Enterprise data security risk level-to-level management method and system
By hierarchical processing of enterprise data and phased splitting of business processes, combined with primary detection and module detection, the problem of traditional security management models being difficult to cope with multi-role and multi-department collaborative business scenarios is solved, and flexible detection intensity control and efficient risk management are achieved.
Patent Information
- Application Number
- CN202510677894.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-06-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The traditional security management model with single approval or one-size-fits-all detection as the core is difficult to cope with large-scale, multi-role, and multi-department collaborative business scenarios. Especially when processing data of different sensitivity, it is easy to lead to excessive security levels or insufficient control, affecting business efficiency or leaving hidden dangers of compliance or data leakage.
By obtaining enterprise data and performing data grading processing, the data is divided into ordinary data, sensitive data and core data. The business process is split into multiple stages. Key nodes are marked based on the data grading results, and primary detection is performed at the beginning of each stage. Sub-module detection subprocess is embedded in the key nodes for key detection, and business process stages are switched and risk processing is performed according to the detection results.
It realizes flexible detection intensity control under different sensitivity and risk conditions, which not only ensures data security, but also takes into account the flexibility of business processes, significantly improving the efficiency and security of enterprise data security risk grading management.
Smart Images

Figure CN120197183A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of business process security prevention and control, and particularly to a method and system for hierarchical management of enterprise data security risks. Background Art
[0002] With the continuous advancement of enterprise digital transformation, the traditional security management mode centered on single approval or one-size-fits-all detection has been difficult to cope with large-scale, multi-role, and multi-department collaborative business scenarios. Especially when dealing with data of different sensitivities, without targeted grading means, it often leads to either excessive security levels affecting business efficiency or insufficient control leaving compliance or data leakage risks. In view of the above pain points, the present invention divides the business process at the stage level, introduces a compensation sub-process and rollback mechanism of "review after execution", and combines primary detection with grading information.
[0003] Flexibly control the detection intensity under different sensitivities and different risk conditions, and form an innovative solution that not only ensures data security but also takes into account business flexibility. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the technical problem solved by the present invention is: the problem that the traditional security management mode centered on single approval or one-size-fits-all detection is difficult to cope with large-scale, multi-role, and multi-department collaborative business scenarios.
[0006] To solve the above technical problem, the present invention provides the following technical solution: a method for hierarchical management of enterprise data security risks, including: obtaining enterprise data and business processes, performing data grading processing on the enterprise data, and dividing the enterprise data into ordinary data, sensitive data, and core data; Splitting the business process into multiple business process stages, marking key nodes in the business process stages based on the results of data grading processing, performing primary detection at the beginning of each business process stage, and embedding a modular detection sub-process at the key nodes for focused detection; Performing switching of business process stages and risk handling according to the results of focused detection, completing the overall business process and generating an audit report, so as to realize hierarchical management of enterprise data security risks.
[0007] As a preferred solution of a method for hierarchical management of enterprise data security risks according to the present invention, wherein: the enterprise data includes user and permission information, system configuration data, compliance requirement data, and business-related data, analyzing the enterprise data through a data classification tool, and attaching grading labels to the data in combination with keywords and feature strings configured by the enterprise to complete the data grading processing.
[0008] As a preferred solution of an enterprise data security risk classification management method described in the present invention, wherein: the splitting of the business process into multiple business process stages includes splitting the business process according to splitting dimensions, and the splitting dimensions include department dimension, function dimension and time sequence dimension; Set the start condition and end condition of each business process stage. When the start condition is triggered, primary detection is performed, and the business processes involving sensitive data and core data are marked as key nodes.
[0009] As a preferred solution of an enterprise data security risk classification management method described in the present invention, wherein: the primary detection includes data detection, identity verification and compliance detection. The data detection is performed after the start condition of the business process stage is triggered. According to the data resource ID of the data to be processed in the business process stage, the classification label of the corresponding data is queried. If there is core data, the prior review and post review of the business process stage are disabled; The identity verification includes checking whether the operation account in the current stage has the permission to perform the operations of this business process stage and performing black and white list retrieval. If the operation account permission is missing or a blacklist IP is retrieved, the identity verification fails; The compliance detection includes calling a preset compliance detection script for detection and querying the abnormal operations of the operation account in the current stage. If the compliance detection script detects a compliance restricted area, the compliance detection fails; When the identity verification fails or the compliance detection fails, it is determined that the primary detection fails, the execution of the business process stage is stopped and an alarm is issued; When both the identity verification and the compliance detection are passed, the business process stage continues to execute. Based on the results of the primary detection, a risk score is calculated, and it is judged whether there is a risk in the business process stage according to the risk score. If there is no risk and the business process stage does not involve core data, prior review and post review are allowed when the business process stage is executed; If there is a risk or the business process stage involves core data, prior review and post review are not allowed when the business process stage is executed.
