Data security compliance risk assessment system

By designing a data security compliance risk assessment system that includes risk factor collection, evaluation data processing, risk degree analysis and early warning modules, the problem of difficulty in quantifying and evaluating data risks in existing systems is solved, and a more accurate and intelligent risk assessment is achieved.

CN120180469AInactive Publication Date: 2025-06-20王燕勃
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510248107.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2025-06-20
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing data security compliance risk assessment system is difficult to measure and quantify the risk factor indicators of the data, and evaluate the risk status of the data based on these indicators, affecting the risk assessment results of data security compliance.

Method used

A data security compliance risk assessment system is designed, including a risk factor acquisition module, an evaluation data processing module, a data risk degree analysis module and a risk data early warning module. By calculating the incidence rate of risk events, data backup and recovery time compliance rate, security vulnerability severity and emergency response rate, and using a random forest algorithm to construct a data risk assessment model to evaluate the risk level and status of the data.

Benefits of technology

It realizes the accurate quantification and evaluation of data risk factors, improves the accuracy and intelligence of data security compliance risk assessment, and ensures the improvement of data security protection level.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180469A_ABST
    Figure CN120180469A_ABST
Patent Text Reader

Abstract

The invention, which relates to the technical field of data security compliance risk assessment, discloses a data security compliance risk assessment system comprising a risk factor acquisition module, an assessment data processing module, a data risk degree analysis module and a risk data early warning module. The risk factor acquisition module is used for acquiring risk event data, data backup data, security vulnerability data and emergency response data; the assessment data processing module is used for assessing the risk degree of the data; the data risk degree analysis module is used for analyzing the risk factor data and obtaining a risk degree evaluation result; according to the system, a data entry technology, an intrusion monitoring technology and a vulnerability scanning technology are closely combined with a modern information technology, and related calculation is combined, so that the purpose of quantifying data risk factors is achieved; therefore, the dynamic monitoring standard of the data security compliance risk assessment system can be refined more accurately.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security compliance risk assessment, and specifically to a data security compliance risk assessment system. Background Art

[0002] With the rapid development of information technology, enterprises and organizations have accumulated a vast amount of data during the digital transformation process, covering various types of sensitive information such as customer information, business secrets, and financial data. At the same time, data security threats have become increasingly severe. Events such as cyberattacks, data breaches, and malware intrusions occur frequently, bringing huge economic losses and reputational damage to enterprises. Currently, many enterprises lack an effective data security compliance risk assessment mechanism, making it difficult to comprehensively and accurately identify potential risks and unable to take corresponding measures in a timely manner for prevention and response. There is an urgent need for a data security compliance risk assessment system that, by integrating various technical means, comprehensively sorts out and scans the risk of an enterprise's data assets, accurately quantifies the degree of risk based on relevant laws, regulations, and industry standards, provides a clear insight into the risk situation for the enterprise, helps it formulate reasonable security strategies, improve the data security protection level, and ensure the stable operation and sustainable development of the enterprise;

[0003] Although the existing data security compliance risk assessment systems have made great progress, there are still some problems to be optimized. In the data security compliance risk assessment system, it is difficult to measure and quantify the risk factor indicators of the data and evaluate the risk status of the data based on the risk factor indicators, which affects the risk assessment results of data security compliance. Summary of the Invention

[0004] To achieve the above objectives, the present invention is realized through the following technical solutions: A data security compliance risk assessment system, including a risk factor collection module, an assessment data processing module, a data risk degree analysis module, and a risk data warning module;

[0005] The risk factor collection module is used to obtain risk event data, data backup data, security vulnerability data, and emergency response data;

[0006] The assessment data processing module is divided into a risk assessment calculation unit, an assessment standard division unit, and an assessment degree processing unit. Among them, the risk factor calculation unit is used to calculate the risk event occurrence rate, the data backup recovery time compliance rate, the security vulnerability severity, and the emergency response rate; the assessment risk status unit is used to evaluate the risk status of the data according to the risk factors; the assessment degree processing unit uses the random forest algorithm to construct a data risk degree assessment model;

[0007] The data risk level analysis module analyzes risk event data, data backup data, security vulnerability data, and emergency response data to evaluate the risk level of the data;

[0008] The risk data warning module receives the evaluation results of the data risk level analysis module and issues a warning message to remind the client to execute response measures;

[0009] Furthermore, the risk event data is the total number of business operations within one month and the number of data security risk events occurring within one month. The acquisition process includes:

[0010] Using an intrusion detection system, the event logs generated within one month are monitored in real time, the data security risk events are screened out, and the number of data security risk events occurring within one month is recorded;

[0011] Determine the storage location of the business system operation logs, use a data analysis tool to screen out the operation logs within one month, and through the counting function of the data analysis tool, count the subset of the operation logs within one month that is screened out to obtain the total number of business operations within one month.

