Data security assessment method and device, electronic equipment and storage medium
By identifying the risk source and predicting the potential risk impact results of important core data, combined with the evaluation value of general data, the shortcomings of data security assessment in the existing technology are solved, and the comprehensiveness and accuracy of data security assessment are achieved.
Patent Information
- Application Number
- CN202510395199.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-25
AI Technical Summary
In the data security assessment, the existing technology has problems such as insufficient data classification and grading, failure to process important core data separately from general data, failure to conduct full-life cycle security analysis, large manpower and material resources consumption, and insufficient impact on important core data.
Identify the risk source of important core data, predict the potential risk impact results, determine the first security assessment value, and combine the second security assessment value of general data, and conduct a comprehensive and accurate data security assessment through weighted summing.
It realizes a comprehensive and accurate security assessment of the data to be processed, improves the accuracy and efficiency of data security assessment, and reduces manpower and material consumption.
Smart Images

Figure CN120372638A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data processing, and particularly to a data security assessment method, apparatus, electronic device, and storage medium. Background Art
[0002] With the rapid development of the digital economy, the importance of data security has become increasingly urgent. The general treatment of data security in related technologies generally focuses on network security, and there are problems of one-sidedness and inaccuracy in the treatment of data security. Summary of the Invention
[0003] The main purpose of the embodiments of this application is to propose a data security assessment method, apparatus, electronic device, and storage medium to comprehensively assess the security of data and improve the accuracy of security assessment.
[0004] To achieve the above object, on the one hand, an embodiment of this application proposes a data security assessment method, and the method includes the following steps:
[0005] Identify risk sources for important core data to obtain potential risk sources; wherein, the important core data is data in the to-be-processed data whose importance level reaches a preset threshold;
[0006] Predict the potential risk impact results brought by the potential risk sources;
[0007] Determine a first security assessment value of the important core data according to the potential risk sources and the potential risk impact results;
[0008] Determine a second security assessment value of general data; wherein, the general data is data in the to-be-processed data whose importance level is lower than the preset threshold;
[0009] Determine a comprehensive assessment value of the to-be-processed data according to the first security assessment value and the second security assessment value.
[0010] In some embodiments, before identifying risk sources for important core data to obtain potential risk sources, the method further includes a step of obtaining the to-be-processed data, and the step of obtaining the to-be-processed data includes the following steps:
[0011] Divide the data of the target data source according to the importance level to obtain data of each importance level;
[0012] Extract data with a proportion lower than a preset proportion from the data whose importance level is lower than the preset threshold as sampling data;
[0013] Combine all the data whose importance level reaches the preset threshold and the sampling data into the to-be-processed data.
[0014] In some embodiments, the method further includes the following steps:
[0015] Determine the data processing activities of each item of the data to be processed according to different data scenarios; wherein, the data processing activities include at least one of collection, storage, use, processing, transmission, provision, cross-border transfer or disclosure;
[0016] Judge whether each of the data processing activities complies with preset rules, analyze the legitimate necessity, analyze the potential risk problems existing in the management, and analyze the potential risk problems of each of the data processing activities to conduct a compliance assessment and obtain a compliance assessment result.
[0017] In some embodiments, the identification of risk sources for important core data to obtain potential risk sources includes the following steps:
[0018] Identify the technical risk sources, institutional risk sources, personnel risk sources and industry standard risk sources of the important core data to obtain the potential risk sources.
[0019] In some embodiments, the prediction of the potential risk impact results brought by the potential risk sources includes the following steps:
[0020] Predict the potential economic losses and potential social problems brought by the potential risk sources as the potential risk impact results.
[0021] In some embodiments, the determination of the first security assessment value of the important core data according to the potential risk sources and the potential risk impact results includes the following steps:
[0022] Determine the first security assessment value of the important core data according to the risk quantification evaluation calculation formula;
[0023] The risk quantification evaluation calculation formula is:
[0024] R i =σ i +V i ;
[0025] Wherein, R i represents the first security assessment value of the i-th important core data; σ i represents the assignment value of the potential risk source of the i-th important core data; V i represents the assignment value of the potential risk impact result of the i-th important core data.
[0026] In some embodiments, the determination of the comprehensive assessment value of the data to be processed according to the first security assessment value and the second security assessment value includes the following steps:
[0027] Determine the weights corresponding to the important core data and the general data respectively;
[0028] Perform weighted summation on the first security evaluation value and the second security evaluation value according to the corresponding weights to obtain the comprehensive evaluation value of the data to be processed.
[0029] To achieve the above object, another aspect of the embodiments of the present application proposes a data security evaluation device, the device includes:
[0030] A risk source identification unit, configured to identify risk sources for important core data to obtain potential risk sources; wherein, the important core data is data in the data to be processed whose importance level reaches a preset threshold;
[0031] A risk impact prediction unit, configured to predict the potential risk impact results brought by the potential risk sources;
[0032] A first evaluation value determination unit, configured to determine the first security evaluation value of the important core data according to the potential risk sources and the potential risk impact results;
[0033] A second evaluation value determination unit, configured to determine the second security evaluation value of general data; wherein, the general data is data in the data to be processed whose importance level is lower than the preset threshold;
[0034] A comprehensive evaluation value determination unit, configured to determine the comprehensive evaluation value of the data to be processed according to the first security evaluation value and the second security evaluation value.
