A method and system for automatic auditing and scoring of compliance of permissions for a telecommunications service system

By constructing a multi-dimensional permission compliance audit indicator system and an automated scoring method, the problems of low efficiency and lack of quantitative standards in traditional audits have been solved. This has enabled automatic auditing and scoring of permission compliance in telecommunications business systems, improving audit efficiency and rectification effectiveness, and adapting to the special needs of the telecommunications industry.

CN122243421APending Publication Date: 2026-06-19BEIJING JINAO HERUN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING JINAO HERUN TECHNOLOGY CO LTD
Filing Date
2026-05-08
Publication Date
2026-06-19

AI Technical Summary

Technical Problem

Traditional compliance audits rely on manual spot checks, which are inefficient, prone to missing hidden problems, lack quantitative standards, cannot be compared horizontally, and make it difficult to guarantee the effectiveness of rectification. Furthermore, general systems are not adapted to the needs of the telecommunications industry.

Method used

Construct a multi-dimensional permission compliance audit indicator system to achieve automated auditing and quantitative scoring, generate standardized rectification work orders and establish a closed-loop tracking mechanism, and support dynamic adjustment of indicator weights.

Benefits of technology

It enables full-scale checks on permission compliance, improves audit efficiency, identifies hidden problems, reduces internal control risks, provides scientific assessment criteria, ensures thorough rectification, and adapts to the needs of the telecommunications industry.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122243421A_ABST
    Figure CN122243421A_ABST
Patent Text Reader

Abstract

This invention relates to the field of business data processing technology, specifically to a method and system for automatic auditing and scoring of permission compliance in telecommunications business systems. The method includes the following steps: S1: Collecting full data on employee IDs and compliance standard data; S2: Constructing a multi-dimensional permission compliance audit indicator system and assigning weights to each core audit indicator; S3: Auditing employee ID permissions item by item and obtaining the audit results of each core audit indicator; S4: Calculating a comprehensive compliance score and classifying compliance levels; S5: Generating a permission compliance audit report, generating rectification work orders for non-compliant items and dispatching them; S6: Tracking the closed-loop processing of rectification work orders and inputting the rectified data into step S1 for re-auditing. This achieves automated auditing and quantitative scoring of employee ID permission compliance, forming a standardized rectification closed-loop mechanism, thereby ensuring the compliance of employee ID permission management and meeting the needs of large-scale and refined permission internal control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of business data processing technology, and in particular to a method and system for automatic auditing and scoring of permission compliance in telecommunications business systems. Background Technology

[0002] Telecommunications operators have numerous internal business systems, including customer service, billing, operations and maintenance, network management, and sales offices. Each system is configured with a large number of operator IDs, with numerous permission items and high job suitability requirements. At the same time, the telecommunications industry is subject to strict internal control and supervision requirements, with clear compliance requirements for minimum permission configuration, separation of responsibilities, and control of highly sensitive permissions.

[0003] In recent years, telecom operators have successively built unified employee ID management platforms, realizing centralized creation and permission configuration of employee IDs. However, there are still significant shortcomings in permission compliance control: traditional permission compliance audits rely on manual spot checks, which are not only extremely inefficient when faced with massive numbers of employee IDs and permission items, but also prone to overlooking hidden compliance issues; permission compliance is judged only qualitatively, lacking unified quantitative standards, making it impossible to conduct horizontal comparisons and assessments of permission compliance levels across departments and positions; non-compliance items discovered during audits lack standardized rectification work orders and closed-loop tracking mechanisms, making it difficult to guarantee rectification effectiveness and leading to recurring compliance issues. Therefore, traditional manual auditing methods can no longer meet the large-scale and refined permission internal control needs of telecom operators, while general permission management systems have not been customized for the compliance requirements of the telecom industry and are difficult to adapt to the special needs of telecom business scenarios. Summary of the Invention

[0004] In view of the above-mentioned shortcomings and deficiencies of the existing technology, the present invention provides an automatic audit and scoring method and system for permission compliance of telecommunications business systems. It constructs a multi-dimensional permission compliance audit index system, realizes automated audit and quantitative scoring of employee number permission compliance, and forms a standardized rectification closed-loop mechanism, thereby ensuring the compliance of employee number permission management and meeting the needs of large-scale and refined permission internal control.

