Data security capability rating method based on DSMM
By introducing dynamic threshold setting, in-depth technical tool evaluation and automated evaluation tool design into the DSMM rating method, the problems of insufficient flexibility in the evaluation standards and cumbersome evaluation process in the existing methods are solved, and a more scientific, adaptable and continuously improved data security capability rating is achieved, and the rating of data security management capabilities is improved.
Patent Information
- Application Number
- CN202510297291.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-06-27
AI Technical Summary
The existing DSMM-based data security capability rating method has problems such as insufficient flexibility in evaluation standards, insufficient in-depth evaluation of technical tools, cumbersome evaluation processes, inability to track and verify evaluation results for a long time, and inability to improve data security capabilities.
A DSMM-based data security capability rating method is proposed. Through the steps of demand analysis, current status evaluation, model design, deployment and implementation, and continuous improvement, dynamic threshold setting, technical tool in-depth evaluation, automated evaluation tool design, regular evaluation and long-term tracking mechanism are adopted to ensure the scientificity, adaptability and continuous improvement of the evaluation results.
It improves the flexibility of evaluation standards and the objectivity and comprehensiveness of technical tool evaluation, simplifies the evaluation process, ensures continuous improvement and optimization of evaluation results, and improves the rating of data security management capabilities.
Smart Images

Figure CN120217384A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security, and in particular to a data security capability rating method based on DSMM. Background Art
[0002] DSMM (Data Security Management Model) is a systematic data security management framework designed to help enterprises or organizations effectively manage and protect their data assets. The main goal of DSMM is to establish a comprehensive data security management system to ensure the confidentiality, integrity and availability of data by identifying, evaluating, controlling and monitoring data security risks. It is suitable for all types of organizations, especially those industries with high requirements for data security, such as finance, healthcare, technology, etc.
[0003] According to the publication number CN114118212A - A data classification and grading method based on DSMM, it is recorded that "it includes the following steps: A. Business segmentation: segment the enterprise's business and determine the management subject of the associated data of each type of business; B. Data classification: collect and organize all data in the enterprise's business system, perform statistical analysis on the data, associate the corresponding data sum with the matching business category, and divide the data sum into multiple levels according to the business characteristics; C. Level determination: according to the data classification result, determine the level of the data to obtain the data classification result". Therefore, those skilled in the art can know that the reference patent has the following problems: Questions: 1. The evaluation criteria are not flexible enough to meet the special needs of different industries or enterprises; 2. The evaluation of technical tools in the plan is mainly based on the compliance rate, and the actual effects of the technical tools (such as protection capabilities, response speed, etc.) are not deeply analyzed, which may lead to deviations between the evaluation results and the actual security capabilities; 3. The plan needs to evaluate basic practices (BP) and process areas (PA) one by one. The process is cumbersome and may lead to low evaluation efficiency, especially in large enterprises; 4. The plan does not involve long-term tracking and verification of evaluation results, and cannot ensure the company's continued compliance after improvement; 5. The plan only has ratings, and cannot improve the ratings of target units.
[0004] In summary, a data security capability rating method based on DSMM is designed. Summary of the invention
[0005] In order to overcome the above-mentioned shortcomings, the present invention provides a data security capability rating method based on DSMM.
[0006] The present invention achieves the above-mentioned purpose through the following technical solutions:
[0007] A data security capability rating method based on DSMM includes the following steps:
[0008] Step 1: Requirement analysis. Clearly define the organization's data security management requirements and determine the implementation scope of DSMM.
[0009] Step 2: Current situation assessment. Evaluate the current data security management level through in-depth assessment of technical tools and quantitative testing of personnel capabilities.
[0010] Step 3: Model design. Design the DSMM framework according to the requirements and formulate specific security policies and processes.
[0011] Step 4: Deployment and implementation. Deploy technical measures, train employees, and implement security management processes.
[0012] Step 5: Continuous improvement. Regularly evaluate the operation effect of DSMM and optimize and improve the data security management system.
