Personal information security protection capability evaluation system and method
The system addresses the inflexibility of existing evaluation schemes by offering a dynamic, adaptive, and automated approach to personal information security assessment, enhancing security through customizable indicators and large language model analysis.
Patent Information
- Application Number
- CN202510366171.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-07-15
AI Technical Summary
The existing evaluation model of personal information security protection capability evaluation scheme is solidified and single, and it is impossible to make an objective, efficient and specific evaluation of personal information protection capabilities, and it is unable to adapt to changes in the network environment and the evolution of security threats.
It provides a personal information security protection capability evaluation system, including certification and authorization units, evaluation index system construction units, evaluation project management units, personal information security protection capability evaluation units, evaluation report pre-filling units and evaluation report export units. It analyzes relevant documents through a large language model, builds a personalized evaluation index system, and conducts multi-link evaluation and report generation.
It has achieved quantitative, objective and efficient evaluation of personal information security protection capabilities, identified potential risk points, provided targeted security suggestions, and improved the ability to resist network security threats.
Smart Images

Figure CN120316752A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cyberspace security, and specifically to an evaluation scheme for personal information security protection capabilities. Background Art
[0002] In the context of the rapid development of information technology today, the protection of personal information security has become one of the global focus issues. With the rapid development of Internet technology, security issues such as personal information leakage, privacy infringement, and identity theft have become increasingly prominent, posing a serious threat to personal privacy, enterprise data, and even national security. The evaluation technology for personal information security protection capabilities, as a key means to address these challenges, has become increasingly important.
[0003] The evaluation technology for personal information security protection capabilities is a key technology in the field of network security. Its core purpose is to comprehensively evaluate and deeply analyze the security protection measures of personal information in the network environment through systematic methods and tools. This technology focuses on identifying weak links in personal information security protection, which may include but are not limited to weak password, leakage of sensitive personal information, unauthorized viewing of sensitive personal information, unencrypted data transmission, etc. By identifying these potential risk points, the evaluation technology for personal information security protection capabilities can provide targeted security suggestions and improvement measures for enterprises, thereby effectively improving the enterprise's resistance to network security threats.
[0004] With the rapid development of the Internet, the network environment has changed rapidly, and at the same time, new security threats have emerged, which puts forward higher requirements for personal information security protection capabilities. However, the evaluation models of existing personal information security protection capability evaluation schemes are rigid and single, and cannot objectively, efficiently, and specifically evaluate personal information protection capabilities, and can no longer meet the requirements.
[0005] Therefore, providing an evaluation scheme for personal information security protection capabilities that can continuously update the evaluation model according to the changes in the network environment and the evolution of security threats is a technical problem that urgently needs to be solved in this field. Summary of the Invention
[0006] Aiming at the problems existing in the existing personal information security protection capability evaluation scheme, the purpose of the present invention is to provide an evaluation scheme for personal information security protection capabilities, which has real-time and dynamic characteristics, can continuously update the evaluation model and protection strategy according to the changes in the network environment and the evolution of security threats, and can quantitatively, objectively, efficiently, and specifically evaluate the personal information security protection capabilities in the field of network security.
[0007] To achieve the above purpose, the present invention provides an evaluation system for personal information security protection capabilities, including:
[0008] An authentication and authorization unit, which is configured to authenticate the identity information of system users and set permissions;
[0009] An evaluation index system construction unit, which is configured to be associated with the authentication and authorization unit and can construct a personalized evaluation index system by setting one or more of evaluation categories, evaluation items, and evaluation index data information;
[0010] An evaluation project management unit, which is configured to be associated with the authentication and authorization unit and the evaluation index system construction unit, and can establish and manage personal information security protection ability evaluation task projects based on the evaluation index system constructed in the evaluation index system construction unit;
[0011] A personal information security protection ability evaluation unit, which is associated with the authentication and authorization unit, the evaluation index system construction unit, and the evaluation project management unit, and can, according to the evaluation index system associated with the personal information security protection ability evaluation task project established by the evaluation project management unit, perform multi-link evaluation on the personal information security protection ability through evaluation calculation processing including evaluation project overview, basic information investigation, risk identification, risk comprehensive analysis, and evaluation report export, and generate an evaluation result;
[0012] An evaluation report pre-filling unit, which is associated with the evaluation index system construction unit, the evaluation project management unit, and the personal information security protection ability evaluation unit, and can call a large language model, parse files related to personal information security protection according to a preset prompt template, extract key information therefrom, and thus pre-fill the content of the personal information security protection ability evaluation report;
[0013] An evaluation report export unit, which is associated with the evaluation project management unit, the personal information security protection ability evaluation unit, and the evaluation report pre-filling unit, and can form and export a protection ability evaluation report containing various evaluation indexes and in-depth analysis conclusions based on the evaluation result generated by the personal information security protection ability evaluation unit and / or the content of the evaluation report pre-filled by the evaluation report pre-filling unit.
[0014] In some embodiments of the present invention, the authentication and authorization unit includes:
[0015] A role management module, which is used to define the specific operation permissions of different user roles;
[0016] A user management module, which is used to edit user role information;
[0017] Log monitoring module, which is used to record the login behaviors of all users.
[0018] In some embodiments of the present invention, the evaluation index system construction unit includes:
[0019] Evaluation category management module, which is used to define different evaluation categories;
[0020] Evaluation item management module, which is associated with the evaluation category management module and can set specific evaluation items for each evaluation category defined by the evaluation category management module. The evaluation items include specific contents and requirements, and establish the logical relationship between the evaluation categories and the evaluation items;
[0021] Evaluation index management module, which creates a diversified, detailed and extensible evaluation index library, and each index is configured with corresponding standards and scoring rules.
[0022] In some embodiments of the present invention, the evaluation project management unit includes:
[0023] Project life cycle management module, which is used to create and manage the personal information security protection ability evaluation task project;
[0024] Document and resource management module, which is associated with the project life cycle management module and obtains and manages various documents and resources related to the project according to the created personal information security protection ability evaluation task project.
[0025] In some embodiments of the present invention, the personal information security protection ability evaluation unit includes:
[0026] Project overview module, which obtains and records the basic information of the project according to the personal information security protection ability evaluation task project established by the evaluation project management unit;
[0027] Information research module, which obtains and records the detailed information of the personal information processor according to the basic information of the project recorded by the project overview module;
[0028] Baseline verification module. The baseline verification module obtains and records information on all key components in the network system involved in the personal information security protection ability evaluation task project according to the basic project information recorded by the project overview module, evaluates the security configuration of the involved network system based on the recorded information, and verifies the accuracy and integrity of the involved device information. The baseline verification module also checks each security control node of the personal information processing activities in the actual environment through on-site inspections according to the basic project information recorded by the project overview module, and records the compliance situation and supporting documents.
[0029] Risk identification module. The risk identification module is associated with the project overview module, information research module, and baseline verification module, and conducts comprehensive risk calculation and identification on information from the management system to the organizational structure level for the personal information security protection ability evaluation task project, generating risk identification result information. It conducts compliance checks on the information of the compliance situation and supporting documents recorded in each security control link of the personal information processing activities, identifies potential risk points, and generates non-compliance evaluation index item information.
[0030] Evaluation conclusion generation module. The evaluation conclusion generation module is associated with the project overview module, information research module, and risk identification module, and automatically calculates the scores of each evaluation index based on a preset scoring model to obtain a comprehensive score.
