A dynamically adjustable enterprise data security risk management system
Through the dynamically adjusted enterprise data security risk control system, risk factors are collected and evaluated in real time, and the existing system is difficult to adapt to data changes and inflexible weight adjustments is solved, real-time and precise control of enterprise data security risks is achieved.
Patent Information
- Application Number
- CN202510671207.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2045-05-23
AI Technical Summary
The existing data security risk control system lacks a dynamic evaluation mechanism, making it difficult to adapt to data changes and inflexible weight adjustments, making it difficult for enterprises to adapt to complex and changeable production environments.
Design a dynamically adjustable enterprise data security risk management system, including data acquisition module, risk assessment and weight adjustment module and control measure adjustment module. By collecting risk factor information and key change information in real time, dynamically adjust risk assessment and weight, and achieving all-round, real-time and flexible control of enterprise data security risks.
Real-time reflection and dynamic adaptation of enterprise data security risks is achieved, the system's adaptability and flexibility is improved, and the accuracy and efficiency of risk control are ensured.
Smart Images

Figure CN120200854B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of enterprise data security risk management and control, and in particular to a dynamically adjustable enterprise data security risk management and control system. Background Art
[0002] In today's digital age, enterprises' data and information transmission faces many security risks. These risk factors are intertwined and in dynamic change, posing huge challenges to the data security of enterprises.
[0003] Some existing data security risk management systems often use static configurations, and thus cannot reflect the dynamic changes in enterprise data security risks in real time. During the data information transmission process, key parameters will continue to change, and some existing systems lack effective monitoring and response mechanisms for these key parameter changes. In addition, once the risk factor weights of the existing system are set, it is difficult to adjust them according to the actual risk situation, making it difficult for enterprises to adapt to complex and changing production environments and data changes.
[0004] Therefore, the development of a dynamically adjustable enterprise data security risk management and control system has important practical significance. The system draws on relevant technologies and concepts in the field of digital information transmission, and realizes all-round, real-time and flexible management and control of enterprise data security risks through effective data collection, transmission, processing and dynamic adjustment. Summary of the Invention
[0005] The technical problem to be solved by the present invention is that the existing technology has the shortcomings of lacking a dynamic evaluation mechanism, being difficult to adapt to data changes, and inflexible weight adjustment. To this end, we propose a dynamically adjustable enterprise data security risk management and control system.
[0006] The technical solution mainly includes: a dynamically adjustable enterprise data security risk management and control system, including a data collection module, a risk assessment and weight adjustment module, and a control measure adjustment module;
[0007] The data collection module is used to obtain risk factor information and key change information collected by each collection submodule;
[0008] The risk assessment and weight adjustment module receives the risk factor information and the key change information transmitted by the data acquisition module;
[0009] Obtaining risk impact weight information based on the risk factor information;
[0010] Obtaining a basic risk value based on the risk factor information and the risk impact weight information;
[0011] Obtaining a risk value under the influence of key changes according to the basic risk value and the key change information;
[0012] Extracting a risk warning value that is pre-set and stored in the risk assessment and weight adjustment module;
[0013] According to the changes of the sub-factors in the risk factor information, obtaining the sub-weight in the risk impact weight information that matches the sub-factor with the largest change;
[0014] Obtaining an adjusted weight based on the risk value under the influence of the key change, the risk warning value, and the sub-weight matched with the sub-factor with the largest change before and after;
[0015] The control measure adjustment module receives and executes the adjusted weight transmitted by the risk assessment and weight adjustment module;
[0016] According to the adjusted weights, risk management of the sub-factors matching the adjusted weights is performed.