[0005] An automated auditing and scoring method for permission compliance in telecommunications business systems includes the following steps: S1: Collect full data on employee IDs and compliance standard data on permissions from telecommunications business systems; S2: Construct a multi-dimensional permission compliance audit indicator system. The multi-dimensional permission compliance audit indicator system includes multiple core audit indicators and assigns weights to each core audit indicator. S3: Based on a multi-dimensional permission compliance audit indicator system, the employee ID permissions are audited item by item to obtain the audit results of each core audit indicator; S4: Calculate the comprehensive compliance score and classify the compliance level based on the indicator configuration weights and indicator audit results; S5: Generate permission compliance audit reports, generate rectification work orders for non-compliance items found in the audit, and dispatch them; S6: Track the closed-loop processing of rectification work orders and input the rectified data into step S1 for re-audit.

[0006] Furthermore, the full data of the employee ID collected in step S1 includes basic employee ID information, permission configuration data, permission management records, and operation log data. The basic employee ID information includes the department to which the employee belongs and the associated position. The compliance standard data includes the internal control management methods of the telecommunications industry, the minimum permission configuration standard for the position, the list of permissions with conflict of rights and responsibilities, and the approval standard for highly sensitive permissions.

[0007] Furthermore, the multi-dimensional permission compliance audit indicator system in step S2 includes 5 core audit indicators, namely, permission over-allocation rate, high-sensitivity permission non-approval rate, number of conflicting rights and responsibilities, proportion of long-term idle permissions, and unauthorized operation rate.

[0008] Furthermore, in step S2, the configuration weights are subjectively assigned to each core audit indicator based on the opinions of experts from multiple departments, and objectively assigned to each core audit indicator based on the dispersion of historical audit data. The ratio of subjective weighting to objective weighting is allocated to obtain the combined weights, and the combined weights are then assigned to each core audit indicator.

[0009] Furthermore, the automated item-by-item audit in step S3 includes audits of over-allocation of permissions, audits of highly sensitive permissions, audits of conflicts of rights and responsibilities, audits of idle permissions, and audits of unauthorized operations.

[0010] Furthermore, the specific steps of step S3 are as follows: Over-permission audit: Compare the permission configuration data with the minimum permission configuration standard for each position, count the number of over-permission items, calculate the ratio of the number of over-permission items to the number of permission configuration items, and obtain the permission over-permission rate; High-sensitivity permission audit: Based on the high-sensitivity permission approval standard, verify the completeness of the approval process of high-sensitivity permission configuration in the permission management record, count the number of unapproved high-sensitivity permission items, calculate the ratio of the number of unapproved high-sensitivity permission items to the number of high-sensitivity permission configuration items, and obtain the high-sensitivity permission non-approval rate. Audit of conflicts of authority and responsibility: Match permission configuration data with the list of conflicting permissions and responsibilities, and count the number of conflicting items; Audit of idle permissions: The number of permission items that have not been used for 90 consecutive days in the operation log data is counted as the number of idle permission items. The ratio of the number of idle permission items to the number of permission configuration items is calculated to obtain the proportion of long-term idle permissions. Unauthorized operation audit: Operation log data includes authorized operation records. According to the internal control management methods of the telecommunications industry, the authorized operation records are compared with the authorized configuration data to identify unauthorized operation behaviors, count the number of unauthorized operations, and calculate the ratio of the number of unauthorized operations to the number of authorized operations to obtain the unauthorized operation occurrence rate.

[0011] Furthermore, step S4 uses a weighted summation method to calculate the comprehensive compliance score for permissions. The comprehensive compliance score is divided into four compliance levels from high to low: excellent, qualified, warning, and unqualified.

[0012] Furthermore, the permission compliance audit report generated in step S5 includes multi-dimensional compliance scores and compliance level statistics, details of non-compliance items, distribution of abnormal permissions, and compliance rectification suggestions. The rectification work order includes the work number identifier, non-compliance type, rectification requirements, rectification responsible person and rectification deadline.

