Data processing activity evaluation method and device, electronic equipment and storage medium

By automatically obtaining and analyzing the actual information of data processing activities, combining preset processing links and security requirements, an automated risk assessment of enterprise data processing activities is realized, solving the problems of low efficiency and poor accuracy of manual evaluation in the existing technology, and improving the accuracy and efficiency of evaluation results.

CN120197180APending Publication Date: 2025-06-24CHONGQING SOKON IND GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510327158.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The existing technology is difficult to achieve automated risk assessment of enterprise data processing activities, resulting in inefficiency of manual analysis methods and inaccurate evaluation results.

Method used

By obtaining the actual activity information of the data processing activity to be evaluated and its affiliated processing links, the target evaluation items and safety standard requirements are determined based on the correspondence between the preset processing link and the data processing security requirements, and determining whether these standards are met based on the actual information to obtain the security evaluation results.

Benefits of technology

It realizes automated evaluation of data processing activities, saves labor costs, and improves the accuracy of evaluation results through standardized evaluation goals and basis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197180A_ABST
    Figure CN120197180A_ABST
Patent Text Reader

Abstract

The invention provides a data processing activity assessment method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining the actual activity information of a to-be-assessed data processing activity and a processing link to which the data processing activity belongs, and carrying out the assessment of the data processing activity according to a corresponding relation between a preset processing link and a preset data processing safety requirement; determining the target evaluation item and the target safety standard requirement corresponding to the processing link, judging whether the actual execution condition corresponding to the target evaluation item in the data processing activity meets the target safety standard requirement or not according to the actual activity information, and obtaining the safety evaluation result of the data processing activity, thereby achieving the automatic evaluation of the data processing activity, and improving the safety of the data processing activity. And the labor cost is saved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data protection, and particularly to a method, apparatus, electronic device, and storage medium for evaluating data processing activities. Background Art

[0002] According to the requirements of personal data security protection, enterprises need to conduct security risk assessments on data processing activities. Currently, most enterprises collect and analyze data related to data processing activities through specialized personnel. Since there are many data processing activities in enterprises, the manual analysis method is no longer applicable, and there is an urgent need for a method that can automatically evaluate and analyze the risk of enterprises' data processing activities. Summary of the Invention

[0003] The purpose of the embodiments of this application is to provide a method, apparatus, electronic device, and storage medium for evaluating data processing activities to solve the above technical problems.

[0004] On the one hand, a method for evaluating data processing activities is provided, including: Obtaining the actual activity information of the data processing activity to be evaluated, and the processing link to which the data processing activity belongs; According to the corresponding relationship between the preset processing link and the preset data processing security requirements, determining the target evaluation item and the target security standard requirements corresponding to the processing link; each of the preset data processing security requirements includes a preset evaluation item and the corresponding preset security standard requirements; According to the actual activity information, determining whether the actual execution situation corresponding to the target evaluation item in the data processing activity meets the target security standard requirements, and obtaining a security evaluation result for the data processing activity.

[0005] In one of the embodiments, the target evaluation item includes a first evaluation item corresponding to a first region and a second evaluation item corresponding to a second region; the target security standard requirements include a first security standard requirement corresponding to the first region and a second security standard requirement corresponding to the second region; The step of determining whether the actual execution situation corresponding to the target evaluation item in the data processing activity meets the target security standard requirements according to the actual activity information, and obtaining a security evaluation result for the data processing activity includes: Determining whether the actual execution situation corresponding to the first evaluation item meets the first security standard requirement according to the actual activity information, obtaining a security evaluation result for the data processing activity in the first region, and determining whether the actual execution situation corresponding to the second evaluation item meets the second security standard requirement according to the actual activity information, obtaining a security evaluation result for the data processing activity in the second region.

[0006] In one embodiment, each of the preset evaluation items in each of the preset data processing security requirements includes at least one of the protection measures for sensitive information involved in the corresponding preset processing link and the regulations followed by the corresponding preset processing link; each of the preset security standard requirements in each of the preset data processing security requirements includes at least one of the corresponding protection measure standard requirements and regulation standard requirements.

[0007] In one embodiment, the method further includes: Periodically obtaining official regulatory documents; Updating the regulation standard requirements in each of the preset data processing security requirements according to the official regulatory documents.

[0008] In one embodiment, the corresponding relationship includes at least one of a first corresponding relationship between a data collection link and data collection security requirements, a second corresponding relationship between a data usage link and data usage security requirements, a third corresponding relationship between a data storage link and data storage security requirements, a fourth corresponding relationship between a data transmission link and data transmission security requirements, and a fifth corresponding relationship between a data deletion link and data deletion security requirements.

[0009] In one embodiment, when the corresponding relationship includes the first corresponding relationship, each of the preset evaluation items in the data collection security requirements includes at least one of the data collection type, data collection accuracy, and data source; When the corresponding relationship includes the second corresponding relationship, each of the preset evaluation items in the data usage security requirements includes at least one of the usage purpose, the entity using the data, the range of data fields used, the audit retention period, and the pattern baseline; When the corresponding relationship includes the third corresponding relationship, each of the preset evaluation items in the data storage security requirements includes at least one of the data residence area, storage encryption algorithm, data retention policy, number of backup copies, location of backup copies, and storage data access policy; When the corresponding relationship includes the fourth corresponding relationship, each of the preset evaluation items in the data transmission security requirements includes at least one of the transmission purpose, transmission protocol, transmission encryption algorithm, data transmission area, data transmission integrity, recipient qualification, and log record; When the corresponding relationship includes the fifth corresponding relationship, each of the preset evaluation items in the data deletion security requirements includes at least one of deletion timeliness, deletion integrity, non-recoverability of destruction, and deletion audit.

[0010] In one embodiment, judging whether the actual execution situation corresponding to the target evaluation item in the data processing activity meets the requirements of the target security standard according to the actual activity information, and obtaining a security evaluation result of the data processing activity, includes: When it is determined that the actual execution situation corresponding to a certain target evaluation item in the data processing activity does not meet the corresponding target security standard requirements, determining that the target evaluation item is an insecure evaluation item; Determining a threat event caused by the data processing activity according to the insecure evaluation item, and determining the threat level of the threat event; Determining the impact level of the impact caused by the threat event; Determining control measures taken for the threat event according to the actual execution situation of the data processing activity; Determining the effectiveness of solving the threat event through the control measures; Evaluating the security of the data processing activity according to the threat level, the impact level and the effectiveness level, and obtaining an evaluation result.

