Data flow compliance evaluation method and system

By constructing a data business information model and a security compliance risk assessment model, and combining intelligent assessment and expert assessment, the problem of insufficient autonomy and controllability in existing technologies has been solved, achieving comprehensiveness, accuracy and flexibility in data business security compliance assessment, and improving the systematicness and automation of the assessment.

CN121808301APending Publication Date: 2026-04-07SHANGHAI BIG DATA INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-07
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing data business security compliance assessment technologies rely on external institutions, lack independent and controllable routine assessment capabilities, cannot achieve flexible and in-depth customized assessments, and have disjointed assessment processes, making it difficult to form an efficient and coherent assessment system. Furthermore, the information collection and verification mechanisms are imperfect, making it impossible to achieve automated assessments.

Method used

Construct a data business information model and a security compliance risk assessment model. Import data through the data business information collection module, combine intelligent assessment and expert assessment to generate assessment reports, use a security compliance knowledge base and external intelligence data sources for cross-validation, and provide a variety of report templates to adapt to different business needs.

Benefits of technology

It has achieved comprehensiveness, accuracy, and flexibility in data business security compliance assessment, improved the systematicness and automation of the assessment, and ensured the authenticity of the data and the reliability of the assessment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121808301A_ABST
    Figure CN121808301A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security, in particular to a data flow compliance evaluation method, which comprises the following steps of: constructing a data service information model through a data service model definition module; constructing a safety compliance risk assessment model through a safety compliance risk model definition module; establishing an association relationship between the data service information model and the security compliance risk assessment model, and importing the acquired data service information into the data service information model through a data service information acquisition module; a data service security compliance evaluation module is used for carrying out data service security compliance evaluation to obtain a security compliance evaluation result and manual and intelligent evaluation suggestions; the evaluation report generation module generates an evaluation report. According to the invention, by integrating a plurality of functional modules, accurate modeling of data service information, scientific assessment of risks, reliable verification of data and efficient generation of assessment reports are realized, so that the comprehensiveness, accuracy and flexibility of data service security compliance assessment are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, specifically to a data circulation compliance assessment method and system. Background Technology

[0002] With the booming development of data services, the importance of data service security compliance assessment has become increasingly prominent. Currently, data service security compliance assessment technologies are diversified, but all have certain limitations.

[0003] Some companies rely on third-party security assessment agencies to conduct data compliance and security testing, thereby generating professional assessment reports and risk warnings and rectification measures. While this approach can identify problems to some extent, it depends on external agencies and is greatly affected by the professional capabilities of the assessors. Companies lack independent and controllable routine assessment capabilities and cannot conduct flexible, in-depth, customized assessments and special assessments for different business scenarios.

[0004] In data security compliance checks, inspections are typically conducted based on relevant laws and policies, covering multiple aspects such as data security system standards, data operation process security, R&D security, data lifecycle security, and personal information protection. The process generally consists of four stages: preliminary status survey, determination of inspection content, implementation of management and technical inspections, and summary and improvement. The survey stage involves reviewing the company's basic information, information systems, data status, and security measures; the inspection content is categorized according to dimensions such as management and technology, personnel and tools, and data level. However, in practice, this approach suffers from a problem where tools cannot effectively correlate detection results with the inspection content, leading to a disconnect in the inspection process and making it difficult to form an efficient and coherent evaluation system.

[0005] Existing data business security compliance assessment solutions rely primarily on manual review and lack systematic model support, making it difficult for assessment models to accurately adapt to complex business scenarios. At the same time, the information collection and verification mechanisms are imperfect, leading to doubts about the authenticity of the collected data. Furthermore, the assessment process depends on a single mode, making it impossible to achieve automated assessment and difficult to achieve efficient collaboration with manual assessment. Summary of the Invention

[0006] To address the above problems, the purpose of this invention is to provide a data circulation compliance assessment method; Another objective of this invention is to provide a data circulation compliance assessment system.

[0007] A data circulation compliance assessment method includes the following steps: Step S1: Construct a data business information model through the data business model definition module; Step S2: Construct a security compliance risk assessment model through the security compliance risk model definition module; Step S3: Establish the relationship between the data service information model and the security compliance risk assessment model, and import the acquired data service information into the data service information model through the data service information acquisition module; Step S4: Use the data service security compliance assessment module to conduct a data service security compliance assessment and obtain the security compliance assessment results and human and intelligent assessment opinions; Step S5: The assessment report generation module generates an assessment report based on the data business information, the security and compliance risk assessment results, and the human and intelligent assessment opinions.