[0013] Furthermore, the specific steps of step S6 are as follows: S61. Work order tracking: The person responsible for rectification updates the progress of the work order in real time and sends a reminder notice one day before the rectification deadline. Work orders that are not rectified by the deadline are automatically upgraded and pushed to the superior management department. S62. Submission of rectification: After the person responsible for rectification completes the permission adjustment, upload the rectification results and rectification vouchers, and submit the rectification for review. S63: Automatic verification; Input the rectification results into step S1 for re-verification, and re-audit the compliance of the permissions of this work number; S64: Work order judgment; if the verification passes, the work order is marked as completed; if the verification fails, the work order is returned with a prompt indicating insufficient rectification and requiring rectification again. S65: Data Update; After all work orders are completed, update the rectified data to the audit database, overwriting the original data.

[0014] An automated audit and scoring system for permission compliance in telecommunications business systems is provided. The system employs an automated audit and scoring method for permission compliance in telecommunications business systems, including a data collection module, an indicator system construction module, an automated audit module, a scoring and grading module, a report and work order module, and a rectification closed-loop module. The data acquisition module is used to collect and store the full data of employee IDs and compliance standard data of permissions in the telecommunications business system; The indicator system construction module is used to create a multi-dimensional permission compliance audit indicator system and configure the weights of various core audit indicators; The automated audit module is used to audit employee ID permissions. The scoring and grading module is used to calculate and classify comprehensive compliance scores. The report and work order module is used to generate permission compliance audit reports, generate rectification work orders, and dispatch them. The rectification closed-loop module is used for closed-loop processing of rectification work orders.

[0015] The beneficial effects of this invention are: This invention provides an automatic audit and scoring method and system for permission compliance in telecommunications business systems. By uniformly collecting employee ID data, it achieves full-scale checks on permission compliance, which greatly improves audit efficiency compared to traditional manual spot checks, achieves full audit coverage, effectively discovers hidden permission compliance issues, and reduces internal control risks.

[0016] By constructing a multi-dimensional permission compliance audit indicator system, this invention can comprehensively consider multiple core compliance factors in the telecommunications industry, such as permission over-allocation, high-sensitivity permission control, conflict of rights and responsibilities, long-term idle permissions, and unauthorized operations. It is tailored to the permission management scenarios of telecommunications business systems, and the audit results are more targeted and practical.

[0017] By constructing a quantitative scoring method, the compliance of permissions is transformed from a qualitative judgment to a quantitative evaluation, enabling multi-dimensional comparison of compliance levels based on employee ID, position, and department, and providing a scientific basis for the operator's internal control assessment of permissions.

[0018] By establishing standardized rectification work orders and a closed-loop tracking mechanism, we can track, submit, automatically verify, and judge work orders for non-compliant items, ensuring that non-compliant items are rectified in place, preventing problems from recurring, and improving the effectiveness of compliance management.

[0019] The indicator system and weights of this invention support dynamic adjustment, enabling rapid adaptation to changes in telecommunications industry regulatory requirements and operators' internal control priorities, maintaining the timeliness and accuracy of audits and scoring. Furthermore, this invention is developed based on existing employee ID management platforms and data collection conditions of telecommunications operators, requiring no large-scale modification of existing systems, thus possessing strong operability and industry-wide applicability, and is easy to implement and deploy within telecommunications operators. Attached Figure Description

[0020] Figure 1 This is a flowchart of an automatic audit and scoring method for permission compliance in a telecommunications business system according to the present invention; Figure 2 This is a schematic diagram of the multi-dimensional permission compliance audit indicator system of the present invention; Figure 3 This is a flowchart illustrating the closed-loop processing of tracking and rectification work orders in this invention. Detailed Implementation

[0021] To better explain and facilitate understanding of the present invention, it will be described in detail below with reference to the accompanying drawings and specific embodiments. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a clearer and more thorough understanding of the invention and to fully convey the scope of the invention to those skilled in the art.