[0011] On the other hand, an evaluation device for a data processing activity is also provided, including: An acquisition module, configured to acquire the actual activity information of the data processing activity to be evaluated, and the processing link to which the data processing activity belongs; A determination module, configured to determine a target evaluation item and target security standard requirements corresponding to the processing link according to the corresponding relationship between the preset processing link and the preset data processing security requirements; each of the preset data processing security requirements includes a preset evaluation item and corresponding preset security standard requirements; An evaluation module, configured to judge whether the actual execution situation corresponding to the target evaluation item in the data processing activity meets the target security standard requirements, and obtain a security evaluation result of the data processing activity.

[0012] On the other hand, an electronic device is also provided, including a processor and a memory, where a computer program is stored in the memory, and the processor executes the computer program to implement the method as described in any one of the above.

[0013] On the other hand, a computer-readable storage medium is also provided, where a computer program is stored in the computer-readable storage medium, and when the computer program is executed by at least one processor, the method as described in any one of the above is implemented.

[0014] The evaluation method, device, electronic device, and storage medium for data processing activities provided by this application obtain the actual activity information of the data processing activity to be evaluated and the processing link to which the data processing activity belongs, determine the target evaluation items and target security standard requirements corresponding to the processing link according to the corresponding relationship between the preset processing link and the preset data processing security requirements, and judge whether the actual execution situation corresponding to the target evaluation items in the data processing activity meets the target security standard requirements based on the actual activity information, so as to obtain the security evaluation result of the data processing activity, realizing the automated evaluation of the data processing activity and saving labor costs. Since corresponding preset evaluation items and preset security standard requirements are set for each preset processing link in advance, standardized evaluation objectives and evaluation bases are provided, which can solve the problem of inaccurate evaluation results caused by incomplete selected evaluation items and inaccurate evaluation criteria due to limited experience when manually evaluating data processing activities in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on the provided drawings without creative efforts.

[0016] Figure 1 It is a schematic flowchart of the evaluation method for data processing activities provided in Embodiment 1 of the present application; Figure 2 It is a schematic flowchart of evaluating the security of a data processing activity according to the target evaluation items and target security standard requirements provided in Embodiment 1 of the present application; Figure 3 It is a schematic structural diagram of the evaluation device for data processing activities provided in Embodiment 2 of the present application; Figure 4 It is a schematic structural diagram of the electronic device provided in Embodiment 3 of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] In order to make the objectives, technical solutions, and advantages of the present application clearer, the following further details the present application in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0018] An embodiment of the present application provides an evaluation method for data processing activities. Please refer to Figure 1 as shown, including the following steps: S11: Obtain the actual activity information of the data processing activity to be evaluated and the processing link to which the data processing activity belongs.

[0019] S12: Determine a target evaluation item and a target security standard requirement corresponding to the processing step according to the corresponding relationship between the preset processing step and the preset data processing security requirement; each preset data processing security requirement includes a preset evaluation item and a corresponding preset security standard requirement.

[0020] S13: According to the actual activity information, determine whether the actual execution situation corresponding to the target evaluation item in the data processing activity meets the target security standard requirement, and obtain a security evaluation result of the data processing activity.

[0021] Next, the above steps will be introduced in detail.

[0022] In the embodiment of the present application, each data processing operation can be used as a data processing activity. The actual activity information of the data processing activity refers to the information used to reflect the actual data processing activity situation, such as the log information related to the data processing activity.

[0023] In an embodiment, the evaluation of the data processing activity can be triggered when the data processing activity occurs. In this embodiment, each occurring data processing activity is used as the data processing activity to be evaluated, and the above steps are executed, realizing the real-time evaluation of the data processing activity.

[0024] The real-time evaluation has relatively high configuration requirements for the system environment. Therefore, in an embodiment, step S11 can be executed when it is determined that the current preset data processing activity evaluation condition is met. The data processing activity evaluation condition can be flexibly set by developers. For example, it can be triggered according to time. When it is determined that the current time meets the preset time requirement, all data processing activities occurring in the preset historical time period are used as the data processing activities to be evaluated, and the above steps are executed.

[0025] In this embodiment, the processing step to which the corresponding data processing activity belongs can be determined by analyzing the log information of the data processing activity.

[0026] Exemplarily, the processing step to which it belongs can be determined according to the protocol type involved in the data processing activity. For example, if it is determined according to the log information that the protocol involved in the activity is a data transmission protocol, it means that the data processing activity belongs to the data transmission step.

[0027] Exemplarily, the log information of each data processing activity carries a step identifier for identifying the processing step to which the data processing activity belongs, and the processing step to which the data processing activity belongs can be determined according to the step identifier.

[0028] Exemplarily, it is possible to determine the processing stage to which the data processing activity belongs according to the command that triggers the data processing activity. For example, if the command is a storage command, it indicates that the data processing activity belongs to the data storage stage.

[0029] According to different stages of the data life cycle, data processing includes data collection, data usage, data storage, data transmission, and data deletion. In order to evaluate the security of data in different life cycle stages, in one embodiment, the corresponding relationship between the preset processing stage and the preset data processing security requirements includes at least one of the following corresponding relationships: The first corresponding relationship between the data collection stage and the data collection security requirements, the second corresponding relationship between the data usage stage and the data usage security requirements, the third corresponding relationship between the data storage stage and the data storage security requirements, the fourth corresponding relationship between the data transmission stage and the data transmission security requirements, and the fifth corresponding relationship between the data deletion stage and the data deletion security requirements.

[0030] It should be noted that the preset evaluation items corresponding to each preset processing stage in the embodiments of the present application can be one or multiple.

[0031] In one embodiment, the corresponding relationship includes the first corresponding relationship. The preset evaluation items in the data collection security requirements include at least one of the data collection type, the data collection accuracy, and the data source.