[0012] Furthermore, the data backup data is the total number of times of data backup and recovery required within one month and the number of times of data backup and recovery completed within two hours. The acquisition process includes:

[0013] Using a data backup and recovery management system, determine the time range as one month, screen out the task records of data backup and recovery required within one month and the task records of data backup and recovery completed within one month, count the screened records, and obtain the total number of times of data backup and recovery required within one month and the number of times of data backup and recovery completed within one month.

[0014] Furthermore, the security vulnerability data is the total sum of security vulnerability severity scores and the total number of security vulnerabilities. The acquisition process includes:

[0015] Use a vulnerability scanning tool to scan the target system. After the scanning is completed, the vulnerability scanning tool generates a scanning report. Then, import the data in the scanning report into Excel. In the Excel data, retrieve the column of the total number of security vulnerabilities to obtain the total number of security vulnerabilities. In the Excel data, retrieve the column of the security vulnerability severity scores to obtain the security vulnerability severity scores, and then sum up the security vulnerability severity scores to obtain the total sum of security vulnerability severity scores.

[0016] Furthermore, the emergency response data is the total number of data security events within 24 hours and the number of data security events for which emergency response is initiated. The acquisition process includes:

[0017] Log in to the SIEM system management platform, find the time filtering option on the SIEM system query page, set the time range to 24 hours, execute the query operation, view the number of query results, and obtain the total number of data security incidents within 24 hours; then query the alarm and notification records of the SIEM system, find the alarms of the emergency response program, filter out the data security incidents associated with the alarms, view the number of filtered results, and obtain the number of data security incidents that have initiated an emergency response within 24 hours.

[0018] Further, the risk assessment calculation unit calculates the risk event incidence rate, data backup and recovery time compliance rate, security vulnerability severity, and emergency response rate as follows:

[0019] S1. Preprocess the collected risk event data, data backup data, security vulnerability data, and emergency response data;

[0020] S2. Use the preprocessed risk event data to calculate the risk event incidence rate:

[0021]

[0022] Where A is the risk event incidence rate, a0 is the total number of business operations in a month, and a is the number of data security risk events that occurred in a month;

[0023] S3. Use the preprocessed data backup data to calculate the data backup and recovery time compliance rate:

[0024]

[0025] Where B is the data backup and recovery time compliance rate, b0 is the total number of data backup and recovery operations required in a month, and b is the number of data backup and recovery operations completed in a month;

[0026] S4. Use the preprocessed security vulnerability data to calculate the security vulnerability severity:

[0027]

[0028] Where C is the security vulnerability severity, c0 is the total score of security vulnerability severity ratings, and c is the total number of security vulnerabilities;

[0029] S5. Use the preprocessed emergency response data to calculate the emergency response rate:

[0030]

[0031] Where D is the emergency response rate, d0 is the total number of data security incidents within 24 hours, and d is the number of data security incidents that have initiated an emergency response.

[0032] Further, the process of the risk status evaluation unit for evaluating the risk status of data based on risk factors includes:

[0033] Data with a risk event occurrence rate lower than 0.01% is set as low risk, data with a risk event occurrence rate between 0.01% and 0.1% is set as medium risk, and data with a risk event occurrence rate higher than 0.1% is set as high risk;

[0034] Data with a data backup and recovery time compliance rate of more than 80% is set as low risk, data with a data backup and recovery time compliance rate between 60% and 80% is set as medium risk, and data with a data backup and recovery time compliance rate lower than 60% is set as high risk;

[0035] Data with a security vulnerability severity below 4 points is set as low risk, data with a security vulnerability severity between 4 and 7 points is set as medium risk, and data with a security vulnerability severity above 7 points is set as high risk;