[0022] like Figure 1 As shown, an automatic audit and scoring method for permission compliance in telecommunications business systems includes the following steps: S1: Collect full data on employee IDs and compliance standard data on permissions from telecommunications business systems; S2: Construct a multi-dimensional permission compliance audit indicator system. The multi-dimensional permission compliance audit indicator system includes multiple core audit indicators and assigns weights to each core audit indicator. S3: Based on a multi-dimensional permission compliance audit indicator system, the employee ID permissions are audited item by item to obtain the audit results of each core audit indicator; S4: Calculate the comprehensive compliance score and classify the compliance level based on the indicator configuration weights and indicator audit results; S5: Generate permission compliance audit reports, generate rectification work orders for non-compliance items found in the audit, and dispatch them; S6: Track the closed-loop processing of rectification work orders and input the rectified data into step S1 for re-audit.

[0023] The data collected in step S1 specifically includes: (1) Basic information of employee ID: employee ID number, branch company and department, associated position, responsible person, activation status and validity period; (2) Permission configuration data: menu access permissions, operation execution permissions, data viewing and modification permissions, and permission configuration time for each business system; (3) Access control records: access application forms, approval process records, access change history and cancellation records; (4) Operation log data: system login records, permission operation records, operation time and operation terminal for the past 6 months; (5) Compliance standard data: internal control management methods for the telecommunications industry, minimum authority configuration standards for positions, list of authority conflicts and approval standards for highly sensitive authority.

[0024] Data collection is achieved through system integration and standardized extraction, including API calls with the operator's unified employee ID management platform, various business systems, and OA approval systems to achieve automatic data synchronization. For a small number of non-systematized compliance standards, manual entry and standardized storage are used to ensure data integrity.

[0025] By designing step S1, the unified collection of employee ID data and automatic auditing achieve a full-scale check of permission compliance. Compared with the traditional manual sampling method, this greatly improves audit efficiency, achieves full audit coverage, effectively discovers hidden permission compliance issues, and reduces internal control risks.

[0026] Step S2 specifically includes the following steps: S21. Indicator creation: In conjunction with the internal control management methods of the telecommunications industry, five core audit indicators were created, namely, the over-allocation rate of permissions, the rate of unapproved high-sensitivity permissions, the number of items with conflicting rights and responsibilities, the proportion of long-term idle permissions, and the rate of unauthorized operations. Each indicator has a clear calculation method and judgment standard. S22. Weight Determination: The Analytic Hierarchy Process (AHP) is used to subjectively assign weights to each core audit indicator based on the opinions of experts from internal control, information security, and business departments. The entropy weight method is used to objectively assign weights to each core audit indicator based on the dispersion of historical audit data. The ratio of subjective weighting to objective weighting is allocated to obtain the combined weights, which are then assigned to each core audit indicator. like Figure 2 As shown, in this embodiment, the combined weight is calculated according to the ratio of 60% subjective weight and 40% objective weight, wherein the weight of the over-allocation rate of permissions is set to 15%, the weight of the unapproved rate of high-sensitivity permissions is set to 25%, the weight of the number of conflicting rights and responsibilities is set to 20%, the weight of the proportion of long-term idle permissions is set to 15%, and the weight of the occurrence rate of unauthorized operations is set to 25%. S23. System Maintenance: Establish an indicator management system to support the addition, deletion, and editing of core audit indicators, as well as the dynamic adjustment of their weights. This enables the dynamic editing and adjustment of core audit indicators and their weights based on changes in the operator's internal control priorities and regulatory requirements.

[0027] By designing step S2, a multi-dimensional permission compliance audit indicator system was constructed. This system aligns with the compliance requirements of the telecommunications industry and the actual permission management practices of operators. It comprehensively considers multiple core compliance factors in the telecommunications industry, including permission over-allocation, high-sensitivity permission control, conflicts of rights and responsibilities, long-term idle permissions, and unauthorized operations. This achieves multi-dimensional and scalable permission compliance audits, making the audit results more targeted and practical. The weights of each indicator are determined using the analytic hierarchy process combined with the entropy weight method, ensuring the scientific nature of the scoring by combining subjective and objective methods. Furthermore, the core audit indicators and weights can be dynamically edited and adjusted according to changes in operators' internal control priorities and regulatory requirements, providing real-time performance and flexibility.