[0010] As a preferred solution of an enterprise data security risk classification management method described in the present invention, wherein: the sub-process of module-by-module detection includes defining the detection modules of the sub-process of module-by-module detection, and the detection modules are docked with external security systems and output results; Using the sub-process call function of the workflow, when the key node arrives, the system automatically calls the detection module for detection. The results of each detection module are saved in the sub-process context, and after the sub-process ends, they are summarized into an overall status and returned to the main process; The results of each detection module are divided into three types: passed, warned, and blocked. Based on the content returned by the sub-process, the key detection results are judged. If the results of all detection modules are passed, the sub-process returns passed, and the business process continues without other processing; If there are warnings in the results of the detection module and no blocks, the sub-process returns a warning, the business process continues, but the results of the detection module are sent for manual review; If there are blocks in the results of the detection module, the sub-process returns a block, immediately stops the operation of the key node and suspends the business process stage, and issues a security alert to notify the staff.
[0011] As a preferred solution of an enterprise data security risk grading management method described in the present invention, wherein: the detection module includes a permission and role verification module M1, a data compliance detection module M2, an abnormal behavior detection module M3, and a vulnerability scanning and external threat detection module M4; The permission and role verification module M1 includes, through a role-based access control system, calling a permission service API at a key node, passing in the user and permission information of the operating account, and judging the detection result of M1 according to the API return; The data compliance detection module M2 includes, at a key node, passing the enterprise data to be processed to a DLP tool, and identifying whether the entity data processed at the key node meets the requirements of desensitization, authorization, and compliant use according to the data grading information; The abnormal behavior detection module M3 includes, when the business process reaches a key node, M3 docks with a security information and event management platform to detect the operation behavior and network traffic of the key node; The vulnerability scanning and external threat detection module M4 includes, through an automated vulnerability scanner, quickly scanning for vulnerabilities in the system services and interfaces relied on by the key node.
[0012] As a preferred solution of an enterprise data security risk grading management method described in the present invention, wherein: the prior review and subsequent approval include, for the business process stage allowing prior review and subsequent approval, preparing an intermediate storage area for the operation of the current business process stage, the business operation is first written into the intermediate storage area, and can only be merged into the formal business process after subsequent review and approval; The executed state is presented in the system visualization interface, and the actual data is stored in the intermediate storage area, isolated from the data of the formal business process; The system attaches an unreviewed label to each operation. If risks are found during subsequent review, the unreviewed label is used to lock and roll back the operation, without affecting the data that has passed the review; In the prior review and subsequent approval mode, the system performs an embedded sub-module detection sub-process on the key node in an asynchronous verification manner, without blocking the operation of the business process stage; The asynchronous verification includes that whenever a user operation reaches a critical node, the system automatically sends enterprise data to the detection module for detection in the background. If the detection result is passed or warned, the unverified label of the operation that passes the detection is removed; If the detection is blocked, the rollback mechanism is immediately triggered, and the operation with the unverified label is rolled back in the temporary environment and marked as a risky operation, and a blocking alarm is sent to the staff; After the end condition of the business process stage is triggered, the system conducts a centralized review, summarizes the detection results of the detection module. If there is no blocking alarm in all the detection results, it enters the final merging link, merges the enterprise data in the intermediate storage area into the formal business process, outputs the stage log audit list, and completes the prior review and post review of the business process stage.
[0013] An enterprise data security risk classification management system adopting any of the methods of the present invention, wherein: a data acquisition module, which acquires enterprise data and business processes, performs data classification processing on the enterprise data, and classifies the enterprise data into ordinary data, sensitive data, and core data; A classification detection module, which splits the business process into multiple business process stages, marks the critical nodes in the business process stages based on the results of the data classification processing, conducts primary detection at the beginning of each business process stage, and embeds a sub-module detection sub-process at the critical nodes for key detection; A summary module, which performs switching and risk handling of the business process stage according to the key detection results, completes the overall business process and generates an audit report, and realizes the classification management of enterprise data security risks.
[0014] A computer device, comprising: a memory and a processor; the memory stores a computer program, including: when the processor executes the computer program, the steps of any of the methods of the present invention are implemented.
[0015] A computer-readable storage medium, on which a computer program is stored, including: when the computer program is executed by a processor, the steps of any of the methods of the present invention are implemented.
[0016] The beneficial effects of the present invention: The method of the present invention performs risk detection at the initial stage of the business process and distinguishes between core and non-core data, endows the low-risk and non-core data scenarios with the advantage of the compensation sub-process of "prior review and post review", and significantly improves the execution efficiency; at the same time, for high-risk or core data-involved stages, a real-time detection and blocking mechanism is strictly adopted to kill potential threats in the process operation in time. The phased technical design can not only reduce the waste of resources caused by repeated detection, but also quickly compensate or correct with the help of the rollback function after discovering anomalies, taking into account both flexibility and security. The method of the present invention is closely linked with the data classification management, realizes the differential control of the whole process, not only meets the compliance audit requirements, but also effectively balances the efficiency and risk prevention goals. Brief Description of the Drawings
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0018] Figure 1 It is the overall flowchart of a method for hierarchical management of enterprise data security risks provided by an embodiment of the present invention. Detailed Embodiments
[0019] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will describe the detailed embodiments of the present invention in conjunction with the drawings of the specification. Obviously, the described embodiments are some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0020] Embodiment 1 Referring to Figure 1 , an embodiment of the present invention provides a method for hierarchical management of enterprise data security risks, including: S1: Obtain enterprise data and business processes, perform data classification processing on the enterprise data, and classify the enterprise data into ordinary data, sensitive data, and core data.
