网络安全与数据治理2024,Vol.43Issue(9) :49-54.DOI:10.19358/j.issn.2097-1788.2024.09.008

个人信息保护合规审计的辅助实现技术框架研究

Research on the framework of assisting technology for implementation of personal information protection compliance audit

刁毅刚 张玲翠 刘晓蒙
网络安全与数据治理2024,Vol.43Issue(9) :49-54.DOI:10.19358/j.issn.2097-1788.2024.09.008

个人信息保护合规审计的辅助实现技术框架研究

Research on the framework of assisting technology for implementation of personal information protection compliance audit

刁毅刚 1张玲翠 2刘晓蒙3
扫码查看

作者信息

  • 1. 中央网信办(国家网信办)数据与技术保障中心,北京 100048
  • 2. 中国科学院信息工程研究所,北京 100085
  • 3. 中电科网络安全科技股份有限公司,四川 成都 610095
  • 折叠

摘要

数字经济时代背景下,合格评定工作呈现出数字转型趋势,这将对开展个人信息保护合规审计活动产生重要影响.概述了个人信息保护合规检查技术工具概况和相关关键技术,在此基础上,提出了个人信息保护合规审计可以依托技术辅助实现的审计项,指明了个人信息合规审计工作技术辅助实现的路径.依托以上研究成果,提出《个人信息保护合规审计技术能力及工具要求(征求意见稿)》标准,明确了个人信息保护合规审计辅助实现技术框架,介绍了依据标准研发的个人信息保护合规审计技术工具原型,及其对于个人信息保护合规审计辅助技术框架的示范验证作用.

Abstract

In the context of digital economy,the process of digital transformation trend is appearing among conformity assessment activities,which would exert important influence on the personal information protection compliance audit activities afterwards.This article introduces the situation and development of checking software for personal information protection and the relevant tech-nologies.According to basis of pre-research,this article enlists audit items that could be implemented and supported with the help of technical methods,specifying the path to accomplish personal information protection compliance audit activity with the aid of technical assistance.Basing on the research production done beforehand,the research team proposes the standard of"Specifi-cation for the technical ability of auditing for personal information protection compliance and Software",which demonstrates the framework of assisting technology for implementation of personal information protection compliance audit.This article also intro-duces the prototype of software assisting for personal information protection compliance audit and its function as the demonstration and verification for the framework.

关键词

个人信息保护/合规审计/合格评定/数字化

Key words

protection of personal information/compliance audit/conformity assessment/digitization

引用本文复制引用

基金项目

国家重点研发计划基金项目(2023YFB3106505)

出版年

2024
网络安全与数据治理
华北计算机系统工程研究所(中国电子信息产业集团有限公司第六研究所)

网络安全与数据治理

影响因子:0.348
ISSN:2097-1788
参考文献量3
段落导航相关论文