[0036] Data with an emergency response rate higher than 70% is set as low risk, data with an emergency response rate between 50% and 70% is set as medium risk, and data with an emergency response rate lower than 50% is set as high risk;

[0037] During the risk assessment process of the data security compliance risk assessment system, when the risk event occurrence rate, data backup and recovery time compliance rate, security vulnerability severity, and emergency response rate of the evaluated data are all in the low-risk state, the evaluated data is in the low-risk state; when there are risk factors in the medium-risk state among the risk event occurrence rate, data backup and recovery time compliance rate, security vulnerability severity, and emergency response rate of the evaluated data without being in the high-risk state, the evaluated data is in the medium-risk state; when there are risk factors in the high-risk state among the risk event occurrence rate, data backup and recovery time compliance rate, security vulnerability severity, and emergency response rate of the evaluated data, the evaluated data is in the high-risk state.

[0038] Further, the process of the evaluation degree processing unit for constructing a data risk degree evaluation model using the random forest algorithm includes:

[0039] Taking the risk event data, data backup data, security vulnerability data, and emergency response data as a data set, dividing it into a training set and a test set according to a ratio of 7:3, and selecting random forest model parameters;

[0040] The random forest model is trained using the data in the training set. Through iterative learning, the non-linear relationship between risk event data, data backup data, security vulnerability data, and emergency response data and the data risk level is obtained. When the evaluation data corresponding to the risk event data, data backup data, security vulnerability data, and emergency response data is in a low-risk state, the data risk level output by the random forest model is lower than 20%; when the evaluation data corresponding to the risk event data, data backup data, security vulnerability data, and emergency response data is in a medium-risk state, the data risk level output by the random forest model is between 20% and 60%; when the evaluation data corresponding to the risk event data, data backup data, security vulnerability data, and emergency response data is in a high-risk state, the data risk level output by the random forest model is higher than 60%.

[0041] The performance of the random forest model is evaluated using the test set. According to the difference between the actual data risk level of the data and the data risk level output by the random forest model, the model parameters are adjusted to optimize the random forest model, and the random forest model is deployed into the data security compliance risk assessment system to obtain the data risk level assessment model.

[0042] Furthermore, in the data risk level analysis module, the process of analyzing the risk event data, data backup data, security vulnerability data, and emergency response data and evaluating the data risk level includes:

[0043] Analyze the risk event data, data backup data, security vulnerability data, and emergency response data, and combine with the data risk level assessment model. When the risk event occurrence rate, data backup recovery time compliance rate, security vulnerability severity, and emergency response rate of the evaluation data are all in a low-risk state, the data risk level is lower than 20%; when there are risk factors in the medium-risk state among the risk event occurrence rate, data backup recovery time compliance rate, security vulnerability severity, and emergency response rate of the evaluation data without being in a high-risk state, the data risk level is between 20% and 60%; when there are risk factors in the high-risk state among the risk event occurrence rate, data backup recovery time compliance rate, security vulnerability severity, and emergency response rate of the evaluation data, the data risk level is higher than 60%.

[0044] Furthermore, in the risk data warning module, the process of receiving the evaluation result of the data risk level analysis module and sending a warning message to remind the client to execute the response measure includes:

[0045] Receives the evaluation results of the data risk level analysis module. When the data risk level is lower than 20%, it issues a low-risk warning signal, and the client regularly collects and analyzes data risk factors for detection to maintain continuous monitoring of the data. When the data risk level is between 20% and 60%, it issues a medium-risk warning signal, and the client reviews and improves the existing emergency response plan, and takes specific risk reduction measures for the specified targeted risk factors. When the data risk level is higher than 60%, it issues a high-risk warning signal, reminding the client to activate the highest-level security response mechanism and conduct a comprehensive review and rectification of the data with high-risk factors.