[0013] The said Step 1 includes the following steps:
[0014] S11. Requirement research. Understand the organization's business characteristics, data asset distribution, and security requirements through interviews, questionnaires, and document reviews.
[0015] S12. Scope determination. According to the research results, clarify the implementation scope of DSMM, such as specific business systems, data life cycle stages, etc.
[0016] S13. Dynamic threshold setting. Set flexible evaluation standard thresholds according to the organization's scale, industry characteristics, and business complexity. For example, the compliance rate of process areas (PAs) can be adjusted to 50%-70% according to industry characteristics.
[0017] Preferably, the said dynamic threshold setting includes the following steps:
[0018] S131. Define the goal of the dynamic threshold. According to the organization's scale, industry characteristics, business complexity, and data security requirements, set flexible evaluation criteria to ensure that the evaluation results are more in line with the actual situation. At the same time, the principles to be followed are adaptability, the threshold should be able to adapt to the characteristics of different organizations, operability: the threshold setting should be simple and easy to understand and convenient for implementation, and scientificity: the threshold setting should be based on data analysis and industry standards.
[0019] S132. Data collection and analysis. Include collecting industry data, analyzing organizational characteristics, and identifying key indicators. Through data collection and analysis, provide a scientific basis for dynamic threshold setting, where
[0020] Collect industry data: Obtain DSMM evaluation data of the same industry or similar organizations, including the compliance rates of basic practices and process areas.
[0021] Analyze organizational characteristics: Analyze the requirements for data security capabilities based on the organization's scale, business complexity, and data security needs;
[0022] Identify key metrics: Determine the key metrics that affect the threshold setting, such as data asset value, business risk level, and compliance requirements;
[0023] S133. Set the basic threshold. First, set the basic threshold according to national standards, such as GB / T 37988-2019 and industry best practices. For example, the basic value of the process area (PA) compliance rate is 60%. Then divide the threshold into multiple levels, such as low, medium, and high, corresponding to different data security capability requirements;
[0024] S134. Select adjustment factors. The adjustment factors include scale factor, risk factor, compliance factor, and industry factor. Scale factor: Reflects the impact of organizational scale on data security capabilities. Quantification method: Classify and assign values according to the number of employees, business revenue, or IT infrastructure scale (e.g., small enterprise = 1.0, medium enterprise = 1.2, large enterprise = 1.5). Risk factor: Reflects the impact of business risks on data security capabilities. Quantification method: Classify and assign values according to the business risk level (e.g., low risk = 1.0, medium risk = 1.1, high risk = 1.3). Compliance factor: Reflects the impact of compliance requirements on data security capabilities. Quantification method: Classify and assign values according to the strictness of compliance requirements (e.g., basic compliance = 1.0, full compliance = 1.2, super compliance = 1.5). Industry factor: Reflects the impact of industry characteristics on data security capabilities. Quantification method: Classify and assign values according to industry characteristics (e.g., financial industry = 1.3, medical industry = 1.2, manufacturing industry = 1.0). By selecting adjustment factors closely related to the data security capability assessment, ensure the scientificity and adaptability of the dynamic threshold;
[0025] S135. Dynamically adjust the threshold. According to organizational characteristics, introduce adjustment factors (such as scale factor, risk factor, compliance factor, etc.). Through the formula of dynamic threshold = basic threshold × scale factor × risk factor × compliance factor, calculate the dynamic threshold in combination with the adjustment factors. Through simulation evaluation or pilot testing, verify the rationality and effectiveness of the dynamic threshold. By introducing adjustment factors, achieve the dynamic adjustment of the threshold and ensure that the evaluation results are more in line with the actual situation of the organization;
[0026] S136. Implement and feedback. Apply the dynamic threshold to the actual assessment, record the assessment results and improvement suggestions. Through interviews, questionnaires, etc., collect the feedback from the assessors and the assessed. Then, according to the feedback and actual effects, optimize the adjustment factors and calculation methods to further improve the scientificity and adaptability of the threshold. Through implementation and feedback, continuously optimize the dynamic threshold to ensure its long-term effectiveness;
[0027] S137. Tool support: Develop automated tools to support the calculation and application of dynamic thresholds, and integrate the dynamic threshold calculation tool into the DSMM evaluation system to achieve automated evaluation and threshold adjustment. Through tool support, improve the efficiency and accuracy of dynamic threshold setting.