[0032] The preset security standard requirements refer to the security standard requirements that need to be met when performing a security evaluation on the preset evaluation items. Therefore, for the data collection type, the corresponding preset security standard requirements can be the allowable range of data collection types; similarly, for the data collection accuracy, the corresponding preset security standard requirements can be the allowable range of data collection accuracies; similarly, the preset security standard requirements corresponding to the data source can be the allowable range of data sources.

[0033] In one embodiment, the corresponding relationship includes the second corresponding relationship. The preset evaluation items in the data usage security requirements include at least one of the usage purpose, the subject using the data, the range of data fields used, the audit retention period, and the pattern baseline.

[0034] In one embodiment, the corresponding relationship includes the third corresponding relationship. The preset evaluation items in the data storage security requirements include at least one of the data residence area, the storage encryption algorithm, the data retention policy, the number of backup copies, the location of backup copies, and the storage data access policy.

[0035] In one embodiment, the corresponding relationship includes the fourth corresponding relationship, and the preset evaluation items in the data transmission security requirements include at least one of transmission purpose, transmission protocol, transmission encryption algorithm, data transmission region, data transmission integrity, recipient qualification, and log record.

[0036] It should be noted that the preset security standard requirements corresponding to the recipient qualification include at least one of the identity requirements, role requirements, processing purpose requirements, and processing method requirements for the recipient.

[0037] The following is an example description of the processing method requirements for the recipient.

[0038] Exemplarily, after receiving the data packet, the recipient first performs identity verification to ensure that the data packet comes from a legitimate data source. The verification methods include but are not limited to at least one of password-based authentication, digital certificate-based authentication, token-based authentication, biometric technology-based authentication, IP (Internet Protocol) address and MAC (Media Access Control) address-based authentication, dynamic verification code-based authentication, multi-factor authentication, and blockchain-based authentication.

[0039] The recipient records each received data packet, including but not limited to at least one of reception time, data packet size, data source identifier, data packet sequence number, data packet type, checksum, hash value, protocol type, port number, data packet content summary, priority, encryption status, data packet life cycle, data packet source geographical location, data packet processing status, associated transaction ID, and duplicate detection identifier. The recorded information can be stored in a log file for subsequent data tracking and auditing.

[0040] The recipient preprocesses the received data, including data cleaning, format conversion, deduplication, data integration, data transformation, data reduction, and data visualization operations to ensure the accuracy and consistency of the data. In the data reduction process, principal component analysis or linear regression can be used to process the data.

[0041] After preprocessing the data, the recipient can further process the preprocessed data by using at least one of the following processing measures: Data analysis: Calculate statistics such as the mean, standard deviation, maximum value, and minimum value of the data, calculate the correlation coefficients between different variables, identify the correlations between variables, and classify the data into different categories or groups.

[0042] Data mining: Determine the correlations between data items, and use machine learning algorithms to classify or predict data, such as predicting customer churn, credit scoring, etc.

[0043] Advanced processing: Conduct trend analysis, seasonal analysis, cycle analysis, etc. on time series data to predict future trends. Conduct sentiment analysis, topic extraction, keyword extraction, etc. on text data to mine useful information in the text. Conduct recognition, classification, segmentation, etc. on image data to extract useful information in the image. Intermediate results and final processing results are generated during the processing, and the results are stored in a specified database or file system. The recorded information is also stored in a log file, which together with the received records constitutes a complete data processing record.

[0044] Data transmission: The processed data is sent to the next link and users according to the preset output format and transmission protocol.

[0045] Database writing: Insert the processed data into the tables of relational databases MySQL, PostgreSQL, Oracle for complex queries and analysis. Store the processed data in NoSQL databases MongoDB, Cassandra, Redis, which are suitable for processing large-scale, unstructured data. Write the data into data warehouses Snowflake, Redshift, BigQuery for large-scale data analysis and report generation.

[0046] API interface call: Send the processed data to the next link or users in formats such as JSON or XML through the API interface.

[0047] Message queue: Send the processed data to the queues of message middleware RabbitMQ, Kafka, ActiveMQ for subsequent processing by consumers. In an event-driven architecture, the processed data is published as an event to an event bus or message queue for consumption by subscribers.

[0048] Direct memory access: In high-performance computing or real-time processing systems, the processed data can be directly written into a shared memory area for access by other processes or threads.

[0049] Other output methods: Send the processed data as an attachment to an email to a specified user or email address. Format the processed data into a report or document and print it out. For mobile applications, send the processed data summary or reminder to users through push notifications APNs, FCM.

[0050] Status feedback: Provide a data processing status feedback mechanism, and send the processing status information to the data source or other relevant parties through the API interface or message queue.

[0051] Among them, the feedback information includes at least one of a processing flag, a processing time, an error code, processing details, resource usage, log information, database feedback, and subsequent operation suggestions.

[0052] The success flag in the processing flag indicates that the data processing has been successfully completed, usually using a boolean value true, a status code 200 (the success response code in the HTTP protocol), or a custom success message string. The failure flag indicates that an error or exception has occurred during the data processing, usually using a boolean value false, a status code 4xx or 5xx (the client or server error response code in the HTTP protocol), or a string containing an error description.

[0053] The start time in the processing time represents the timestamp when the data processing task starts, facilitating the tracking of the task execution time point. The end time is the timestamp when the data processing task ends, used to calculate the total duration of the task execution. The processing duration gives the time taken for the data processing, which can be in time units such as seconds, milliseconds, etc.

[0054] The error code is used to identify the specific error type or reason when the processing fails.

[0055] The processing details are used to briefly describe the main steps or stages experienced during the data processing, providing a summary of the processed data or key results.

[0056] The resource usage is used to feedback the CPU occupancy, the consumed memory resources, and the frequency and amount of disk read and write operations during the processing.

[0057] The log information is the detailed information recorded during the processing, including timestamps, operations, status changes, etc. When the processing fails, it provides detailed error logs, including the time, location, and reason of the error occurrence.

[0058] The database feedback is used to confirm whether the data sent by the data source has been successfully received and verify whether the received data is complete and error-free.

[0059] The subsequent operation suggestions are used to provide retry suggestions or strategies for retryable errors and provide contact information or suggestions for contacting technical support for problems that cannot be solved by oneself.

[0060] In one embodiment, the corresponding relationship includes the fifth corresponding relationship, and the preset evaluation items in the data deletion security requirements include at least one of deletion timeliness, deletion integrity, destruction irreversibility, and deletion auditing.