[0017] Preferably, the collection submodule includes a fault monitoring device, a network flow monitoring device, a network performance monitoring tool, a network connection monitoring device, a system operation log, and a total factor collection amount that matches the fault monitoring device, the network flow monitoring device, the network performance monitoring tool, the network connection monitoring device, and the system operation log;
[0018] The sub-factors of the risk factor information include the number of equipment failures, the number of traffic anomalies, the number of data transmission delays, the number of network interruptions and the number of human errors;
[0019] The fault monitoring device is used to obtain the number of faults of the device;
[0020] The network traffic monitoring device is used to obtain the number of traffic anomalies;
[0021] The network performance monitoring tool is used to obtain the number of data transmission delays;
[0022] The network connection monitoring device is used to obtain the number of network interruptions;
[0023] The system operation log is used to obtain the number of human errors.
[0024] Preferably, the risk impact weight information includes a first weight, a second weight, a third weight, a fourth weight and a fifth weight;
[0025] The number of device failures is multiplied by the first weight to obtain a first risk of causing data loss, business interruption, and affecting normal storage and transmission of enterprise data;
[0026] The number of traffic anomalies is multiplied by the second weight to obtain a second risk of a network attack interfering with the normal data transmission of the enterprise or even causing data leakage;
[0027] The number of data transmission delays is multiplied by the third weight to obtain a third risk that affects the real-time nature of the service, thereby causing untimely data processing and indicating a potential problem in the network;
[0028] The fourth risk of preventing normal transmission and sharing of enterprise data, thereby seriously affecting business continuity, is obtained by multiplying the number of network interruptions by the fourth weight.
[0029] The fifth risk of data loss and leakage directly caused by human errors is obtained by multiplying the number of human errors by the fifth weight;
[0030] Add the first risk, the second risk, the third risk, the fourth risk, and the fifth risk to obtain a comprehensive basic risk;
[0031] Divide the comprehensive basic risk by the total factor collection amount to obtain a basic risk value;
[0032] The sum of the first weight, the second weight, the third weight, the fourth weight and the fifth weight is 1.
[0033] Preferably, the key change information includes the previous and next changes and the historical average change;
[0034] According to the positive and negative values of the before and after changes, the risk value under the influence of the key changes is obtained as follows:
[0035] When the before-after change is a negative value, the risk value under the influence of the key change under the negative value condition is directly obtained according to the basic risk value;
[0036] When the before-after change is a positive value, the relative change impact is obtained according to the before-after change and the historical average change;
[0037] According to the basic risk value and the relative change impact, the risk value under the key change impact in the case of a positive value is obtained.
[0038] Preferably, the before-after change and the historical average change are both divided into two key factors: device temperature and data transmission rate;
[0039] When the key factor is the device temperature:
[0040] The before-after change is the temperature change;
[0041] The historical average change is the average temperature change;
[0042] When the key factor is the data transmission rate:
[0043] The before-after change is the transmission rate change;
[0044] The historical average change is the average change in transmission rate;
[0045] During the initial control, one of the key factors is manually set to be selected from the device temperature and the data transmission rate.
[0046] Preferably, based on the changes of the sub-factors in the risk factor information, a specific method for obtaining the sub-weight matching the sub-factor with the largest change is as follows:
[0047] Obtaining the current and previous number of device failures, the number of traffic anomalies, the number of data transmission delays, the number of network interruptions, and the number of human errors from the risk assessment and weight adjustment module;
[0048] Divide the current number of device failures by the previous number of device failures to obtain a first change ratio;
[0049] Dividing the current number of flow anomalies by the previous number of flow anomalies to obtain a second change ratio;
[0050] Dividing the current number of data transmission delays by the previous number of data transmission delays to obtain a third change ratio;
[0051] Dividing the current number of network interruptions by the previous number of network interruptions to obtain a fourth change ratio;
[0052] Dividing the current number of human errors by the previous number of human errors to obtain a fifth change ratio;
[0053] The sub-weight of the maximum change ratio is intelligently selected from the first change ratio, the second change ratio, the third change ratio, the fourth change ratio and the fifth change ratio.
[0054] Preferably, after the initial control, the key factors are intelligently selected according to the sub-weights of the maximum change ratio, as follows:
[0055] If the maximum change ratio is the first change ratio, intelligently selecting the key factor as the device temperature;
[0056] If the maximum change ratio is the second change ratio, the third change ratio, and the fourth change ratio, then the key factor of the data transmission rate is intelligently selected.
