情报科学 ›› 2023, Vol. 41 ›› Issue (8): 18-24.

• 专题组稿 • 上一篇    下一篇

基于零信任的公共数据平台安全指数构建研究

  

  • 出版日期:2023-08-01 发布日期:2023-09-18

  • Online:2023-08-01 Published:2023-09-18

摘要: 【 目的/意义】大数据时代,公共数据平台作为数据资源价值创造的重要载体得以迅速发展,但同时也面临 着各种复杂的安全问题。通过构建科学有效的公共数据平台安全指数,为完善其安全评估机制提供评价标准与量 化测评工具。【方法/过程】本文结合零信任理念,提出包括身份安全、数据安全和基础安全在内的三维度公共数据 平台安全指数分析框架,并通过主成分分析法和层次分析法进行指标筛选和权重计算。【结果/结论】结果表明,该 指数具有较高的可信性和有效性,能够有助于国家及各级政府量化了解公共数据平台安全状态,为公共数据平台 安全建设提供策略。【创新/局限】本研究引入零信任理念,并选取安全指数为量化研究对象,旨在创新性地打破默 认的“信任”,以“持续验证,永不信任”为原则,为提升公共数据平台安全提供管理思路与实践路径。

Abstract:

【Purpose/significance】In the era of big data, the public data platform has developed rapidly as an important carrier of data resource value creation, but it also faces various complex security problems. By building a scientific and effective public data platform security index, it provides evaluation criteria and quantitative evaluation tools for improving its security evaluation mechanism.【Method/process】Combining the zero trust theory, this paper proposes a three-dimensional public data platform security index analy⁃ sis framework including identity security, data security and basic security, and uses principal component analysis and analytic hierar⁃ chy process to screen indicators and calculate weights【. Result/conclusion】The results show that the index has high credibility and ef⁃ fectiveness, and it can facilitate the the country and governments at all levels to quantify the the security status of the public data plat⁃ form , and provide strategies for the security construction of the public data platform【. Innovation/limitation】This research introduces the theory of zero trust and selects the security index as the quantitative research object, aiming to innovatively break the default "trust", and provide management ideas and practical paths for improving the security of public data platforms based on the principle of "continuous verification and never trust".