[0035] To achieve the above object, another aspect of the embodiments of the present application proposes an electronic device, the electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the above method is implemented.
[0036] To achieve the above object, another aspect of the embodiments of the present application proposes a computer-readable storage medium, the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above method is implemented.
[0037] The embodiments of the present application at least include the following beneficial effects:
[0038] This application can identify risk sources for important core data to obtain potential risk sources; among them, the important core data are data in the to-be-processed data whose importance level reaches a preset threshold; predict the potential risk impact results brought by the potential risk sources; determine the first security evaluation value of the important core data according to the potential risk sources and the potential risk impact results; determine the second security evaluation value of the general data; among them, the general data are data in the to-be-processed data whose importance level is lower than the preset threshold; determine the comprehensive evaluation value of the to-be-processed data according to the first security evaluation value and the second security evaluation value. By classifying and evaluating the to-be-processed data and identifying potential risk sources and potential risk impact results, this application can comprehensively and accurately evaluate the security of the to-be-processed data. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0040] Figure 1 It is a schematic flowchart of a data security evaluation method provided by an embodiment of the present application;
[0041] Figure 2 It is an example flowchart of a data security evaluation method provided by an embodiment of the present application;
[0042] Figure 3 It is a schematic structural diagram of a data security evaluation device provided by an embodiment of the present application;
[0043] Figure 4 It is a schematic hardware structure diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] In order to make the purpose, technical solutions and advantages of the present application clearer, the following will further describe the present application in detail in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application. When the following description involves drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the embodiments of the present application. They are only examples of devices and methods consistent with some aspects of the embodiments of the present application described in detail in the appended claims.
[0045] It can be understood that the terms "first", "second", etc. used in this application may be used herein to describe various concepts, but unless otherwise specified, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of this application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, words such as "if" and "when" used herein may be interpreted as "when...", "while...", or "in response to determining".
[0046] The terms "at least one", "multiple", "each", "any one", etc. used in this application, "at least one" includes one, two, or more than two, "multiple" includes two or more than two, "each" refers to each one of the corresponding multiple, and "any one" refers to any one of the multiple.
[0047] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0048] Before elaborating on the embodiments of this application in detail, some related technologies involved in the embodiments of this application are described first as follows:
[0049] The evaluation scheme of the business data security index proposed by the related technology targets business data rather than the overall enterprise data, and this scheme does not classify and grade the data.
[0050] The existing technical solutions for data security index mainly involve inputting multiple levels of business data, vulnerability index, and threat index into a risk assessment model, obtaining the data risk index of a single business data in the multiple levels of business data output by the risk assessment model, and determining the security index of the business data within the target business party according to the data risk indices of all business data, such as the above-mentioned related technology.
[0051] The existing main disadvantages are as follows: ① Data classification and grading have not been carried out; ② The legitimate necessity analysis of data processing activities has not been conducted; ③ Important core data and general data have not been processed separately; ④ Sampling has not been used to carry out work on general data, resulting in a huge consumption of manpower and material resources. ⑤ There is a lack of security analysis of the entire life cycle of data-centered data collection, storage, use, processing, transmission, provision, cross-border transfer, disclosure, etc. ⑥ The impact of important core data on the overall security index is not adequately reflected. The existing methods treat important core data and general data equally and do not reflect the importance of important core data.
[0052] To at least solve one problem of the prior art, embodiments of the present application propose a data security assessment method, apparatus, electronic device, and storage medium. The solution of the present application includes: identifying risk sources for important core data to obtain potential risk sources; wherein, the important core data is data in the data to be processed whose importance level reaches a preset threshold; predicting the potential risk impact results brought by the potential risk sources; determining a first security assessment value of the important core data according to the potential risk sources and the potential risk impact results; determining a second security assessment value of general data; wherein, the general data is data in the data to be processed whose importance level is lower than the preset threshold; determining a comprehensive assessment value of the data to be processed according to the first security assessment value and the second security assessment value. By performing hierarchical assessment on the data to be processed and identifying potential risk sources and potential risk impact results, the present application can comprehensively and accurately assess the security of the data to be processed.
[0053] Embodiments of the present application provide a data security assessment method, apparatus, electronic device, and storage medium, which relate to the technical field of data processing. The data security assessment method, apparatus, electronic device, and storage medium provided by the embodiments of the present application can be applied to a terminal, can also be applied to a server, or can be software running on a terminal or a server. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, a vehicle-mounted terminal, etc., but is not limited thereto; the server side can be configured as an independent physical server, can also be configured as a server cluster or a distributed system composed of multiple physical servers, or can be configured as a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The server can also be a node server in a blockchain network; the software can be an application implementing a data security assessment method, etc., but is not limited to the above forms.
[0054] This application can be used in numerous general or specific computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This application can also be practiced in a distributed computing environment where tasks are executed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0055] Referring to Figure 1 , an embodiment of this application provides a data security assessment method, which may include but is not limited to S110 to S150, specifically as follows:
[0056] S110: Identify risk sources for important core data to obtain potential risk sources; wherein, the important core data is data in the data to be processed whose importance level reaches a preset threshold.
[0057] Further, S110 may include the following steps S111:
[0058] S111: Identify the technical risk sources, institutional risk sources, personnel risk sources, and industry standard risk sources of the important core data to obtain the potential risk sources.
[0059] S120: Predict the potential risk impact results brought by the potential risk sources.