[0061] It can be understood that, in one embodiment, all data processing activities within a historical time period can be obtained, and the security of each data processing activity is evaluated according to the processing link to which each data processing activity belongs.

[0062] Further, on this basis, for each processing link, according to the actual execution situation of all data processing activities corresponding to this processing link, a security assessment is carried out on all data processing activities corresponding to this processing link. For example, for the data collection link, the security of the data collection link is evaluated according to the actual execution situation of all data collection links within a historical time period. Exemplarily, if it is determined that the data collection source of a certain data collection link is non-compliant, it is determined that there is a security risk in the data collection link; or when it is determined that the ratio of the number of insecure data processing activities in the data collection link is greater than a preset ratio threshold, it is determined that there is a security risk in the data collection link. It can be understood that for a data processing activity, if at least one corresponding target evaluation item does not meet the requirements of its corresponding target security standard, it can be determined that this data processing activity is insecure.

[0063] Further, on this basis, it is also possible to evaluate the overall security of all data processing activities within this historical time period according to the actual execution situation of the data processing activities corresponding to each processing link. For example, when it is determined that each processing link is insecure, it can be determined that the overall security of all data processing activities within this historical time period is relatively low.

[0064] In the above embodiments, it is introduced to set the corresponding relationship based on the life cycle of data processing, that is, this processing link reflects the life cycle stage of data processing. It can be understood that in other embodiments, the corresponding relationship can also be set according to the business type. At this time, this processing link reflects the link of data processing under the corresponding business type. For example, for the e-commerce business type, the corresponding preset processing links may include but are not limited to the login link, the online payment link, the order processing link, and the customer service link.

[0065] In the embodiments of the present application, after determining the target evaluation items, corresponding evaluation methods can be determined for each target evaluation item, and then according to each evaluation method and the actual activity information, a security assessment is carried out on the actual execution situation corresponding to this target evaluation item in the data processing activity.

[0066] Exemplarily, for data processing activities belonging to the data collection link, a comparison tool can be used to verify whether the actually collected data types exceed the allowable data collection type range; a data analysis tool can be used to determine whether the accuracy of data collection is within the allowable data collection accuracy range.

[0067] Exemplarily, for data processing activities belonging to the data usage phase, the legality of the usage purpose can be evaluated through purpose matching queries. For example, whether user profiling analysis exceeds the scope of the statement of "enhancing driving safety". Use a high-privilege account to confirm the authorized role list for access control result evaluation. For example, verify whether an after-sales engineer has unauthorized access to high-precision positioning data. Evaluate data minimization through data lineage tracing. For example, detect whether unstated fields such as steering wheel torque are used. Conduct third-party sharing evaluation through API (Application Programming Interface) call log analysis. For example, verify whether navigation data is illegally shared with an unsigned advertising platform. Conduct log auditing through log integrity verification and timestamp continuity checks to ensure that all data access operations are traceable within a certain period. Conduct abnormal usage detection through statistical deviation analysis to identify accounts that frequently access biometric data during non-working hours.

[0068] Exemplarily, for data processing activities belonging to the data storage phase, the compliance of the storage location can be evaluated through cloud service provider API queries. Evaluate the storage encryption situation through KMS (Key Management Service). Evaluate the execution of the data retention period by obtaining the database TTL configuration rules.

[0069] Exemplarily, for data processing activities belonging to the data transmission phase, the security of the transmission protocol can be evaluated through TLS (Transport Layer Security) version detection. For example, if it is found that diagnostic data is transmitted using the TLS 1.1 protocol, it proves that the version is non-compliant. Evaluate the encryption strength of the transmission encryption algorithm through key length verification. For example, verify whether the AES (Advanced Encryption Standard) key reaches 256 bits. Evaluate the compliance of the data transmission region through geolocation tracing. For example, if it is detected that data is routed through an unapproved third-country node, it proves that cross-border compliance is abnormal. Conduct data integrity evaluation through hash value comparison to verify that the OTA (Over-the-Air Technology) upgrade package has not been tampered with during transmission. Conduct recipient qualification evaluation through certificate revocation list checks. If the certificate of the data recipient has expired, it indicates a violation. Conduct transmission log evaluation through timestamp continuity checks and abnormal transmission volume detection to identify abnormal peaks within a certain period.

[0070] Exemplarily, for data processing activities belonging to the data deletion process, irrecoverable destruction verification can be performed through physical media degaussing records and inspection of service provider qualification certificates for destruction. Deletion audit verification can be performed through inspection of the integrity of deletion operation logs and the coverage of audit reports.

[0071] Security requirements for data processing activities vary in different regions, such as different countries. Therefore, in one embodiment, corresponding evaluation items and security standard requirements can be preset for different regions in the preset data processing security requirements.

[0072] Correspondingly, the target evaluation items in step S12 include a first evaluation item corresponding to the first region and a second evaluation item corresponding to the second region; the target security standard requirements include a first security standard requirement corresponding to the first region and a second security standard requirement corresponding to the second region.

[0073] Then step S13 includes: Judging whether the actual execution situation corresponding to the first evaluation item meets the first security standard requirement according to the actual activity information, obtaining the security evaluation result of the data processing activity in the first region, and judging whether the actual execution situation corresponding to the second evaluation item meets the second security standard requirement according to the actual activity information, obtaining the security evaluation result of the data processing activity in the second region.

[0074] Exemplarily, the first region and the second region can be different national regions, such as domestic and foreign regions. By comparing the differences in domestic and foreign data protection laws and regulations, possible compliance conflict points can be identified.

[0075] The restrictions and requirements for data processing at home and abroad are different, which may lead to compliance conflicts for enterprises operating at home and abroad. For example, domestic regulations require enterprises to obtain user consent when processing sensitive data, while this requirement may not exist in some foreign markets. Enterprises may face compliance risks when processing data for failing to comply with domestic laws.

[0076] Due to differences in the definition and scope of sensitive information at home and abroad, enterprises may face compliance conflicts when processing data for failing to correctly identify sensitive information. For example, certain data information is regarded as sensitive information and requires special protection in China, but may not be regarded as sensitive information abroad. Enterprises may face risks when processing these data for failing to comply with domestic laws.

