Common approaches to data security administration
Data security administration involves three phases: asset discovery and data classification, risk assessment, and capability building. This topic describes the specific goals of each phase.
Data security administration typically includes the following phases.

Phase one: Take stock of your assets

Discover and catalog your assets to create a Data Asset Checklist. For example:
What data does your organization have? What business categories does it serve?
Where is the data stored? What is the data volume?
What are the data types?
Which department and owner are responsible for the data?
Perform data classification to create a Data Classification Checklist. For example:
Identify business categories based on your organization's service scenarios.
Determine data sensitivity levels based on business importance.
Phase two: Assess risks
Perform the following three assessments:
Compliance risk assessment: Assess the current compliance status based on laws, regulations, and national standards. Identify compliance risks and perform a gap analysis to create a Compliance Risk Report.
Technical risk assessment: Assess the current technical status across the full data lifecycle. Identify technical risks related to data leaks (confidentiality), tampering (integrity), and unavailability (availability) to create a Technical Risk Report.
Manage risk assessment: Assess current management practices based on the organizational structure, processes, and standards. Identify management risk points based on legal and regulatory requirements, and generate a Management Risk Report.
Phase three: Build capabilities

Build the following three systems based on the assessment reports from phase two:
Management system development: Develop the organization's personnel, policies, processes, responsibilities, authorities, resource allocation, and training. This process establishes various organizational bodies, management methods, and standards.
Technical system development: Deploy various security protection products as needed. This involves using security technologies for identification, detection, protection, and response throughout the data lifecycle.
Operations system development: Regularly perform risk assessments and baseline scans, and conduct routine and special audits. Establish a monitoring and alert mechanism and implement emergency response for risk events. This process results in the 'Data Security Operations Effectiveness Evaluation Metrics'.