[0028] Preferably, step two includes the following steps:
[0029] S21. Classification and grading of data assets: Classify and grade data assets according to industry standards and organizational characteristics to clarify the protection priorities.
[0030] S22. In-depth evaluation of technical tools: Include three evaluation items: function verification, performance testing, and compatibility check. Function verification is to test the actual protection ability of technical tools, such as the rule effectiveness of firewalls and the response speed of intrusion detection systems. Performance testing is to evaluate the stability and performance of technical tools under high load. Compatibility check is to verify the compatibility of technical tools with existing systems.
[0031] S23. Quantitative evaluation of personnel capabilities: First, evaluate the security awareness of employees through online tests or simulation exercises, and then conduct skills tests on technical personnel to evaluate their data security practice capabilities.
[0032] Preferably, step three includes the following steps:
[0033] S31. Process domain extension: On the basis of existing process domains, add data security evaluation content for emerging technologies such as artificial intelligence and blockchain.
[0034] S32. Design of automated evaluation tools: First, develop automated evaluation tools to support the rapid evaluation of basic practices and process domains, and then integrate the evaluation tools with the organization's existing systems to achieve automatic data collection and analysis.
[0035] S33. Refinement of improvement suggestions: Provide specific implementation paths, resource requirements, and successful cases for each improvement suggestion. Through the refinement of automated evaluation tools and improvement suggestions, improve the evaluation efficiency and ensure the implementation of improvement measures.
[0036] Preferably, step four includes the following steps:
[0037] S41. Deployment of technical measures: First, deploy the evaluated technical tools to ensure that they meet the requirements of security policies, and then optimize the configuration of technical tools according to the evaluation results to improve the protection effect.
[0038] S42. Employee training: First, improve the security awareness of employees through online courses or on-site training, and then conduct special training for technical personnel to enhance their data security practice capabilities.
[0039] S43. Process implementation: Implement the designed security management process in daily work to ensure its effective execution.
[0040] Preferably, step five includes the following steps:
[0041] S51. Regular evaluation: Conduct a comprehensive evaluation of the data security management system every quarter and a in-depth audit annually to ensure the continuous compliance of the system.
[0042] S52. Long-term tracking: Establish a data monitoring mechanism to track data security incidents and risks in real time, and verify the effectiveness of improvement measures through simulated attack tests and actual incident analysis.
[0043] S53. Optimization and improvement: Analyze the existing problems based on the evaluation results, formulate an optimization plan, and continuously improve the effectiveness of the data security management system through iterative improvement.
[0044] The beneficial effects of the present invention are as follows: In this DSMM-based data security capability rating method,
[0045] 1. Dynamic threshold setting: Improve the flexibility of the evaluation criteria, and at the same time ensure the scientificity and adaptability of the dynamic threshold by selecting adjustment factors closely related to data security capability evaluation.
[0046] 2. In-depth evaluation of technical tools: Include three evaluation items: function verification, performance testing, and compatibility check. Function verification is to test the actual protection capabilities of technical tools, such as the rule effectiveness of firewalls and the response speed of intrusion detection systems. Performance testing is to evaluate the stability and performance of technical tools under high load. Compatibility check is to verify the compatibility of technical tools with existing systems, enhancing the objectivity and comprehensiveness of technical tool evaluation.
[0047] 3. Design of automated evaluation tools: First, develop automated evaluation tools to support rapid evaluation of basic practices and process areas. Subsequently, integrate the evaluation tools with the organization's existing systems to achieve automatic data collection and analysis, improving evaluation efficiency and reducing labor costs.