[0060] Further, S120 may include the following steps S121:
[0061] S121: Predict the potential economic losses and potential social problems brought by the potential risk sources as the potential risk impact results.
[0062] S130: Determine the first security assessment value of the important core data according to the potential risk sources and the potential risk impact results.
[0063] Further, S120 may include the following steps S131:
[0064] S131: Determine the first security assessment value of the important core data according to the risk quantification evaluation calculation formula;
[0065] The risk quantification evaluation calculation formula is as follows:
[0066] R i = σ i + V i ;
[0067] Wherein, R i represents the first security evaluation value of the i-th important core data; σ i represents the assignment value of the potential risk source of the i-th important core data; V i represents the assignment value of the potential risk impact result of the i-th important core data.
[0068] S140: Determine the second security evaluation value of general data; wherein, the general data is data in the to-be-processed data whose importance level is lower than the preset threshold.
[0069] S150: Determine the comprehensive evaluation value of the to-be-processed data according to the first security evaluation value and the second security evaluation value.
[0070] Further, S150 may include steps S151 to S152:
[0071] S151: Determine the weights corresponding to the important core data and the general data respectively;
[0072] S152: Perform weighted summation on the first security evaluation value and the second security evaluation value according to the corresponding weights to obtain the comprehensive evaluation value of the to-be-processed data.
[0073] Further, in some embodiments of the present application, before S110, it may further include the step of S100 to obtain the to-be-processed data, and S100 may include the following steps S101 to S103:
[0074] S101: Divide the data of the target data source according to the importance level to obtain data of each importance level;
[0075] S102: Extract data with a proportion lower than the preset proportion from the data whose importance level is lower than the preset threshold as sampling data;
[0076] S103: Combine all the data whose importance level reaches the preset threshold and the sampling data into the to-be-processed data.
[0077] As another alternative implementation manner, the embodiments of the present application may further include the following steps:
[0078] Determine the data processing activities for each piece of data to be processed according to different data scenarios; wherein, the data processing activities include at least one of collection, storage, use, processing, transmission, provision, cross-border transfer or disclosure.
[0079] Judge whether each of the data processing activities complies with preset rules, analyze the justifiable necessity, analyze the potential risk problems existing in the management, and analyze the potential risk problems of each of the data processing activities to conduct a compliance assessment and obtain a compliance assessment result.
[0080] Next, the solution of the embodiment of the present application will be introduced and described in detail with specific application examples.
[0081] Refer to Figure 2 , this embodiment provides an exemplary flowchart of a data security assessment method.
[0082] Exemplarily, the solution of this embodiment may include the following steps:
[0083] The first step: Data classification and grading. Classify the enterprise's data into core data, important data, and general data according to the comparison of the importance level with a preset threshold.
[0084] The second step: Data sampling. Sample according to full coverage of core data and important data, and the total proportion of general data does not exceed 20% (preset ratio).
[0085] The third step: According to different data scenarios, analyze various data processing activities such as collection, storage, use, processing, transmission, provision, cross-border transfer, and disclosure for each piece of data.
[0086] The fourth step: Judge whether each data processing activity complies with preset rules, analyze the justifiable necessity, analyze the potential risk problems existing in the management, and analyze the potential risk problems of each data processing activity to conduct a compliance assessment and obtain a compliance assessment result. Specifically:
[0087] (1) Judge whether it complies with preset rules:
[0088] Whether the purpose, method, and scope of data processing are legal, justifiable, and necessary.
[0089] The formulation and implementation of data security management systems and process strategies.
[0090] The data security organizational structure, position allocation, and duty performance.
[0091] The construction and application of data security technical protection capabilities.
[0092] Whether the personnel involved in data processing activities are familiar with data security specifications, possess data security knowledge and skills, and have received data security-related education and training, etc.
[0093] In the event of security incidents such as data being tampered with, damaged, leaked, lost, or illegally obtained and used, the scope and degree of impact on public security and other risks.
[0094] In cases involving data provision, entrusted processing, and transfer, the security guarantee capabilities, liability and obligation constraints, and fulfillment situations of the data acquirer or trustee.
[0095] In cases involving data outbound security assessment, the fulfillment of data outbound security assessment requirements.
[0096] (2) Analyze justifiable necessity:
[0097] Legitimacy of purpose: The purpose of data processing must comply with relevant regulations. For example, data processing is for the normal business operations of the enterprise, improving service quality, ensuring user security, etc.
[0098] Clarity of purpose: The purpose of data processing should be clear and specific, not ambiguous. For example, an enterprise collects user data to provide personalized services, rather than for other unclear purposes.
[0099] Principle of minimization: Data processing should follow the principle of minimization, that is, the data collected, used, stored, and transmitted should be within the minimum scope necessary to achieve the purpose. For example, for an enterprise to provide personalized services, it is necessary to collect users' browsing history and preference information, but collecting users' personal privacy information (such as home address, ID number, etc.) may exceed the necessary scope.
[0100] (3) Analyze potential risk issues in management:
[0101] Potential risk issues in basic management systems mainly involve the formulation and implementation of data security management systems, process strategies. The specific potential risk issues are as follows:
[0102] Incomplete data security system: The overall data security strategy, policy, goal, and principle have not been formulated; the work plan or work program for data security management has not been developed; the data security management system documents covering basic data security management and all links of the data full life cycle have not been established.