[0028] Step S3 involves auditing each employee's permissions based on a multi-dimensional permission compliance audit indicator system to obtain the audit results for each core audit indicator. The specific steps are as follows: (1) Over-permission audit: Compare the permission configuration data with the minimum permission configuration standard for each position, count the number of over-permission items, calculate the ratio of the number of over-permission items to the number of permission configuration items, and obtain the permission over-permission rate; (2) High-sensitivity permission audit: Based on the high-sensitivity permission approval standard, verify the completeness of the approval process of the high-sensitivity permission configuration in the permission management record, count the number of unapproved high-sensitivity permission items, calculate the ratio of the number of unapproved high-sensitivity permission items to the number of high-sensitivity permission configuration items, and obtain the high-sensitivity permission non-approval rate. (3) Audit of conflict of rights and responsibilities: Match the permission configuration data with the list of conflicting rights and responsibilities, and count the number of conflicting rights and responsibilities; a conflict of rights and responsibilities is a combination of rights and responsibilities that conflict in the permission configuration data of the same employee number, such as accounting and auditing, operation and auditing. (4) Audit of idle permissions: The number of idle permissions is calculated by counting the number of permissions that have not been used for 90 consecutive days in the operation log data, and the ratio of the number of idle permissions to the number of permission configuration items is calculated to obtain the proportion of long-term idle permissions. (5) Audit of unauthorized operations: The operation log data includes authorized operation records. According to the internal control management method of the telecommunications industry, the authorized operation records are compared with the authorized configuration data to identify unauthorized operation behaviors, count the number of unauthorized operations, calculate the ratio of the number of unauthorized operations to the number of authorized operations, and obtain the unauthorized operation occurrence rate.

[0029] The entire audit process is automated and requires no manual intervention. All audit results are recorded in detail by work number, forming an audit result detail table, which provides a basis for subsequent scoring and rectification.

[0030] The specific steps of step S4 are as follows: The weighted summation method is used to calculate the overall compliance score for permissions. The calculation formula is as follows: Overall compliance score = Σ (core audit indicator score × combined weight); The overall compliance score is divided into four compliance levels from high to low: excellent, qualified, warning, and unqualified.

[0031] In this embodiment, each core audit indicator is converted into a score of 0-100 based on the audit results. For example, a score of 100 is obtained if the non-approval rate of high-sensitivity permissions is 0, and a score of 0 is obtained if the non-approval rate of high-sensitivity permissions is ≥50%. Four compliance levels are determined based on the comprehensive compliance score: Excellent (90-100 points), Qualified (70-89 points), Warning (50-69 points), and Unqualified (0-49 points).

[0032] Scores and grades are statistically summarized according to three dimensions: employee number, position, and department, generating a multi-dimensional comprehensive compliance score statistical report to enable horizontal comparison of compliance levels.

[0033] By designing step S4, a quantitative scoring method was constructed, transforming permission compliance from qualitative judgment to quantitative evaluation, enabling multi-dimensional comparison of compliance levels based on employee ID, position, and department, and providing a scientific basis for operator permission internal control assessment.

[0034] The specific steps of step S5 are as follows: Based on the audit results and scoring statistics, a visual permission compliance audit report is automatically generated. The report can be filtered and viewed by branch, department, and business system, and includes an overall compliance overview, multiple compliance and level statistics, non-compliance details, abnormal permission distribution, and compliance rectification suggestions. Meanwhile, a standardized rectification work order is automatically generated for each non-compliance detail. The work order includes the work order number, the department to which it belongs, the person responsible for rectification, the type of non-compliance, a specific description of the problem, rectification requirements, and a rectification deadline. In this embodiment, the rectification deadline is set to 3-7 working days, and the work order is automatically dispatched to the person responsible for rectification through the operator's internal office system, while also being copied to the department head.

[0035] like Figure 3 As shown, the specific steps of step S6 are as follows: S61. Work order tracking: The person responsible for rectification updates the progress of the work order in real time and sends a reminder notice one day before the rectification deadline. Work orders that are not rectified by the deadline are automatically upgraded and pushed to the superior management department. S62. Submission of rectification: After the person responsible for rectification completes the permission adjustment, upload the rectification results and rectification vouchers, and submit the rectification for review. S63: Automatic verification; Input the rectification results into step S1 for re-verification, and re-audit the compliance of the permissions of this work number; S64: Work order judgment; if the verification passes, the work order is marked as completed; if the verification fails, the work order is returned with a prompt indicating insufficient rectification and requiring rectification again. S65: Data Update; After all work orders are completed, the rectified data is updated to the audit database, overwriting the original data; This provides accurate data support for subsequent routine audits.