[0031] In some embodiments of the present invention, the evaluation report pre-filling unit includes:
[0032] Prompt template library management module. The prompt template library management module is used to provide various types of evaluation report filling prompt templates.
[0033] Large language model pre-filling module. The large language model pre-filling module can call the large language model, parse files related to personal information security protection capabilities, identify and extract key information therefrom, and integrate the extracted key information into the knowledge base. The large language model pre-filling module can also extract corresponding key information from the knowledge base according to the evaluation report filling prompt templates provided by the prompt template library management module to pre-fill the content of the personal information security protection ability evaluation report.
[0034] In some embodiments of the present invention, the evaluation report export unit includes:
[0035] Standardized report generation module. The standardized report generation module can generate a protection ability evaluation report based on the evaluation results generated by the personal information security protection ability evaluation unit and / or the content of the evaluation report pre-filled by the evaluation report pre-filling unit, and in accordance with a unified format and layout.
[0036] An export module, which interacts with the standardized report generation module and can support the export of evaluation report data generated by the standardized report generation module in multiple formats.
[0037] To achieve the above object, the present invention also provides a method for evaluating personal information security protection capabilities, the evaluation method comprising:
[0038] Construct a personalized evaluation index system by setting one or more of evaluation categories, evaluation items, and evaluation index data information;
[0039] Establish and manage personal information security protection capability evaluation task projects based on the constructed evaluation index system;
[0040] According to the evaluation index system associated with the personal information security protection capability evaluation task project established by the evaluation project management unit, conduct multi-link evaluation of the personal information security protection capability through evaluation calculation processing including evaluation project overview, basic information research, risk identification, risk comprehensive analysis, and evaluation report export, and generate an evaluation result;
[0041] Call a large language model to parse files related to personal information security protection capabilities, extract key information therefrom, and pre-fill the content of the personal information security protection capability evaluation report accordingly;
[0042] Form a protection capability evaluation report containing various evaluation indexes and in-depth analysis conclusions based on the generated evaluation result and / or the pre-filled content of the evaluation report.
[0043] In some embodiments of the present invention, when constructing the evaluation index system, the evaluation method includes:
[0044] First, define different evaluation categories;
[0045] Next, set specific evaluation items for each located evaluation category, where the evaluation items include specific content and requirements, and establish the logical relationship between the evaluation category and the evaluation item;
[0046] Finally, create a multi-element, detailed, and extensible evaluation index library, and each index is configured with corresponding standards and scoring rules.
[0047] In some embodiments of the present invention, when pre-filling the content of the personal information security protection capability evaluation report, by calling a large language model, parsing files related to personal information security protection capabilities, identifying and extracting key information therefrom, and integrating the extracted key information into the knowledge base; then extracting the corresponding key information from the knowledge base according to the evaluation report filling prompt template to pre-fill the content of the personal information security protection capability evaluation report.
[0048] The solution provided by the present invention supports quantitative scoring and comprehensive and systematic evaluation of the personal information security protection ability; the solution of the present invention solves the problems of low efficiency and poor evaluation accuracy of manual evaluation of personal information security protection ability through methods such as constructing an evaluation index system for personal information security protection ability, evaluating the impact of personal information security protection ability throughout the process, pre-filling a personal information security protection ability evaluation report based on a prompt template and a large language model, and one-key export of a personal information security protection ability evaluation report, and can provide strong support for the evaluation unit to carry out the evaluation work of personal information security protection ability throughout the process and index, quantify, and concretize the personal information security protection ability evaluation process. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments.
[0050] Figure 1 It is a schematic diagram of the composition of the personal information security protection ability evaluation system solution in the present invention;
[0051] Figure 2 It is a schematic diagram of the composition of the authentication and authorization unit in the present invention;
[0052] Figure 3 It is a schematic diagram of the composition of the evaluation index system construction unit in the present invention;
[0053] Figure 4 It is a schematic diagram of the composition of the evaluation project management unit in the present invention;
[0054] Figure 5 It is a schematic diagram of the composition of the personal information security protection ability evaluation unit in the present invention;
[0055] Figure 6 It is a schematic diagram of the composition of the evaluation report pre-filling unit in the present invention;
[0056] Figure 7 It is a schematic diagram of the composition of the evaluation report export unit in the present invention;
[0057] Figure 8 It is a system block diagram of the personal information security protection ability evaluation software system in the example of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0058] In order to make the technical means, creative features, achieved purposes and effects of the present invention easy to understand, the present invention will be further described below in conjunction with specific illustrations.
[0059] In order to comprehensively and effectively evaluate the personal information protection ability of the evaluation object, the present invention provides a personal information security protection ability evaluation scheme. This evaluation scheme constructs an evaluation index system for personal information security protection ability and evaluates the impact of the full-process personal information security protection ability. On this basis, it further provides a large language model privacy policy parsing based on a prompt template to pre-fill the personal information security protection ability evaluation report. Thus, it can comprehensively evaluate the effectiveness of personal privacy protection measures, deeply analyze potential risk points, identify weak links in personal information security protection, such as weak password, sensitive information leakage, unauthorized viewing of sensitive information, unencrypted data transmission, etc., provide targeted security suggestions and improvement measures for individuals, thereby effectively improving individuals' resistance to network security threats and providing technical support for the secure sharing of data.
[0060] See Figure 1 , which shows the schematic composition diagram of the personal information security protection ability evaluation system scheme formed when the solution of the present invention is specifically implemented.
[0061] Based on the illustration, the personal information security protection ability evaluation system 100 mainly consists of six functional units, namely, an authentication and authorization unit 110, an evaluation index system construction unit 120, an evaluation project management unit 130, a personal information security protection ability evaluation unit 140, an evaluation report pre-filling unit 150, and an evaluation report export unit 160, which cooperate with each other.
[0062] Among them, the authentication and authorization unit 110 is set to be able to authenticate the system user identity information and set permissions.
[0063] Furthermore, the authentication and authorization unit 110 is configured to allow the administrator to create, delete, and modify user information and permissions, including setting permissions for evaluation staff and super administrators, to ensure the security of the system and the reasonable distribution of operation permissions.
[0064] The evaluation index system construction unit 120 is set to be able to construct a personalized evaluation index system by setting one or more of the evaluation categories, evaluation items, and evaluation index data information.
[0065] Furthermore, the evaluation index system construction unit 120 is set to be associated with the authentication and authorization unit 110. Based on the user permissions set by the authentication and authorization unit 110, it supports the administrator to perform operations such as adding, deleting, querying, and modifying evaluation categories, evaluation items, and evaluation indexes, and construct a personalized evaluation index system to adapt to different evaluation requirements and standard changes.
[0066] The evaluation project management unit 130 is set to be associated with the evaluation index system construction unit 120, and can establish and manage the personal information security protection ability evaluation task project based on the evaluation index system constructed in the evaluation index system construction unit 120.
[0067] Furthermore, the evaluation project management unit 130 is further set to be associated with the authentication and authorization unit 120. Based on the user permissions set by the authentication and authorization unit 110, it is configured to allow administrators and assessment staff to manage the evaluation projects of individuals or teams, including importing assessment results, tracking project progress, and viewing score changes, etc., to help users dynamically monitor and optimize personal information security protection measures.
