农业大数据学报 ›› 2024, Vol. 6 ›› Issue (2): 278-285.doi: 10.19788/j.issn.2096-6369.000035

• “面向高质量共享的科学数据安全”专刊(上) • 上一篇    下一篇

科学数据中心安全工作实践—以国家冰川冻土沙漠科学数据中心为例

张耀南1,2,*(), 张名成1,2, 康建芳1,2   

  1. 1.国家冰川冻土沙漠科学数据中心,兰州 730000
    2.中国科学院西北生态环境资源研究院,兰州 730000
  • 收稿日期:2024-02-25 接受日期:2024-04-26 出版日期:2024-06-26 发布日期:2024-07-03
  • 通讯作者: *
  • 作者简介:张耀南,E-mail:yaonan@lzb.ac.cn
  • 基金资助:
    国家重点研发计划“冰冻圈大数据挖掘分析关键技术及应用”(2022YFF0711700);中国科学院信息化项目“中国科学院冰川冻土沙漠科学数据中心能力建设”(WX 145XQ07-10)

Practice of Security Work in Scientific Data Centers-Taking the National Cryosphere Desert Data Center as an Example

ZHANG YaoNan1,2,*(), ZHANG MingCheng1,2, KANG JianFang1,2   

  1. 1. National Cryosphere Desert Data Center, Lanzhou 730000, Gansu, China
    2. Northwest Institute of Eco-Environment and Resources, CAS, Lanzhou 730000, Gansu, China
  • Received:2024-02-25 Accepted:2024-04-26 Published:2024-06-26 Online:2024-07-03

摘要:

科学数据中心是科学数据的载体,是科学数据资源安全支撑的基础和保障环境,承担着促进科学数据开放共享的使命,科学数据的安全主要依赖于科学数据中心的安全管理。本研究针对国家冰川冻土沙漠科学数据中心的安全工作实践,分析了数据中心安全问题的来源,提出包含工作层级、安全过程、安全对象三个维度的数据中心安全能力建设模型,提出了以数据为中心,兼顾发展和安全,预防为主、全程管控的安全工作思路;分析了数据中心重点关注的物理安全、网络安全、系统安全、应用安全、数据安全的主要防范内容,并针对这些安全对象,设计了相应的安全管理措施,开展了安全能力建设;并从制度流程建设、人员安全能力培训、数据安全审计、数据分级分类、容灾备份和应急处置、安全工作中的防呆设计、技术工具利用七个方面对数据中心十年以来的安全实践经验进行了总结。

关键词: 国家冰川冻土沙漠科学数据中心, 数据中心安全, 数据安全, 安全能力建设, 安全经验总结

Abstract:

The scientific data center is the carrier of scientific data, the foundation and guarantee environment for the security of scientific data resources, and undertakes the mission of promoting the open sharing of scientific data. The security of scientific data mainly depends on the security management of the scientific data center. This paper focuses on the data security work practice of the National Cryosphere Desert Data Center(referred to as NCDC), analyzes the sources of security issues in NCDC, proposes a data center security capacity building model that includes three dimensions: work hierarchy, security process, and security object. proposes a security management approach that focuses on prevention and full process control, and analyzes the main prevention contents of physical security, network security, system security, application security, and data security in NCDC, and corresponding security management measures were designed for these main security objects, security capacity building was carried out, and data security management work was achieved on the basis of overall development of NCDC. The experience of data center security practice in the past 10 years was summarized, and these experiences have certain reference significance for the security management of other scientific data centers.

Key words: National Cryosphere Desert Data Center, data center security, data security, security capacity building, summary of safety management experience