[0046] The beneficial effects of the present invention are as follows: A data security compliance risk assessment system. Compared with traditional data security compliance risk assessment systems, the data entry technology, intrusion monitoring technology, and vulnerability scanning technology in the system of the present invention are closely combined with modern information technology to accurately capture risk event data, data backup data, security vulnerability data, and emergency response data, and obtain the total number of business operations within one month, the number of data security risk events occurring within one month, the total number of data backup and recovery required within one month and the number of data backup and recovery completed within two hours, the total score of security vulnerability severity ratings and the total number of security vulnerabilities, the total number of data security events within 24 hours, and the number of data security events that initiate emergency responses, achieving real-time and comprehensive monitoring of the evaluation data. By calculating the risk event incidence rate, the data backup and recovery time compliance rate, the security vulnerability severity, and the emergency response rate, the purpose of quantifying the risk factors of the data is achieved, and the risk status of the data is evaluated. Using the random forest algorithm, a data risk level assessment model is constructed to output the risk level of the data, solving the problem that it is difficult to measure and quantify the risk factor indicators existing in the data in the data security compliance risk assessment system, and evaluating the risk status of the data based on the risk factor indicators, which affects the risk assessment results of data security compliance, ensuring that the method in the present invention can refine the dynamic monitoring standard of the data security compliance risk assessment system within a more accurate range, making the monitored data more accurate indicators under the same conditions. The research and application of this method significantly enhance the degree of intelligence in the data security compliance risk assessment process. Brief Description of the Drawings

[0047] Figure 1 It is a block diagram of a data security compliance risk assessment system of the present invention. Detailed Embodiments

[0048] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0049] As Figure 1 shown, the present invention provides a technical solution: a data security compliance risk assessment system, including a risk factor collection module, an evaluation data processing module, a data risk degree analysis module, and a risk data warning module;

[0050] The risk factor collection module is used to obtain risk event data, data backup data, security vulnerability data, and emergency response data;

[0051] The evaluation data processing module is divided into a risk assessment calculation unit, an evaluation standard division unit, and an evaluation degree processing unit. Among them, the risk factor calculation unit is used to calculate the risk event occurrence rate, the data backup recovery time compliance rate, the security vulnerability severity, and the emergency response rate; the evaluation risk status unit is used to evaluate the risk status of the data according to the risk factors; the evaluation degree processing unit uses the random forest algorithm to construct a data risk degree evaluation model;

[0052] The data risk degree analysis module analyzes the risk event data, data backup data, security vulnerability data, and emergency response data, and evaluates the risk degree of the data;

[0053] The risk data warning module receives the evaluation results of the data risk degree analysis module and issues a warning message to remind the client to execute response measures;

[0054] The risk event data is the total number of business operations within one month and the number of data security risk events occurring within one month. The acquisition process includes:

[0055] Using an intrusion detection system, real-time monitor the event logs generated within one month, filter out the data security risk events, and record the number of data security risk events occurring within one month;

[0056] Determine the storage location of the business system operation logs, use a data analysis tool to filter out the operation logs within one month, and through the counting function of the data analysis tool, count the subset of the operation logs within one month that has been filtered out to obtain the total number of business operations within one month.

[0057] The data backup data is the total number of times data backup and recovery are required within one month and the number of times data backup and recovery are completed within two hours. The acquisition process includes:

[0058] Using a data backup and recovery management system, determine the time range to be one month, filter out task records that require data backup and recovery within one month and task records that have completed data backup and recovery within one month, count the filtered records, and obtain the total number of times data backup and recovery are required within one month and the number of times data backup and recovery have been completed within one month.

[0059] The security vulnerability data is the sum of the security vulnerability severity scores and the total number of security vulnerabilities. The process of obtaining it includes:

[0060] Use a vulnerability scanning tool to scan the target system. After the scanning is completed, the vulnerability scanning tool generates a scanning report, and then import the data in the scanning report into Excel. Retrieve the column of the total number of security vulnerabilities in the Excel data to obtain the total number of security vulnerabilities. Retrieve the column of the security vulnerability severity scores in the Excel data to obtain the security vulnerability severity scores, and then sum up the security vulnerability severity scores to obtain the sum of the security vulnerability severity scores.

[0061] The emergency response data is the total number of data security incidents within 24 hours and the number of data security incidents for which emergency response has been initiated. The process of obtaining it includes:

[0062] Log in to the SIEM system management platform, find the time filtering option on the SIEM system query page, set the time range to 24 hours, execute the query operation, view the number of query results, and obtain the total number of data security incidents within 24 hours; then query the alarm and notification records of the SIEM system, find the alarms of the emergency response program, filter out the data security incidents associated with the alarms, view the number of filtered results, and obtain the number of data security incidents for which emergency response has been initiated within 24 hours.

