高校数据安全治理框架研究
网络安全与数据治理
牛永亮1,朱江琳2
1.山西财经大学网络与信息教育技术中心; 2.山西财经大学文化旅游与新闻艺术学院
摘要: 高校数据安全治理对保障数据安全、促进数据有序流通与价值释放,进而支撑教育数智化转型具有重要意义。通过分析高校数据安全现状,对比数据安全治理与网络安全、数据治理的差异,结合教育行业特点及相关法规政策要求,提出以合法合规、统筹协调、共享共治和规范集约为基本原则,构建涵盖管理、技术与运维三个维度的数据安全治理框架;进一步从组织、制度、人才等管理体系建设,以及数据分类分级、全生命周期安全及典型应用场景等技术体系保障两个方面,提出具体可行的实施方案。最后,建议树立“数据与人并重”的安全发展理念,持续建设合规管理环境,逐步完善技术保障体系。
中图分类号:TP309.2;G647文献标志码:ADOI:10.19358/j.issn.2097-1788.2026.06.009中文引用格式:牛永亮,朱江琳.高校数据安全治理框架研究[J].网络安全与数据治理,2026,45(6):66-74.
英文引用格式:Niu Yongliang,Zhu Jianglin.Research on university data security governance framework[J].Cyber Security and Data Governance,2026,45(6):66-74.Research on university data security governance framework
Research on university data security governance framework
Niu Yongliang1,Zhu Jianglin2
1. Center of Network and Information Education Technology,Shanxi University of Finance and Economics; 2. School of Culture Tourism and Journalism Arts,Shanxi University of Finance and Economics
Abstract: The governance of data security in higher education institutions is of great significance for ensuring data security,promoting orderly data circulation,and supporting the transformation of education digital intelligence.On the basis of analyzing the current situation of data security,comparing data security governance with network security,data governance,and combining the characteristics of the education industry and the requirements of relevant laws and policies,this paper proposes to build a data security governance framework covering three dimensions of management,technology and operation and maintenance based on the basic principles of legality and compliance,overall coordination,sharing and common governance,and standardization and intensification.Further,it is suggested to establish a management system from aspects such as organization,system,and talent,and build a technical guarantee system from aspects such as data classification and grading,full life cycle security,and typical application scenarios,to form a specific and feasible implementation plan.Finally,it is recommended to establish a security development concept that attaches equal importance to data and people,continuously build a compliant management environment,and gradually improve the technical guarantee system.
Key words : university data security; governance framework; goals and principles; classification and grading

引言

数据作为一种新型生产要素,正成为推动全域数字化转型和国家治理现代化的关键驱动力。然而,随着勒索病毒升级演进、数据泄露事件频发,数据安全问题已演变为关系国家、社会以及个人隐私安全的核心问题。当前,高校面临着数据安全意识薄弱,全生命周期安全管控缺失,数据分类分级标准模糊,数据共享与安全权责不明等严峻挑战。2023年,江西某高校由于数据安全管理制度和技术保障措施不够完善,导致存储3 000余万条信息的数据库被入侵,其中3万余条师生敏感数据在境外互联网被非法兜售[1]。2025年8月,河南某高校网站公示的新闻、通知及附件中存在未脱敏处理的身份证号等敏感信息,被公安部门及教育主管部门通报[2]。因此,开展高校数据安全治理研究,不仅能够完善教育行业数据安全治理理论体系,有效平衡数据安全与利用的双重需求,而且可以为教育行业数字化向数智化的高阶转型提供内生动力,对实现“安全可控、开放共享”的智慧教育生态具有重要实践意义。

近年来,我国数据安全治理体系建设已进入深化发展阶段。2021年,《中华人民共和国数据安全法》(以下简称《数据安全法》)《中华人民共和国个人信息保护法》(以下简称《个人信息保护法》)的相继实施,奠定了数据安全治理的法治基石。2024年,《网络数据安全管理条例》《GB/T 43697—2024 数据安全技术 数据分类分级规则》等政策、标准的出台,进一步细化了技术规范与操作指南,为构建科学化、精准化的数据安全治理体系提供了关键制度支撑。2025年,教育部等九部门联合印发《关于加快推进教育数字化的意见》再次强调全面落实教育数据全生命周期安全防护,强化核心和重要数据防篡改、防泄露、防滥用能力。这一系列政策演进既彰显了数据要素市场化配置与安全治理的制度创新,也反映了教育行业在数字化转型过程中对数据治理安全合规的迫切需求。


本文详细内容请下载:

http://www.chinaaet.com/resource/share/2000007128


作者信息:

牛永亮1,朱江琳2

(1.山西财经大学网络与信息教育技术中心,山西太原030006; 

2.山西财经大学文化旅游与新闻艺术学院,山西太原030006)

通知公告
编辑观点
理事会
参考资料
版权声明

凡《网络安全与数据治理》(原《信息技术与网络安全》)录用的文章,如作者没有关于汇编权、翻译权、印刷权及电子版的复制权、信息网络传播权与发行权等版权的特殊声明,即视作该文章署名作者同意将该文章的汇编权、翻译权、印刷权及电子版的复制权、信息网络传播权与发行权授予本刊,本刊有权授权本刊合作数据库、合作媒体等合作伙伴使用。同时,本刊支付的稿酬已包含上述使用的费用,特此声明。

《网络安全与数据治理》(原《信息技术与网络安全》)编辑部