security execution indicators with the information asset data management system, achieving real-time data updates and sharing.

[0023] Through advanced data analysis and mining techniques, the security management department of the organization can gain in-depth insights into potential security risks and problems, providing strong support for timely taking countermeasures. To further enhance the transparency and efficiency of security management work, the security management department of the organization has established a security work dashboard and reporting system, presenting the digital security execution indicators in intuitive and easy-to-understand charts, reports, etc. In this way, each department or team can understand the security work status in real time, discover problems in a timely manner, and take corresponding improvement measures.

[0024] The security management department of the organization closely combines the digital security execution indicators with the security work performance assessment of each department or team to ensure the effective implementation of all security work. For teams or individuals with ineffective implementation, the security management department of the organization will take supervision and rectification measures to continuously improve the security protection ability of the entire organization. Through the implementation of the above measures, the security management department of the organization can more efficiently manage the security risks of information assets and ensure the stable operation of the organization's information system.

[0025] The present invention is the implementation of a network security management and execution framework based on big data and data analysis frameworks. It forms the ability of information asset management, forms the digital ability of security work, forms the OLA framework ability for the internal organization, and forms the security service SLA framework for external service providers. The present invention can comprehensively construct the execution standards and assessment standards for the organization's security work and external service work. All the execution standards are effectively combined with the information asset data. Based on the work breakdown structure, the security work execution implementation management system is implemented in each team and department of the organization. The security management ability formed by the present invention based on the information digital management architecture is as Figure 3As shown in the figure. The present invention belongs to a solution for pre-risk identification and pre-security compliance specification control. If solutions with other ideas are adopted, generally, methods based on risk-based security management methods or strategies need to be carried out with reference to the requirements of compliance work. However, the disadvantage is that risk assessment work on information technology assets needs to be done first. Using risk assessment tools and technologies, a comprehensive risk analysis of information technology assets is carried out. According to the risk level, the priorities and resource allocations of security management are determined. The goals and requirements of security policies are clarified, and corresponding implementation plans and measures are formulated. Through technical and management means, the effective implementation and monitoring of the policies are ensured. The evaluation may have certain subjectivity and uncertainty and needs to be continuously updated and adjusted. It is impossible to form necessary execution standards and assessment standards through digital means.

[0026] The security control method based on the data standard specification of information technology assets provided by the present invention has the following characteristics: 1. Unified data standard for information technology assets In the information age, a unified data standard for information technology assets is the cornerstone of security work. This standard not only provides a solid foundation for the standardized management of security work but also ensures the accuracy and consistency of asset data. By formulating and implementing a unified data standard, an organization can ensure that all relevant departments and teams follow the same rules and formats when processing asset data, thus avoiding data chaos and misunderstandings.

[0027] Specifically, the unified data standard for information technology assets should include key elements such as the basic information, attributes, classification, location, and responsible persons of assets, and clarify the coding rules, storage formats, update frequencies, etc. of the data. At the same time, the standard should also stipulate the confidentiality level and access rights of the data to ensure the security and compliance of sensitive data.

[0028] 2. Combination of internal and external security work standards To achieve comprehensive coverage and effective coordination of security work, an organization combines the internal security work standard (OLA framework) with the external service provider's security work standard (SLA framework) for the first time. The OLA framework mainly focuses on the internal security work processes, responsibility assignments, and response times within the organization, while the SLA framework focuses on the security service levels and quality guarantees provided by external service providers.

[0029] By combining these two frameworks, an organization can ensure that the internal and external security work standards complement each other and are coordinated. This can not only improve the overall efficiency and effectiveness of security work but also enhance the trust and cooperation between the organization and external service providers. For example, an organization can sign a clear service level agreement with an external service provider, stipulating the specific requirements and responsibilities of the service provider in aspects such as security incident response and data backup and recovery, to ensure a rapid and effective response in the event of a security incident.

[0030] 3. Digital management, transforming safety work specifications into executable data metrics Digital management is the key to improving the accuracy and efficiency of safety management. By transforming safety work specifications into executable data metrics, organizations can more precisely monitor and evaluate the implementation of safety work. These data metrics should include key elements such as the safety risk levels of various assets, the number of safety incidents, response times, and handling results.

[0031] To achieve digital management, organizations need to establish an information-based asset data management system and interface the digital safety implementation metrics with this system. In this way, the system can collect, store, and analyze safety data in real time, providing organizations with a comprehensive view of safety work. At the same time, organizations can also use data analysis and mining techniques to discover potential safety risks and problems, providing a basis for formulating targeted safety strategies.

[0032] In addition, organizations should also establish a safety work dashboard or reporting system to present the digital safety implementation metrics in the form of charts, reports, etc. In this way, each department or team can intuitively understand the safety work status, promptly discover problems, and take corresponding improvement measures. By combining the digital safety implementation metrics with the safety work performance assessment of each department or team, organizations can ensure the effective implementation of various safety work and continuously enhance the overall safety protection ability.

