摘要
以提升数据安全能力为目标,采取分阶段、有序建设思路,逐步在存款、贷款、中间业务、信用卡、投资理财、支付结算、运营管理、网点渠道、互联网渠道等业务领域推广实践GB/T 37988-2019《信息安全技术 数据安全能力成熟度模型》.通过推进数据安全治理体系、制度流程、技术工具与人员能力建设,规范了客户交易等重要业务场景的数据安全管理,有效控制、化解数据安全风险,提升了数据安全保障能力.
Abstract
With the goal of improving data security capability,the stadard of GB/T 37988-2019"Information security technology-Data security capability maturity model"is popularized and applicated in the feilds of deposit,loan,intermediate business,credit card,investment and financing,payment and settlement,operation and management,branch channels,internet channels,ect,in a phased and orderly way.By promoting the data security governance system,regulations,technical tools and personnel capacity,it stadardizes the data security management in important business scenarios such as customer transactions,effectively controlls and resolves data security risks,improves data security assurance capabilities.