[0008] The data circulation compliance assessment method of the present invention includes a data business model definition module in step S1 that abstracts data entities based on data business scenarios and clarifies the attributes and relationships between the data entities to form a standardized and structured data business information model. The data service scenarios include data resource introduction business scenarios and / or data product development business scenarios and / or data service provision business scenarios; The data entities include basic information, data vendors, data products, and data circulation. The data service information model adds, deletes, or modifies the attributes and relationships between data entities according to changes in the data service scenario.

[0009] The data circulation compliance assessment method described in this invention includes a security compliance risk model definition module in step S2 that calls data security regulations, extracts security compliance requirements and risk control points from the data security regulations, classifies and grades risk factors into different risk categories, and sets assessment rules and weights for each risk control point. The risk categories include data breach risk, data misuse risk, and compliance violation risk; the data security regulations include data security policies, data security laws and regulations, and data security standards and specifications, which are stored in the security compliance knowledge base management module.

[0010] The present invention discloses a data circulation compliance assessment method, wherein the relationship in step S3 includes the mapping relationship between the data entities in the data business information model and the risk control points in the security compliance risk assessment model. The data business information collection module obtains the data business information from the assessment template and questionnaire survey, and imports it into the data business information model according to a predetermined format and rules.

[0011] The present invention discloses a data circulation compliance assessment method, wherein the data business security compliance assessment in step S4 includes intelligent assessment, which uses a security compliance risk assessment model to automatically assess the business data imported into the data business information model, automatically calculates the risk score, identifies the risk level, and generates a preliminary risk assessment report, marking the risk details and recommended measures according to preset assessment rules and weights; The data service security compliance assessment in step S4 also includes expert assessment, which involves joint analysis of risk control points through collaboration to supplement or revise the assessment results.

[0012] The data circulation compliance assessment method described in this invention further includes data query and verification in step S4, which involves cross-verifying the basic information, operational information, and risk information of the collected enterprise entities by connecting to external intelligence data sources.

[0013] The data circulation compliance assessment method described in this invention provides multiple report templates in step S5, allowing users to customize the report content and format according to their business needs.

[0014] This invention also provides a data circulation compliance assessment system for implementing the above-described data circulation compliance assessment method, comprising: The data business model definition module is used to construct data business information models; The data service information acquisition module is used to collect data service information and import it into the data service information model. The security compliance risk model definition module is used to build security compliance risk assessment models; The data service security compliance assessment module is used to perform data service security compliance assessments. Assessment Report Generation Module: Used to generate assessment reports and output alarm prompts for data service violations.

[0015] The present invention also provides a data circulation compliance assessment system, wherein the data business security compliance assessment module includes an intelligent assessment module and an expert assessment module.

[0016] This invention also provides a data circulation compliance assessment system, which further includes: The security compliance knowledge base management module is used to manage and maintain data security regulations and knowledge. External intelligence data source interface, used to connect to external intelligence data sources.

[0017] Beneficial effects: By integrating multiple functional modules, this invention enables accurate modeling of data business information, scientific risk assessment, reliable data verification, and efficient generation of assessment reports, thereby improving the comprehensiveness, accuracy, and flexibility of data business security compliance assessment. Attached Figure Description

[0018] Figure 1 This is a flowchart illustrating a data circulation compliance assessment method according to the present invention. Figure 2 This is a structural block diagram of a data circulation compliance assessment system according to the present invention. Detailed Implementation

[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0020] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other.

[0021] The present invention will be further described below with reference to the accompanying drawings and specific embodiments, but this is not intended to limit the scope of the invention.

[0022] Reference Figure 1 A data circulation compliance assessment method includes the following steps: Step S1: Construct a data business information model through the data business model definition module; Step S2: Construct a security compliance risk assessment model through the security compliance risk model definition module; Step S3: Establish the relationship between the data business information model and the security compliance risk assessment model, and import the acquired data business information into the data business information model through the data business information acquisition module; Step S4: Use the data service security compliance assessment module to conduct a data service security compliance assessment and obtain the security compliance assessment results and human and intelligent assessment opinions; Step S5: The assessment report generation module generates an assessment report based on data business information, security and compliance risk assessment results, and human and intelligent assessment opinions.