[0033] The safety control method based on the information-based asset data standard specifications provided by the present invention has the following beneficial effects: 1. Improving the efficiency of internal safety management within the organization By implementing a unified information-based asset data standard, the organization has achieved the standardization and normalization of asset data, greatly simplifying the safety management process. Standardized data formats and coding rules reduce the complexity and error rate of data processing, enabling safety management personnel to obtain, analyze, and utilize asset data more quickly. At the same time, combined with the safety work standards of the internal OLA framework and the external SLA framework, the division of responsibilities and response requirements for safety work are clarified, further improving the implementation efficiency of safety management. This improvement in efficiency not only reduces the labor and time costs of safety management but also increases the response speed and handling quality of safety incidents.

[0034] 2. Enhancing the organization's ability to prevent and control safety work risks The application of digital management technology enables organizations to monitor and warn of security risks in real time. Through the information-based asset data management system, organizations can collect, store, and analyze the security data of various assets in real time, and timely discover potential security hazards and risk points. At the same time, combined with data analysis and mining technologies, organizations can deeply explore the laws and trends behind the data, providing a scientific basis for formulating targeted security strategies. This real-time monitoring and warning mechanism greatly enhances the organization's risk prevention and control capabilities, effectively reducing the probability and impact of security incidents.

[0035] 3. Promote the optimization of resource allocation for external service provider institutions and internal management teams Through a clear work breakdown structure and minimized executable work packages, the organization has optimized the resource allocation for security work. The work breakdown structure decomposes complex security work into a series of clear and specific work tasks, making resource allocation more reasonable and efficient. And the minimized executable work packages ensure that each work task can be effectively executed and monitored, avoiding waste and redundancy of resources. This optimization of resource allocation not only improves resource utilization efficiency but also enhances the flexibility and response ability of security work.

[0036] 4. Promote internal and external collaboration Uniform standards and digital management promote effective collaboration between the organization's internal and external service providers. By formulating and implementing uniform information-based asset data standards and work process standards, each department within the organization and external service providers can operate and collaborate according to the same rules and processes, reducing communication and coordination barriers. At the same time, the application of digital management technology enables real-time sharing and transmission of internal and external information, further enhancing the collaboration effect. This improvement in internal and external collaboration not only raises the overall level of security management but also enhances the organization's adaptability and market competitiveness.

[0037] 5. Promote the development of informatization The implementation of the present invention also promotes the informatization development of enterprises and organizations. By constructing an information-based asset data management system and a digital security execution index system, the organization has achieved the digitization, networking, and intelligence of asset management and security work. This informatization development not only improves the organization's management efficiency and decision-making level but also enhances the organization's innovation ability and market adaptability. With the continuous improvement of the informatization level, the organization will be able to better respond to market changes and competition challenges, enhancing its overall competitiveness and market position.

[0038] Although the present invention has been disclosed above with preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications and improvements without departing from the spirit and scope of the present invention. Therefore, the protection scope of the present invention shall be defined by the claims.

Claims

1. A security management and control method based on information asset data standard specification, characterized in that: The steps include: S1) Formulate unified data standards for information assets: construct standard metadata for information assets, establish master data standards, and keep the data format and coding rules of the same type of assets consistent; set up a classification and grading framework for information asset data, and clarify the relationship and hierarchy between data; S2) Establish internal security work standards: Develop an OLA framework based on information asset data standards, classify and evaluate assets, and determine the security risk level of each type of asset; S3) Establish security standards for external service providers: conduct a comprehensive review of information assets, analyze the security requirements and risk points of various assets, and form an SLA framework; S4) Realize digital management of security work: Based on the SLA framework and OLA framework, combined with information asset data fields, build a digital security execution indicator system.

2. The security control method based on information asset data standard specification according to claim 1 is characterized in that: The information asset data in step S1 includes asset types, quantities and usage status. The asset types include hardware, software, middleware, databases and service equipment. The constructed standard metadata includes asset name, type, number, responsible person, location and life cycle.

3. The security control method based on information asset data standard specification according to claim 1 is characterized in that: The step S2 includes setting specific responsibilities, collaboration methods and response time of each department or team in security work to form an OLA agreement.

4. The security control method based on information asset data standard specification according to claim 1 is characterized in that: The step S3 includes setting specific requirements and standards of the service provider in terms of service content, response time and service quality to form an SLA agreement; during the execution of the SLA, the service content in the SLA framework is further refined to form a specific work breakdown structure, clarifying the specific tasks, responsible persons and completion time of each work, and combining the SLA framework of the external service provider with the internal security work OLA framework.

5. The security control method based on information asset data standard specification according to claim 1 is characterized in that: The security execution indicators constructed in step S4 include the security risk level of each type of assets, the number of security incidents, the response time and the processing results.