[0103] Insufficient organizational guarantee: Personnel with professional capabilities and experience have not been assigned to data security positions; the responsibilities of each position have not been clearly defined, resulting in ineffective implementation of data security management systems.
[0104] Unclear data classification and grading: There is no data classification and grading management system, and no data grading standards are formulated in accordance with relevant standards and rules; important data and core data are not accurately identified, and no differentiated protection strategies are formulated.
[0105] Lax permission management: The "least privilege principle" is not followed, and user access permissions are too large; permissions are not reviewed and updated regularly, resulting in permission allocation not meeting current business requirements.
[0106] Incomplete log retention: The log records of systems and applications are incomplete, making it impossible to trace data processing activities; log audits are not conducted regularly, and abnormal behaviors cannot be discovered and processed.
[0107] Incomplete risk monitoring and early warning: An effective risk monitoring and early warning system has not been established, making it impossible to discover and handle security incidents in a timely manner; no emergency response plan has been formulated, and security incidents cannot be responded to quickly.
[0108] Irregular security assessment: Data security risk assessments are not conducted regularly, making it impossible to discover and handle potential risks in a timely manner; the assessment reports are untrue, incomplete, and inaccurate, and no one is responsible for the assessment results.
[0109] Insufficient education and training: No regular education and training plan has been formulated to improve employees' data security awareness and skills; the training situation is not recorded, and the training effect cannot be ensured.
[0110] (4) Analyze the potential risk issues of each data processing activity:
[0111] The potential risk issues of each data processing activity mainly involve links such as data collection, storage, use, processing, transmission, provision, cross-border transfer, and disclosure. The specific potential risk issues are as follows:
[0112] Data collection: The purpose, method, and scope of data collection are not clear, resulting in data collection not conforming to relevant regulations, being improper, and unnecessary; the explicit consent of the data subject has not been obtained, violating the will of the user.
[0113] Data storage: No security measures such as encryption and backup are taken, resulting in risks of data leakage and damage; data backup and recovery tests are not conducted regularly to ensure data availability.
[0114] Data use: The data use and processing security policies and operating procedures are not followed, resulting in data abuse; the authorization of relevant parties such as data providers and data subjects has not been obtained, violating the will of the user; data use behaviors are inconsistent with commitments or user agreements.
[0115] Data processing: It is not ensured that the purpose, method, and scope of data processing are consistent with administrative licenses, contract authorizations, etc., resulting in data processing not conforming to relevant regulations; no measures are taken to prevent risks of data leakage and tampering during the data processing process.
[0116] Data transmission: Protection measures such as data encryption, interface authentication, and security auditing are not taken, resulting in insecure data transmission links and interfaces; Security risks such as abnormal data traffic and illegal export are not monitored, and they cannot be discovered and processed in a timely manner.
[0117] Data provision: Data provision security assessment and authorization approval are not carried out, resulting in data provision not meeting relevant regulations; The data provision process is not recorded, and it cannot be traced and audited.
[0118] Data outbound: The requirements for data outbound security assessment are not fulfilled, not meeting relevant regulations; The security guarantee capabilities of data recipients are not ensured, resulting in data being leaked and misused overseas.
[0119] Data disclosure: The legality and necessity of data disclosure are not ensured, resulting in data disclosure not meeting relevant regulations; Measures are not taken to prevent risks of data leakage and tampering during the data disclosure process. By identifying and assessing these risk points, enterprises can formulate corresponding risk control measures to ensure the compliance and security of data processing activities.
[0120] Step 5: Determine whether the data to be processed is important data or core data. If not, directly proceed to the security index calculation in Step 9. If so, proceed to Steps 6 to 8 to conduct further risk analysis.
[0121] Step 6: Identification of potential risk sources, identifying potential security risk sources of the data, including aspects such as technology, system, personnel, and industry standards.
[0122] Risk source identification refers to identifying possible security risk sources in data processing activities, including aspects such as technology, system, personnel, and industry standards. The purpose of risk source identification is to comprehensively understand the potential risks in data processing activities and provide a basis for risk assessment and risk control.
[0123] (1) Identification of technical risk sources:
[0124] 1) System and network architecture:
[0125] Identify vulnerabilities in the system and network: Regularly scan the system and network using vulnerability scanning tools (such as Nessus, OpenVAS) to identify known security vulnerabilities.
[0126] Evaluate the configuration of the system and network: Check whether the configuration of the system and network conforms to best practices, such as firewall rules, access control lists (ACLs), etc.
[0127] Monitor abnormal behaviors of the system and network: Use intrusion detection systems (IDS) and security information and event management systems (SIEM) to monitor abnormal behaviors of the system and network, such as unauthorized access, data leakage, etc.
[0128] 2) Data storage and backup:
[0129] Evaluate the security of data storage: Check whether security measures such as encryption and access control are taken for data storage devices.
[0130] Evaluate the integrity and availability of data backup: Regularly conduct data backup and recovery tests to ensure the integrity and availability of data backup.
[0131] 3) Data transmission:
[0132] Evaluate the security of data transmission: Check whether protection measures such as encryption and interface authentication are taken for data transmission links.
[0133] Monitor abnormal behaviors of data transmission: Use network monitoring tools to monitor abnormal behaviors of data transmission, such as abnormal data traffic and illegal exports.