[0048] 4. Establish a data monitoring mechanism to track data security incidents and risks in real time, and verify the effectiveness of improvement measures through simulated attack tests and actual incident analysis to ensure the continuous improvement and optimization of evaluation results.
[0049] 5. This patent not only rates data security capabilities, but also improves and enhances data security capabilities, thereby improving the rating of data security capabilities. Description of the Drawings
[0050] The present invention will be described by way of examples with reference to the accompanying drawings, where:
[0051] Figure 1 It is the flowchart of the method steps of the present invention;
[0052] Figure 2 It is the flowchart of the requirements analysis of the present invention;
[0053] Figure 3 It is the flowchart of the dynamic threshold setting of the present invention;
[0054] Figure 4 It is the flowchart of the current situation assessment of the present invention;
[0055] Figure 5 It is the flowchart of the model design of the present invention;
[0056] Figure 6 It is the flowchart of the deployment and implementation of the present invention;
[0057] Figure 7 It is the flowchart of the continuous improvement of the present invention. Detailed implementation manners
[0058] Now, the present invention will be further described in detail with reference to the accompanying drawings. These drawings are all simplified schematic diagrams, only illustrating the basic structure of the present invention in a schematic manner, so they only show the components related to the present invention.
[0059] As Figures 1-7 shown, a data security capability rating method based on DSMM includes the following steps:
[0060] Step 1: Requirements analysis, clarify the data security management requirements of the organization, and determine the implementation scope of DSMM;
[0061] Step 2: Current situation assessment, evaluate the current data security management level through in-depth assessment of technical tools and quantitative testing of personnel capabilities;
[0062] Step 3: Model design, design the DSMM framework according to the requirements, and formulate specific security policies and processes;
[0063] Step 4: Deployment and implementation, deploy technical measures, train employees, and implement security management processes;
[0064] Step 5: Continuous improvement, regularly evaluate the operation effect of DSMM, and optimize and improve the data security management system;
[0065] The said Step 1 includes the following steps:
[0066] S11. Requirements research, understand the business characteristics, data asset distribution and security requirements of the organization through interviews, questionnaires and document reviews;
[0067] S12. Scope determination: Based on the research results, clarify the implementation scope of DSMM, such as specific business systems, data life cycle stages, etc.;
[0068] S13. Dynamic threshold setting: Set flexible evaluation standard thresholds according to the organization's scale, industry characteristics, and business complexity. For example, the compliance rate of process areas (PAs) can be adjusted to 50%-70% according to industry characteristics.
[0069] Specifically, the dynamic threshold setting includes the following steps:
[0070] S131. Define the goal of the dynamic threshold: Set flexible evaluation criteria based on the organization's scale, industry characteristics, business complexity, and data security requirements to ensure that the evaluation results are more in line with the actual situation. At the same time, the following principles should be adhered to: adaptability, the threshold should be able to adapt to the characteristics of different organizations; operability, the threshold setting should be simple and easy to understand and implement; scientificity, the threshold setting should be based on data analysis and industry standards;
[0071] S132. Data collection and analysis: Include collecting industry data, analyzing organizational characteristics, and identifying key indicators. Through data collection and analysis, provide a scientific basis for dynamic threshold setting, where
[0072] Collect industry data: Obtain DSMM evaluation data of the same industry or similar organizations, including basic practices and the compliance rate of process areas;
[0073] Analyze organizational characteristics: Analyze its requirements for data security capabilities based on the organization's scale, business complexity, and data security requirements;
[0074] Identify key indicators: Determine the key indicators affecting threshold setting, such as data asset value, business risk level, and compliance requirements;
[0075] S133. Set the basic threshold: First, set the basic threshold according to national standards, such as GB / T 37988-2019 and industry best practices. For example, the basic value of the compliance rate of process areas (PAs) is 60%, and then divide the threshold into multiple levels, such as low, medium, and high, corresponding to different data security capability requirements;