[0036] S66: Retrospective Analysis; Conduct a monthly retrospective analysis of the completion status and non-compliance types of all rectification work orders, summarize common problems, and optimize the audit indicator system or access control process.

[0037] By designing steps S5 and S6, a standardized rectification work order and closed-loop tracking mechanism was established to track, submit, automatically verify, and judge work orders for non-compliant items, ensuring that non-compliant items are rectified in place, avoiding recurrence of problems, and improving the effectiveness of permission compliance management.

[0038] An automated audit and scoring system for permission compliance in telecommunications business systems is provided. The system employs an automated audit and scoring method for permission compliance in telecommunications business systems, including a data collection module, an indicator system construction module, an automated audit module, a scoring and grading module, a report and work order module, and a rectification closed-loop module. The data acquisition module is used to collect and store the full data of employee IDs and compliance standard data of permissions in the telecommunications business system; The indicator system construction module is used to create a multi-dimensional permission compliance audit indicator system and configure the weights of various core audit indicators; The automated audit module is used to audit employee ID permissions. The scoring and grading module is used to calculate and classify comprehensive compliance scores. The report and work order module is used to generate permission compliance audit reports, generate rectification work orders, and dispatch them. The rectification closed-loop module is used for closed-loop processing of rectification work orders.

[0039] By designing this system, we can not only achieve the beneficial effects of the method, but also develop it based on the existing employee ID management platform and data collection conditions of telecom operators. It does not require large-scale modification of the existing system, has strong operability and industry promotion, and is easy to implement and deploy within telecom operators.

[0040] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make modifications, alterations, substitutions and variations to the above embodiments within the scope of the present invention.

Claims

1. A method for automatic auditing and scoring of permission compliance in telecommunications business systems, characterized in that, Includes the following steps: S1: Collect full data on employee IDs and compliance standard data on permissions from telecommunications business systems; S2: Construct a multi-dimensional permission compliance audit indicator system. The multi-dimensional permission compliance audit indicator system includes multiple core audit indicators and assigns weights to each core audit indicator. S3: Based on a multi-dimensional permission compliance audit indicator system, the employee ID permissions are audited item by item to obtain the audit results of each core audit indicator; S4: Calculate the comprehensive compliance score and classify the compliance level based on the indicator configuration weights and indicator audit results; S5: Generate permission compliance audit reports, generate rectification work orders for non-compliance items found in the audit, and dispatch them; S6: Track the closed-loop processing of rectification work orders and input the rectified data into step S1 for re-audit.

2. The automatic auditing and scoring method for permission compliance in a telecommunications business system as described in claim 1, characterized in that, The full data of the employee ID collected in step S1 includes basic employee ID information, permission configuration data, permission management records and operation log data. The basic employee ID information includes the department and associated position. The compliance standard data includes the internal control management methods of the telecommunications industry, the minimum permission configuration standard for positions, the list of permissions with conflict of rights and responsibilities, and the approval standard for highly sensitive permissions.

3. The automatic auditing and scoring method for permission compliance in a telecommunications business system as described in claim 2, characterized in that, The multi-dimensional permission compliance audit indicator system in step S2 includes 5 core audit indicators, namely, permission over-allocation rate, high-sensitivity permission non-approval rate, number of rights and responsibilities conflict items, proportion of long-term idle permissions, and unauthorized operation occurrence rate.

4. The automatic auditing and scoring method for permission compliance in a telecommunications business system as described in claim 1, characterized in that, In step S2, the configuration weights are subjectively assigned to each core audit indicator based on the opinions of experts from multiple departments, and objectively assigned to each core audit indicator based on the dispersion of historical audit data. The ratio of subjective weighting to objective weighting is allocated to obtain the combined weights, and the combined weights are then assigned to each core audit indicator.