[0021] In the enterprise informatization environment, a business process refers to a series of ordered activities or operations carried out within an enterprise or between an enterprise and external partners to achieve specific business goals. In an enterprise system, business processes are often digitally configured and managed with the help of a business process management platform (BPM) or a workflow engine, so as to connect the originally scattered operation steps in series and automate the processing or approval of each link. Taking the typical Procure-to-Pay (P2P) business process as an example, the steps are as follows: Initiation of a purchase request (requisition), where an employee of the business department submits a purchase request on the BPM platform, filling in material information, quantity, budget purpose, etc.
[0022] Approval by the department head, the process automatically transfers to the department head, who online reviews whether the application is reasonable and within the budget.
[0023] Budget review and reservation, the system automatically links to the budget module to check for budget occupancy and make reservations.
[0024] The procurement department reviews and generates a purchase order (PO). After passing the review, the procurement staff creates a formal purchase order and submits it to the supplier.
[0025] The supplier ships the goods and generates an invoice. The supplier ships the goods according to the order. After the system receives the goods, it automatically updates the inventory information and receives the invoice.
[0026] The finance department reviews and makes the payment. After the receipt confirmation, the process enters the financial approval stage. The finance staff checks according to the contract and the invoice and completes the payment.
[0027] Archiving and auditing. The entire process and all approval records are saved in the system for subsequent audit and traceability.
[0028] Based on the characteristics of the business process and the different sensitivities of enterprise data, the present invention realizes the differential control of ordinary data, sensitive data and core data through multi-stage business process management and hierarchical enterprise data security policies.
[0029] Furthermore, enterprise data includes user and permission information, system configuration data, compliance requirement data and business-related data. The enterprise data is analyzed by a data classification tool, and classification labels are assigned to the data by combining the keywords and feature strings configured by the enterprise, completing the data classification process.
[0030] Specifically, after obtaining the enterprise data, according to the characteristics of the enterprise business and regulatory requirements, a number of keywords or feature strings (such as personal privacy identifiers, financial account identifiers, confidential labels, etc.) are defined, and these rules are imported into the data classification tool or DLP system so that it can automatically identify potential sensitive data.
[0031] Start the data classification tool, batch scan the database tables, file systems, logs, etc., match the keywords for each record or document, identify labels such as highly sensitive, core confidential or ordinary. For the gray area that the tool cannot accurately judge, it can be marked for manual review.
[0032] For the data items marked by the tool for manual review, the security administrator or business responsible person conducts manual verification, and manually corrects or confirms the final classification result in combination with the actual business scenario, internal management system or external compliance requirements.
[0033] For the final classification of each piece of data, enterprise data is divided into general data, sensitive data, and core data, which are uniformly recorded in the data management library or configuration library for subsequent business processes and detection processes to call. The classification criteria for enterprise data are considered from three aspects: business impact, legal compliance requirements, and internal policies. Core data includes data that has a huge impact on the enterprise's business, is strictly controlled by industry regulations (such as the financial industry, medical industry, military industry, etc.), enterprise internal secrets, R & D patent documents, customer VIP lists, etc. Sensitive data includes data involving personal privacy, financial transactions, medical information, etc., as well as data related to daily business but can be restored through backup or within a short period of time after being damaged.
[0034] Through the above steps, the enterprise can more comprehensively understand which data belongs to core data and needs strict protection; which data is sensitive data and needs to be treated carefully; and that general data can be processed at a relatively low cost or through a relatively simple process. It provides accurate and reliable basic information for subsequent primary detection, module-based detection, and the mechanism of prior review and subsequent audit.
[0035] Data classification processing is the basis for whether subsequent primary detection (to distinguish whether it contains core data) and the embedded sub-processes at key nodes can execute differential security policies. Only after clearly distinguishing general, sensitive, and core data can the subsequent detection sub-processes differentially load more stringent or lighter security policies; S2: Split the business process into multiple business process stages, mark the key nodes in the business process stages based on the results of data classification processing, conduct primary detection at the beginning of each business process stage, and embed module-based detection sub-processes at key nodes for focused detection.
[0036] In the actual enterprise environment, the difficulty of splitting the business process depends on the maturity of the enterprise's internal processes and the degree of digital management. In some enterprises with a relatively high level of application modernization, the core business processes have often been modeled, configured in the business process management platform (BPM platform) or workflow engine, and are accompanied by information such as version management and role assignment.
[0037] In this case, the enterprise has clear flowcharts or process definitions, and can call existing processes through application programming interfaces (APIs) or scripts to implement logic such as process node control, approval, and branching. When introducing new detection or security mechanisms, only new sub-processes (such as security detection modules) need to be inserted at the key nodes of the existing process, without having to draw the entire process from scratch.
