With the rapid development of digital government in recent years, various places have basically completed the construction of governmental big data platforms, which have gathered a large amount of demographic information, legal person information, geographic information, etc., with a high degree of data sensitivity, which is related to personal privacy as well as national security. Government data in the play of data value at the same time, but also lurks in the data security risks:
1、Large volume of data, complex sources, comprehensive sorting and data classification and grading difficulties; data application scenarios, frequent sharing and exchange, security control difficulties;
2、The need to meet security compliance, prevent sensitive data leakage, prevent data from being illegally altered, prevent data from being illegally abused;
3、The need to minimize the limit of data use, comprehensive coverage of data use scenarios, data security can be controlled, data use can be traced;
4、Need to build data security organization, system, operation system, in order to continuously protect data security.
Aiming at the current situation of data security management in government data centers, and combining with the requirements of national laws and regulations, we have established an all-round data security protection solution for government data centers.
1、Data asset sorting and classification and grading, all-round sorting of data assets in government data centers, automatic discovery of sensitive data, classification and grading, forming the basis of data security protection;
2、The use of database auditing, database firewall, API security auditing, etc. to build a monitoring and control system for government data centers;
3、Data desensitization, data watermarking, application desensitization, database encryption, etc., to protect government sensitive data from the source, as well as to improve traceability;
4、Database vulnerability scanning, database status monitoring, monitoring and discovery of database security risks, early detection of risks, early warning;
5、Data security integrated governance platform, the use of AI, big data intelligent modeling, unified analysis of various types of data security risks, the establishment of data security joint prevention and control capabilities;
6、Assist in the establishment of data security organization system, management system, operation system, in order to make government data continuously protected.
1、Government data center data security construction planning, to help establish the organizational system, management system;
2、Comprehensive sorting of data assets in the government affairs data center network, data classification and grading, so that the data asset situation is clear and visible;
3、Security protection under the scenarios of governmental data sharing, exchange, circulation, etc., to protect sensitive governmental data from being leaked;
4、Data security control under the scenarios of third-party development, testing, operation and maintenance of application systems;
5、Government data center data security situation awareness, improve operational efficiency.
Data security situational awareness of the entire network of the big data center allows managers to clearly grasp the status of data assets, data security risks, and the health of data assets.
The data security comprehensive governance platform brings together the security logs of each capability unit, and utilizes big data, AI and other technologies to correlate and analyze data security risks from the dimensions of data sources, operational risks, and data permissions, etc.; and the architecture is open, and it can access the security capabilities of other vendors.
The deployment of each data security capability unit is flexible and fully applicable to government clouds, data centers, containers and other environments.