[0068] The personal information security protection ability evaluation unit 140 is associated with the authentication and authorization unit 110, the evaluation index system construction unit 120, and the evaluation project management unit 130. It can conduct multi-link evaluation of the personal information security protection ability through evaluation calculation processing including evaluation project overview, basic information research, risk identification, risk comprehensive analysis, and evaluation report export based on the evaluation index system associated with the personal information security protection ability evaluation task project established by the evaluation project management unit, and generate evaluation results.
[0069] Specifically, the personal information security protection ability evaluation unit 140 can perform the full-process personal information security protection ability impact evaluation function, covering multiple evaluation links such as evaluation project overview, basic information research, risk identification, risk comprehensive analysis, and evaluation report export, to ensure that personal information processing activities meet requirements and effectively reduce security risks.
[0070] The evaluation report pre-filling unit 150 is associated with the evaluation index system construction unit 120, the evaluation project management unit 130, and the personal information security protection ability evaluation unit 140. It can call the large language model, parse the files related to personal information security protection according to the preset prompt template, extract key information from them, and thus pre-fill the content of the personal information security protection ability evaluation report.
[0071] Specifically, the files related to personal information security protection here mainly include privacy policy files, management reports, evaluation result files generated by the personal information security protection ability evaluation unit, and the test file knowledge base, etc.
[0072] The evaluation report export unit 160 is associated with the evaluation project management unit 130, the personal information security protection ability evaluation unit 140, and the evaluation report pre-filling unit 150. It can generate and export a protection ability evaluation report containing various evaluation indicators and in-depth analysis conclusions based on the evaluation results generated by the personal information security protection ability evaluation unit 140 and / or the content of the evaluation report pre-filled by the evaluation report pre-filling unit 150.
[0073] Furthermore, the evaluation report export unit 160 can generate an evaluation report based on a standardized format. As an example, it can automatically generate a Word format report containing evaluation tables and analysis conclusions according to the project evaluation process and evaluation results, which is convenient for archiving and sharing.
[0074] On this basis, the present invention further gives possible composition schemes for each functional unit in the personal information security protection ability evaluation system 100.
[0075] See Figure 2 , which shows a schematic composition diagram of the authentication and authorization unit 110 in the solution of the present invention.
[0076] Based on the illustration, the authentication and authorization unit 110 given here is mainly composed of a role management module 111, a user management module 112, and a log monitoring module 113 in cooperation.
[0077] Among them, the role management module 111 is set to be able to define the specific operation permissions of different user roles.
[0078] As a further explanation, among the different user roles defined based on this role management module 111, the administrator can define the specific operation permissions of different roles, such as viewing, editing, adding, etc.; at the same time, it provides a clear permission hierarchy view to help the administrator perform refined role permission allocation.
[0079] As an example, when the role management module 111 performs role management, it can enable the administrator to define specific operation permissions for different roles, such as viewing, editing, adding, etc., to ensure that each role can only perform operations within its scope of responsibilities, and provides a clear permission hierarchy view to show the permission relationships between different roles, helping the administrator perform refined role permission allocation to ensure the transparency and rationality of permission settings; in addition, it also supports the permission inheritance mechanism, where high-level roles can have all the permissions of low-level roles and can additionally set specific permissions to override the default settings to meet the needs of complex organizational structures.
[0080] The user management module 112 is set to be used for editing user role information.
[0081] As a further illustration, the user management module 112 specifically supports creating, editing, and deleting detailed user information, including account number, name, department, role, contact information, etc.; it can enable or disable user accounts to ensure that only authorized personnel can access the system; at the same time, it can provide password reset and modification functions to enhance account security.
[0082] As an example, when the user management module 112 conducts user management, it can support creating, editing, and deleting detailed user information, including account number, name, department, role, contact information, etc., so as to ensure the accuracy and integrity of user information. It can also enable or disable user accounts to ensure that only authorized personnel can access the system and prevent unauthorized access. At the same time, it provides password reset and modification functions to enhance account security, supports strong password policies such as minimum length and character combination requirements, improves the security of the account, and supports two-factor authentication mechanisms to further enhance the security of user logins and reduce the risk of unauthorized access.
[0083] The log monitoring module 113 is set to record the login behaviors of all users.
[0084] As a further illustration, the log monitoring module 113 is specifically set to record the login behaviors of all users, including information such as login time, IP address, operating system, browser, etc., which is convenient for tracking abnormal activities; at the same time, it also tracks and records various operations of users in the system, including request module, address, method, parameters, response code, etc., which helps with auditing and troubleshooting.
[0085] As an example, when the log monitoring module 113 monitors and records the login behaviors of all users, it specifically records information such as login time, IP address, operating system, browser, etc., which is convenient for tracking abnormal activities and timely discovering potential security threats. It also tracks and records various operations of users in the system, including request module, address, method, parameters, response code, etc., which helps with auditing and troubleshooting to ensure the stability and security of the system. In addition, the log monitoring module 113 also provides log analysis tools to automatically detect abnormal behavior patterns and trigger an alarm mechanism to remind the administrator to take necessary security measures.
[0086] Based on the authentication and authorization unit 110 configured as such, the evaluation system can first perform authentication and authorization during operation, thereby ensuring the security of the entire system and the reasonable allocation of operation permissions. The administrator user operations are carried out based on this authentication and authorization unit 110, including but not limited to creating, deleting, and modifying user information and permission settings within the system. This function is not limited to the management of ordinary users, but also covers the setting of operation permissions for high-privilege accounts such as evaluation staff and super administrators. Through a strict permission control mechanism, it is ensured that only verified legitimate users can access sensitive data in the system and perform critical operations, thereby effectively preventing unauthorized access and potential security threats.
[0087] See Figure 3 , which shows a schematic diagram of the composition of the evaluation index system construction unit 120 in the solution of the present invention.
[0088] Based on the illustration, the evaluation index system construction unit 120 presented here is mainly composed of an evaluation category management module 121, an evaluation item management module 122, and an evaluation index management module 123 in cooperation.
[0089] Among them, the evaluation category management module 121 is configured to be able to define different evaluation categories.
[0090] As a further explanation, when the evaluation category management module 121 defines different evaluation categories, it also supports multi-version management, allowing different projects to select the most suitable evaluation standard version.
[0091] As an example, when the evaluation category management module 121 defines different evaluation categories, it ensures that the evaluation covers the entire security field, supports multi-version management, allows different projects to select the most suitable evaluation standard version to adapt to changing laws, regulations, and technical standards; at the same time, it can obtain the newly released evaluation standard version in a timely manner and can automatically push update notifications to remind the administrator to apply the new version of the standard in a timely manner to maintain the effectiveness and relevance of the evaluation.
[0092] The evaluation item management module 122 is set to be associated with the evaluation category management module 121 and can set specific evaluation items for each evaluation category located by the evaluation category management module 121. The evaluation items described here include specific contents and requirements, and establish the logical relationship between the evaluation category and the evaluation item.
[0093] For example, when the evaluation item management module 122 sets specific evaluation items for each evaluation category, it clarifies the specific content and requirements of each item to ensure the consistency and coherence of the evaluation process, and establishes the logical relationship between the evaluation category and the evaluation items to ensure the mutual dependence and correlation between the evaluation items, avoiding duplication or omission. In addition, the evaluation item management module 122 also supports the review mechanism of evaluation items to ensure that the content and requirements of the evaluation items comply with the latest laws, regulations and technical standards, and guarantee the authority and accuracy of the evaluation.
