Why data security governance is necessary

Updated at:

Data Security Governance ensures data security through a systematic approach that involves managing personnel behaviors related to organizational Assets to prevent data security events. The goal of Data Security Governance is to help enterprises establish legal awareness of data security, ensure that their business operations are legal and compliant, demonstrate corporate social responsibility, and protect their core interests.

The essence of data security governance

The Data Security Law, enacted on June 10, 2021, provides a clear direction for establishing a sound data security governance system in China. Article 4 states, "To maintain data security, we must adhere to the overall national security concept, establish a sound data security governance system, and improve data security protection capabilities." Article 7 states, "The state protects the data-related rights and interests of individuals and organizations, encourages the lawful, reasonable, and effective use of data, ensures the lawful, orderly, and free flow of data, and promotes the development of the digital economy with data as a key element." This law emphasizes that data security governance is essential for protecting data systematically.

Major international security governance frameworks include Gartner's DSG and Microsoft's DGPC method.

  • Gartner's DSG states that data security governance is not just a product-level solution composed of a combination of tools. It is a complete, top-down chain that extends from the decision-making layer to the technical layer, and from management policies to tool support, throughout organization. All levels within an organization must agree on the goals of data security governance. This ensures that reasonable and appropriate measures are taken to protect information resources in the most effective manner.

  • The Microsoft DGPC method advocates that organizations protect against data-related security and privacy risks in three core areas: people, process, and technology.

    • People: This area involves the organization, roles, and responsibilities. This requires a proper organizational structure and sufficient resources. It also requires strict adherence to DGPC goals and duties, which must be adjusted for each organization's unique situation.

    • Process: This area involves risk management and policy definition. It requires familiarity with data security laws, regulations, standards, and systems. This involves defining data compliance requirements and translating them into your organization's policies and procedures to implement data security practices.

    • Technology: This area involves risk assessment and mitigation. This involves translating DGPC requirements into technical controls and capabilities to manage risks in the information flow. The risk/gap analysis matrix is the most critical component. It combines the information lifecycle and technology domains with data privacy and confidentiality principles. This helps organizations take measures to protect data from privacy, confidentiality, and compliance threats, and manage any remaining risks.

The definitions above show that data security governance cannot be achieved with technical tools alone. From a macro perspective, data security governance must manage the relationships among policies, the organization, people, and tools. From a micro perspective, the essence of data security governance is to manage the actions that various personnel (identities) take on organizational assets, such as IaaS, PaaS, SaaS, and various types of data. If a person takes an inappropriate action on an organizational asset, it can compromise the Confidentiality, Integrity, or Availability of the information on that asset. This results in a data security incident.

image.png

For example, a data analyst at an e-commerce company summarizes monthly sales from an order fact table and configures a dashboard. This is expected behavior. However, if the analyst views detailed user order data without a specific business reason, that action is inappropriate. This type of behavior must be governed.

Goals of data security governance

Before 2016, China's data protection legislation was relatively fragmented, consisting primarily of recommended national or industry standards. Since the enactment of the Cybersecurity Law in 2017, various laws, regulations, and mandatory national standards have been issued with greater frequency and specificity. These legal documents are generally clear, outlining specific rules and severe penalties. Companies that fail to comply with these laws and fulfill their data security obligations risk legal action and penalties.

image.png

Today, when companies conduct business that involves data processing, they must ensure their operations are lawful and compliant whenever they collect, process, or use data. This involves the following aspects.

  • Paying close attention to and complying with relevant laws and regulations. This includes constantly monitoring for any non-compliant behavior. Examples of relevant legislation include the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law, the Civil Code, and the national mandatory standard Multi-Level Protection Scheme (MLPS) 2.0.

  • Referring to relevant action guides, such as the Data Security Governance Practice Guide or the Data Security Maturity Model (DSMM), and industry-specific standards. Companies can also purchase security products or services from vendors to start a data security governance project.

image.png

In the past, companies bought and used security products simply to prevent and manage risks. They wanted to ensure business continuity and prevent assets from being misused, leaked, or controlled. In this era, data is the lifeblood of a business.

Today, however, companies conduct data security governance activities to achieve compliance. The purpose of compliance is not just to satisfy regulators. It is to ensure that every citizen whose data is collected can exercise their legal rights and have their privacy protected. This allows individuals to enjoy the convenience, benefits, and well-being that data provides. This is a key demonstration of corporate social responsibility.

image.png

Appendix: Relevant data security laws and regulations

  • Data Security Law

    • Article 21 states that data must be protected through classification and grading. This requirement also appears in other national or industry-recommended standards.image.png

    • The data security review mentioned in Article 24 corresponds to operation audit in data security governance. The remedial measures and disposal procedures for data security defects, vulnerabilities, and security incidents mentioned in Article 29 correspond to risk response in data security governance. This mainly includes alerting, blocking, and approval.

      These requirements also appear in other legally binding documents, but different industries have specific scenario-based requirements.image.png

  • Technical Specification for Personal Financial Information Protection JR/T 0171-2020image.png

  • Technical Specification for Personal Financial Information Protection JR/T 0171-2020image.png