[0077] The restrictions and requirements for cross-border data transmission at home and abroad are different, which may lead to compliance conflicts for enterprises operating at home and abroad.

[0078] The requirements for user consent in data processing vary between domestic and foreign regions, which may lead to compliance conflicts for enterprises operating both domestically and abroad. For example, domestic regulations require enterprises to obtain explicit consent from users when processing sensitive data, while such a requirement may not exist or may be less stringent in some foreign markets. Enterprises may face compliance risks for failing to comply with domestic laws when processing data.

[0079] In the embodiments of the present application, since corresponding evaluation items and security standard requirements are set in advance for different regions, the security evaluation of data processing activities in different regions can be obtained, facilitating enterprise managers to make relevant decisions based on the security evaluation of different regions and avoid compliance risks.

[0080] When evaluating the security of data processing activities, it is necessary to evaluate the legality of data processing and the security protection measures for sensitive information. In one embodiment, each of the preset evaluation items in the preset data processing security requirements includes at least one of the protection measures for sensitive information involved in the corresponding preset processing link and the regulations followed by the corresponding preset processing link; each of the preset security standard requirements in the preset data processing security requirements includes at least one of the corresponding protection measure standard requirements and regulation standard requirements.

[0081] The sensitive information in the embodiments of the present application includes, but is not limited to, at least one of business functions, processing purposes, identity information data fields, identity information categories, identity information subject categories, identity information sources, identity information collection frequencies, identity information storage locations, identity information storage periods, rights enjoyed by the subjects corresponding to the identity information, legal bases for processing identity information, situations of sharing identity information with third parties, contracts related to the processing of identity information, information of joint controllers, data cross-border situations, and security evaluation requirement information.

[0082] It is understandable that the above identity information can be personal information or entity information. Taking personal information as an example, the business function refers to the specific business or service function involved in processing personal information. Clearly defining the specific business or function served by personal information processing activities helps to understand the background and purpose of information processing. The processing purpose clearly states the purpose and intention of processing personal information. Ensuring that personal information processing activities have a clear purpose can avoid the abuse or misuse of personal information. The identity information data field is used to uniquely represent an identity, such as network identity identification information and personal biometric information. The identity information subject categories include in-vehicle passengers and out-of-vehicle pedestrians. Identifying and processing different categories of personal information subjects ensures compliance and pertinence. The identity information categories include at least one of, but are not limited to, biometric information, sensitive personal information, and general personal information. The identity information source is used to explain the source of the identity information. The identity information storage location includes at least one of the physical location and the logical location where the identity information is stored. The identity information storage period includes at least one of the length of time the identity information is stored, when it will be deleted, and when anonymization processing will be performed. The regulatory basis for processing identity information refers to the laws, regulations, or policy provisions based on which the identity information is processed. The situation of sharing identity information with third parties refers to whether the identity information is shared with third parties and the relevant information of the third parties. Contracts related to processing identity information include at least one of the contract terms, agreements, and links to the corresponding contracts related to processing identity information. The data cross-border situation includes whether the data crosses borders and the purpose of crossing borders. Information about joint controllers includes the identity information of the joint controllers who can process or control the identity information. Information about security assessment requirements includes whether a security assessment is required and the assessment requirements.

[0083] The protection measures for sensitive information include at least one of, but are not limited to, encryption protection measures, firewall protection measures, and protection measures through intrusion detection. The encryption protection measures in the embodiments of the present application include at least one of, but are not limited to, AES encryption, byte substitution algorithm, row shift and column mixing algorithm, and round key addition algorithm.

[0084] The rights enjoyed by the subject corresponding to the identity information refer to the natural person or legal person associated with the data, such as individuals and enterprise customers. The data subject enjoys a series of rights in data processing activities, including at least one of, but not limited to, the right of access, the right of correction, the right of deletion, and the right to restrict processing.

[0085] In the embodiments of the present application, the right information of the data subject can be stored in a dedicated database. The database table fields include, but are not limited to, the right subject ID, subject name, subject type, document type, document number, contact information, patent ID, right type, right status, grant time, start of validity period, end of validity period, and right change record. Encryption technology is used to protect the security of the right records, and strict access control policies are implemented to ensure that only authorized personnel can access and modify them. A data management tool is used to automate the recording, updating, and querying of the data subject's rights.

[0086] It can be understood that in the embodiments of the present application, the conditions for triggering the recording of the right information of the data subject can be preset. When new data subject rights are generated, the recording process is automatically triggered. By writing scripts or using the built-in functions of the data management tool, the relevant information of the new data subject rights is automatically entered into the system.

[0087] Exemplarily, when it is detected that the data subject's rights have changed, the latest data is captured. The newly captured data is compared with the original data, and the data that needs to be updated is automatically updated to the database.

[0088] Exemplarily, when it is determined that the user's permissions meet the permission requirements, the user is allowed to query and obtain the relevant information of the data subject's rights through a preset query interface.

[0089] Exemplarily, the historical situation of the query of the data subject's right information is statistically analyzed, and the query results with a query frequency greater than the preset frequency threshold are cached to reduce the number of database accesses and further improve the query efficiency.

[0090] Similarly, in the embodiments of the present application, the cross-border data situation can be stored in a dedicated database.

[0091] Exemplarily, through the cross-border data identification and transmission module, cross-border data transmission activities are identified, the data transmission types are automatically classified, and key information such as the source country / region and target country / region of the data transmission is marked. The cross-border data situation database is used to store the cross-border data transmission situation, including at least one of the detailed information such as transmission time, transmission method, transmission status, data volume, source / target IP address, and compliance inspection results. The compliance inspection rule library integrates the data protection and privacy legal requirements of major countries and regions. In the embodiments of the present application, a compliance inspection engine can be used to perform compliance inspections on cross-border data, record the inspection results and the compliance measures taken, and generate cross-border data transmission compliance reports regularly or on demand.

[0092] For non-compliant data found in the detection, the compliance measures taken are recorded. The measures include at least one of data encryption, data desensitization, data deletion, and data transmission path adjustment.

[0093] In the embodiments of the present application, when it is determined that the current meets the preset update condition, the content in the preset data processing security requirements is updated.