[0094] The evaluation index management module 123 is configured to create a diversified, detailed and extensible evaluation index library, and each index is configured with corresponding standards and scoring rules.
[0095] As a further illustration, when the evaluation index management module 123 conducts evaluation index management, it creates a diversified, detailed and extensible evaluation index library, and each index has clear standards and scoring rules, and supports real-time updating and adjustment of the evaluation indexes according to the latest laws, regulations and technical standards to maintain the effectiveness and relevance of the evaluation.
[0096] For example, when the evaluation index management module 123 is running, it can create a diversified, detailed and extensible evaluation index library, and each index has clear standards and scoring rules to ensure the scientificity and fairness of the evaluation.
[0097] The evaluation index management module 123 can also regularly obtain the latest laws, regulations and technical standard text information, and parse the obtained laws, regulations and technical standard text information by calling the big data model, put forward the key information related to the evaluation indexes, and accordingly conduct real-time updating and adjustment of the evaluation indexes to maintain the effectiveness and relevance of the evaluation.
[0098] The evaluation index management module 123 also provides an index review mechanism to ensure that the newly added or modified evaluation indexes are strictly reviewed and comply with the overall framework and requirements of the evaluation system.
[0099] Based on the evaluation index system construction unit 120 constituted as such, the evaluation system can support the construction of a highly flexible personal information security protection ability evaluation index system during operation. It enables the administrator to easily realize the operations of adding, deleting, querying and modifying the evaluation categories, evaluation items and specific evaluation indexes through the graphical interface, simplifies the construction process of the personalized evaluation index system, and also enables the system to quickly adapt to the changing evaluation requirements and the latest industry standards, further improving the accuracy and comprehensiveness of the evaluation.
[0100] See Figure 4 , which shows a schematic diagram of a composition of the evaluation item management unit 130 in the solution of the present invention.
[0101] Based on the illustration, the evaluation project management unit 130 presented here is mainly composed of the cooperation of the project life cycle management module 131 and the document and resource management module 132.
[0102] Among them, the project life cycle management module 131 is used to create and manage the personal information security protection ability evaluation task project.
[0103] As a further explanation, the project life cycle management module 131 can perform project life cycle management, covering the entire process from project creation to completion, providing a convenient project creation wizard to guide users to input necessary project information, and supporting batch import of project data to improve the initial setup efficiency.
[0104] As an example, when performing project life cycle management, the project life cycle management module 131 guides users to input necessary project information, such as name, client unit, evaluation object, etc., through a convenient project creation wizard. On this basis, according to project requirements, it guides users to select the evaluation index system established by the associated evaluation index system building unit 120, thereby simplifying the project creation process. This project life cycle management module 131 also supports batch import of project data, improves the initial setup efficiency, and reduces the workload of manual input; this project life cycle management module 131 also displays the implementation progress of the project through a visual progress bar, enabling users to intuitively understand the current stage; this project life cycle management module 131 also automatically updates the project status to ensure that the project progresses as planned, saves the evaluation results of each time, supports historical data comparison and trend analysis, helps users identify long-term changes and development patterns, and provides a basis for continuous improvement.
[0105] The document and resource management module 132 is set to be associated with the project life cycle management module 131, and can obtain and manage various types of documents and resources related to the project according to the created personal information security protection ability evaluation task project.
[0106] When the document and resource management module 132 performs document and resource management, it can support uploading various types of documents related to the project, such as privacy policies, management systems, test reports, etc., as the basic materials for evaluation, and can ensure that all relevant documents and resources are properly managed and utilized.
[0107] As an example, when running, this document and resource management module 132 supports uploading various types of documents related to the project, such as privacy policies, management systems, test reports, etc., as the basic materials for evaluation, and can perform automatic classification and sorting for easy searching and use, and ensure that each revision of the document is traceable, facilitating traceability and auditing; this document and resource management module 132 also supports version rollback to restore to any historical version, ensuring the security and integrity of the document.
[0108] Based on the evaluation item management unit 130 configured as such, this evaluation system can implement the evaluation item management function for personal information security protection capabilities, enabling administrators and evaluation staff to manage the evaluation tasks of individuals or teams, and to complete operations such as importing new evaluation results, tracking the real-time progress of projects, and viewing the change trends of historical scores on a unified platform.
[0109] As needed, it can be further configured to support the visual display of personal information security protection capability scores, thereby achieving an intuitive understanding and analysis of evaluation data, and thus taking more targeted improvement measures.
[0110] See Figure 5 , which shows a schematic diagram of the composition of the personal information security protection capability evaluation unit 140 in the solution of the present invention.
[0111] Based on the illustration, the personal information security protection capability evaluation unit 140 presented here is mainly composed of a project overview module 141, an information research module 142, a baseline verification module 143, a risk identification module 144, and an evaluation conclusion generation module 145 in cooperation.
[0112] Among them, the project overview module 141 is set to be able to obtain and record the basic information of the project according to the personal information security protection capability evaluation task project established by the evaluation item management unit.
[0113] Furthermore, the basic information of the project obtained and recorded by this project overview module 141 includes recording the background information, evaluation purpose, basis, and scope of the project, laying a foundation for subsequent evaluations. This project overview module 141 also supports the upload of attachments to supplement detailed description materials; this project overview module 141 can also cooperate with the formulated evaluation plan to clarify the work tasks and time nodes of each stage, and automatically generate a task list to ensure the systematicness and coherence of the evaluation work.
[0114] As an example, the background information, evaluation purpose, basis, and scope of the project are recorded in this project overview module 141, laying a foundation for subsequent evaluations, supporting the upload of attachments to supplement detailed description materials, formulating a detailed evaluation plan, clarifying the work tasks and time nodes of each stage, automatically generating a task list to ensure the systematicness and coherence of the evaluation work, and confirming the laws, regulations, industry standards, and internal systems on which the evaluation is based to ensure the legality and compliance of the evaluation process.
[0115] The information research module 142 in this personal information security protection capability evaluation unit 140 is set to be able to obtain and record the detailed information of the personal information processor according to the basic information of the project recorded by the project overview module 141.
[0116] As a further illustration, the information research module 142 specifically collects the detailed information of personal information processors through an online form filling mode, including the unit name, responsible person information, business description, etc., to ensure the accuracy of the evaluation and simplify the data collection process.
[0117] Furthermore, the information research module 142 also records in detail the hardware devices and software systems involved, providing a basis for risk assessment.
[0118] As an example, when the information research module 142 is running, it can collect the detailed information of personal information processors through an online form filling mode, including the unit name, responsible person information, business description, etc., to ensure the accuracy of the evaluation, and record in detail the hardware devices and software systems involved, providing a basis for risk assessment. Furthermore, the information research module 142 can provide a standardized template to ensure the integrity and consistency of the recorded content, verify the collected data, ensure the authenticity and accuracy of the information, guarantee the reliability of the subsequent risk identification and analysis results, and avoid misjudgment caused by incorrect information.
[0119] The baseline verification module 143 in the personal information security protection capability evaluation unit 140 is set to be able to obtain and record the information of all key components in the network system involved in the personal information security protection capability evaluation task project according to the basic project information recorded by the project overview module 141, and based on the evaluation index system associated when the evaluation project management unit 130 establishes the personal information security protection capability evaluation task project, evaluate the security configuration of the involved network system according to the recorded information, and verify the accuracy and integrity of the involved device information.