[0038] Many enterprises do have complete SOP (Standard Operating Procedure) documents or department-level process descriptions, but these processes may not have been digitized into the workflow system yet. Although the documents specify how to do each step and who will approve, to integrate them into automated detection or systematic control, it is still necessary to re-model or partially migrate them to the process management platform. In this case, although it is not necessary to completely re-design the process itself, it may be necessary to manually draw or import the existing process structure in the BPM tool and configure the nodes to achieve the automation of business processes.
[0039] Furthermore, splitting the business process into multiple business process stages includes splitting the business process according to the splitting dimension, and the splitting dimension includes department dimension, function dimension, and time sequence dimension. Specifically, according to the department dimension: label the responsible department or execution role for each node in the flowchart. When it is detected that the execution department of the node changes or the role switches significantly, a new stage can be considered to be formed.
[0040] Splitting according to the function dimension: Mark the nodes that can be regarded as milestones in the flowchart (such as contract signing completed, product R & D completed, test passed, online approval passed, etc.). A group of nodes between one milestone and the next milestone are overall divided into a stage.
[0041] Splitting according to the time sequence dimension: If the process itself has a long span, such as a large project, it can be split according to months, quarters or the output nodes of phased results for regular review and monitoring.
[0042] Set the start condition and end condition for each business process stage. The start condition is the "pre-start detection" process set in the stage attributes. When the start condition is triggered, primary detection is performed. If the detection passes, it enters this stage; otherwise, it branches to exception handling or adds an approval link. Mark the high-risk or critical activities belonging to this stage, as well as the business processes involving sensitive data and core data, as critical nodes.
[0043] Even further, the primary detection includes data detection, identity verification, and compliance detection. The data detection is performed after the start condition of the business process stage is triggered. According to the data resource ID of the data to be processed in the upcoming business process stage, the classification label of the corresponding data is queried. If there is core data, the prior-after review of the business process stage is disabled.
[0044] The identity verification includes checking whether the operating account in the current stage has the permission to perform the operations of this business process stage (RBAC role comparison, organizational structure comparison), and performing black and white list retrieval. If the operating account permission is missing or a blacklist IP is retrieved, the identity verification fails.
[0045] Compliance detection includes invoking a preset compliance detection script for detection and querying the abnormal operations of the operating account in the current stage. If the compliance detection script detects a compliance restricted area, the compliance detection fails.
[0046] When the identity verification fails or the compliance detection fails, it is determined that the primary detection fails, the execution of the business process stage is stopped, and an alarm is issued; when both the identity verification and the compliance detection pass, the business process stage continues to execute, calculates a risk score based on the results of the primary detection, and determines whether there is a risk in the business process stage according to the risk score. If there is no risk and the business process stage does not involve core data, then prior review is allowed during the execution of the business process stage; if there is a risk or the business process stage involves core data, then prior review is not allowed during the execution of the business process stage.
[0047] It should be noted that the primary detection includes hard trigger and soft trigger check items. In the primary detection, some conditions have the nature of "one-vote veto", such as: The operator or IP is found in the blacklist; The role permissions are completely invalid; A serious compliance restricted area is detected (such as illegal cross-border transmission); When such hard triggers occur, there is no need to calculate the risk degree score anymore, and it is directly determined that there is a risk, and the subsequent process is stopped or a more strict detection mode is adopted. This is because these conditions themselves are sufficient to indicate the existence of major violations or security threats.
[0048] In contrast, other elements (such as the operator's permissions are slightly lacking but not completely invalid, or this stage involves some sensitive data but not core data, etc.) may only partially increase the risk, which is called a soft trigger. At this time, it is necessary to quantify their cumulative impact through the risk degree score.
[0049] The basic execution logic is hard trigger check - soft trigger summary - scoring threshold judgment - output result. First, check one by one whether there are hard trigger items such as hitting the blacklist, completely inconsistent permissions, major compliance red lines, etc. If any one matches, directly mark the status as having a risk, and there is no need for subsequent scoring.
[0050] If there is no hard trigger, then the soft trigger items such as data classification, permission deviation, gray list, minor compliance warning, etc. are weighted and accumulated / subtracted in turn to obtain the final score value.
[0051] Compare the final score value with the preset security threshold, and judge the risk degree based on the comparison result.
[0052] The present invention introduces a primary detection link at each stage of the business process, which can quickly verify the operating accounts, data types, and compliance requirements, effectively intercept major threats, and identify potential risks. Through two modes of hard trigger one-vote veto and soft trigger score accumulation, it can decide whether to block the process or continue execution within an extremely short time, and flexibly enable the method of prior review and then approval or more stringent detection according to the risk score. This mechanism not only significantly reduces the interference to the production process but also avoids the waste of resources caused by one-size-fits-all security control, thus taking into account both security and efficiency.
[0053] Furthermore, the sub-process of modular detection includes defining a detection module for the sub-process of modular detection. The detection module is docked with an external security system and outputs results.