[0094] Exemplarily, official regulatory documents can be obtained periodically, and the regulatory standard requirements in each preset data processing security requirement are updated according to the official regulatory documents.

[0095] It should be noted that official regulatory documents in different regions can be obtained separately, and then the corresponding regulatory standard requirements in each region are updated separately.

[0096] It can be understood that the corresponding relationship between the preset processing links and the preset data processing security requirements in the embodiments of the present application can be recorded in the ROPA (Record of Processing Activities).

[0097] In one embodiment, please refer to Figure 2 As shown, step S13 includes: S131: When it is determined that the actual execution situation corresponding to a certain target evaluation item in the data processing activity does not meet the corresponding target security standard requirement, determine the target evaluation item as an insecure evaluation item.

[0098] S132: Determine the threat event caused by the data processing activity according to the insecure evaluation item, and determine the threat level of the threat event.

[0099] S133: Determine the impact level of the threat event.

[0100] S134: Determine the control measures taken for the threat event according to the actual execution situation of the data processing activity.

[0101] S135: Determine the effectiveness of solving the threat event through the control measures.

[0102] S136: Evaluate the security of the data processing activity according to the threat level, impact level and effectiveness level to obtain an evaluation result.

[0103] The threat events in the embodiments of the present application include but are not limited to at least one of data misuse, data leakage, network attack, system failure, data corruption and data loss.

[0104] In one embodiment, a correspondence table between insecure evaluation items and threat events can be preset. The correspondence table contains the correspondence between preset insecure evaluation items and preset threat events. It can be understood that each preset insecure evaluation item can correspond to one preset threat event, or can correspond to multiple preset threat events, or multiple preset insecure evaluation items can correspond to one preset threat event. For a certain data processing activity, when a certain preset evaluation item corresponding to it does not meet the requirements of the corresponding preset security standard, the preset evaluation item is used as the insecure evaluation item of the data processing activity.

[0105] When it is determined that there is an insecure evaluation item in the data processing activity, the threat event corresponding to the insecure evaluation item can be determined according to the correspondence between the preset insecure evaluation item and the preset threat event. Or, when it is determined that there are multiple insecure evaluation items in the data processing activity, the threat events corresponding to these multiple insecure evaluation items can be determined according to the correspondence between the multiple preset insecure evaluation items and the preset threat events.

[0106] In the embodiment of the present application, the threat level of the threat event can be determined based on CVSS (Common Vulnerability Scoring System). The higher the threat level, the greater the possibility of the potential threat.

[0107] In step S133, the impact degree can be determined according to at least one of the impact on the technical level, the impact on the data level, and the impact on the business level of the threat event.

[0108] For example, the first impact degree of the threat event on the entire business system can be determined according to the number and type of affected services, the second impact degree of the threat event on the data level can be determined according to the number, type, and value of the damaged data, and the third impact degree of the threat event on the business level can be determined according to the impact of the threat event on financial losses, legal consequences, etc.

[0109] According to each impact degree and the corresponding preset weight, the impact degree of the threat event can be determined. For example, the sum of the products of the above-mentioned impact degrees and the corresponding preset weights is used as the impact degree in step S133.

[0110] For steps S134 and S135, according to the actual execution situation of the data processing activity, the currently deployed security policies and / or technical measures can be obtained, such as firewalls, intrusion detection systems, encryption technologies, and access control mechanisms, and the effectiveness of each policy and / or measure in actual operations can be evaluated through security audits.

[0111] For step S136, in one embodiment, the levels of threat degree, impact degree, and effectiveness degree of control measures can be described separately, and then the overall risk level can be determined based on each level, and a decision can be made on whether further actions are needed.

[0112] Exemplarily, the way to determine the overall risk level can be as follows: Low risk: When it is determined that the threat degree and impact degree are at the low-risk level, and the control measure is at the general effectiveness level or high effectiveness level, the overall risk level is determined to be low risk.

[0113] Medium risk: When it is determined that the threat degree and impact degree are at the medium-risk level, and the control measure is at the high effectiveness level, the overall risk level is determined to be medium risk.

[0114] High risk: When it is determined that the threat degree and impact degree are at the high-risk level, and the control measure is at the low effectiveness level, the overall risk level is determined to be high risk.

[0115] Through this method, the security risks existing in data processing activities can be analyzed more systematically, and targeted strategies can be formulated to reduce these risks. Repeating this process regularly helps to adapt to the changing security environment and ensure that the security of data processing activities always remains at an acceptable level.

[0116] In another embodiment, the overall risk level can be directly determined according to the formula: risk value = threat degree × impact degree × effectiveness degree.

[0117] It can be understood that when there are multiple threat events, the risk values of each threat event can be calculated separately according to this formula, and then the weights of each threat event can be determined. The sum of the products of each weight and the corresponding risk value is used as the overall risk value of all data processing activities within the historical time period.

[0118] Exemplarily, the weight of a threat event can be determined in the following way: For each threat event, count the number of occurrences of the data processing activities that caused this threat event within the historical time period, and use the ratio of this number of occurrences to the total number of data processing activities within this historical time period as the weight of this threat event.

[0119] It should be understood that although the various steps in the above flowcharts are shown sequentially according to the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless specifically stated herein, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the above flowcharts may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential either, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.

[0120] Embodiment 2: Based on the same inventive concept, please refer to Figure 3 As shown, this embodiment provides an evaluation device for data processing activities, including: An acquisition module 301, configured to acquire the actual activity information of the data processing activity to be evaluated, as well as the processing link to which the data processing activity belongs; A determination module 302, configured to determine a target evaluation item and a target security standard requirement corresponding to the processing link according to the correspondence between the preset processing link and the preset data processing security requirement; each of the preset data processing security requirements includes a preset evaluation item and a corresponding preset security standard requirement; An evaluation module 303, configured to determine whether the actual execution situation corresponding to the target evaluation item in the data processing activity meets the target security standard requirement, and obtain a security evaluation result of the data processing activity.