[0076] S134. Select adjustment factors. The adjustment factors include scale factor, risk factor, compliance factor, and industry factor. Scale factor: Reflects the impact of organizational scale on data security capabilities. Quantification method: Classify and assign values according to the number of employees, business revenue, or IT infrastructure scale (e.g., small enterprise = 1.0, medium enterprise = 1.2, large enterprise = 1.5). Risk factor: Reflects the impact of business risks on data security capabilities. Quantification method: Classify and assign values according to the business risk level (e.g., low risk = 1.0, medium risk = 1.1, high risk = 1.3). Compliance factor: Reflects the impact of compliance requirements on data security capabilities. Quantification method: Classify and assign values according to the strictness of compliance requirements (e.g., basic compliance = 1.0, full compliance = 1.2, super compliance = 1.5). Industry factor: Reflects the impact of industry characteristics on data security capabilities. Quantification method: Classify and assign values according to industry characteristics (e.g., financial industry = 1.3, medical industry = 1.2, manufacturing industry = 1.0). By selecting adjustment factors closely related to the evaluation of data security capabilities, ensure the scientificity and adaptability of the dynamic threshold;
[0077] S135. Dynamically adjust the threshold. According to organizational characteristics, introduce adjustment factors (such as scale factor, risk factor, compliance factor, etc.). Calculate the dynamic threshold through the formula dynamic threshold = basic threshold × scale factor × risk factor × compliance factor. Verify the rationality and effectiveness of the dynamic threshold through simulation evaluation or pilot testing. By introducing adjustment factors, achieve dynamic adjustment of the threshold to ensure that the evaluation results are more in line with the actual situation of the organization;
[0078] S136. Implementation and feedback. Apply the dynamic threshold to the actual evaluation, record the evaluation results and improvement suggestions. Collect the feedback from the evaluator and the evaluated through interviews, questionnaires, etc. Then, according to the feedback and actual effects, optimize the adjustment factors and calculation methods to further improve the scientificity and adaptability of the threshold. Through implementation and feedback, continuously optimize the dynamic threshold to ensure its long-term effectiveness;
[0079] S137. Tool support. Develop an automated tool to support the calculation and application of the dynamic threshold, and integrate the dynamic threshold calculation tool into the DSMM evaluation system to achieve automated evaluation and threshold adjustment. Through tool support, improve the efficiency and accuracy of setting the dynamic threshold.
[0080] Specifically, the second step includes the following steps:
[0081] S21. Classify and grade data assets. Classify and grade data assets according to industry standards and organizational characteristics to clarify the protection priorities;
[0082] S22. In-depth evaluation of technical tools, including three evaluation items: function verification, performance testing, and compatibility check. Function verification is to test the actual protection capabilities of technical tools, such as the rule effectiveness of firewalls and the response speed of intrusion detection systems. Performance testing is to evaluate the stability and performance of technical tools under high loads. Compatibility check is to verify the compatibility of technical tools with existing systems.
[0083] S23. Quantitative evaluation of personnel capabilities. First, evaluate the security awareness of employees through online tests or simulation exercises, and then conduct skills tests on technical personnel to evaluate their data security practice capabilities.
[0084] Specifically, Step 3 includes the following steps:
[0085] S31. Process domain expansion. On the basis of existing process domains, add data security assessment content for emerging technologies such as artificial intelligence and blockchain.
[0086] S32. Design of automated assessment tools. First, develop automated assessment tools to support rapid assessment of basic practices and process domains, and then integrate the assessment tools with the organization's existing systems to achieve automatic data collection and analysis.
[0087] S33. Refinement of improvement suggestions. Provide specific implementation paths, resource requirements, and success cases for each improvement suggestion. Through the refinement of automated assessment tools and improvement suggestions, improve the assessment efficiency and ensure the implementation of improvement measures.
[0088] Specifically, Step 4 includes the following steps:
[0089] S41. Deployment of technical measures. First, deploy the evaluated technical tools to ensure that they meet the requirements of security policies, and then optimize the configuration of technical tools according to the evaluation results to improve the protection effect.
[0090] S42. Employee training. First, improve the security awareness of employees through online courses or on-site training, and then conduct special training for technical personnel to enhance their data security practice capabilities.