[0054] Using the sub-process call function of the workflow, when a key node arrives, the system automatically calls the detection module for detection. The results of each detection module are saved in the sub-process context and summarized into an overall status and returned to the main process after the sub-process ends.
[0055] The results of each detection module are divided into three types: pass, warning, and block. Based on the content returned by the sub-process, the judgment of the key detection results is made. If the results of all detection modules are passes, the sub-process returns a pass, and the business process continues without further processing.
[0056] If there are warnings in the results of the detection modules and no blocks, the sub-process returns a warning, the business process continues, but the results of the detection modules are sent for manual review.
[0057] If there is a block in the results of the detection module, the sub-process returns a block, immediately stops the operation of the key node, suspends the business process stage, and issues a security alarm to notify the staff.
[0058] In this way, no matter which security information and event management, DLP, vulnerability scanner, or permission system it is, as long as it provides an API / SDK interface, it can be mounted as a ServiceTask in the sub-process of modular detection and automatically orchestrated by the BPM engine, truly reflecting the implementation of "modular + embedded detection" at the business process level.
[0059] The detection modules include a permission and role verification module M1, a data compliance detection module M2, an abnormal behavior detection module M3, and a vulnerability scanning and external threat detection module M4; The permission and role verification module M1 includes, through a role-based access control system, calling the permission service API at the key node, passing in the user and permission information of the operating account, and judging the detection result of M1 according to the API return. Most enterprises have an RBAC (role-based access control) or ACL (access control list) system, and directory services such as LDAP / AD can also be used for permission verification.
[0060] The data compliance detection module M2 includes that at key nodes, the enterprise data to be processed is transmitted to the DLP tool, and according to the data classification information, it is identified whether the entity data processed at the key nodes meets the requirements of desensitization, authorization, and compliant use.
[0061] The abnormal behavior detection module M3 includes that when the business process reaches a key node, M3 interfaces with the security information and event management platform to detect the operation behavior and network traffic at the key node.
[0062] The vulnerability scanning and external threat detection module M4 includes quickly scanning for vulnerabilities in the system services and interfaces relied on by the key nodes through an automated vulnerability scanner.
[0063] Specifically, taking the abnormal behavior detection module M3 as an example, the complete process of the sub-module detection sub-process is given. Security information and event management platforms such as IBM QRadar, Splunk Enterprise Security, Micro Focus ArcSight, Elastic SIEM, Wazuh, etc. These platforms usually have functions such as centralized log collection, event correlation analysis, and alarm triggering, and can perform rule matching and anomaly detection on massive logs. It is also possible to implement the function of the abnormal behavior detection module M3 by establishing a machine learning model or using network security monitoring tools (Snort, Suricata).
[0064] When the business process reaches a key node, the workflow engine calls the sub-process of the abnormal behavior detection module M3, interfaces with the SIEM or UEBA platform, and performs the following operations through the API / SDK or message queue: Set the log time range to be analyzed (for example, the last 5 minutes, 30 minutes, 1 hour, etc. before the key node is triggered) to capture user operations or system events related to the key node; There may be preset rules (such as threshold triggering, event correlation rules) in the SIEM platform to quickly compare the number of failed login attempts, a large number of query operations, and data download volume of the selected user or IP. If the UEBA function is enabled, the system automatically compares the current operator with his historical baseline or the baseline of the same role. Once the gap exceeds the preset threshold, a warning or block is returned; SIEM or UEBA will return the alarm level (pass, warning, and block). After the sub-process is executed, the detection result is transmitted back to the main process through the workflow engine API or intermediate table.
[0065] In the present invention, at the key nodes of the business process, a "sub-process of modular detection" is adopted to interface with the existing security system, and the output results (pass, warning, block) of each module are uniformly summarized as the sub-process status. The main difference between this "service-oriented + modular" design concept and conventional technologies lies in that it does not let security tools independently and passively give alarms. Instead, security means such as DLP, SIEM, and vulnerability scanning are deeply integrated into the enterprise workflow engine, and are triggered synchronously and intervene in business decisions in the form of sub-processes. In this way, security detection is no longer post-positioned or bypassed, but becomes an built-in link in the execution of the business process, achieving precise detection and automatic orchestration of key nodes, thereby significantly enhancing the pertinence and control efficiency of security protection.
[0066] By invoking the sub-process of modular detection at key nodes, the present invention can automatically integrate the detection results of multiple security systems, and process scenarios of pass, warning, or block respectively in a visual workflow management manner, reducing manual operations and delays in message passing. Once a high risk is detected, the process is immediately suspended and an alarm is issued to quickly prevent potential hazards; for medium risks, a manual review is initiated to balance security and efficiency. With this differentiated disposal mode, the present invention not only enhances the synchronous control ability for data compliance, privilege overstep, and network threats, but also reduces repeated or redundant inspections in low-risk scenarios, thus achieving efficient, flexible, and refined business security management overall.