[0121] In one embodiment, the target evaluation item includes a first evaluation item corresponding to a first region and a second evaluation item corresponding to a second region; the target security standard requirement includes a first security standard requirement corresponding to the first region and a second security standard requirement corresponding to the second region; the evaluation module 303 is configured to determine whether the actual execution situation corresponding to the first evaluation item meets the first security standard requirement according to the actual activity information, obtain a security evaluation result of the data processing activity in the first region, and determine whether the actual execution situation corresponding to the second evaluation item meets the second security standard requirement according to the actual activity information, and obtain a security evaluation result of the data processing activity in the second region.

[0122] In one embodiment, each of the preset evaluation items in each of the preset data processing security requirements includes at least one of the protection measures for sensitive information involved in the corresponding preset processing link and the regulations followed by the corresponding preset processing link; each of the preset security standard requirements in each of the preset data processing security requirements includes at least one of the corresponding protection measure standard requirements and regulation standard requirements.

[0123] In one embodiment, the device further includes an update module, configured to periodically obtain official regulation documents and update the regulation standard requirements in each of the preset data processing security requirements according to the official regulation documents. In one embodiment, the corresponding relationship includes at least one of a first corresponding relationship between a data collection link and data collection security requirements, a second corresponding relationship between a data usage link and data usage security requirements, a third corresponding relationship between a data storage link and data storage security requirements, a fourth corresponding relationship between a data transmission link and data transmission security requirements, and a fifth corresponding relationship between a data deletion link and data deletion security requirements.

[0124] In one embodiment, when the corresponding relationship includes the first corresponding relationship, each of the preset evaluation items in the data collection security requirements includes at least one of the data collection type, data collection accuracy, and data source. When the corresponding relationship includes the second corresponding relationship, each of the preset evaluation items in the data usage security requirements includes at least one of the usage purpose, the entity using the data, the range of data fields used, the audit retention period, and the pattern baseline. When the corresponding relationship includes the third corresponding relationship, each of the preset evaluation items in the data storage security requirements includes at least one of the data residency region, storage encryption algorithm, data retention policy, number of backup copies, location of backup copies, and storage data access policy. When the corresponding relationship includes the fourth corresponding relationship, each of the preset evaluation items in the data transmission security requirements includes at least one of the transmission purpose, transmission protocol, transmission encryption algorithm, data transmission region, data transmission integrity, recipient qualification, and log record. When the corresponding relationship includes the fifth corresponding relationship, each of the preset evaluation items in the data deletion security requirements includes at least one of deletion timeliness, deletion integrity, destruction irreversibility, and deletion audit.

[0125] In one embodiment, the evaluation module 303 is configured to determine that a target evaluation item is an insecure evaluation item when it is determined that the actual execution corresponding to a certain target evaluation item in the data processing activity does not meet the requirements of the corresponding target security standard; determine a threat event caused by the data processing activity according to the insecure evaluation item, and determine the threat level of the threat event; determine the impact level of the threat event; determine control measures taken for the threat event according to the actual execution of the data processing activity; determine the effectiveness of resolving the threat event through the control measures; and evaluate the security of the data processing activity according to the threat level, the impact level, and the effectiveness, to obtain an evaluation result.

[0126] It should be understood that, for the sake of concise description, the content described in some embodiments will not be repeated in this embodiment.

[0127] Embodiment Three: Please refer to Figure 4 As shown, an embodiment of the present application provides an electronic device, including a processor 401 and a memory 402. A computer program is stored in the memory 402, and the processor 401 executes the computer program. The processor executes the computer program to implement the steps of the method introduced above, which will not be repeated here.

[0128] The processor 401 may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor 401 may be a general-purpose processor, including a CPU (Central Processing Unit), an NP (Network Processor), etc.; it may also be a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0129] The memory 402 may include, but is not limited to, RAM (Random Access Memory), ROM (Read Only Memory), PROM (Programmable Read Only Memory), EPROM (Erasable Programmable Read-Only Memory), and EEPROM (Electrically Erasable Programmable Read Only Memory), etc.

[0130] Those skilled in the art can understand that Figure 4 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the electronic devices to which the solution of this application is applied. The specific electronic device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0131] Based on the same inventive concept, the embodiments of this application also provide a computer-readable storage medium, such as a floppy disk, optical disk, hard disk, flash memory, USB flash drive, SD (Secure Digital) card, MMC (Multi-Media Card), etc. One or more programs for implementing the above steps are stored in the computer storage medium. These one or more programs can be executed by one or more processors to implement the steps of the methods in the above embodiments, which will not be elaborated here.

[0132] Based on the same inventive concept, the embodiments of this application also provide a computer program product, including a computer program, and the computer program implements the method described in any one of the above when executed by a processor.

[0133] Among them, the program code for the computer program product for executing this application can be written in any combination of one or more programming languages. The program code can be executed completely on the user device, partially on the user device, executed as an independent software package, partially on the user device and partially on a remote device, or executed completely on a remote device.

[0134] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, optical storage, etc.) that contain computer-usable program code.

[0135] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer-readable storage media according to the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.

[0136] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.

[0137] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of user operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.

[0138] It should be noted that the illustrations provided in this embodiment only schematically illustrate the basic concept of the present application. Therefore, only the components related to the present application are shown in the drawings, rather than being drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and proportion of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex. The structures, proportions, sizes, etc. shown in the drawings of this specification are only used to cooperate with the content disclosed in the specification for those skilled in this technology to understand and read, and are not used to limit the limiting conditions for the implementation of the present application. Therefore, they do not have substantial technical significance. Any modification of the structure, change in the proportional relationship, or adjustment of the size, without affecting the efficacy that the present application can produce and the purpose that can be achieved, should still fall within the scope covered by the technical content disclosed in the present application. At the same time, the terms such as "upper", "lower", "left", "right", "middle", and "one" cited in this specification are only for the convenience of clear narration and are not used to limit the scope of implementation of the present application. The change or adjustment of their relative relationship, without substantial change in the technical content, should also be regarded as the scope of implementation of the present application.

[0139] References to "embodiments" in this document mean that the particular features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The phrase appears in various places in the text and does not necessarily refer to the same embodiment each time, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0140] As shown herein, unless the context clearly indicates otherwise, words such as "a", "an", "one", and / or "the" are not specifically singular and can also include the plural. Generally speaking, the terms "comprising" and "including" only indicate the inclusion of the steps and elements that have been clearly identified, and these steps and elements do not constitute an exclusive list. The method or device may also include other steps or elements.