[0023] This invention integrates multiple functional modules to achieve accurate modeling of data business information, scientific risk assessment, reliable data verification, and efficient generation of assessment reports. This improves the comprehensiveness, accuracy, and flexibility of data business security compliance assessment, and constructs a modular and intelligent assessment system to meet the stringent requirements of data business security compliance management.

[0024] The present invention provides a data circulation compliance assessment method, wherein in step S1, the data business model definition module abstracts data entities based on data business scenarios and clarifies the attributes and relationships between data entities to form a standardized and structured data business information model. Data business scenarios include data resource introduction business scenarios and / or data product development business scenarios and / or data service provision business scenarios; Data entities include basic information, data vendors, data products, and data circulation; The data business information model adds, deletes, or modifies the attributes and relationships between data entities according to changes in the data business scenario.

[0025] The data business model definition module of this invention, based on specific business scenarios such as data resource introduction, data product development, and data service provision, deeply analyzes business processes, abstracts data entities such as basic information, data vendors, data products, and data circulation, and clarifies the attributes and relationships between each entity, forming a standardized and structured data business information model. Furthermore, this model supports dynamic adjustment, allowing for flexible addition, deletion, or modification of entities and attributes according to business changes to adapt to diverse business needs.

[0026] In a data circulation compliance assessment method of the present invention, in step S2, the security compliance risk model definition module calls data security regulations, extracts security compliance requirements and risk control points from the data security regulations, classifies and grades risk factors into different risk categories, and sets assessment rules and weights for each risk control point. Risk categories include data breach risk, data misuse risk, and compliance violation risk; data security regulations include data security policies, data security laws and regulations, and data security standards and specifications, which are stored in the security compliance knowledge base management module.

[0027] The security compliance risk model definition module of this invention calls upon data security-related policies, laws, regulations, standards, and specifications from the security compliance knowledge base management module. It extracts key security compliance requirements and risk control points from these sources. Combining the characteristics of data business and focusing on data processing activities, it categorizes and grades risk factors, such as data leakage risk, data misuse risk, and compliance violation risk, and sets assessment rules and weights for each risk point. Furthermore, it continuously optimizes the model using machine learning, knowledge graphs, and other technologies to ensure its accuracy and timeliness.

[0028] The present invention provides a data circulation compliance assessment method. In step S3, the relationship includes the mapping relationship between data entities in the data business information model and risk control points in the security compliance risk assessment model. The data business information collection module obtains data business information from the assessment template and questionnaire survey, and imports it into the data business information model according to the predetermined format and rules.

[0029] This invention clarifies the mapping relationship between various entities in data business information and risk points in the risk assessment model. Through interface integration or data import, business information collected from assessment templates, questionnaires, and other channels is accurately imported according to the format and rules defined in the model, providing reliable data support for subsequent risk assessments.

[0030] The present invention provides a data circulation compliance assessment method, wherein step S4 of the data business security compliance assessment includes intelligent assessment, which uses a security compliance risk assessment model to automatically assess the business data imported into the data business information model, automatically calculates the risk score, identifies the risk level, and generates a preliminary risk assessment report, marking the risk details and recommended measures according to preset assessment rules and weights; Step S4, the data service security compliance assessment, also includes expert assessment, which involves joint analysis of risk control points through collaboration, supplementing or correcting the assessment results.

[0031] The data circulation compliance assessment method of the present invention further includes data query and verification in step S4. By connecting to external intelligence data sources, the basic information, business information and risk information of the collected enterprise entities are cross-verified.

[0032] The data service security compliance assessment of this invention includes the following steps: Intelligent assessment, executed by the intelligent assessment module, uses a security and compliance risk assessment model to automatically evaluate the imported business data. Based on preset assessment rules and weights, the algorithm automatically calculates risk scores, identifies risk levels, quickly locates high, medium, and low risk points, and generates a preliminary risk assessment report, annotating risk details and recommended measures. Expert evaluation utilizes an expert evaluation module to enable collaborative assessments between internal and third-party experts. For controversial, complex, or high-risk issues identified in the intelligent assessment, internal security, compliance, and legal experts, as well as external industry experts, are invited to jointly analyze risk points through collaboration. The intelligent assessment results are supplemented or revised by incorporating real-world business scenarios and professional experience. Data query and verification involves connecting to external intelligence data sources (such as enterprise credit reporting platforms and industry regulatory databases) to cross-verify the collected basic information, operational information, and risk information of enterprise entities, ensuring the authenticity and completeness of the data, and issuing compliance alerts for any violations in the enterprise entity's data business.