[0067] Furthermore, taking a common business process stage in an enterprise as an example (such as a certain department needs to quickly process a batch of ordinary or low-sensitivity data), when the preliminary detection determines that there is no risk and no core data in this stage, the pre-execution and post-review mode can be enabled.
[0068] The pre-execution and post-review includes, for the business process stage where pre-execution and post-review are allowed, preparing an intermediate storage area for the operations of the current business process stage. Business operations are first written into the intermediate storage area and can only be merged into the formal business process after subsequent review and approval. The intermediate storage area creates a temporary execution environment (which can also be called a "sandbox", "transition area", or "staging area") at the database or file system level, and is implemented using existing technologies (such as database transaction branches, temporary branch tables, version control, mirror / copy environments, etc.).
[0069] It should be noted that conventional pre-execution and post-review usually rely on pure post-audit, that is, operations are directly implemented in the production system and then inspections are made up. The method of the present invention creates an intermediate storage area as a temporary environment while "executing first", and when problems occur, risky operations can be quickly rolled back, without having to search through the whole process or perform data repair, reducing the pollution and irreversible impact on production data.
[0070] It should also be noted that most of the cases that require prior review are for speeding up the process. For conventional technologies, due to considerations of speed, the mode of an intermediate storage area is generally not adopted. However, in the present invention, the overall business process is split into small stages, and the establishment of an intermediate storage area for the small stages can be quickly completed, and a large amount of computing power is not required for data transmission. While enhancing the security of prior review, it does not affect the rapid review.
[0071] During the normal progress of read, write, update, and approval operations in the business process stage, the executed status is presented in the system visualization interface, and the actual data is stored in the intermediate storage area, isolated from the data of the formal business process.
[0072] The system attaches an unreviewed label to each operation. If risks are found during subsequent review, the operation is locked and rolled back using the unreviewed label, without affecting the data that has passed the review.
[0073] In the prior review mode, the system executes an embedded sub-process of module detection for key nodes in an asynchronous verification manner, without blocking the operations in the business process stage.
[0074] Asynchronous verification includes that whenever a user operation reaches a key node, the system automatically sends enterprise data to the detection module for detection in the background, without blocking the current operation. If the detection result is passed or warned, the unreviewed label of the operation that has passed the detection is removed. In this design, modular detection is still embedded in each key node, but in an "asynchronous" or "parallel" manner. Once a high risk is detected, a rollback can be immediately triggered; greatly improving the security response speed in the prior review mode.
[0075] If the detection is blocking, the rollback mechanism is immediately triggered, and the operation with the unreviewed label is rolled back in the temporary environment and marked as a risky operation, and a blocking alarm is sent to the staff.
[0076] After the end condition of the business process stage is triggered, the system conducts a centralized review, summarizes the detection results of the detection module. If there is no blocking alarm in all the detection results, it enters the final merging link, merges the enterprise data in the intermediate storage area into the formal business process, outputs the stage log audit list, and completes the prior review of the business process stage.
[0077] Under the prior review after implementation mode, by introducing the combination of an intermediate storage area and asynchronous detection based on the splitting of business process stages, the present invention significantly improves the process handling efficiency and security controllability. Specifically, the intermediate storage area allows user operations to be first written into a temporary environment without directly modifying production data. Once risks are detected, the system can accurately roll back operations with an unreviewed label to avoid large-scale data contamination; while asynchronous detection conducts security reviews in parallel at key nodes, which does not interrupt the actual operations of business process stages, but can trigger rollback and alarms immediately after detecting high-risk warnings, thus minimizing potential losses. By conducting centralized review and data merging at the end of the stage, the present invention not only retains the advantages of rapid business advancement in prior review after implementation, but also takes into account high-sensitivity data security protection, organically combines rapid processing and risk controllability, and overall improves the flexibility and security of enterprise data processing.
[0078] S3: Switch business process stages and handle risks according to the key detection results, complete the overall business process and generate an audit report to achieve hierarchical management of enterprise data security risks.
[0079] Furthermore, when the end condition of each business process stage is triggered, the system will summarize all detection information within the stage, including: Primary detection results (whether there are hard trigger / soft trigger scores); Warning / blocking situations of sub-processes detected by modules; Operation records and rollback operations of unreviewed labels in the prior review after implementation mode.
[0080] If there is no blocking or warning prompt, it indicates that this stage is basically safe and allows normal entry into the next business process stage; if there is a blocking or warning prompt, corresponding risk handling will be executed.
[0081] Risk handling includes, if the key detection result is high risk (blocking occurs): The system automatically suspends the current business process stage and issues an alarm to notify the security administrator or relevant person in charge; It is decided by a dedicated security team or process approver whether to roll back the operations of this stage, whether more in-depth compliance reviews or external audits are required; After rollback or repair, phased detection can be restarted. If it is confirmed that there are no subsequent risks, it will be un-suspended and continue, otherwise the process can be terminated in advance or transferred to a higher-level review.
[0082] Medium risk (warning occurs): The system records the warning and allows the process to continue as appropriate; At the same time, initiate manual approval or review by the security team to conduct more rigorous inspections on some suspicious operations; Based on the manual approval results, decide whether to delegate the remaining operations of this stage or upgrade to a stricter "first review, then review" mode (if it was previously in normal mode).