[0141] The definitions included herein, as used herein, the terms "having", "may have", "including", or "may include" indicate the existence of the corresponding functions, operations, elements, etc. of the present application, and do not limit the existence of one or more other functions, operations, elements, etc. In addition, it should be understood that as used herein, the terms "including" or "having" indicate the existence of the features, numbers, steps, operations, elements, components, or combinations thereof described in the specification, and do not exclude the existence or addition of one or more other features, numbers, steps, operations, elements, components, or combinations thereof.

[0142] In the embodiments of the present application, prefix words such as "first" and "second" are only used to distinguish different described objects, and have no restrictive effect on the position, order, priority, quantity, content, etc. of the described objects. The use of prefix words such as ordinal numbers for distinguishing described objects in the embodiments of the present application does not constitute a restriction on the described objects. For the description of the described objects, reference should be made to the description in the claims or the context of the embodiments, and no redundant restrictions should be formed due to the use of such prefix words. In addition, in the description of this embodiment, unless otherwise specified, the meaning of "a plurality" is two or more.

[0143] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0144] The above-described embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.

Claims

1. A method for evaluating data processing activities, characterized in that: include: Obtaining actual activity information of the data processing activity to be evaluated and the processing link to which the data processing activity belongs; According to the correspondence between the preset processing links and the preset data processing security requirements, determine the target evaluation items and target security standard requirements corresponding to the processing links; Each of the preset data processing security requirements includes preset evaluation items and corresponding preset security standard requirements; Based on the actual activity information, it is determined whether the actual execution status corresponding to the target assessment item in the data processing activity meets the target security standard requirements, and a security assessment result of the data processing activity is obtained.

2. The method for evaluating data processing activities according to claim 1, characterized in that: The target assessment item includes a first assessment item corresponding to the first region and a second assessment item corresponding to the second region; the target safety standard requirement includes a first safety standard requirement corresponding to the first region and a second safety standard requirement corresponding to the second region; The determining, based on the actual activity information, whether the actual execution status corresponding to the target assessment item in the data processing activity meets the target security standard requirements, and obtaining the security assessment result of the data processing activity includes: Based on the actual activity information, it is determined whether the actual execution situation corresponding to the first assessment item meets the first security standard requirements, and a security assessment result of the data processing activity in the first region is obtained; and based on the actual activity information, it is determined whether the actual execution situation corresponding to the second assessment item meets the second security standard requirements, and a security assessment result of the data processing activity in the second region is obtained.

3. The method for evaluating data processing activities according to claim 1, characterized in that: The preset evaluation items in each of the preset data processing security requirements include protection measures for sensitive information involved in the corresponding preset processing link and at least one of the regulations followed by the corresponding preset processing link; the preset security standard requirements in each of the preset data processing security requirements include at least one of the corresponding protection measures standard requirements and regulatory standard requirements.

4. The method for evaluating data processing activities according to claim 3, characterized in that: The method further comprises: Periodically obtain official regulatory documents; The regulatory standard requirements in each of the preset data processing security requirements are updated according to the official regulatory documents.

5. The method for evaluating data processing activities according to claim 1, characterized in that: The corresponding relationships include at least one of a first corresponding relationship between a data collection link and data collection security requirements, a second corresponding relationship between a data usage link and data usage security requirements, a third corresponding relationship between a data storage link and data storage security requirements, a fourth corresponding relationship between a data transmission link and data transmission security requirements, and a fifth corresponding relationship between a data deletion link and data deletion security requirements.

6. The method for evaluating data processing activities according to claim 5, characterized in that: When the corresponding relationship includes the first corresponding relationship, the preset evaluation item in the data collection security requirement includes at least one of the type of collected data, the accuracy of collected data, and the source of data; When the corresponding relationship includes the second corresponding relationship, the preset evaluation item in the data usage security requirement includes at least one of the purpose of use, the subject of data use, the scope of data fields used, the audit retention period, and the model baseline; When the corresponding relationship includes the third corresponding relationship, the preset evaluation item in the data storage security requirement includes at least one of a data residency region, a storage encryption algorithm, a data retention policy, a number of backup copies, a backup copy location, and a storage data access policy; When the corresponding relationship includes the fourth corresponding relationship, the preset evaluation item in the data transmission security requirement includes at least one of transmission purpose, transmission protocol, transmission encryption algorithm, data transmission area, data transmission integrity, recipient qualification and log record; When the corresponding relationship includes the fifth corresponding relationship, the preset evaluation items in the data deletion security requirement include at least one of deletion timeliness, deletion integrity, destruction irreversibility, and deletion audit.

7. The method for evaluating data processing activities according to any one of claims 1 to 6, characterized in that: The determining, based on the actual activity information, whether the actual execution status corresponding to the target assessment item in the data processing activity meets the target security standard requirements, and obtaining the security assessment result of the data processing activity includes: When it is determined that the actual execution status corresponding to a certain target assessment item in the data processing activity does not meet the corresponding target safety standard requirement, determining that the target assessment item is an unsafe assessment item; Determining a threat event caused by the data processing activity according to the insecurity assessment item, and determining a threat level of the threat event; Determine the extent of the impact caused by the threat event; Determine the control measures taken against the threat events based on the actual execution of the data processing activities; Determine the degree to which the threat events are effectively addressed by the control measures; The security of the data processing activity is evaluated according to the threat level, the impact level and the effectiveness level to obtain an evaluation result.

8. An evaluation device for data processing activities, characterized in that include: An acquisition module, used to acquire actual activity information of the data processing activity to be evaluated, and the processing link to which the data processing activity belongs; A determination module, used to determine the target evaluation items and target security standard requirements corresponding to the processing link according to the correspondence between the preset processing link and the preset data processing security requirements; Each of the preset data processing security requirements includes preset evaluation items and corresponding preset security standard requirements; The evaluation module is used to determine whether the actual execution status corresponding to the target evaluation item in the data processing activity meets the target security standard requirements, and obtain the security evaluation result of the data processing activity.

9. An electronic device, characterized in that: The method comprises a processor and a memory, wherein a computer program is stored in the memory, and the processor executes the computer program to implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by at least one processor, the method according to any one of claims 1 to 7 is implemented.