[0057] Preferably, based on the risk value and the risk warning value under the influence of the key change, a weight adjustment amount representing the deviation ratio of the current risk relative to the threshold is obtained, so as to more intuitively reflect the degree to which the risk exceeds or falls below the threshold;
[0058] The adjusted weight is obtained based on the sub-weight of the maximum change ratio and the weight adjustment amount.
[0059] Technical effects and advantages of the present invention:
[0060] In the present invention, the system can collect the sub-factors of each risk factor and the changes before and after of the key factors in real time through the collection of the data collection module and the processing of the risk assessment and weight adjustment module, and combine the pre-set risk impact weight information and the historical average change to obtain the basic risk value and the risk value under the influence of key changes. This enables the system to reflect the dynamic changes of enterprise data security risks in real time and discover potential risks in a timely manner.
[0061] In addition, the system can automatically select key change information based on changes in key factors, and affect the risk value under the influence of key changes in real time to adapt to changes in the internal and external environment of the enterprise, thereby accurately assessing risks and improving the adaptability and flexibility of the system.
[0062] In the present invention, the process of obtaining the adjusted weights provides a flexible weight adjustment mechanism. Specifically, the system determines the sub-weights that match the sub-factors that need to be adjusted by comparing the changes before and after the sub-factors, and adjusts the sub-weights of the maximum change ratio according to the relationship between the risk value and the risk warning value under the influence of key changes. This enables the system to more accurately control the main risk factors, thereby improving the efficiency and effectiveness of risk control. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Figure 1 A risk management flow chart for the enterprise's data security risk management system;
[0064] Figure 2 This is a collection schematic diagram of the collection submodule in the present invention. DETAILED DESCRIPTION
[0065] The present invention will now be described in further detail with reference to the accompanying drawings and preferred embodiments.
[0066] Reference Figure 1 and Figure 2 As shown, the present invention provides a technical solution: a dynamically adjustable enterprise data security risk management and control system, including a data acquisition module, a risk assessment and weight adjustment module, and a control measure adjustment module;
[0067] Data collection module: obtains risk factor information and key change information collected by each collection sub-module;
[0068] The collection submodule includes fault monitoring equipment, network flow monitoring equipment, network performance monitoring tools, network connection monitoring equipment, system operation logs, and the total factor collection volume that matches the fault monitoring equipment, network flow monitoring equipment, network performance monitoring tools, network connection monitoring equipment, and system operation logs;
[0069] Risk assessment and weight adjustment module: receives risk factor information and key change information transmitted by the data acquisition module;
[0070] Obtain risk impact weight information based on risk factor information;
[0071] Obtain basic risk value based on risk factor information and risk impact weight information;
[0072] Based on the basic risk value and key change information, obtain the risk value under the influence of key changes;
[0073] Extract the risk warning value that is pre-set and stored in the risk assessment and weight adjustment module;
[0074] According to the changes of sub-factors in the risk factor information, the sub-weight in the risk impact weight information that matches the sub-factor with the largest change is obtained;
[0075] Obtain the adjusted weight based on the risk value, risk warning value, and sub-weights matching the sub-factor with the largest change before and after the key change;
[0076] Control measures adjustment module: receives and executes the adjusted weights transmitted by the risk assessment and weight adjustment module;
[0077] Based on the adjusted weights, risk management of the corresponding sub-factors is performed.
[0078] In this embodiment, first, for each acquisition submodule, the number of device failures can be counted by the device's own fault monitoring device, which records the number of failures when the device fails.
[0079] The number of traffic anomalies is counted by network traffic monitoring devices. These devices monitor network traffic in real time and record the number of abnormal traffic fluctuations.
[0080] The number of data transmission delays can be counted by network performance monitoring tools, which can monitor data transmission delays in real time;
[0081] The number of network interruptions is counted by the network connection monitoring device, which records when the network connection is interrupted;
[0082] The number of human errors can be recorded through the system operation log, and statistics are collected when operators make mistakes.