[0083] When a stage completes all processing and passes security checks or remediation, the system automatically jumps to the next stage according to the flowchart (stage connection rules defined by the BPM / workflow engine). If the process is at the end stage, the overall business process ends after performing finishing work such as audit report generation.
[0084] Furthermore, after completing all phased risk detection and corresponding disposal, if no major blockage occurs or necessary rollback compensation has been processed, the system declares the business process officially completed. At this time, the key node detection records, pre-review rollback results, warnings or blockages, and conclusions of manual review or security team intervention can be summarized and automatically generate an audit summary or brief report for review by management or auditors.
[0085] Subsequently, the system archives or exports the report and related log files (test results, data classification, rollback operation details, etc.) according to the requirements of internal compliance or external supervision of the enterprise. Through this centralized process end processing, the enterprise not only obtains operational data for traceability and optimization, but also can quickly issue a chain of evidence of the overall process and security risk control status in audit and compliance scenarios.
[0086] After completing the risk assessment and disposal at each stage, the present invention realizes real-time monitoring and flexible disposal of business operations through unified management of stage switching and overall process closing. Once high risks are found, they are immediately blocked and rolled back to reduce the potential loss of the company's core assets. For acceptable or minor risks, warnings or manual approval are used to balance safety and efficiency without excessively interfering with normal processes. This mechanism generates audit reports centrally at the end of the process, which is not only convenient for traceability and management decision-making, but also meets legal compliance and external regulatory requirements. Module detection and first-come, first-served methods are seamlessly connected in each link, and security incidents can be accurately intervened at any time, realizing an integrated closed-loop enterprise data security risk classification management, which greatly improves the company's security operation capabilities in a digital environment.
[0087] Example 2 In an exemplary embodiment, an enterprise data security risk classification management system is also provided, including: The data acquisition module acquires enterprise data and business processes, performs data classification on enterprise data, and divides enterprise data into general data, sensitive data, and core data.
[0088] The hierarchical detection module splits the business process into multiple business process stages, marks the key nodes in the business process stages based on the results of data hierarchical processing, conducts primary detection at the beginning of each business process stage, and embeds sub-processes for modular detection at the key nodes for focused detection.
[0089] The summary module switches the business process stages and handles risks according to the results of focused detection, completes the overall business process and generates an audit report, and realizes the hierarchical management of enterprise data security risks.
[0090] If the above functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs, etc., which can store program codes.
[0091] The logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a defined sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch instructions from the instruction execution system, apparatus, or device and execute the instructions), or in combination with these instruction execution systems, apparatuses, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device.
[0092] More specific examples (non-exhaustive list) of computer-readable media include the following: electrical connections (electronic devices) having one or more wirings, portable computer diskettes (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber devices, and portable compact disc read-only memory (CDROM). Additionally, the computer-readable media can even be paper or other suitable media on which a program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or other suitable processing as necessary, and then stored in a computer memory.
[0093] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), and the like.
[0094] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
Claims
1. A method for hierarchical management of enterprise data security risks, characterized in that, Including: Obtain enterprise data and business processes, perform data grading processing on the enterprise data, and classify the enterprise data into ordinary data, sensitive data, and core data; Split the business process into multiple business process stages, mark the key nodes in the business process stages based on the results of the data grading processing, perform primary detection at the beginning of each business process stage, and embed a sub-module detection sub-process at the key nodes for focused detection; The sub-module detection sub-process includes defining the detection modules of the sub-module detection sub-process, and the detection modules are docked with external security systems and output results; Utilize the sub-process call function of the workflow. When the key node arrives, the system automatically calls the detection module for detection. The results of each detection module are saved in the sub-process context, and after the sub-process ends, they are summarized into an overall status and returned to the main process; Classify the results of each detection module into three types: pass, warning, and block. Based on the content returned by the sub-process, judge the results of the focused detection. If the results of all detection modules are passes, the sub-process returns a pass, and the business process continues without other processing; If there are warnings in the results of the detection modules and no blocks, the sub-process returns a warning, the business process continues but the results of the detection modules are sent for manual review; If there are blocks in the results of the detection modules, the sub-process returns a block, immediately stops the operation of the key node and suspends the business process stage, and issues a security alert to notify the staff; Perform the switching of the business process stage and risk handling according to the results of the focused detection, complete the overall business process and generate an audit report, and achieve the hierarchical management of enterprise data security risks.
2. The enterprise data security risk classification and management method according to claim 1, characterized in that: The enterprise data includes user and permission information, system configuration data, compliance requirement data, and business-related data. Analyze the enterprise data through a data classification tool, and assign a grading label to the data in combination with the keywords and feature strings configured by the enterprise to complete the data grading processing.
3. The enterprise data security risk classification management method according to claim 2, characterized in that: The splitting of the business process into multiple business process stages includes splitting the business process according to the splitting dimension, and the splitting dimension includes the department dimension, the function dimension, and the time sequence dimension; Set the start condition and end condition of each business process stage. When the start condition is triggered, perform primary detection, and mark the business processes involving sensitive data and core data as key nodes.