[0063] The process of calculating the risk event incidence rate, the data backup and recovery time compliance rate, the security vulnerability severity, and the emergency response rate by the risk assessment calculation unit includes:

[0064] S1. Preprocess the collected risk event data, data backup data, security vulnerability data, and emergency response data;

[0065] S2. Use the preprocessed risk event data to calculate the risk event incidence rate:

[0066]

[0067] Where A is the risk event incidence rate, a0 is the total number of business operations within one month, and a is the number of data security risk events that occurred within one month;

[0068] S3. Use the preprocessed data backup data to calculate the data backup and recovery time compliance rate:

[0069]

[0070] Among them, B is the compliance rate of data backup and recovery time, b0 is the total number of times data backup and recovery are required within one month, and b is the number of times data backup and recovery are completed within one month;

[0071] S4. Use the preprocessed security vulnerability data to calculate the severity of security vulnerabilities:

[0072]

[0073] Among them, C is the severity of security vulnerabilities, c0 is the total score of security vulnerability severity ratings, and c is the total number of security vulnerabilities;

[0074] S5. Use the preprocessed emergency response data to calculate the emergency response rate:

[0075]

[0076] Among them, D is the emergency response rate, d0 is the total number of data security incidents within 24 hours, and d is the number of data security incidents for which emergency response is initiated.

[0077] The process of evaluating the risk status unit and evaluating the risk status of data according to risk factors includes:

[0078] Set the data with a risk event occurrence rate lower than 0.01% as low risk, the data with a risk event occurrence rate between 0.01% and 0.1% as medium risk, and the data with a risk event occurrence rate higher than 0.1% as high risk;

[0079] Set the data with a data backup and recovery time compliance rate above 80% as low risk, the data with a data backup and recovery time compliance rate between 60% and 80% as medium risk, and the data with a data backup and recovery time compliance rate below 60% as high risk;

[0080] Set the data with a security vulnerability severity below 4 points as low risk, the data with a security vulnerability severity between 4 and 7 points as medium risk, and the data with a security vulnerability severity above 7 points as high risk;

[0081] Set the data with an emergency response rate higher than 70% as low risk, the data with an emergency response rate between 50% and 70% as medium risk, and the data with an emergency response rate below 50% as high risk;

[0082] During the risk assessment process of the data security compliance risk assessment system, when the incidence rate of risk events, the compliance rate of data backup and recovery time, the severity of security vulnerabilities, and the emergency response rate of the evaluated data are all at low risk, the evaluated data is in a low-risk state; when there are risk factors at medium risk among the incidence rate of risk events, the compliance rate of data backup and recovery time, the severity of security vulnerabilities, and the emergency response rate of the evaluated data without being at high risk, the evaluated data is in a medium-risk state; when there are risk factors at high risk among the incidence rate of risk events, the compliance rate of data backup and recovery time, the severity of security vulnerabilities, and the emergency response rate of the evaluated data, the evaluated data is in a high-risk state.

[0083] The evaluation degree processing unit uses the random forest algorithm. The process of constructing the data risk degree evaluation model includes:

[0084] Taking the risk event data, data backup data, security vulnerability data, and emergency response data as a data set, dividing it into a training set and a test set according to a ratio of 7:3, and selecting the random forest model parameters;

[0085] Using the data in the training set to train the random forest model. Through iterative learning, obtain the non-linear relationship between the risk event data, data backup data, security vulnerability data, emergency response data, and the data risk degree. When the evaluated data corresponding to the risk event data, data backup data, security vulnerability data, and emergency response data is in a low-risk state, the data risk degree output by the random forest model is lower than 20%; when the evaluated data corresponding to the risk event data, data backup data, security vulnerability data, and emergency response data is in a medium-risk state, the data risk degree output by the random forest model is between 20% and 60%; when the evaluated data corresponding to the risk event data, data backup data, security vulnerability data, and emergency response data is in a high-risk state, the data risk degree output by the random forest model is higher than 60%;

[0086] Using the test set to evaluate the performance of the random forest model. According to the difference between the actual data risk degree of the data and the data risk degree output by the random forest model, adjust the model parameters, optimize the random forest model, and deploy the random forest model into the data security compliance risk assessment system to obtain the data risk degree evaluation model.