[0083] Secondly, the risk assessment and weight adjustment module collects comprehensive multi-factor data from various collection submodules to obtain the basic risk value and provide the system with the initial risk status;
[0084] Based on the basic risk value, the risk assessment is dynamically adjusted in combination with key change information to obtain the risk value under the influence of key changes, thereby enhancing the system's ability to respond to risk changes;
[0085] The final adjustment and control is completed based on the sub-weights matching the sub-factors with the largest changes before and after, allowing the system to accurately focus on the main risk factors;
[0086] The basic risk value, risk value under the influence of key changes and risk warning value obtained work together to form a closed-loop management through data collection, analysis, decision-making and control modules and related equipment, realizing comprehensive, real-time and accurate control of enterprise data security risks and improving the adaptability and effectiveness of the system.
[0087] Reference Figure 1 and Figure 2 As shown, in this embodiment: the sub-factors of the risk factor information include the number of equipment failures, the number of traffic anomalies, the number of data transmission delays, the number of network interruptions and the number of human errors;
[0088] Fault monitoring equipment is used to obtain the number of equipment failures;
[0089] Network traffic monitoring equipment is used to obtain the number of traffic anomalies;
[0090] Network performance monitoring tools are used to obtain data transmission delay times;
[0091] Network connection monitoring equipment is used to obtain the number of network interruptions;
[0092] System operation logs are used to obtain the number of human errors;
[0093] The risk impact weight information includes the first weight, the second weight, the third weight, the fourth weight and the fifth weight;
[0094] Multiply the number of device failures by the first weight to obtain the primary risk of causing data loss, business interruption, and impacting the normal storage and transmission of enterprise data.
[0095] The number of traffic anomalies is multiplied by the second weight to obtain the second risk of a network attack interfering with the normal data transmission of the enterprise, or even causing data leakage.
[0096] The number of data transmission delays is multiplied by the third weight to obtain the third risk that affects the real-time nature of the service, leading to delayed data processing and indicating potential network problems.
[0097] Multiply the number of network interruptions by the fourth weight to obtain the fourth risk of preventing normal transmission and sharing of enterprise data, thereby seriously affecting business continuity;
[0098] Multiply the number of human errors by the fifth weight to obtain the fifth risk of data loss and leakage directly caused by human errors;
[0099] Add the first risk, second risk, third risk, fourth risk and fifth risk to obtain the comprehensive basic risk;
[0100] Divide the comprehensive basic risk by the total factor collection amount to obtain the basic risk value;
[0101] The sum of the first weight, the second weight, the third weight, the fourth weight and the fifth weight is 1.
[0102] In this embodiment, the calculation formula of the basic risk value is as follows:
[0103] ;
[0104] in:
[0105] F1 is the basic risk value that reflects the basic data security risk level of the enterprise in its current state;
[0106] A larger F1 value indicates a higher risk;
[0107] The smaller the F1 value, the lower the risk;
[0108] N is the total number of factors collected, and N=5;
[0109] w i is any i-th weight among the first weight, the second weight, the third weight, the fourth weight and the fifth weight in the risk impact weight information;
[0110] f i is any i-th real-time measurement value among the risk factor information, including the number of equipment failures, the number of traffic anomalies, the number of data transmission delays, the number of network interruptions, and the number of human errors;
[0111] The result of reflects any i-th risk among the first risk, the second risk, the third risk, the fourth risk and the fifth risk;
[0112] The result is the comprehensive basic risk;
[0113] It is worth noting that the i-th weight w i The setting reflects the different importance of different risk factors to enterprise data security. Factors that have a greater impact on data security, such as the number of network interruptions, can be given a higher weight, while factors with relatively smaller impacts, such as some small errors in the number of human errors, can be given a lower weight. This can more accurately reflect the contribution of each risk factor to the overall risk and make the assessment results more targeted.