[0120] The baseline verification module 143 further checks each security control node of the personal information processing activities in the actual environment through on-site inspection according to the basic project information recorded by the project overview module 141, and records the compliance situation and supporting documents.
[0121] As an example, when performing baseline verification operations based on this baseline verification module 143, it can cover the recording of information of all key components in the system, such as network devices, servers, databases, etc., and specifically record through an online form filling mode. The evaluation index system associated when the evaluation project management unit 130 establishes the personal information security protection capability evaluation task project is extracted for the recorded information to evaluate its security configuration, and the accuracy and integrity of the device information are automatically verified.
[0122] Based on this baseline verification module 143, the security control points in the actual environment are inspected. Specifically, the compliance situation is recorded through the online form filling mode and the supporting documents are uploaded, and the evaluation index system associated with the personal information security protection ability evaluation task project established by the evaluation project management unit 130 is extracted for evaluation. For the security control points that do not meet the requirements, a problem list is generated based on the requirements of the evaluation index system to clarify the rectification direction and responsibility assignment, ensuring that the problems are effectively solved and tracked.
[0123] The risk identification module 144 in this personal information security protection ability evaluation unit 140 is associated with the project overview module 141, the information research module 142, and the baseline verification module 143. For the personal information security protection ability evaluation task project, a comprehensive risk calculation and identification are carried out on the information from the management system to the organizational structure level to generate risk identification result information; a compliance check is carried out on the record compliance situation and supporting document information of each security control link in the personal information processing activity to identify potential risk points and generate non-compliance evaluation index item information.
[0124] As an example, this risk identification module 144 integrates the data of the project overview module 141, the information research module 142, and the baseline verification module 143 to conduct a comprehensive risk assessment of the personal information security protection ability. Specifically, this risk identification module 144 first analyzes and understands the management system and organizational structure data information of the organization. Based on the analyzed management system and organizational structure data, analysis and identification are carried out to identify potential security vulnerabilities and non-compliance points. For example, through natural language processing (NLP) of the system documents, key policy terms can be automatically extracted and compared with best practices or regulatory requirements.
[0125] Next, this risk identification module 144 conducts quantitative and qualitative risk assessments on the information collected by the information research module 142 or the baseline verification module 143.
[0126] Among them, for quantitative analysis, the evaluation results of the compliance degree of each indicator are divided into compliant, partially compliant, non-compliant, and not applicable. As an example, the process of quantitative analysis is as follows:
[0127] When a certain security control measure fully meets the expected standard without any deviation or omission, this indicator will be marked as compliant, indicating that the relevant control measure is effectively implemented and can fully guarantee the security of personal information;
[0128] When an indicator does not fully meet the requirements, but reaches the goal to a certain extent, or only has minor deficiencies, and these deficiencies will not significantly affect the overall security level, it will be regarded as partially compliant; in this case, although the system or process still has room for improvement in some aspects, its basic functions and effects are still acceptable;
[0129] On the other hand, if a certain indicator significantly deviates from the established standard, has serious defects or loopholes, and cannot provide due protection, it will be judged as non-compliant, which means immediate action needs to be taken for rectification to prevent potential risks from becoming real threats;
[0130] Finally, for indicators that cannot be applied to the current environment due to specific reasons (such as technical limitations, business model differences, etc.), they will be marked as inapplicable; such situations usually require detailed explanations and may require the provision of alternative solutions or other forms of proof to ensure that the overall security is not affected.
[0131] Based on this analysis, the score factor for "compliant" items is 1, the score factor for "partially compliant" items is 0.7, and the score factor for "non-compliant" items is 0.4.
[0132] For qualitative analysis, the nature and scope of impact of risks are specifically evaluated based on the knowledge base. This ensures a comprehensive and detailed identification of all potential risks and generates a detailed report according to the severity and priority of the risks.
[0133] The evaluation conclusion generation module 145 in this personal information security protection capability evaluation unit 140 is associated with the project overview module 141, the information research module 142, and the risk identification module 143, and automatically calculates the scores of various evaluation indicators based on a preset scoring model to obtain a comprehensive score.
[0134] As a further illustration, this evaluation conclusion generation module 145 specifically uses a weighted scoring model for data importance classification to automatically calculate the scores of various evaluation indicators and obtain a comprehensive score.
[0135] As an example, the corresponding scoring process has two steps:
[0136] In the first step, for indicators related to the security requirements of processing activities, the same indicators are used to evaluate three data categories: critical data, important data, and general data. Among them, critical data refers to those data and information that will cause major damage to organizational operations, national security, or personal privacy once leaked or lost; important data covers data and information that, although not as severely impactful as critical data, still have a significant impact on business continuity or personal rights and interests; general data refers to those data and information that will not cause serious consequences even if made public. The weight configured for critical data is 0.6, the weight configured for important data is 0.3, and the weight configured for general data is 0.1. Based on this, the weighted sum of the corresponding weights and score factors is used to obtain the score of this indicator.
[0137] In the second step, different evaluation indicators are weighted according to their importance. The importance of a single indicator may be 1 or 2. For example, if an indicator is considered relatively important, its weight will be set to 2; otherwise, the weight will be 1. The indicator scores are weighted and summed with the indicator weights and linearly mapped to a score range of 0 - 100 to obtain a quantified comprehensive score.
[0138] Accordingly, the final score generated by the evaluation conclusion generation module 145 not only provides a quantified comprehensive score but also comes with detailed scoring details, such as the specific scores of each evaluation indicator, the corresponding weights, and the reasons for any score deductions.
[0139] As a further illustration, based on generating the quantified comprehensive score, this evaluation conclusion generation module 145 further automatically generates a problem list, clearly listing the number of high, medium, and low-risk problems, providing a clear direction for improvement measures and a guide for responsibility division.
[0140] As a further example, this evaluation conclusion generation module 145 automatically calculates the scores of each evaluation indicator based on a preset scoring model, obtains a quantified comprehensive score and the corresponding level of personal information security protection ability, and provides scoring details. Among them, according to the evaluation scores, the personal information security protection ability can be divided into four levels: excellent, good, medium, and poor. Among them, "excellent" means that the overall score of the organization is above 90 points and there are no major security risks; "good" means that the overall score of the organization is between 80 - 89 points and there are no high-level security risks; "medium" means that the score is between 70 - 79 points, there are certain security problems but the risks are controllable; "poor" means that the score is below 70 points and there may be high-level security risks. The quantified comprehensive score and the corresponding level of security protection ability formed thereby can help users understand the scoring basis, summarize the number of high, medium, and low-risk problems, provide guidance for improvement measures, the system generates a problem list, clarifies the rectification direction and responsibility division, and ensures that problems are effectively solved and tracked.
[0141] As can be seen from the above, in the solution of the present invention, through the organic logical cooperation among the project overview module 141, the information research module 142, the baseline verification module 143, the risk identification module 144, and the evaluation conclusion generation module 145, a complete personal information security protection ability evaluation functional unit is formed. Among them, the project overview module 141 provides a basic information framework, the information research module 142 is responsible for collecting necessary background information, the baseline verification module 143 focuses on the security configuration evaluation at the technical level, and the risk identification module 144 conducts in-depth risk analysis on this basis. Finally, the evaluation conclusion generation module 145 summarizes all the previous work results and outputs the final evaluation report. This modular design not only improves the flexibility and scalability of the system but also ensures the comprehensiveness and meticulousness of the evaluation process.
[0142] Based on the personal information security protection capability evaluation unit 140 configured as such, the present evaluation system can cover multiple evaluation links such as evaluation project overview, basic information research, risk identification, risk comprehensive analysis, and evaluation report export, ensuring that personal information processing activities meet requirements and effectively reducing security risks.
[0143] See Figure 6 , which shows a schematic diagram of the composition of the evaluation report pre-filling unit 150 in the solution of the present invention.
[0144] Based on the illustration, the evaluation report pre-filling unit 150 presented here is mainly composed of a prompt template library management module 151 and a large language model pre-filling module 152 in cooperation.
[0145] Among them, the prompt template library management module 151 is set to provide various types of evaluation report filling prompt templates.
[0146] As an example, this prompt template library management module 151 can provide various types of prompt templates for selection, suitable for evaluation requirements in different scenarios, and supports users to customize templates to flexibly respond to special evaluation requirements.
[0147] This prompt template library management module 151 can also regularly update the template content to ensure its synchronization with the latest regulations and technological developments. This prompt template library management module 151 can regularly obtain the latest legal regulations and technical standard text information, and parse the obtained legal regulations and technical standard text information by calling a big data model to put forward key information related to personal information protection, and accordingly regularly update the template content to ensure its synchronization with the latest regulations and technological developments; for the completed updated templates, this prompt template library management module 151 automatically pushes update notifications to remind users to apply the new version of the template in a timely manner to maintain the timeliness and applicability of the evaluation tool.
[0148] This large language model pre-filling module 152 is set to be able to call a large language model, parse documents related to personal information security protection capabilities, identify and extract key information from them, and integrate the extracted key information into the knowledge base; on this basis, this large language model pre-filling module 152 can also extract corresponding key information from the knowledge base according to the evaluation report filling prompt templates provided by the prompt template library management module 151 to pre-fill part of the content of the personal information security protection ability evaluation report.
[0149] The documents related to personal information security protection capabilities here include uploaded privacy policies, management systems, test reports and other documents.
[0150] For example, the large language model pre-filling module 152 can parse uploaded files such as privacy policies, management systems, and test reports by using the API of ChatGPT, extract key information, support multi-language parsing, adapt to evaluation requirements, automatically complete part of the report content according to the extracted information, reduce manual workload, improve the efficiency of report writing, and at the same time provide a quality control mechanism to ensure the accuracy and integrity of the pre-filled content, and avoid report distortion caused by incorrect information extraction.
[0151] Based on the evaluation report pre-filling unit 150 configured as such, the present evaluation system realizes the functions of large language model privacy policy parsing and knowledge base construction based on a prompt template. The large model API is automatically called through the preset prompt template, and thus the large language model is called to parse complex privacy policy documents and extract valuable information from them, efficiently identifying and extracting key information such as the types of sensitive personal information and the purposes of processing from a large amount of privacy policy texts; then integrating this information into the knowledge base of the system automatically to provide users with detailed privacy protection guidance and services.
[0152] See Figure 7 , which shows a schematic diagram of a composition of the evaluation report export unit 160 in the solution of the present invention.
[0153] Based on the illustration, the evaluation report export unit 160 given here is mainly composed of a standardized report generation module 161 and an export module 162 cooperating with each other.
[0154] Among them, the standardized report generation module 161 is configured to be able to generate a protection ability evaluation report based on the evaluation results generated by the personal information security protection ability evaluation unit and / or the content of the evaluation report pre-filled by the evaluation report pre-filling unit, and in accordance with a unified format and layout.
[0155] As a further illustration, the present standardized report generation module 161 can generate an evaluation report in a unified format and layout, ensuring the professionalism and consistency of the report; and can provide a preview function to enable viewing the report effect before export.
[0156] The report generated by the present standardized report generation module 161 contains all necessary evaluation indicators and analysis conclusions, providing sufficient information support for decision-makers.
[0157] The export module 162 is specifically configured to perform data interaction with the standardized report generation module 161 and can support exporting the evaluation report data generated by the standardized report generation module in multiple formats.
[0158] As a further illustration, the export module 162 is configured to support the Word format and can selectively export project data to meet different usage requirements. The export module 162 is also configured to provide a batch export function, saving time and effort, and allowing customization of the cover, header, footer, and other contents of the report to create a unique report style.
[0159] Based on the evaluation report export unit 160 configured as such, the evaluation system can implement the function of exporting the personal information protection evaluation report. Based on the automatically generated evaluation results, a professional report containing various evaluation indicators and in-depth analysis conclusions can be exported with one click. These reports are in a standardized Word format, facilitating archiving and sharing, and can serve as an important basis for internal audits or external compliance reviews.
[0160] The personal information security protection ability evaluation system solution formed based on the above solution can help the evaluation unit make an objective, efficient, and specific evaluation of the personal information protection ability of the evaluated object, promoting the development of the equal protection evaluation industry.
[0161] At the same time, the personal information security protection ability evaluation system solution of the present invention is applicable to key fields such as finance, education, and healthcare, and can provide strong technical support for protecting personal privacy and data security in these fields, promoting the improvement of the overall social security level.
[0162] To further illustrate the personal information security protection ability evaluation system solution, the following will be further described through specific application examples.
[0163] In this example, based on the personal information security protection ability evaluation system solution, a corresponding software program is constructed to form a corresponding personal information security protection ability evaluation software system. When the software program runs, it will execute the functions of the above-mentioned personal information security protection ability evaluation system, and at the same time, it is stored in a corresponding storage medium for the processor to retrieve and execute.
[0164] See Figure 8 , which shows the system block diagram of the personal information security protection ability evaluation software system given in this example.
[0165] As can be seen from the figure, the overall framework of the personal information security protection ability evaluation software system is divided into a front-end layer and a back-end layer, and the back-end layer includes a database model layer and a large model function module layer.
[0166] Among them, the front-end layer realizes the functions of the server-side functional architecture, specifically including the user's data import interface and data visualization function, forming a management interface.
[0167] In this example, the server-side functional architecture is specifically implemented based on the Django-vue3-admin framework, which can read the imported data and visualize the corresponding data table output; and through the Vue interface configuration, it provides a management platform with rich functions and user-friendly for the evaluation staff.
[0168] At the same time, by rewriting the get_queryset and save_model methods, fine-grained control of data access permissions is achieved, so that ordinary evaluation staff can only manage their own data, while administrators have broader management permissions, which not only ensures data security but also meets the needs of different users.
[0169] The backend layer in this software system implements the privacy policy parsing and personal information security capability protection evaluation functions, including the database model layer and the large model functional module layer.
[0170] Among them, the database model layer uses the ORM (Object Relational Mapping) method of the Django framework to define multiple data models. The multiple data models correspond to various data tables used in the system, covering the key information in the personal information security protection evaluation process, and further through the relationships and attributes between the models, the organization and logical processing of data are realized. In this way, it not only supports the whole-process management of personal information security protection evaluation, but also through the model method and signal mechanism, realizes the dynamic processing and automated calculation of data, improving the intelligent level of the system.