[0134] (2) Identification of institutional risk sources:
[0135] 1) Data security management system:
[0136] Evaluate the integrity of the system: Check whether the overall data security strategy, policy, objectives and principles are formulated, and whether the work plan or work program for data security management is formulated.
[0137] Evaluate the implementation of the system: Check whether the data security management system is effectively implemented, and whether the system is reviewed and updated regularly.
[0138] 2) Data classification and grading system:
[0139] Evaluate the accuracy of classification and grading: Check whether the data classification and grading management system is formulated, and whether the data grading standard is formulated according to relevant standard rules.
[0140] Evaluate the implementation of classification and grading: Check whether important data and core data are accurately identified, and whether a differential protection strategy is formulated.
[0141] 3) Permission management system:
[0142] Evaluate the strictness of permission management: Check whether the "least privilege principle" is followed and whether the user access permission is too large.
[0143] Evaluate the dynamics of permission management: Check whether permissions are reviewed and updated regularly to ensure that permission allocation meets the current business requirements.
[0144] 4) Log management system:
[0145] Evaluate the integrity of log records: Check whether the log records of systems and applications are complete and whether data processing activities can be traced.
[0146] Evaluate the regularity of log auditing: Check whether log auditing is carried out regularly and whether abnormal behaviors can be detected and handled.
[0147] 5) Risk monitoring and early warning system:
[0148] Evaluate the effectiveness of the risk monitoring and early warning system: Check whether an effective risk monitoring and early warning system has been established and whether security incidents can be detected and handled in a timely manner.
[0149] Evaluate the perfection of the emergency response plan: Check whether an emergency response plan has been formulated and whether security incidents can be responded to quickly.
[0150] 6) Security assessment system:
[0151] Evaluate the regularity of security assessment: Check whether data security risk assessments are carried out regularly and whether potential risks can be detected and handled in a timely manner.
[0152] Check the authenticity of the assessment report: Check whether the assessment report is true, complete, and accurate and whether it can be responsible for the assessment results.
[0153] 7) Education and training system:
[0154] Evaluate the regularity of education and training: Check whether a regular education and training plan has been formulated and whether employees' data security awareness and skills can be improved.
[0155] Evaluate the integrity of training records: Check whether training situations are recorded and whether the training effects can be ensured.
[0156] (3) Identification of personnel risk sources:
[0157] 1) Employees' security awareness:
[0158] Evaluate employees' security awareness: Evaluate employees' data security awareness through methods such as questionnaire surveys and interviews.
[0159] Evaluate employees' security training situations: Check whether data security training is carried out regularly and whether training situations are recorded.
[0160] 2) Employees' operation behaviors:
[0161] Monitor employees' operation behaviors: Use behavior monitoring tools to monitor employees' operation behaviors, such as unauthorized access and data leakage.
[0162] Evaluate the standardization of employees' operations: Check whether employees follow data usage and processing security policies and operation procedures.
[0163] 3) Management of third-party personnel:
[0164] Assess the security management of third-party personnel: Check whether security assessments and authorization approvals have been conducted on third-party personnel.
[0165] Evaluate the operational behavior of third-party personnel: Check whether third-party personnel comply with data usage and processing security policies and operating procedures.
[0166] (4) Identify industry standard risk sources:
[0167] Assess compliance with industry standards: Check for compliance with industry-specific data security standards and regulations.
[0168] Assess updates to industry standards: Check whether data security policies are updated in a timely manner to ensure compliance with the latest industry standard requirements.
[0169] Step 7: Security impact analysis to determine the possible impact on the enterprise and society.
[0170] Data security incidents may have specific impacts including but not limited to the following:
[0171] (1) Impact on enterprises:
[0172] Economic loss: One of the most direct impacts of data leakage is economic loss. Companies may need to pay high fines and compensation, especially when personal privacy information is leaked. In addition, data leakage may also cause business interruption, affect the normal operation of the company, and thus affect revenue.
[0173] Reputational damage: Data breaches tend to spread quickly and attract widespread public attention. Once a company is exposed to data breaches, its brand image and reputation will be severely damaged. Consumers' trust in the company will decline, which may lead to the loss of existing customers and increase the difficulty of attracting new customers.
[0174] Customer churn: The leakage of customer information may cause customers to lose trust in the company and choose to leave. In a highly competitive market, customer churn means a reduction in market share, which is extremely detrimental to the long-term development of the company.
[0175] Loss of business opportunities: Data breaches may affect a company’s future business opportunities. Partners and investors may reassess their relationship with the company due to data breaches, resulting in the loss of potential cooperation opportunities.
[0176] Internal management chaos: Data breaches often require companies to invest a lot of resources to respond, including investigating the cause of the breach, fixing security vulnerabilities, notifying affected customers, etc. This may lead to internal management chaos and affect the daily operations of the company.
[0177] Competitive disadvantage: Enterprises lagging behind in data security may be at a disadvantage in the market competition. Consumers and partners increasingly value data security. If an enterprise fails to effectively protect data, it may lose its competitive advantage.
[0178] Long-term impact: The impact of a data breach may persist for a long time. Even if an enterprise controls the situation in the short term, the negative impact of the data breach may continue to affect the enterprise's business and reputation for a long time.
[0179] (2) Impact on society:
[0180] Social order: Large-scale data breaches may trigger social panic and affect social order. For example, the leakage of personal information may lead to an increase in social problems such as fraud and harassment.
[0181] Public interest: Data breaches may have a serious impact on public interest. For example, the leakage of medical data may expose patients' privacy and affect public health security.