5. The automatic auditing and scoring method for permission compliance in a telecommunications business system as described in claim 3, characterized in that, The automated item-by-item audit in step S3 includes audits of over-allocation of permissions, audits of highly sensitive permissions, audits of conflicts of rights and responsibilities, audits of idle permissions, and audits of unauthorized operations.

6. The automatic auditing and scoring method for permission compliance in a telecommunications business system as described in claim 5, characterized in that, The specific steps of step S3 are as follows: Over-permission audit: Compare the permission configuration data with the minimum permission configuration standard for each position, count the number of over-permission items, calculate the ratio of the number of over-permission items to the number of permission configuration items, and obtain the over-permission rate; High-sensitivity permission audit: Based on the high-sensitivity permission approval standard, verify the completeness of the approval process of high-sensitivity permission configuration in the permission management record, count the number of unapproved high-sensitivity permission items, calculate the ratio of the number of unapproved high-sensitivity permission items to the number of high-sensitivity permission configuration items, and obtain the high-sensitivity permission non-approval rate. Audit of conflicts of authority and responsibility: Match permission configuration data with the list of conflicting permissions and responsibilities, and count the number of conflicting items; Audit of idle permissions: The number of permission items that have not been used for 90 consecutive days in the operation log data is counted as the number of idle permission items. The ratio of the number of idle permission items to the number of permission configuration items is calculated to obtain the proportion of long-term idle permissions. Unauthorized operation audit: Operation log data includes authorized operation records. According to the internal control management methods of the telecommunications industry, the authorized operation records are compared with the authorized configuration data to identify unauthorized operation behaviors, count the number of unauthorized operations, and calculate the ratio of the number of unauthorized operations to the number of authorized operations to obtain the unauthorized operation occurrence rate.

7. The automatic auditing and scoring method for permission compliance in a telecommunications business system as described in claim 1, characterized in that, Step S4 uses a weighted summation method to calculate the comprehensive compliance score. The comprehensive compliance score is divided into four compliance levels from high to low: excellent, qualified, warning, and unqualified.

8. The automatic auditing and scoring method for permission compliance in a telecommunications business system as described in claim 1, characterized in that, The permission compliance audit report generated in step S5 includes multi-dimensional compliance scores and compliance level statistics, details of non-compliance items, distribution of abnormal permissions, and compliance rectification suggestions. The rectification work order includes the work number identifier, non-compliance type, rectification requirements, rectification responsible person and rectification deadline.

9. The automatic auditing and scoring method for permission compliance in a telecommunications business system as described in claim 1, characterized in that, The specific steps of step S6 are as follows: S61. Work order tracking: The person responsible for rectification updates the progress of the work order in real time and sends a reminder notice one day before the rectification deadline. Work orders that are not rectified by the deadline are automatically upgraded and pushed to the superior management department. S62. Submit rectification; After the person responsible for rectification completes the permission adjustment, they should upload the rectification results and rectification vouchers and submit them for rectification review. S63: Automatic verification; Input the rectification results into step S1 for re-verification, and re-audit the compliance of the permissions of the work number. S64: Work order judgment; if the verification passes, the work order is marked as completed; if the verification fails, the work order is returned with a prompt indicating insufficient rectification and requiring rectification again. S65: Data Update; After all work orders are completed, update the rectified data to the audit database, overwriting the original data.

10. An automatic access control compliance audit and scoring system for telecommunications business systems, employing the automatic access control compliance audit and scoring method for telecommunications business systems as described in any one of claims 1-9, characterized in that, It includes a data acquisition module, an indicator system construction module, an automated audit module, a scoring and grading module, a report and work order module, and a rectification closed-loop module; The data acquisition module is used to collect and store the full data of employee IDs and compliance standard data of permissions in the telecommunications business system; The indicator system construction module is used to create a multi-dimensional permission compliance audit indicator system and configure the weights of various core audit indicators; The automated audit module is used to audit employee ID permissions. The scoring and grading module is used to calculate and classify comprehensive compliance scores. The report and work order module is used to generate permission compliance audit reports, generate rectification work orders, and dispatch them. The rectification closed-loop module is used for closed-loop processing of rectification work orders.