随着中国《网络安全法》《网络产品和服务安全审查办法(试行)》《数据安全管理办法(征求意见稿)》等法律法规的陆续实施,对大数据运营商提出了诸多合规要求。如何应对大数据时代日益显著的数据安全风险,确保其符合网络安全法律法规政策,需要对网络运营者数据业务及安全管控措施进行规范化。在明确了大数据安全内涵、指出了大数据产业面临的安全挑战后,对照工业界大数据平台和大数据应用安全解决方案阐述了大数据安全目标及其大数据平台与应用关键技术与机制。
Since the launching of the series laws and regulations on network security, the audition of network products and services, data security, there are growing needs for big data service providers for compliance implementation. In order to respond to the data security risks sufficiently and ensure the compliance to network security laws and regulations on big data related business operations, this paper summarizes the key definitions of big data security, the major risks in big data security, and describes the big data security objectives, key security protection technology and mechanisms for big data platforms, as a reference to practitioners in the big data industry.
[1] 全国信息安全标准化委员会, 大数据安全标准特别工作组. 大数据安全标准化白皮书(2018版)[R]. 北京:全国信息安全标准化委员会, 2018.
[2] NIST big data interoperability framework, Volume 4:Security & privacy[R/OL].[2019-11-15]. https://bigdatawg.nist.gov/V3_output_draft_docs.php.
[3] 杜小勇, 陈跃国, 范举, 等. 数据整理——大数据治理的关键技术[J]. 大数据, 2019, 5(3):16-25.
[4] 刘贤刚, 孙彦, 胡影, 等. 数据安全国际标准研究[J]. 信息安全与通信保密, 2018(12):33-49.
[5] Curriculum guidelines for post-secondary degree programs in cybersecurity[EB/OL].[2019-11-15] https://www.acm.org/.../education/curricula-recommendations/csec2017.pdf.
[6] Smith K T. Big data security:The evolution of Hadoop's security model[R/OL].[2019-11-15]. https://www.infoq.com/articles/HadoopSecurityModel.
[7] Thangaraj M, Balamurugan S. Survey on big data security framework[C]//International Conference on Knowledge Management in Organizations. Berlin:Springer, 2017:470-481.
[8] Moreno J, Serrano M A, Fernandez-Medina E, et al. Towards a security reference architecture for big data[C/OL].[2019-11-15]. https://www.researchgate.net/publication/325218224_Towards_a_Security_Reference_Architecture_for_Big_Data.[2019-11-15]. https://www.researchgate.net/publication/325218224_Towards_a_Security_Reference_Architecture_for_Big_Data.