[0091] S43. Implementation of processes. Implement the designed security management processes into daily work to ensure their effective execution.
[0092] Specifically, Step 5 includes the following steps:
[0093] S51. Regular evaluation. Conduct a comprehensive evaluation of the data security management system every quarter and a in-depth audit every year to ensure the continuous compliance of the system.
[0094] S52. Conduct long-term tracking, establish a data monitoring mechanism, track data security incidents and risks in real time, and verify the effectiveness of improvement measures through simulated attack tests and actual event analysis;
[0095] S53. Optimize and improve, analyze existing problems based on the evaluation results, formulate an optimization plan, and continuously enhance the effectiveness of the data security management system through iterative improvement.
[0096] Example 1: Small and medium-sized financial enterprises
[0097] Background: A small and medium-sized financial enterprise whose business involves online payment and user data management hopes to reach the DSMM level 2 standard.
[0098] 1. Requirement analysis
[0099] - Requirement research: Understand the business characteristics and data security requirements of the enterprise through interviews and questionnaires.
[0100] - Scope determination: Determine the evaluation scope as the online payment system and the user data management system.
[0101] - Dynamic threshold setting: Due to the small scale of the enterprise, set the scale factor to 1.0, the risk factor to
[0102] 1.2 (high risk in the financial industry), and the compliance factor to 1.1 (basic compliance). Dynamic threshold = 60% × 1.0 × 1.2 × 1.1 = 79.2%.
[0103] 2. Current situation assessment
[0104] - In-depth assessment of technical tools: Test the actual protection capabilities of the firewall and intrusion detection system, and find loopholes in the firewall rules.
[0105] - Quantitative assessment of personnel capabilities: Through online tests, it is found that the security awareness of employees is low and training needs to be strengthened.
[0106] 3. Model design
[0107] - Process domain extension: Add process domains for the online payment system, such as PA17 Data Interface Security.
[0108] - Design of automated assessment tools: Develop tools to automatically collect and analyze the security data of the online payment system.
[0109] 4. Deployment and implementation
[0110] - Deployment of technical measures: Repair the firewall rules and deploy the intrusion detection system.
[0111] - Employee training: Conduct security awareness training to improve the security awareness of employees.
[0112] 5. Continuous Improvement
[0113] - Regular Assessment: Conduct a comprehensive assessment of the data security management system every quarter.
[0114] - Long-term Tracking: Establish a data monitoring mechanism to track security incidents in real-time.
[0115] Result: The enterprise successfully reached the DSMM Level 2 standard, and the data security management ability was significantly improved.
[0116] Example 2: Large Manufacturing Enterprise
[0117] Background: A large manufacturing enterprise whose business involves production data and supply chain management, and hopes to reach the DSMM Level 3 standard.
[0118] 1. Requirement Analysis
[0119] - Requirement Investigation: Understand the business characteristics and data security requirements of the enterprise through interviews and document reviews.
[0120] - Scope Determination: Determine the evaluation scope as the production data system and the supply chain management system.
[0121] - Dynamic Threshold Setting: Since the enterprise is large in scale, set the scale factor to 1.5, the risk factor to
[0122] 1.1 (risk in manufacturing), and the compliance factor to 1.2 (fully compliant). Dynamic Threshold = 60% × 1.5 × 1.1 × 1.2 = 118.8%.
[0123] 2. Current Situation Assessment
[0124] - In-depth Assessment of Technical Tools: Test the performance of the data backup and recovery system and find that the recovery speed is slow.
[0125] - Quantitative Assessment of Personnel Competence: Through skills assessment, it is found that the practical ability of technical personnel is insufficient and needs to be improved.
[0126] 3. Model Design
[0127] - Process Area Expansion: Add process areas for supply chain management, such as PA24 Data Supply Chain Security.
[0128] - Design of Automated Assessment Tools: Develop tools to automatically collect and analyze the security data of the production data system.