[0033] The present invention provides a data circulation compliance assessment method, in step S5 of which multiple report templates are provided, and users can customize the report content and format according to business needs.

[0034] The assessment report generation module of this invention generates assessment reports based on data business information, security and compliance risk assessment results, and human and intelligent assessment opinions, according to a custom template. By pre-setting multiple report templates, it supports users in customizing report content and format according to business needs, automatically formats various information according to the template to generate reports, and provides report editing and export functions, facilitating report review and distribution.

[0035] A specific implementation: In a business scenario of introducing enterprise data resources, the data business model definition module constructs a data business information model, determines entities and attributes such as data vendor qualifications and data product specifications, and completes the model construction.

[0036] The data service information collection module collects information such as qualification documents and product descriptions submitted by manufacturers and imports them into the data service information model according to the model rules.

[0037] The security compliance risk model definition module calls upon the regulatory knowledge in the security compliance knowledge base management module to construct a security compliance risk assessment model, setting incomplete manufacturer qualifications as a high-risk item and assigning it a corresponding weight.

[0038] The intelligent assessment module automatically analyzes the imported data based on the security and compliance risk assessment model, discovers that a certain manufacturer has missing qualifications, and generates a preliminary risk report.

[0039] In response to this high-risk issue, the expert assessment module invites experts to jointly analyze the risk points, confirm the risk level, and supplement and revise the intelligent assessment results.

[0040] The data service security compliance assessment module connects to external intelligence data sources to cross-verify the vendor's business information and other data to ensure the authenticity and reliability of the data.

[0041] The assessment report generation module automatically generates an assessment report based on the above data business information, risk assessment results, and expert opinions, and recommends that the company request the manufacturer to supplement its qualifications or terminate the cooperation.

[0042] Another specific implementation: In the data product development scenario, the data business model definition module combines the data product development process to construct a data business information model suitable for the scenario, clarifying entities and attributes such as technical solutions and data sources. The data business information collection module collects technical solution documents, data source descriptions, data product interface specifications, and other data from the product development process, and imports them into the data business information model.

[0043] The security compliance risk model definition module constructs a targeted security compliance risk assessment model and extracts compliance requirements and risk control points related to product development. After the intelligent assessment module conducts a preliminary analysis, for complex technical compliance issues that the algorithm struggles to identify, the expert assessment module organizes internal and external experts to conduct discussions and supplement the assessment results.

[0044] The data service security compliance assessment module completes the verification of relevant data to ensure data authenticity. The assessment report generation module outputs detailed assessment reports, providing comprehensive decision-making support for product development compliance and helping companies avoid potential risks.

[0045] Reference Figure 2 The present invention also provides a data circulation compliance assessment system for implementing the above-mentioned data circulation compliance assessment method, comprising: Data business model definition module 11 is used to construct data business information model A; Data service information acquisition module 12 is used to collect data service information and import it into data service information model A; Security compliance risk model definition module 13 is used to construct security compliance risk assessment model B; Data service security compliance assessment module 15 is used to perform data service security compliance assessments; The assessment report generation module 16 is used to generate assessment reports and output alarm prompts for data service violations.

[0046] The evaluation system of this invention has many advantages. Modular collaboration improves evaluation efficiency. Each functional module has a clear division of labor and works closely together, forming a complete closed loop from information modeling and risk analysis to result output, which significantly improves evaluation efficiency and accuracy.

[0047] This invention also provides a data circulation compliance assessment system, wherein the data service security compliance assessment module 15 includes: The intelligent assessment module 151 uses a security and compliance risk assessment model to automatically assess the business data of the imported data business information model. Based on preset assessment rules and weights, it automatically calculates risk scores, identifies risk levels, and generates a preliminary risk assessment report, marking risk details and recommended measures. The expert evaluation module 152 conducts joint assessments of risk control points through collaboration, supplementing or revising the evaluation results.

[0048] This invention optimizes assessment quality by combining an intelligent assessment module with an expert assessment module. The intelligent assessment enables automated and rapid analysis, improves assessment efficiency, and reduces the ability requirements of ordinary assessors. The internal and external expert assessment compensates for the limitations of the algorithm and enables comprehensive judgment based on expert experience for key and difficult points. The combination of the two ensures that complex risk issues are accurately judged.

[0049] This invention also provides a data circulation compliance assessment system, which further includes: The security compliance knowledge base management module is used to manage and maintain data security regulations and knowledge. External intelligence data source interface, used to connect to external intelligence data source C.