[0182] Economic operation: Data breaches may affect economic operation. For example, the leakage of financial data may lead to market fluctuations and affect economic stability.
[0183] Through the aspects mentioned above, the impact degree that data security risks may bring to enterprises and society can be analyzed comprehensively and systematically.
[0184] Eighth step: Security risk assessment. Based on the comprehensive analysis of risk sources and security impacts, a quantitative risk value for data processing activities is given.
[0185] (1) Quantitative analysis of the likelihood of risk occurrence:
[0186] Classification of the likelihood of occurrence: Through the historical data of this data risk source and industry standards, the likelihood of data risk occurrence is quantitatively evaluated. According to the likelihood of data security risk occurrence, it is divided into different levels and corresponding score values are assigned. The higher the score, the higher the likelihood of risk occurrence.
[0187] High: The likelihood of risk occurrence is very high, almost certain to occur.
[0188] Medium: The likelihood of risk occurrence is relatively high, but not necessarily occur.
[0189] Low: The likelihood of risk occurrence is relatively low, not likely to occur.
[0190] The scores for the above high, medium, and low levels are respectively assigned as: 5, 3, 1.
[0191] For example, a company quantifies the likelihood of a risk occurring in a certain data storage and backup area. Its historical data shows that no data loss event has occurred in the past year, and the industry standard is that the probability of data loss for similar storage devices is 5%. Likelihood assessment: Combining historical data and industry standards, the assessed likelihood is 5% (low), and the quantification of the likelihood of the risk occurring is 1 point.
[0192] (2) Quantitative analysis of the degree of risk harm:
[0193] Classification of the degree of harm: According to the degree of harm of data security risks, they are classified into different levels and corresponding score values are assigned. The higher the score, the higher the degree of risk harm.
[0194] Based on the nature of the risk event, determine the evaluation indicators. Optional evaluation indicators include:
[0195] Economic loss: Evaluate the direct and indirect economic losses that may be caused by the risk event.
[0196] Reputation loss: Evaluate the degree of negative impact on the organization's reputation.
[0197] Legal risk: Evaluate the possible legal lawsuits or compliance issues.
[0198] User impact: Evaluate the potential impact on users or customers, such as the trust crisis caused by data leakage.
[0199] Business interruption: Evaluate the time or scope of business interruption that may be caused by the risk event.
[0200] Develop a quantitative standard based on the evaluation indicators and divide the degree of risk harm into different numerical intervals. Exemplarily, as shown in Table 1:
[0201] Hazard level Quantification value range Description Very high 80-100 Extremely high economic loss, reputation loss or risk High 60-79 Significant economic loss, reputation loss or risk Medium 40-59 Certain economic loss, reputation loss or risk Low 20-39 Minor economic loss, reputation loss or risk Very low 0-19 Extremely low economic loss, reputation loss or risk
[0202] Table 1
[0203] The specific quantitative method is as follows:
[0204] 1) Economic loss:
[0205] Direct loss: Calculate the direct economic loss caused by the risk event, such as equipment damage, data recovery cost, etc.
[0206] Indirect loss: Calculate the indirect economic loss caused by the risk event, such as business interruption, customer loss, etc.
[0207] Quantitative method:
[0208] Direct loss: Calculate according to the actual cost.
[0209] Indirect loss: Estimate according to historical data or industry standards.
[0210] Example:
[0211] Data leakage incident of a certain database:
[0212] Direct loss: The data recovery cost is 500,000 yuan.
[0213] Indirect loss: The revenue loss caused by customer churn is 300,000 yuan.
[0214] Total economic loss: 800,000 yuan.
[0215] Quantification value: According to the quantification standard, 800,000 yuan belongs to the "very high" level, and the quantification value is 90.
[0216] 2) Reputation loss:
[0217] Decline in brand value: Evaluate the degree of decline in brand value caused by the risk event.
[0218] Decline in public trust: Evaluate the degree of decline in public trust caused by the risk event.
[0219] Quantification method:
[0220] Decline in brand value: Estimate based on the brand value assessment report or market research data.
[0221] Decline in public trust: Evaluate through questionnaire surveys or social media analysis.
[0222] Example:
[0223] Data leakage incident of a certain database:
[0224] Decline in brand value: According to market research, the brand value has decreased by 10%.
[0225] Decline in public trust: Through questionnaire surveys, the trust level has decreased by 20%.
[0226] Quantification value: According to the quantification standard, it belongs to the "high" level, and the quantification value is 70.
[0227] 3) User impact:
[0228] User data leakage: Evaluate the degree of user data leakage caused by the risk event.
[0229] Decline in user trust: Evaluate the degree of decline in user trust caused by the risk event.
[0230] Quantification method:
[0231] User data leakage: Estimate based on the number of affected users or the amount of data.
[0232] Decrease in user trust: Evaluate through questionnaire surveys or user feedback.
[0233] Example:
[0234] Data leakage incident of a certain database:
[0235] Number of affected users: 100,000 users.
[0236] Decrease in user trust: According to the questionnaire survey, the trust level decreased by 30%.
[0237] Quantification value: According to the quantification standard, it belongs to the "high" level, and the quantification value is 70.