[0129] 4. Deployment and Implementation
[0130] - Deployment of Technical Measures: Optimize the data backup and recovery system to improve the recovery speed.
[0131] - Employee Training: Conduct skills improvement training to enhance the practical abilities of technical personnel.
[0132] 5. Continuous Improvement
[0133] - Regular Assessment: Conduct a comprehensive assessment of the data security management system once every quarter.
[0134] - Long-term Tracking: Establish a data monitoring mechanism to track security incidents in real time.
[0135] Result: The enterprise successfully reached the DSMM Level 3 standard, and its data security management capabilities were significantly improved.
[0136] Example 3: Medium-sized Enterprise in the Medical Industry
[0137] Background: A medium-sized enterprise in the medical industry, whose business involves patient data management and medical device data collection, hopes to reach the DSMM Level 2 standard.
[0138] 1. Requirement Analysis
[0139] - Requirement Research: Understand the business characteristics and data security requirements of the enterprise through interviews and questionnaires.
[0140] - Scope Determination: Determine the evaluation scope as the patient data management system and the medical device data collection system.
[0141] - Dynamic Threshold Setting: Since the enterprise is of medium size, set the scale factor as 1.2, the risk factor as
[0142] 1.3 (high risk in the medical industry), and the compliance factor as 1.2 (fully compliant). Dynamic Threshold = 60% × 1.2 × 1.3 × 1.2 = 112.32%.
[0143] 2. Current Situation Assessment
[0144] - In-depth Assessment of Technical Tools: Test the actual protection capabilities of the data encryption system and find vulnerabilities in the encryption algorithm.
[0145] - Quantitative Assessment of Personnel Competence: Through simulation drills, it is found that the emergency response capabilities of employees are insufficient and need to be improved.
[0146] 3. Model Design
[0147] - Process Domain Extension: Add process domains for medical device data collection, such as PA02 Data Collection Security Management.
[0148] - Design of Automated Assessment Tools: Develop tools to automatically collect and analyze the security data of the patient data management system.
[0149] 4. Deployment and Implementation
[0150] - Technical measure deployment: Update the data encryption system and adopt a more secure encryption algorithm.
[0151] - Employee training: Conduct emergency response training to improve employees' emergency response capabilities.
[0152] 5. Continuous improvement
[0153] - Regular evaluation: Conduct a comprehensive evaluation of the data security management system every quarter.
[0154] - Long-term tracking: Establish a data monitoring mechanism to track security incidents in real time.
[0155] Result: The enterprise has successfully reached the DSMM Level 2 standard, and its data security management capabilities have been significantly improved.
[0156] Based on the inspiration of the present invention, through the above description, relevant staff can completely make various changes and modifications without departing from the technical idea of this invention. The technical scope of this invention is not limited to the content in the specification, and its technical scope must be determined according to the scope of the claims.
Claims
1. A data security capability rating method based on DSMM, characterized by: The following steps are involved: Step 1: Demand analysis, clarify the organization's data security management needs and determine the scope of DSMM implementation; Step 2: Current status assessment: evaluate the current level of data security management through in-depth evaluation of technical tools and quantitative testing of personnel capabilities; Step 3: Model design: design the DSMM framework according to the requirements and formulate specific security strategies and processes; Step 4: Deployment and implementation: deploy technical measures, train employees, and implement safety management processes; Step 5: Continuously improve, regularly evaluate the operating effect of DSMM, and optimize and improve the data security management system; The step 1 comprises the following steps: S11. Demand research: understand the organization’s business characteristics, data asset distribution, and security requirements through interviews, questionnaires, and document reviews; S12. Scope determination: Based on the survey results, the scope of implementation of DSMM should be clarified; S13. Dynamic threshold setting: Set flexible assessment standard thresholds based on organizational size, industry characteristics and business complexity.