[0171] The large model functional module layer realizes the parsing and effective management of privacy policies, management systems, and test report knowledge bases through automated text processing and intelligent analysis of large models. Specifically, in this example, multiple Python libraries are used to implement it. Among them, pandas is used to implement data processing, concurrent.futures is used to implement parallel task execution, and pydantic is used to implement data verification; on this basis, through the openai library, interaction with the large model is carried out to realize in-depth understanding and analysis of the privacy policy content. In this way, not only the efficiency of privacy policy analysis is improved, but also the accuracy and reliability of the system are enhanced through the automated extraction and judgment mechanism. In this way, this system can provide strong data support and decision-making basis for users in personal information security protection.
[0172] When the personal information security protection capability evaluation software system in this example is running, the following functional operations can be performed to evaluate the personal information security protection capability.
[0173] (1) Authentication and authorization
[0174] By restricting access to the system to super administrators and allowing administrators to flexibly set the operating permissions of roles in the system by checking specific permission points for different functional modules, such as viewing, editing, adding, etc. The page provides a clear permission hierarchy structure for refined management.
[0175] (2) Log Management
[0176] First, log in to the log management function to monitor and track user login behaviors. Each record contains the following information: serial number, login username, login IP, operator, operating system, browser name, agent information, affiliated department, and operations.
[0177] Next, log operations can be carried out to track and record various operation activities of users in the system. Each operation record details important information such as the requested module, request address, operation description, request method, IP address, request parameters, request browser, response code, and operating system.
[0178] (3) Index System Version Management
[0179] First, new versions of the index system can be added. This system lists the index versions within the current system, and each version also includes a detailed version introduction. Users can view and understand the specific content of the version, which facilitates the maintenance of multiple versions of the index system and supports the selection of appropriate versions for different projects.
[0180] Next, access the equal protection knowledge base, which is classified by protection level and lists the corresponding security control points and evaluation indicators for each level. Users can clearly see the specific requirements under each classification, such as data confidentiality, data backup and recovery, etc. The content in the equal protection knowledge base provides a reference basis and standard for the project evaluation process to ensure that the evaluation work meets the requirements of level protection.
[0181] (4) Project Management
[0182] After entering the project management function, the system displays the overview page of project management, showing the basic information of all projects entered in the system, including project number, name, client unit, evaluation object name, creation time, modification time, evaluation index version, protection level, evaluation team leader, etc. Users can add new projects through the new button, batch import project data through the import button, or quickly locate specific projects using the filtering and query functions. In addition, existing projects can also be viewed, edited, or deleted.
[0183] (5) Implementation of Personal Information Security Protection Ability Evaluation Project
[0184] After entering the implementation function of the personal information security protection ability evaluation project, the system includes multiple implementation stages, including "Project Description", "Information Research", "Knowledge Base Import", "Basic Metrics", "Risk Identification", "Comprehensive Analysis", and "Evaluation Conclusion" stages, and synchronously displays the overall progress of the test process so that users can intuitively grasp the implementation progress.
[0185] In the "Project Overview" stage, it is used to fill in the basic information of the project, including the evaluation purpose, evaluation basis, name of the evaluation object, type of the evaluation object (information system or business scenario), description of the basic function business scenario, etc. It can also record the provision of data such as personal information and an overview of the evaluation conclusion, which is used to allocate specific tasks to evaluation members and participants. Users can add the evaluation team leader and team members and specify their roles and task assignments. At the same time, it can also record the information of the participants of the evaluated party, the evaluation time arrangement, evaluation tools, and environmental conditions, providing clear personnel arrangements and implementation details for the project implementation.
[0186] In the "Information Research" stage, it is required to fill in the detailed background information of the personal information processor, including the unit name, abbreviation, unified social credit code, registered address, office address, data center address, etc. At the same time, record the name, position, department affiliation, and contact information of the person in charge, and record the business and information system situation of the evaluation object. Users can describe the specific situation of relevant businesses, information systems, Apps, or websites and upload attachments to supplement the description to help accurately identify the identity of the processor, providing support for subsequent evaluation steps.
[0187] In the "Knowledge Base Import" stage, it is used to upload privacy policies, management systems, and test report files to support users in clarifying the privacy policies, management systems, and test report situations of the evaluation objects during the evaluation process. Users can supplement relevant document information through file uploads, providing a basis for the baseline verification and comprehensive analysis stages.
[0188] In the "Baseline Verification - System Composition" stage, it is used to detail the hardware devices and software systems involved in the system. It is divided into modules such as network devices, security devices, servers, database management systems, and business application systems. Users can add device information for each module, including device name, brand, model, usage, importance level, IP address, etc.; and evaluate each device. This page helps to completely record the system architecture, providing a basis for subsequent risk assessment.
[0189] In the "Baseline Verification - On-site Verification" stage, it supports the recording of the on-site inspection link, listing the security control points and their corresponding evaluation indicators, such as the integrity requirements for communication transmission and network architecture. Users can fill in the compliance situation on-site in the result record and select the corresponding degree of compliance, providing direct review results for the security assessment work.
[0190] In the "Risk Identification - Overall Requirements for Security Protection" stage, the overall requirements for security protection work are listed, and the project is comprehensively evaluated from the management system to the organizational structure level. Users can fill in the evaluation result records, compliance status, and upload supporting documents. This function helps to clarify the implementation status of each security protection requirement.
[0191] In the "Risk Identification - Security Requirements for Processing Activities" stage, the security requirements in personal information processing activities are presented, including multiple evaluation categories such as data collection, notice and consent, and notice of changes. Users can fill in the result records of each activity and upload relevant supporting documents for verifying the compliance of processing activities.
[0192] In the "Evaluation Conclusion - Comprehensive Score" stage, the comprehensive score and problem statistics of the project are presented. Users can view the number of high, medium, and low-risk problems and the comprehensive score, and at the same time rate the evaluation object based on the evaluation basis and criteria. The results of this page provide key support for the final evaluation report.
[0193] The "Evaluation Conclusion - Report Export" stage is used for the typesetting and export of the personal information security protection ability evaluation report.
[0194] In the above embodiments, the descriptions of each embodiment have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0195] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and modules described above can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0196] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0197] The present invention is described with reference to the flowcharts and / or block diagrams of the methods, apparatuses (systems), and computer program products of the embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, and the combination of processes and / or blocks in the flowcharts and / or block diagrams, can be realized by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, so that the instructions executed by the processors of the computer or other programmable data processing devices generate for realizing the processFigure 1 means for the functions specified in one or more processes and / or blocks Figure 1 or means for the functions specified in a block or blocks.
[0198] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means that implement the functions in the process Figure 1 one or more processes and / or blocks Figure 1 or the functions specified in a block or blocks.
[0199] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus, such that a series of operational steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions in the process Figure 1 one or more processes and / or blocks Figure 1 or the functions specified in a block or blocks.
[0200] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0201] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory. The memory is an example of a computer-readable medium.
[0202] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for storage of information such as computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device.
[0203] It should also be noted that the term "comprise", "include" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.