[0238] Calculation of comprehensive hazard degree:
[0239] Calculate the comprehensive hazard degree based on the quantification values of each indicator. For example, the weighted average method can be used:
[0240] Comprehensive hazard degree = ∑(quantification value × weight);
[0241] Assume the weights are: economic loss (0.4), reputation loss (0.3), risk of relevant regulations (0.2), user impact (0.1).
[0242] Taking the data leakage incident of the above-mentioned database as an example:
[0243] Quantification value of economic loss: 90;
[0244] Quantification value of reputation loss: 70;
[0245] Quantification value of risk of relevant regulations: 90;
[0246] Quantification value of user impact: 70.
[0247] Comprehensive hazard degree:
[0248] Comprehensive hazard degree = (90 × 0.4) + (70 × 0.3) + (90 × 0.2) + (70 × 0.1) = 83;
[0249] Hazard degree level: Very high.
[0250] Through the above steps, enterprises can systematically quantify the hazard degree of each risk event, providing a scientific basis for subsequent risk assessment and response measures. The determination of the quantification value needs to combine specific evaluation indicators and actual situations to ensure the accuracy and reliability of the evaluation results.
[0251] (3) Risk quantification evaluation method:
[0252] Risk assessment score calculation: Combine the risk hazard level and the likelihood of risk occurrence to calculate the risk assessment score for each piece of data. The calculation formula is: R i =σ i +V i , where:
[0253] R i : Represents the security assessment value of the i-th important core data;
[0254] σi: Represents the assignment value of the potential risk source of the i-th important core data;
[0255] V i : Represents the assignment value of the potential risk impact result of the i-th important core data.
[0256] Step 9: Comprehensive assessment value calculation. Assign different risk weights according to the importance of core data, important data, and general data, and calculate the overall data security index of the enterprise by integrating the quantitative scores of all data processing activities.
[0257] Exemplarily, assign weights according to the importance of the data:
[0258] Core data weight: 0.6;
[0259] Important data weight: 0.3;
[0260] General data weight: 0.1;
[0261] The calculation formula for the comprehensive security index is: where:
[0262] w i : Represents the weight of the i-th piece of data
[0263] R i : Represents the security assessment value of the i-th piece of data.
[0264] In summary, the technical features of this embodiment include:
[0265] 1. Classify and grade data into core, important, and general levels;
[0266] 2. Conduct a legitimate necessity analysis on data processing activities;
[0267] 3. Carry out work on general data by sampling;
[0268] 4. Conduct security analysis on the entire life cycle of data collection, storage, use, processing, transmission, provision, cross-border transfer, and disclosure;
[0269] 5. Assign different risk weights according to the importance of core data, important data, and general data.
[0270] Advantages of this embodiment:
[0271] 1. Data classification and grading are carried out. Different security assessment strategies and sampling methods are adopted for data of different categories and levels, and different risk weights are given, which not only reflects scientificity but also greatly improves work efficiency.
[0272] 2. This embodiment covers the entire life cycle of data collection, storage, use, processing, transmission, provision, cross-border transfer, and disclosure. It takes the entire life cycle of data as the core assessment object, which is very different from the traditional assessment method centered on network assets, reflecting the importance of data as a production factor.
[0273] 3. The analysis of the justifiable necessity of data processing activities is proposed, and relevant security regulations are used as part of the data security index, making the coverage of the index more comprehensive.
[0274] Referring to Figure 3 , the embodiment of the present application also provides a data security assessment device, which can implement the above-mentioned data security assessment method. The device includes:
[0275] A risk source identification unit, configured to identify risk sources for important core data to obtain potential risk sources; wherein, the important core data is data with an important level reaching a preset threshold among the data to be processed;
[0276] A risk impact prediction unit, configured to predict the potential risk impact results brought by the potential risk sources;
[0277] A first evaluation value determination unit, configured to determine a first security evaluation value of the important core data according to the potential risk sources and the potential risk impact results;
[0278] A second evaluation value determination unit, configured to determine a second security evaluation value of general data; wherein, the general data is data with an important level lower than the preset threshold among the data to be processed;
[0279] A comprehensive evaluation value determination unit, configured to determine a comprehensive evaluation value of the data to be processed according to the first security evaluation value and the second security evaluation value.
[0280] It can be understood that the content in the above method embodiment is applicable to the device embodiment of the present application. The functions specifically implemented by the device embodiment are the same as those in the above method embodiment, and the beneficial effects achieved are also the same as those in the above method embodiment.
[0281] An embodiment of the present application further provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the above-mentioned data security assessment method is implemented. The electronic device can be any intelligent terminal including a tablet computer, an in-vehicle computer, etc.
[0282] It can be understood that the content in the above method embodiments is applicable to this device embodiment. The functions specifically implemented by this device embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those of the above method embodiments.
[0283] Please refer to Figure 4 , Figure 4 which schematically shows the hardware structure of an electronic device in another embodiment. The electronic device includes:
[0284] A processor 401, which can be implemented in ways such as a general-purpose CPU (Central Processing Unit), a microprocessor, an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided by the embodiments of the present application;
[0285] A memory 402, which can be implemented in forms such as a Read Only Memory (ROM), a static storage device, a dynamic storage device, or a Random Access Memory (RAM). The memory 402 can store an operating system and other application programs. When implementing the technical solutions provided by the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 402 and are called by the processor 401 to execute a data security assessment method of the embodiments of the present application;
[0286] An input / output interface 403, which is used to implement information input and output;
[0287] A communication interface 404, which is used to implement communication interaction between this device and other devices. Communication can be achieved through a wired method (such as USB, network cable, etc.) or through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.);
[0288] A bus 405, which transmits information between various components of the device (such as the processor 401, the memory 402, the input / output interface 403, and the communication interface 404);
[0289] Among them, the processor 401, the memory 402, the input / output interface 403, and the communication interface 404 are communicatively connected to each other inside the device through the bus 405.