2. The data security capability rating method based on DSMM according to claim 1 is characterized in that: The dynamic threshold setting comprises the following steps: S131. Clarify the goals of dynamic thresholds and set flexible assessment criteria based on the size of the organization, industry characteristics, business complexity, and data security needs; S132. Data collection and analysis, including collecting industry data, analyzing organizational characteristics and identifying key indicators, provides a scientific basis for dynamic threshold setting through data collection and analysis, including Collect industry data: Obtain DSMM assessment data from the same industry or similar organizations, including compliance rates for basic practices and process areas; Analyze organizational characteristics: Analyze the organization's requirements for data security capabilities based on its size, business complexity, and data security needs; Identify key indicators: determine the key indicators that affect threshold setting, such as data asset value, business risk level, and compliance requirements; S133. Set basic thresholds. First, set basic thresholds according to national standards and industry best practices, and then divide the thresholds into multiple levels corresponding to different data security capability requirements; S134. Select adjustment factors, which include scale factors, risk factors, compliance factors and industry factors; S135. Dynamically adjust the threshold. According to the characteristics of the organization, introduce adjustment factors. The dynamic threshold is calculated by combining the adjustment factors with the formula of dynamic threshold = basic threshold × scale factor × risk factor × compliance factor. The rationality and effectiveness of the dynamic threshold are verified through simulation evaluation or pilot testing. S136, implementation and feedback, apply dynamic thresholds to actual assessments, record assessment results and improvement suggestions, collect feedback from assessors and assessed parties through interviews, questionnaires, etc., and then optimize adjustment factors and calculation methods based on feedback and actual results; S137. Tool support: Develop automated tools to support the calculation and application of dynamic thresholds, and integrate dynamic threshold calculation tools into the DSMM evaluation system to achieve automated evaluation and threshold adjustment.
3. The data security capability rating method based on DSMM according to claim 1 is characterized in that: The step 2 comprises the following steps: S21. Classify and grade data assets. Classify and grade data assets according to industry standards and organizational characteristics, and clarify protection priorities; S22. In-depth evaluation of technical tools, including three evaluation items: functional verification, performance testing, and compatibility checking. Functional verification is to test the actual protection capabilities of technical tools. Performance testing is to evaluate the stability and performance of technical tools under high load. Compatibility checking is to verify the compatibility of technical tools with existing systems. S23. Quantitative assessment of personnel capabilities: First, evaluate employees’ security awareness through online tests or simulation exercises, and then conduct skill tests on technical personnel to evaluate their data security practice capabilities.
4. The data security capability rating method based on DSMM according to claim 1 is characterized in that: The step three comprises the following steps: S31, process domain expansion, based on the existing process domain, adding data security assessment content for emerging technologies; S32, Automated assessment tool design, first develop an automated assessment tool to support the rapid assessment of basic practices and process areas, then integrate the assessment tool with the organization's existing systems to achieve automatic data collection and analysis; S33. Elaborate on improvement suggestions, and provide specific implementation paths, resource requirements and success cases for each improvement suggestion.
5. The data security capability rating method based on DSMM according to claim 1 is characterized in that: The step 4 comprises the following steps: S41. Deployment of technical measures: First, deploy the evaluated technical tools to ensure that they meet the security policy requirements, and then optimize the configuration of the technical tools based on the evaluation results to improve the protection effect; S42. Employee training: First, improve employees’ security awareness through online courses or on-site training, and then carry out special training for technical personnel to improve their data security practice capabilities; S43. Process implementation: Implement the designed safety management process into daily work to ensure its effective execution.
6. The data security capability rating method based on DSMM according to claim 1 is characterized in that: The step five comprises the following steps: S51. Regular assessment: conduct a comprehensive assessment of the data security management system every quarter and an in-depth audit every year to ensure the continuous compliance of the system; S52. Long-term tracking, establishing a data monitoring mechanism, real-time tracking of data security events and risks, and verifying the effectiveness of improvement measures through simulated attack tests and actual event analysis; S53. Optimization and improvement: Analyze existing problems based on the evaluation results, formulate optimization plans, and continuously improve the effectiveness of the data security management system through iterative improvements.
Citation Information
Patent Citations
Data classification and grading method based on DSMM
CN114118212A