[0087] The data risk degree analysis module analyzes the risk event data, data backup data, security vulnerability data, and emergency response data. The process of evaluating the risk degree of the data includes:

[0088] Analyze risk event data, data backup data, security vulnerability data, and emergency response data. Combining with the data risk degree assessment model, when the incidence rate of risk events, the compliance rate of data backup recovery time, the severity of security vulnerabilities, and the emergency response rate of the evaluated data are all at low risk, the data risk degree is lower than 20%; when there are risk factors at medium risk among the incidence rate of risk events, the compliance rate of data backup recovery time, the severity of security vulnerabilities, and the emergency response rate of the evaluated data without being at high risk, the data risk degree is between 20% and 60%; when there are risk factors at high risk among the incidence rate of risk events, the compliance rate of data backup recovery time, the severity of security vulnerabilities, and the emergency response rate of the evaluated data, the data risk degree is higher than 60%.

[0089] The process of the risk data warning module receiving the evaluation result of the data risk degree analysis module and sending out a warning message to remind the client to execute response measures includes:

[0090] Receive the evaluation result of the data risk degree analysis module. When the data risk degree is lower than 20%, send out a low-risk warning signal, and let the client regularly collect and analyze data risk factors for detection to maintain continuous monitoring of the data; when the data risk degree is between 20% and 60%, send out a medium-risk warning signal, and let the client review and improve the existing emergency response plan and take specific risk reduction measures for the specified targeted risk factors; when the data risk degree is higher than 60%, send out a high-risk warning signal to remind the client to activate the highest-level security response mechanism and conduct a comprehensive review and rectification of the data with high-risk factors.

[0091] First, collect the total number of business operations within a month and the number of data security risk events occurring within a month using the business system operation log and the intrusion detection system respectively. Collect the total number of data backup and recovery operations required within a month and the number of completed data backup and recovery operations within a month using the data backup and recovery management system. Collect the total severity score of security vulnerabilities and the total number of security vulnerabilities through the vulnerability scanning tool, and use the SIEM system management platform to obtain the total number of data security events within 24 hours and the number of data security events triggering emergency responses. Secondly, calculate the risk event incidence rate, the data backup and recovery time compliance rate, the severity of security vulnerabilities, and the emergency response rate, and evaluate the risk status of the data. Immediately afterwards, use the random forest algorithm to construct a data risk degree assessment model to obtain the non-linear relationship between risk event data, data backup data, security vulnerability data, emergency response data, and the data risk degree, so that when the risk event data, data backup data, security vulnerability data, and emergency response data corresponding to the evaluation data are in a low-risk state, the data risk degree output by the random forest model is less than 20%; when the risk event data, data backup data, security vulnerability data, and emergency response data corresponding to the evaluation data are in a medium-risk state, the data risk degree output by the random forest model is between 20% and 60%; when the risk event data, data backup data, security vulnerability data, and emergency response data corresponding to the evaluation data are in a high-risk state, the data risk degree output by the random forest model is higher than 60%. Finally, combine the data risk degree assessment model to analyze the risk event data, data backup data, security vulnerability data, and emergency response data. When the data risk degree is less than 20%, send a low-risk warning signal, and the client regularly collects and analyzes data risk factors for detection to maintain continuous monitoring of the data; when the data risk degree is between 20% and 60%, send a medium-risk warning signal, and the client reviews and improves the existing emergency response plan and takes specific risk reduction measures for specific risk factors; when the data risk degree is higher than 60%, send a high-risk warning signal to remind the client to activate the highest-level security response mechanism and conduct a comprehensive review and rectification of the data with high-risk factors.

[0092] It should be noted that, in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising said element.