[0114] Reference Figure 1 and Figure 2 As shown, in this embodiment: the key change information includes the previous and subsequent changes and the historical average change;
[0115] Based on the positive and negative values of the changes before and after, the risk value under the influence of key changes is obtained as follows:
[0116] When the change before and after is a negative value, the risk value under the influence of the key change in the negative value is directly obtained based on the basic risk value;
[0117] When the before-after change is a positive value, the relative change impact is obtained based on the before-after change and the historical average change;
[0118] According to the basic risk value and the relative change impact, the risk value under the influence of key changes in the positive case is obtained.
[0119] In this embodiment, the calculation formula of the risk value under the influence of key changes is as follows:
[0120] ;
[0121] in:
[0122] F2 is the risk value under the influence of key changes;
[0123] △B is the change before and after;
[0124] B avg is the historical average change;
[0125] When △B≤0, that is, when the change △B is negative and 0, F2=F1;
[0126] When △B>0, that is, the change △B before and after is positive, .
[0127] Among them, it is worth mentioning that the two cases of △B≤0 and △B>0 are to avoid When F2 is less than 0, it is negative. In actual situations, the risk assessment value will generally not be negative, because the risk always exists, but the degree is different. The above operation can be retained when △B≤0, and the risk of F2=F1 is maintained.
[0128] Reference Figure 1 and Figure 2 As shown, in this embodiment, based on the changes of sub-factors in the risk factor information, the specific method for obtaining the sub-weight matching the sub-factor with the largest change is as follows:
[0129] Obtain the current and previous device failure counts, traffic anomalies, data transmission delays, network outages, and human errors from the risk assessment and weight adjustment module;
[0130] Divide the current number of device failures by the previous number of device failures to obtain a first change ratio;
[0131] Divide the current number of flow anomalies by the previous number of flow anomalies to obtain a second change ratio;
[0132] Divide the current number of data transmission delays by the previous number of data transmission delays to obtain a third change ratio;
[0133] Divide the current number of network interruptions by the number of the previous network interruption to obtain a fourth change ratio;
[0134] Divide the current number of human errors by the previous number of human errors to obtain a fifth change ratio;
[0135] Intelligently select the sub-weight of the maximum change ratio from the first change ratio, the second change ratio, the third change ratio, the fourth change ratio and the fifth change ratio;
[0136] Based on the risk value and risk warning value under the influence of key changes, obtain the weight adjustment amount representing the deviation ratio of the current risk relative to the threshold, so as to more intuitively reflect the degree to which the risk exceeds or falls below the threshold;
[0137] Based on the sub-weight of the maximum change ratio and the weight adjustment amount, the adjusted weight is obtained;
[0138] In this embodiment, the calculation formula of the adjusted weight is as follows:
[0139] ;
[0140] in:
[0141] W i,new is the adjusted weight;
[0142] F0 is the risk warning value;
[0143] The result is the weight adjustment amount;
[0144] When F2 exceeds F0, the weight adjustment amount is greater than 1, which will make the adjusted weight W i,new Increase;
[0145] When F2 is lower than F0, the weight adjustment amount is less than 1, which will make the adjusted weight W i,new reduce;
[0146] Among them, w i Here, it refers to any i-th weight among the first weight, the second weight, the third weight, the fourth weight and the fifth weight based on the maximum change ratio.
[0147] By comparing the proportion changes of the first change ratio, the second change ratio, the third change ratio, the fourth change ratio and the fifth change ratio, the sub-weight w of the maximum change ratio that needs to be adjusted is determined. i , thereby utilizing The calculation formula highlights the main risk factors, enabling enterprises to focus more resources and attention on key risks and improve the efficiency of risk management. The adjusted weight W i,new It will be used for the next risk assessment and control, so that risk control measures can target the main risk factors more accurately.