[0204] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0205] The above method of the present invention, or a specific system unit, or a part of it, is a pure software architecture and can be distributed through program code on a physical medium such as a hard disk, a CD-ROM, or any electronic device (such as a smart phone, a computer-readable storage medium). When the machine loads the program code and executes it (such as a smart phone loading and executing), the machine becomes a device for implementing the present invention. The above method and device of the present invention can also be in the form of program code and be transmitted through some transmission media such as cables, optical fibers, or any transmission type. When the program code is received, loaded, and executed by a machine (such as a smart phone), the machine becomes a device for implementing the present invention.
[0206] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification only illustrate the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements fall within the scope of the present invention claimed. The scope of the present invention claimed is defined by the appended claims and their equivalents.
Claims
1. A personal information security protection ability evaluation system, characterized in that Including: An authentication and authorization unit configured to authenticate system user identity information and set permissions; An evaluation index system construction unit configured to be associated with the authentication and authorization unit and construct a personalized evaluation index system by setting one or more of evaluation categories, evaluation items, and evaluation index data information; An evaluation project management unit configured to be associated with the authentication and authorization unit and the evaluation index system construction unit, and establish and manage personal information security protection ability evaluation task projects based on the evaluation index system constructed in the evaluation index system construction unit; A personal information security protection ability evaluation unit associated with the authentication and authorization unit, the evaluation index system construction unit, and the evaluation project management unit, which can perform multi-link evaluation of personal information security protection ability through evaluation calculation processing including evaluation project overview, basic information investigation, risk identification, risk comprehensive analysis, and evaluation report export, and generate evaluation results; An evaluation report pre-filling unit associated with the evaluation index system construction unit, the evaluation project management unit, and the personal information security protection ability evaluation unit, which can call a large language model, parse files related to personal information security protection according to a preset prompt template, extract key information therefrom, and pre-fill the content of the personal information security protection ability evaluation report accordingly; An evaluation report export unit associated with the evaluation project management unit, the personal information security protection ability evaluation unit, and the evaluation report pre-filling unit, which can form and export a protection ability evaluation report containing various evaluation indicators and in-depth analysis conclusions based on the evaluation results generated by the personal information security protection ability evaluation unit and / or the content of the evaluation report pre-filled by the evaluation report pre-filling unit; 2. The personal information security protection capability evaluation system according to claim 1, wherein, The authentication and authorization unit includes: A role management module for defining specific operation permissions for different user roles; A user management module for editing user role information; A log monitoring module for recording all user login behaviors.
3. The personal information security protection capability evaluation system according to claim 1, wherein The evaluation index system construction unit includes: An evaluation category management module for defining different evaluation categories; An evaluation item management module associated with the evaluation category management module, which can set specific evaluation items for each evaluation category located by the evaluation category management module. The evaluation items include specific content and requirements, and establish the logical relationship between the evaluation category and the evaluation item; An evaluation index management module that creates a diverse, detailed, and extensible evaluation index library, and each index is configured with corresponding standards and scoring rules.
4. The personal information security protection capability evaluation system according to claim 1, wherein, The evaluation project management unit includes: Project Lifecycle Management Module, which is used to create and manage the project of personal information security protection ability evaluation task; Document and Resource Management Module, which is associated with the Project Lifecycle Management Module, and obtains and manages various types of documents and resources related to the project according to the created project of personal information security protection ability evaluation task.
5. The personal information security protection capability evaluation system according to claim 1, characterized in that The personal information security protection ability evaluation unit includes: Project Overview Module, which obtains and records the basic information of the project according to the project of personal information security protection ability evaluation task established by the Evaluation Project Management Unit; Information Research Module, which obtains and records the detailed information of the personal information processor according to the basic information of the project recorded by the Project Overview Module; Baseline Verification Module, which obtains and records the information of all key components in the network system involved in the project of personal information security protection ability evaluation task according to the basic information of the project recorded by the Project Overview Module, evaluates the security configuration of the involved network system according to the recorded information, and verifies the accuracy and integrity of the involved device information; the Baseline Verification Module also checks each security control node of the personal information processing activities in the actual environment through on-site inspection according to the basic information of the project recorded by the Project Overview Module, and records the compliance situation and supporting documents; Risk Identification Module, which is associated with the Project Overview Module, Information Research Module, and Baseline Verification Module, and conducts comprehensive risk calculation and identification on the information from the management system to the organizational structure level for the project of personal information security protection ability evaluation task, generating risk identification result information; conducts compliance inspection on the information of the compliance situation and supporting documents recorded in each security control link of the personal information processing activities, identifies potential risk points, and generates non-compliance evaluation index item information; Evaluation Conclusion Generation Module, which is associated with the Project Overview Module, Information Research Module, and Risk Identification Module, and automatically calculates the scores of each evaluation index based on a preset scoring model to obtain a comprehensive score.
6. The personal information security protection capability evaluation system according to claim 1, wherein The evaluation report pre-filling unit includes: Prompt Template Library Management Module, which is used to provide various types of evaluation report filling prompt templates; Large Language Model Pre-filling Module, which can call the large language model, parse the documents related to personal information security protection ability, identify and extract key information from them, and integrate the extracted key information into the knowledge base; the Large Language Model Pre-filling Module can also extract the corresponding key information from the knowledge base according to the evaluation report filling prompt templates provided by the Prompt Template Library Management Module to pre-fill the content of the personal information security protection ability evaluation report.
7. The personal information security protection capability evaluation system according to claim 1, characterized in that, The evaluation report export unit includes: Standardized Report Generation Module, which can generate a protection ability evaluation report based on the evaluation results generated by the personal information security protection ability evaluation unit and / or the content of the evaluation report pre-filled by the evaluation report pre-filling unit, and generate the protection ability evaluation report according to a unified format and layout; An export module that interacts with the standardized report generation module and can support the export of evaluation report data generated by the standardized report generation module in multiple formats.
8. A method for evaluating the personal information security protection ability, characterized in that, The evaluation method includes: Constructing a personalized evaluation index system by setting one or more of the evaluation categories, evaluation items, and evaluation index data information; Establishing and managing personal information security protection ability evaluation task items based on the constructed evaluation index system; According to the evaluation index system associated with the personal information security protection ability evaluation task items established by the evaluation project management unit, conducting multi-link evaluation of the personal information security protection ability through evaluation calculation processing including evaluation project overview, basic information research, risk identification, risk comprehensive analysis, and evaluation report export, and generating evaluation results; Invoking a large language model to parse files related to personal information security protection ability, extracting key information therefrom, and pre-filling the content of the personal information security protection ability evaluation report accordingly; Forming a protection ability evaluation report containing various evaluation indicators and in-depth analysis conclusions based on the generated evaluation results and / or pre-filled evaluation report content.
9. The personal information security protection capability evaluation method according to claim 8, wherein When constructing the evaluation index system, the evaluation method includes: First, defining different evaluation categories; Next, setting specific evaluation items for each located evaluation category, where the evaluation items include specific content and requirements, and establishing the logical relationship between the evaluation category and the evaluation item; Finally, creating a diverse, detailed, and extensible evaluation index library, with each index configured with corresponding standards and scoring rules.
10. The personal information security protection capability evaluation method according to claim 8, wherein When pre-filling the content of the personal information security protection ability evaluation report, the evaluation method invokes a large language model to parse files related to personal information security protection ability, identifies and extracts key information therefrom, and integrates the extracted key information into the knowledge base; then extracts the corresponding key information from the knowledge base according to the evaluation report filling prompt template to pre-fill the content of the personal information security protection ability evaluation report.