[0093] Although the embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention, and the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A data security compliance risk assessment system, comprising a risk factor collection module, an assessment data processing module, a data risk level analysis module and a risk data early warning module, characterized in that: The risk factor collection module is used to obtain risk event data, data backup data, security vulnerability data and emergency response data; The evaluation data processing module is divided into a risk evaluation calculation unit, an evaluation standard division unit and an evaluation degree processing unit, wherein the risk factor calculation unit is used to calculate the risk event occurrence rate, data backup and recovery time compliance rate, security vulnerability severity and emergency response rate; the risk status evaluation unit is used to evaluate the risk status of the data according to the risk factors; the evaluation degree processing unit uses the random forest algorithm to construct a data risk degree evaluation model; The data risk level analysis module analyzes risk event data, data backup data, security vulnerability data and emergency response data to assess the risk level of the data; The risk data early warning module receives the evaluation result of the data risk level analysis module and issues early warning information to remind the client to execute response measures.

2. A data security compliance risk assessment system according to claim 1, characterized in that: The risk event data refers to the total number of business operations and the number of data security risk events that occurred in a month. The acquisition process includes: Use the intrusion monitoring system to monitor the event logs generated within a month in real time, filter out data security risk events, and record the number of data security risk events that occurred within a month; Determine the storage location of the business system operation logs, use data analysis tools to filter out the operation logs within one month, and use the counting function of the data analysis tool to count the filtered subset of operation logs within one month to obtain the total number of business operations within one month.

3. A data security compliance risk assessment system according to claim 2, characterized in that: The data backup data is the total number of times data backup and recovery are required within a month and the number of times data backup and recovery are completed within two hours. The acquisition process includes: Using the data backup and recovery management system, the time range is determined as one month, and the task records that require data backup and recovery within one month and the task records that complete data backup and recovery within one month are screened out. The screened records are counted to obtain the total number of times data backup and recovery are required within one month and the number of times data backup and recovery are completed within one month.

4. A data security compliance risk assessment system according to claim 3, characterized in that: The security vulnerability data is the sum of the security vulnerability severity scores and the total number of security vulnerabilities, and the acquisition process includes: Use the vulnerability scanning tool to scan the target system. After the scan is completed, the vulnerability scanning tool generates a scan report, and then imports the data in the scan report into Excel, retrieves the column of the total number of security vulnerabilities in the Excel data, obtains the total number of security vulnerabilities, retrieves the column of the security vulnerability severity score in the Excel data, obtains the security vulnerability severity score, and then sums the security vulnerability severity scores to obtain the total security vulnerability severity score.

5. A data security compliance risk assessment system according to claim 4, characterized in that: The emergency response data is the total number of data security incidents within 24 hours and the number of data security incidents that triggered emergency responses. The acquisition process includes: Log in to the SIEM system management platform, find the time filtering option on the SIEM system query page, set a 24-hour time range, perform a query, view the number of query results, and obtain the total number of data security incidents within 24 hours; then query the SIEM system's alarm and notification records, find the alarms of the emergency response program, filter out the data security incidents associated with the alarms, view the number of filtered results, and obtain the number of data security incidents for which emergency responses were initiated within 24 hours.

6. A data security compliance risk assessment system according to claim 5, characterized in that: The process of the risk assessment calculation unit calculating the risk event occurrence rate, data backup and recovery time compliance rate, security vulnerability severity and emergency response rate includes: S1. Pre-process the collected risk event data, data backup data, security vulnerability data and emergency response data; S2. Calculate the risk event rate using the pre-processed risk event data: Where A is the risk event occurrence rate, a0 is the total number of business operations in a month, and a is the number of data security risk events that occur in a month; S3. Calculate the data backup and recovery time compliance rate using the pre-processed data backup data: Among them, B is the data backup and recovery time compliance rate, b0 is the total number of data backup and recovery required within a month, and b is the number of data backup and recovery completed within a month; S4. Calculate the severity of security vulnerabilities using the preprocessed security vulnerability data: Among them, C is the severity of the security vulnerability, c0 is the sum of the severity scores of the security vulnerabilities, and c is the total number of security vulnerabilities; S5. Calculate the emergency response rate using the pre-processed emergency response data: Among them, D is the emergency response rate, d0 is the total number of data security incidents within 24 hours, and d is the number of data security incidents that initiated emergency response.