[0148] In addition, if the first change ratio has the largest change, the system will increase the inspection frequency control of the equipment and carry out equipment maintenance and care in advance;
[0149] If the second change is greater than the previous change, the system will strengthen the control of network traffic monitoring to promptly detect and prevent potential network attacks;
[0150] If the third change ratio has the largest change, the system will optimize network configuration control to reduce data transmission delay;
[0151] When the fourth change ratio reaches its maximum value, the system will increase the backup network line control to improve network reliability;
[0152] If the fifth change ratio has the largest change, the system will strengthen the control of employee training;
[0153] It should be noted that, since the sum of the first weight, the second weight, the third weight, the fourth weight and the fifth weight is 1, when the adjusted weight W among the first weight, the second weight, the third weight, the fourth weight and the fifth weight is i,new After the adjustment is made, the other weights will also be averaged and reduced so that the sum of the first weight, the second weight, the third weight, the fourth weight and the fifth weight is always 1.
[0154] Reference Figure 1As shown, in this implementation, both the before-after change and the historical average change are divided into two key factors: device temperature and data transmission rate;
[0155] When the key factor is device temperature:
[0156] The change before and after is the temperature change;
[0157] The historical average change is the average temperature change;
[0158] When data transfer rate is the key factor:
[0159] The change before and after is the change in transmission rate;
[0160] The historical average change is the average change in transmission rate;
[0161] Among them, during the initial control, one key factor is manually set from the device temperature and data transmission rate;
[0162] After the initial control, key factors are intelligently selected based on the sub-weights of the maximum change ratio, as follows:
[0163] If the maximum change ratio is the first change ratio, the key factor of the device temperature is selected intelligently;
[0164] If the maximum change ratio is the second change ratio, the third change ratio, and the fourth change ratio, then intelligent selection is a key factor for the data transmission rate.
[0165] In this embodiment, enterprise data security risks are closely related to the device operating status and data transmission conditions. Excessively high device temperature can cause device failure, which in turn affects data security. Similarly, abnormal data transmission rates may indicate network attacks or data leakage risks. By dividing the before-after change and the historical average change into two key factors, namely device temperature and data transmission rate, the actual situation closely related to data security risks can be captured more accurately, making risk assessment more suitable for the enterprise's actual operating scenarios.
[0166] During the initial control, key factors can be manually set, which fully takes into account the personalized needs of the enterprise and the experience and judgment of managers. After the initial control, key factors are intelligently selected based on the sub-weights of the maximum change ratio, so that the system can automatically adjust the focus according to actual conditions, enhancing the adaptability and flexibility of the system.
[0167] It should be noted that any modification, equivalent replacement, improvement, etc. within the spirit and principles of the present invention should also be within the scope of protection of the present invention.
Claims
1. A dynamically adjustable enterprise data security risk management and control system, characterized by: Including data collection module, risk assessment and weight adjustment module and control measures adjustment module; The data collection module is used to obtain risk factor information and key change information collected by each collection submodule; The risk assessment and weight adjustment module receives the risk factor information and the key change information transmitted by the data acquisition module; The key change information includes the previous and subsequent changes and the historical average change; The before-after change and the historical average change are both divided into two key factors: device temperature and data transmission rate; Obtaining risk impact weight information based on the risk factor information; Obtaining a basic risk value based on the risk factor information and the risk impact weight information; Obtaining a risk value under the influence of key changes according to the basic risk value and the key change information; Extracting a risk warning value that is pre-set and stored in the risk assessment and weight adjustment module; According to the changes of the sub-factors in the risk factor information, obtaining the sub-weight in the risk impact weight information that matches the sub-factor with the largest change; Obtaining an adjusted weight based on the risk value under the influence of the key change, the risk warning value, and the sub-weight matched with the sub-factor with the largest change before and after; The control measure adjustment module receives and executes the adjusted weight transmitted by the risk assessment and weight adjustment module; According to the adjusted weights, risk management of the sub-factors matching the adjusted weights is performed.
