Home >

Data Security: CEO'S First Responsibility

2021/7/23 14:26:00 0

DataSecurityCEOResponsibility

With the rapid development of digital economy, the volume of data is becoming larger and larger, at the same time, its importance is also increasingly prominent. In April 2020, data has been recognized as the "Fifth Element" after land, labor, capital and technology.

However, how to better manage and use data, the industry has been lack of clear guidance, and the "data security law of the people's Republic of China" (hereinafter referred to as "data security law") which will be implemented on September 1 this year, points out the direction for the development of the entire data industry.

On July 21, fan yuan, chairman of Anheng information, said in an interview with the 21st century economic report that after several years of discussion, the introduction of the data security law is at the right time“ As a new means of production and production factors, data has emerged in the entire digital reform and innovation of digital economy. At this time, how to make data more standardized and systematic has become very important. "

The introduction of data security law is the first time in China to put forward clear requirements for data security protection, risk early warning, data application and management.

Fan Yuan said that in the long run, the law will enhance the governance ability of the government, but also enhance the core competitiveness and brand power of enterprises, because if an enterprise can not really understand and protect data assets, it is impossible to establish a real brand in the market.

Data security law standardizes Industrial Development

In fact, before the data security law, there were many relevant laws, regulations and policy documents in data security in China, but they were in the state of decentralized legislation at that time.

Hu Ying, director of the data security department of the network security research center of China Institute of electronic technology standardization, said that data security is also mentioned in the network security law, but it is more the CIA three elements to protect traditional information security, namely confidentiality, integrity and availability; Other laws, such as the civil code, focus more on the protection of users' personal information.

The applicable object of data security law is to carry out data processing activities and safety supervision in China. Data processing includes data collection, storage, use, processing, transmission, provision and disclosure, which has covered the whole process of data.

In Hu Ying's view, the data security law has the following significance for the development of the data industry: first, it takes into account the security and development of data“ From the overall content, on the one hand, the data security law stands in the perspective of strictly protecting data security, on the other hand, it also encourages the legitimate development and utilization of data. "

Secondly, it defines the regulatory framework of data security in China. Article 5 of the data security law mentions that the central national security leading body is responsible for the decision-making, deliberation and coordination of the national data security work, studying, formulating and guiding the implementation of the national data security strategy and relevant major policies, coordinating major issues and important work of national data security, and establishing a coordination mechanism for national data security.

Hu Ying said that the overall coordination of national data security is the responsibility of the central national security leading organization, and if it is network data security, it is the responsibility of the state network and information department. In the data security law, it is the first time that several industries, such as industry, telecommunications, transportation, finance, natural resources, health, education, science and technology, should assume the responsibility of data security supervision in this industry and field.

Finally, the data security law puts forward the system of data security management in China. In the third chapter of data security law, it is mentioned to establish data classification and classification protection system; Establish data security risk assessment, reporting, information sharing, monitoring and early warning mechanism; Establish data security emergency response mechanism; Establish data security review system.

Hu Ying believes that the application of data security law needs the cooperation of the state, industry and enterprises. Taking the classification and classification of data as an example, from the perspective of the state, it pays more attention to the classification management and hierarchical protection of important data, personal information and public data.

From the perspective of the industry, it is necessary to clarify the industry important data catalog, and establish detailed data classification and classification protection for industry business data based on the national data classification and classification protection framework. From the perspective of enterprises, enterprises need to clarify the scope of important data, personal information and public data, and refer to the data classification and classification rules of the country and the industries involved.

Hu Ying pointed out that only by ensuring the orderly flow of data according to law, fully coordinating from the government to the industry and then to the enterprise level, and doing a good job of data security together, can the value of data be better released.

Data security protection will be a top priority project

As a veteran of the security industry, fan yuan has been witnessing the development of the entire security industry since he founded Anheng information in 2007. He told reporters that from the earliest border firewall to the development of cloud, big data, Internet of things and other technologies, great changes have taken place in the whole network security industry.

"In 2007, we proposed that data is the core asset of enterprises and the government. Around this core asset, there are two main risks: one is external hacker attack, the other is internal leakage, so the solution at that time was mainly to protect these two points," said fan yuan.

However, with the development of digitization, the scene of data emergence becomes more complex, and the original protection model can not cope with it. At this time, a new generation of data security system came into being.

Fan Yuan said that the core feature of the new generation of data security system is to change from single point protection to systematic and full scene protection. From the perspective of the enterprise, it means that the security business will be the top-level project of each enterprise in the future, starting from the top-level design.

For example, the overall data security solution recently released by Anheng information includes the "Cape" data lifecycle protection system, data security consulting service system, ailand data security Island, aitrust zero trust solution, aidsc data security management and control platform, EDR and data blackmail protection and other product services, covering the data security risks.

Fan Yuan said that in the future, when a more standardized governance and protection system is really established around data, the market space for data utilization will also be released. For example, in the past, many big data trading centers did not really work, because of the lack of real laws and regulations guidance, and driven by the data security law, data transactions will become more transparent and credible.

In this process, the application of some new technologies has become very important. For example, privacy computing, intelligent identification, dynamic behavior analysis and so on, based on these new technology systems, data value will be better flow. Fan yuan believes that in many scenarios in the future, data will be more widely used under the premise of being reasonable and legal. In the past, some enterprises were playing the edge ball, but in fact, it has been proved that by playing the edge ball, the sustainable development can not be achieved.

 

  • Related reading

After 95 Luxury Appraiser: I Have Seen One Million Bags, Half Of Which Are Fake

Law lecture hall
|
2021/7/16 9:20:00
1

Attention Of Textile Enterprises: Penalty Threshold For Illegal Discharge Of Pollutants Increased From 100000 To 200000

Law lecture hall
|
2021/6/22 11:40:00
6

Taihe Group'S "65 Sets Of Real Estate Leasing Contract In Beijing" Reveals The Inside Story Of China Construction Investment Trust Stepping On Thunder

Law lecture hall
|
2021/6/12 12:39:00
7

Behind The Murder Case Of Jiangxi Developer Zhang Xinming: Deeply Involved In Private Lending Disputes

Law lecture hall
|
2021/5/27 6:33:00
9

The "War Of Separatism" In The Global Semiconductor Industry Intensifies, And The US, Japan And South Korea Have Invested More Than 500 Billion US Dollars

Law lecture hall
|
2021/5/21 13:21:00
59
Read the next article

"Report On The Development Of Pension Financial Responsibility (2021)" Project Launched, China Southern Fund And 21St Century Capital Research Institute Discuss The Future Of The Third Pillar

Recently, the "third pillar development" jointly sponsored by China Southern Fund, 21st century economic report and 21st Century Capital Research Institute promotes pension finance to usher in new opportunities