[0050] This invention adapts to complex scenarios through dynamic models. The data business information model and security compliance risk assessment model support dynamic adjustments, allowing for the selection of key assessment content as needed, flexibly addressing different data business scenarios. Furthermore, multi-source data verification ensures authenticity, cross-validating with external intelligence data sources to prevent data distortion.

[0051] The description and accompanying drawings provide typical embodiments of specific structures for specific implementations. Other modifications are possible based on the spirit of the invention. While the above-described invention presents preferred embodiments, these are not intended to be limiting.

[0052] For those skilled in the art, various changes and modifications will undoubtedly be apparent after reading the above description. Therefore, the appended claims should be construed as covering all changes and modifications that encompass the true intent and scope of the invention. Any and all equivalent scope and content within the scope of the claims should be considered to remain within the intent and scope of the invention.

Claims

1. A data circulation compliance assessment method, characterized in that, Includes the following steps: Step S1: Construct a data business information model through the data business model definition module; Step S2: Construct a security compliance risk assessment model through the security compliance risk model definition module; Step S3: Establish the relationship between the data service information model and the security compliance risk assessment model, and import the acquired data service information into the data service information model through the data service information acquisition module; Step S4: Use the data service security compliance assessment module to conduct a data service security compliance assessment and obtain the security compliance assessment results and human and intelligent assessment opinions; Step S5: The assessment report generation module generates an assessment report based on the data business information, the security and compliance risk assessment results, and the human and intelligent assessment opinions.

2. The data circulation compliance assessment method according to claim 1, characterized in that, In step S1, the data business model definition module abstracts data entities based on data business scenarios and clarifies the attributes and relationships between the data entities to form a standardized and structured data business information model. The data service scenarios include data resource introduction business scenarios and / or data product development business scenarios and / or data service provision business scenarios; The data entities include basic information, data vendors, data products, and data circulation. The data service information model adds, deletes, or modifies the attributes and relationships between data entities according to changes in the data service scenario.

3. The data circulation compliance assessment method according to claim 2, characterized in that, In step S2, the security compliance risk model definition module calls data security regulations, extracts security compliance requirements and risk control points from the data security regulations, classifies and grades risk factors into different risk categories, and sets evaluation rules and weights for each risk control point. The risk categories include data breach risk, data misuse risk, and compliance violation risk; the data security regulations include data security policies, data security laws and regulations, and data security standards and specifications, which are stored in the security compliance knowledge base management module.

4. The data circulation compliance assessment method according to claim 3, characterized in that, The relationship mentioned in step S3 includes the mapping relationship between the data entities in the data business information model and the risk control points in the security compliance risk assessment model. The data business information collection module obtains the data business information from the assessment template and questionnaire survey, and imports it into the data business information model according to the predetermined format and rules.

5. The data circulation compliance assessment method according to claim 1, characterized in that, The data service security compliance assessment in step S4 includes intelligent assessment, which uses a security compliance risk assessment model to automatically assess the business data imported into the data service information model. Based on preset assessment rules and weights, it automatically calculates risk scores, identifies risk levels, and generates a preliminary risk assessment report, marking risk details and recommended measures. The data service security compliance assessment in step S4 also includes expert assessment, which involves joint analysis of risk control points through collaboration to supplement or revise the assessment results.

6. The data circulation compliance assessment method according to claim 1, characterized in that, Step S4 also includes data query and verification, which involves cross-verifying the basic information, business information and risk information of the collected enterprise entities by connecting to external intelligence data sources.

7. The data circulation compliance assessment method according to claim 4, characterized in that, Step S5 provides a variety of report templates, allowing users to customize the report content and format according to their business needs.

8. A data circulation compliance assessment system, characterized in that, A data circulation compliance assessment method for implementing any one of claims 1-7 includes: The data business model definition module is used to construct data business information models; The data service information acquisition module is used to collect data service information and import it into the data service information model. The security compliance risk model definition module is used to build security compliance risk assessment models; The data service security compliance assessment module is used to perform data service security compliance assessments. Assessment Report Generation Module: Used to generate assessment reports and output alarm prompts for data service violations.

9. The data circulation compliance assessment system according to claim 8, characterized in that, The data service security compliance assessment module includes an intelligent assessment module and an expert assessment module.

10. The data circulation compliance assessment system according to claim 8, characterized in that, It also includes, The security compliance knowledge base management module is used to manage and maintain data security regulations and knowledge. External intelligence data source interface, used to connect to external intelligence data sources.