2. The dynamically adjustable enterprise data security risk management and control system according to claim 1, characterized in that: The collection submodule includes a fault monitoring device, a network flow monitoring device, a network performance monitoring tool, a network connection monitoring device, a system operation log, and a total factor collection amount that matches the fault monitoring device, the network flow monitoring device, the network performance monitoring tool, the network connection monitoring device, and the system operation log; The sub-factors of the risk factor information include the number of equipment failures, the number of traffic anomalies, the number of data transmission delays, the number of network interruptions and the number of human errors; The fault monitoring device is used to obtain the number of faults of the device; The network traffic monitoring device is used to obtain the number of traffic anomalies; The network performance monitoring tool is used to obtain the number of data transmission delays; The network connection monitoring device is used to obtain the number of network interruptions; The system operation log is used to obtain the number of human errors.
3. The dynamically adjustable enterprise data security risk management and control system according to claim 2, characterized in that: The risk impact weight information includes a first weight, a second weight, a third weight, a fourth weight and a fifth weight; Multiplying the number of equipment failures by the first weight to obtain a first risk; Multiplying the number of traffic anomalies by the second weight to obtain a second risk; Multiplying the number of data transmission delays by the third weight to obtain a third risk; Multiplying the number of network interruptions by the fourth weight to obtain a fourth risk; The fifth risk is obtained by multiplying the number of human errors by the fifth weight; Add the first risk, the second risk, the third risk, the fourth risk, and the fifth risk to obtain a comprehensive basic risk; Divide the comprehensive basic risk by the total factor collection amount to obtain a basic risk value; The sum of the first weight, the second weight, the third weight, the fourth weight and the fifth weight is 1.
4. The dynamically adjustable enterprise data security risk management and control system according to claim 3, characterized in that: According to the positive and negative values of the before and after changes, the risk value under the influence of the key changes is obtained as follows: When the before-after change is a negative value, the risk value under the influence of the key change under the negative value condition is directly obtained according to the basic risk value; When the before-after change is a positive value, the relative change impact is obtained according to the before-after change and the historical average change; According to the basic risk value and the relative change impact, the risk value under the key change impact in the case of a positive value is obtained.
5. The dynamically adjustable enterprise data security risk management and control system according to claim 4, characterized in that: When the key factor is the device temperature: The before-after change is the temperature change; The historical average change is the average temperature change; When the key factor is the data transmission rate: The before-after change is the transmission rate change; The historical average change is the average change in transmission rate; During the initial control, one of the key factors is manually set to be selected from the device temperature and the data transmission rate.
6. The dynamically adjustable enterprise data security risk management and control system according to claim 5, characterized in that: Based on the changes of the sub-factors in the risk factor information, a specific method for obtaining the sub-weight matching the sub-factor with the largest change is as follows: Obtaining the current and previous number of device failures, the number of traffic anomalies, the number of data transmission delays, the number of network interruptions, and the number of human errors from the risk assessment and weight adjustment module; Divide the current number of device failures by the previous number of device failures to obtain a first change ratio; Dividing the current number of flow anomalies by the previous number of flow anomalies to obtain a second change ratio; Dividing the current number of data transmission delays by the previous number of data transmission delays to obtain a third change ratio; Dividing the current number of network interruptions by the previous number of network interruptions to obtain a fourth change ratio; Dividing the current number of human errors by the previous number of human errors to obtain a fifth change ratio; The sub-weight of the maximum change ratio is intelligently selected from the first change ratio, the second change ratio, the third change ratio, the fourth change ratio and the fifth change ratio.
7. The dynamically adjustable enterprise data security risk management and control system according to claim 6, characterized in that: After the initial control, the key factors are intelligently selected based on the sub-weights of the maximum change ratio, as follows: If the maximum change ratio is the first change ratio, intelligently selecting the key factor as the device temperature; If the maximum change ratio is the second change ratio, the third change ratio, and the fourth change ratio, then the key factor of the data transmission rate is intelligently selected.
8. The dynamically adjustable enterprise data security risk management and control system according to claim 6, characterized in that: Obtaining a weight adjustment amount based on the risk value and risk warning value under the influence of the key changes; The adjusted weight is obtained based on the sub-weight of the maximum change ratio and the weight adjustment amount.
Citation Information
Patent Citations
Data security protection supervision system
CN119249459A
Visual monitoring system and method for electric power facilities
CN119628221A