摘要
[目的/意义]从生命周期视角归纳科学数据安全分级管理实践,为我国科学数据的分级管理和安全治理提供参考。[方法/过程]将科学数据的生命周期分为数据获取、数据存储与传输、数据处理与分析、数据发布与共享、数据销毁5个阶段,调研国外科学数据管理平台与高校在各阶段针对不同风险等级数据的安全管理措施,并从制度层、管理层、执行层和技术设施层构建分级管理框架。[结果/结论]科学数据的分级大多基于数据的敏感性和风险性,并据此设定数据的访问规则和操作规范等管理措施;在数据生命周期的各阶段,通常从物理、技术和管理3方面保障各等级数据的安全。
[Purpose/significance] The paper summarizes the practice of the security hierarchical management for scientific data from a lifecycle perspective, so as to provide reference for the hierarchical management and security governance of scientific data in China.[Method/process] The paper divides the life cycle of scientific data into five stages: data acquisition, data storage and transmission, data processing and analysis, data release and sharing, and data destruction.The paper investigates the security management measures adopted by foreign scientific data management platforms and universities for data of different risk levels in each of these stages.Then, a hierarchical management framework is constructed based on the system layer, management layer, implementation layer, and technology and facilities layer.[Result/conclusion] The grading of scientific data is mostly based on its sensitivity and riskiness, then management measures such as data access rules and operation specifications are set accordingly.At each stage of the data lifecycle, the relevant subjects usually guarantee the security of each level of data from physical, technical and managerial means.
出处
《情报理论与实践》
北大核心
2023年第3期68-74,共7页
Information Studies:Theory & Application
关键词
科学数据
分级管理
数据安全管理
生命周期
scientific data
hierarchical management
data security management
life cycle