[0290] An embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above-described data security assessment method is implemented.
[0291] It can be understood that the content in the above method embodiments is applicable to the present storage medium embodiment. The functions specifically implemented by the present storage medium embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those of the above method embodiments.
[0292] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0293] The embodiments described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art will know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0294] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown, or combine certain steps, or different steps.
[0295] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0296] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof.
[0297] In the description of this application and the above-mentioned accompanying drawings, terms such as "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that comprises a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0298] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that three relationships can exist. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or its similar expressions refer to any combination of these items, including any combination of single items (ones) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0299] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above-mentioned division of units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.
[0300] The units described above as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0301] In addition, in each embodiment of the present application, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0302] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The foregoing storage medium includes: various media that can store programs, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0303] The preferred embodiments of the embodiments of the present application have been described above with reference to the accompanying drawings, which does not limit the scope of the rights of the embodiments of the present application. Any modification, equivalent replacement, and improvement made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall be within the scope of the rights of the embodiments of the present application.
Claims
1. A data security assessment method, characterized in that, The method includes the following steps: Identify risk sources for important core data to obtain potential risk sources; wherein, the important core data are data with an important level reaching a preset threshold among the data to be processed; Predict the potential risk impact results brought by the potential risk sources; Determine a first security evaluation value of the important core data according to the potential risk sources and the potential risk impact results; Determine a second security evaluation value of general data; wherein, the general data are data with an important level lower than the preset threshold among the data to be processed; Determine a comprehensive evaluation value of the data to be processed according to the first security evaluation value and the second security evaluation value.
2. The data security assessment method according to claim 1, characterized in that Before identifying risk sources for the important core data to obtain potential risk sources, the method further includes a step of obtaining the data to be processed, and the step of obtaining the data to be processed includes the following steps: Divide the data of the target data source according to the important level to obtain data of each important level; Extract data with a proportion lower than a preset proportion from the data with an important level lower than the preset threshold as sampling data; Combine all the data with an important level reaching the preset threshold and the sampling data as the data to be processed.
3. The data security assessment method according to claim 1, characterized in that The method further includes the following steps: Determine data processing activities of each item of data in the data to be processed according to different data scenarios; wherein, the data processing activities include at least one of collection, storage, use, processing, transmission, provision, cross-border transfer or disclosure; Judge whether each of the data processing activities complies with preset rules, analyze justifiable necessity, analyze potential risk problems existing in management, and analyze potential risk problems of each of the data processing activities to conduct compliance evaluation and obtain a compliance evaluation result.
4. A data security assessment method according to claim 1, wherein The step of identifying risk sources for the important core data to obtain potential risk sources includes the following steps: Identify technical risk sources, institutional risk sources, personnel risk sources and industry standard risk sources of the important core data to obtain the potential risk sources.
5. A data security assessment method according to claim 1, characterized in that, The step of predicting the potential risk impact results brought by the potential risk sources includes the following steps: Predict potential economic losses and potential social problems brought by the potential risk sources as the potential risk impact results.
6. A data security assessment method according to claim 1, characterized in that The step of determining the first security evaluation value of the important core data according to the potential risk sources and the potential risk impact results includes the following steps: Determine the first security evaluation value of the important core data according to a risk quantification evaluation calculation formula; The risk quantification evaluation calculation formula is: R i = σ i + V i ; Among them, R i represents the first security assessment value of the i-th said important core data; σ i represents the assignment value of the potential risk source of the i-th said important core data; V i represents the assignment value of the potential risk impact result of the i-th said important core data.
7. A data security assessment method according to any one of claims 1 to 6, characterized in that The step of determining the comprehensive evaluation value of the data to be processed according to the first security evaluation value and the second security evaluation value includes the following steps: Respectively determine the weights corresponding to the important core data and the general data; Perform weighted summation of the first security evaluation value and the second security evaluation value according to the corresponding weights to obtain the comprehensive evaluation value of the data to be processed.
8. A data security assessment device, characterized in that, The device includes: A risk source identification unit for identifying risk sources for important core data to obtain potential risk sources; wherein, the important core data are data in the to-be-processed data whose importance level reaches a preset threshold; A risk impact prediction unit for predicting the potential risk impact results brought by the potential risk sources; A first evaluation value determination unit for determining a first security evaluation value of the important core data according to the potential risk sources and the potential risk impact results; A second evaluation value determination unit for determining a second security evaluation value of general data; wherein, the general data are data in the to-be-processed data whose importance level is lower than the preset threshold; A comprehensive evaluation value determination unit for determining a comprehensive evaluation value of the to-be-processed data according to the first security evaluation value and the second security evaluation value.
9. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Data security risk prediction method and device, computer equipment and medium
CN116401688A
Data security risk assessment method and system
CN116720194A
Customer service center call platform data security risk assessment method based on artificial intelligence
CN117670023A
Data security compliance detection analysis method
CN118041672A
Automobile data security risk assessment method and equipment based on data asset architecture
CN118611912A