Information and Communications Technology and Policy

Information and Communications Technology and Policy

Information and Communications Technology and Policy ›› 2026, Vol. 52 ›› Issue (8): 23-29.doi: 10.12267/j.issn.2096-5931.2026.08.004

Previous Articles     Next Articles

Common problems and improvement approaches in data security management capability assessment practice

CAO Haixiao, WANG Yan   

  1. CTTL Terminal Labs, China Academy of Information and Communications Technology, Beijing 100191, China
  • Received:2026-07-02 Online:2026-08-25 Published:2026-09-02
  • Contact: WANG Yan

Abstract:

Data security management capability assessment is an important means of promoting regularized and systematic enterprise data security compliance. This paper reviews the development of China’s data security legislation, evaluation systems, and relevant standards. Drawing on frontline assessment practice, it examines the current state of enterprise data security management capabilities across four dimensions: organizational structure, institutional framework, technical capabilities, and operational mechanisms. Five common problems are identified: formalistic assignment of responsibilities, gaps between policies and actual operations, ineffective data classification and grading, weak internal audit and management review, and inadequate partner management. Accordingly, five improvement approaches are proposed: strengthening organizational safeguards, aligning policies with operations, improving the practical application of data classification and grading, establishing a closed loop for internal audit and continual improvement, and strengthening full-lifecycle security management of partners.

Key words: data security, management capability assessment, compliance practice, assessment-driven improvement

CLC Number: