Common approaches to data security administration

Updated at:

Data security administration involves three phases: asset discovery and data classification, risk assessment, and capability building. This topic describes the specific goals of each phase.

Data security administration typically includes the following phases.

image.png

Phase one: Take stock of your assets

image.png

  1. Discover and catalog your assets to create a Data Asset Checklist. For example:

    • What data does your organization have? What business categories does it serve?

    • Where is the data stored? What is the data volume?

    • What are the data types?

    • Which department and owner are responsible for the data?

  2. Perform data classification to create a Data Classification Checklist. For example:

    • Identify business categories based on your organization's service scenarios.

    • Determine data sensitivity levels based on business importance.

Phase two: Assess risks

image.pngPerform the following three assessments:

  • Compliance risk assessment: Assess the current compliance status based on laws, regulations, and national standards. Identify compliance risks and perform a gap analysis to create a Compliance Risk Report.

  • Technical risk assessment: Assess the current technical status across the full data lifecycle. Identify technical risks related to data leaks (confidentiality), tampering (integrity), and unavailability (availability) to create a Technical Risk Report.

  • Manage risk assessment: Assess current management practices based on the organizational structure, processes, and standards. Identify management risk points based on legal and regulatory requirements, and generate a Management Risk Report.

Phase three: Build capabilities

image.png

Build the following three systems based on the assessment reports from phase two:

  • Management system development: Develop the organization's personnel, policies, processes, responsibilities, authorities, resource allocation, and training. This process establishes various organizational bodies, management methods, and standards.

  • Technical system development: Deploy various security protection products as needed. This involves using security technologies for identification, detection, protection, and response throughout the data lifecycle.

  • Operations system development: Regularly perform risk assessments and baseline scans, and conduct routine and special audits. Establish a monitoring and alert mechanism and implement emergency response for risk events. This process results in the 'Data Security Operations Effectiveness Evaluation Metrics'.