7. A data security compliance risk assessment system according to claim 6, characterized in that: The process of the risk status assessment unit assessing the risk status of data according to the risk factors includes: The data with a risk event rate lower than 0.01% are set as low risk, the data with a risk event rate between 0.01% and 0.1% are set as medium risk, and the data with a risk event rate higher than 0.1% are set as high risk. Set the data with a data backup and recovery time compliance rate of more than 80% as low risk, the data with a data backup and recovery time compliance rate between 60% and 80% as medium risk, and the data with a data backup and recovery time compliance rate below 60% as high risk; Set the data with security vulnerability severity below 4 points as low risk, the data with security vulnerability severity between 4 and 7 points as medium risk, and the data with security vulnerability severity above 7 points as high risk; Set the data with an emergency response rate higher than 70% as low risk, the data with an emergency response rate between 50% and 70% as medium risk, and the data with an emergency response rate lower than 50% as high risk; During the risk assessment process of the data security compliance risk assessment system, when the risk event occurrence rate, data backup and recovery time compliance rate, security vulnerability severity and emergency response rate of the assessment data are all at low risk, the assessment data is in a low-risk state; when the risk event occurrence rate, data backup and recovery time compliance rate, security vulnerability severity and emergency response rate of the assessment data are not at high risk, but there are risk factors of medium risk, the assessment data is in a medium-risk state; when the risk event occurrence rate, data backup and recovery time compliance rate, security vulnerability severity and emergency response rate of the assessment data have risk factors of high risk, the assessment data is in a high-risk state.

8. A data security compliance risk assessment system according to claim 7, characterized in that: The process of constructing a data risk degree assessment model by the assessment degree processing unit using a random forest algorithm includes: The risk event data, data backup data, security vulnerability data and emergency response data are used as data sets, divided into training sets and test sets in a ratio of 7:3, and the random forest model parameters are selected; The random forest model is trained using the data from the training set. Through iterative learning, the nonlinear relationship between risk event data, data backup data, security vulnerability data, emergency response data and data risk level is obtained. When the assessment data corresponding to the risk event data, data backup data, security vulnerability data and emergency response data are in a low-risk state, the data risk level output by the random forest model is less than 20%; when the assessment data corresponding to the risk event data, data backup data, security vulnerability data and emergency response data are in a medium-risk state, the data risk level output by the random forest model is between 20% and 60%; when the assessment data corresponding to the risk event data, data backup data, security vulnerability data and emergency response data are in a high-risk state, the data risk level output by the random forest model is higher than 60%; Use the test set to evaluate the performance of the random forest model. According to the difference between the actual data risk level of the data and the data risk level output by the random forest model, adjust the model parameters, optimize the random forest model, and deploy the random forest model to the data security compliance risk assessment system to obtain the data risk level assessment model.

9. A data security compliance risk assessment system according to claim 8, characterized in that: The data risk level analysis module analyzes risk event data, data backup data, security vulnerability data and emergency response data, and the process of assessing the risk level of data includes: Analyze risk event data, data backup data, security vulnerability data and emergency response data, and combine them with the data risk level assessment model. When the risk event occurrence rate, data backup and recovery time compliance rate, security vulnerability severity and emergency response rate of the assessment data are all at low risk, the data risk level is less than 20%; when the risk event occurrence rate, data backup and recovery time compliance rate, security vulnerability severity and emergency response rate of the assessment data are not at high risk, but there are risk factors at medium risk, the data risk level is between 20% and 60%; when the risk event occurrence rate, data backup and recovery time compliance rate, security vulnerability severity and emergency response rate of the assessment data have risk factors at high risk, the data risk level is higher than 60%.

10. A data security compliance risk assessment system according to claim 9, characterized in that: The process of the risk data early warning module receiving the evaluation result of the data risk degree analysis module and issuing early warning information to remind the client to execute response measures includes: Receive the evaluation results of the data risk analysis module. When the data risk level is lower than 20%, a low-risk warning signal is issued. The client will regularly collect and analyze data risk factors for testing and maintain continuous monitoring of the data. When the data risk level is between 20% and 60%, a medium-risk warning signal is issued, and the client reviews and improves the existing emergency response plan, specifies targeted risk factors and takes specific risk reduction measures; When the data risk level is higher than 60%, a high-risk warning signal is issued to remind the client to activate the highest level security response mechanism and conduct a comprehensive review and rectification of data with high-risk factors.