4. The enterprise data security risk classification management method according to claim 3, wherein: The primary detection includes data detection, identity verification, and compliance detection. The data detection is executed after the start condition of the business process stage is triggered. According to the data resource ID of the data to be processed in the business process stage, query the grading label of the corresponding data. If there is core data, disable the prior review and post-review of the business process stage; The identity verification includes checking whether the operation account in the current stage has the permission to perform the operations in this business process stage, and performing black and white list retrieval. If the operation account lacks permission or a blacklisted IP is retrieved, the identity verification fails; The compliance detection includes calling a pre-set compliance detection script for detection and querying the abnormal operations of the operation account in the current stage. If the compliance detection script detects a compliance restricted area, the compliance detection fails; When the identity verification fails or the compliance detection fails, it is determined that the primary detection fails, the execution of the business process stage is stopped, and an alarm is issued; When both the identity verification and the compliance detection pass, the business process stage continues to execute. Based on the results of the primary detection, a risk score is calculated, and it is determined whether there is a risk in the business process stage according to the risk score. If there is no risk and the core data is not involved in the business process stage, then prior review and subsequent approval are allowed during the execution of the business process stage; If there is a risk or the core data is involved in the business process stage, then prior review and subsequent approval are not allowed during the execution of the business process stage.
5. The enterprise data security risk classification management method according to claim 4, wherein: The detection module includes a permissions and roles verification module M1, a data compliance detection module M2, an abnormal behavior detection module M3, and a vulnerability scanning and external threat detection module M4; The permissions and roles verification module M1 includes, through a role-based access control system, calling the permissions service API at key nodes, passing in the user and permission information of the operating account, and judging the detection result of M1 according to the API return; The data compliance detection module M2 includes, at key nodes, passing the enterprise data to be processed to the DLP tool, and identifying whether the entity data processed at the key nodes meets the requirements of desensitization, authorization, and compliant use according to the data classification information; The abnormal behavior detection module M3 includes, when the business process reaches a key node, M3 docks with the security information and event management platform to detect the operation behavior and network traffic at the key node; The vulnerability scanning and external threat detection module M4 includes, through an automated vulnerability scanner, quickly scanning for vulnerabilities in the system services and interfaces relied on by the key nodes.
6. The enterprise data security risk classification and management method according to claim 5, wherein: The prior review and subsequent approval includes, for the business process stage where prior review and subsequent approval are allowed, preparing an intermediate storage area for the operation of the current business process stage. The business operation is first written into the intermediate storage area and can only be merged into the formal business process after subsequent review passes; The executed status is presented in the system visualization interface, and the actual data is stored in the intermediate storage area, isolated from the data of the formal business process; The system attaches an un-reviewed label to each operation. If a risk is found during subsequent review, the operation is locked and rolled back using the un-reviewed label, without affecting the data that has passed the review; In the prior review and subsequent approval mode, the system performs an embedded sub-module detection sub-process on key nodes in an asynchronous verification manner, without blocking the operation of the business process stage; The asynchronous verification includes that whenever a user operation reaches a key node, the system automatically sends enterprise data to the detection module for detection in the background. If the detection result is pass and warning, the un-reviewed label of the operation that passes the detection is removed; If the detection is blocking, the rollback mechanism is immediately triggered, the operation with the un-reviewed label is rolled back in the temporary environment and marked as a risky operation, and a blocking alarm is sent to the staff; After the end condition of the business process stage is triggered, the system conducts a centralized review, summarizes the detection results of the detection module. If there is no blocking alarm in all the detection results, it enters the final merging link, merges the enterprise data in the intermediate storage area into the formal business process, outputs the stage log audit list, and completes the prior review and subsequent approval of the business process stage.
7. An enterprise data security risk classification management system for implementing the enterprise data security risk classification management method described in any one of claims 1 to 6, characterized in that, Including: A data acquisition module, which acquires enterprise data and business processes, performs data classification processing on the enterprise data, and classifies the enterprise data into ordinary data, sensitive data, and core data; A classification detection module, which splits the business process into multiple business process stages, marks the key nodes in the business process stages based on the results of the data classification processing, performs primary detection at the beginning of each business process stage, and embeds a sub-module detection sub-process at the key nodes for key detection; A summary module, which switches the business process stages and performs risk handling according to the key detection results, completes the overall business process and generates an audit report, and realizes the hierarchical management of enterprise data security risks.
8. A computer device, comprising: A memory and a processor; The memory stores a computer program, and is characterized in that: when the processor executes the computer program, the steps of an enterprise data security risk hierarchical management method as described in any one of claims 1-6 are realized.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, the steps of an enterprise data security risk hierarchical management method as described in any one of claims 1-6 are realized.
Citation Information
Cited By
Electronic warranty full-process management and control method and system
CN120746489A
Electronic guarantee letter whole-process management and control method and system
CN120746489B