Frequent Data Breaches: How to Safeguard Information System Security
In recent years, with the evolution of new technologies such as cloud services, many users have started building and upgrading their IT systems with these technologies. However, due to a lack of security awareness and compliance in some cases, data breaches have become common. Against this backdrop, GBASE information security experts emphasize: For information systems with high security requirements—such as classified information systems, systems rated Level 3 and above under China’s information system security classified protection requirements, core information systems of pillar industries of the national economy, and other domains demanding strong data management security—the databases in use should adopt enhanced security measures across three dimensions: data encryption, compliance with national information security standards, and institutional security policies:
1. Data Encryption
Data encryption is one of the most reliable methods to protect user data. By employing techniques such as data encryption, storage encryption, data integrity verification, and key management, databases can effectively safeguard information against breaches in the event of data scraping, and prevent data from being compromised during storage and transmission.
A secure database product should also support hardware-based commercial cryptographic algorithms and comply with national security algorithms. Strictly adhering to the Cryptographic Device Application Interface Specification, using hardware cryptographic cards certified with a national cryptography model certificate can effectively secure user keys and guarantee the confidentiality of stored data.
2. Compliance with National Information Security Standards
Every component of an information system (e.g., operating systems, databases, middleware) must use products that meet national security standards. No compromises should be made simply because a particular product (such as a cloud service or cloud database) lacks the necessary security certification. During on-site implementation, physical isolation between regular and sensitive data must be ensured, especially when adopting inherently less secure models like public cloud services.
High-security business systems should adopt secure database products that offer high security, high performance, and high availability. Such database products typically should hold the China National Information Security Product Certification, pass the Security Database Product Cryptographic Testing Criteria, possess a Commercial Cryptography Product Model Certificate issued by China's State Cryptography Administration, satisfy the national confidentiality standard Technical Requirements for Security Database Products in Systems Handling State Secrets and the Classified Information System Product Testing Certificate, and meet the Level 4 technical requirements specified in the national standard (GB/T 20273-2019 Information security technology — Technical requirements for security of database management systems).
A database product that meets national information security standards should provide users with security features and mechanisms such as data transmission encryption, storage encryption, identity authentication, discretionary access control, security labeling, mandatory access control, security auditing, data integrity protection, separation of duties, and inference control. These capabilities significantly enhance data security and safeguard sensitive data within information systems.
Therefore, when selecting databases for information system development, it is crucial to choose products that strictly conform to national security standards to prevent such data breach incidents from recurring.
3. Security Policies
Finally, the operation of information systems with high security requirements must be underpinned by robust security management policies. Establishing a set of compliant monitoring and usage procedures, regulating personnel information security management, enhancing security awareness, and ensuring that each role undertakes and fulfills its corresponding information security responsibilities form the prerequisite for any secure information system.
GBase 8s — A Shared-Storage Database Cluster
GBase 8s is a shared-storage database cluster independently developed by GBASE, offering high security, high performance, and high availability. It is the first secure database to obtain the China National Information Security Product Certification, the first to pass the Security Database Product Cryptographic Testing Criteria and receive the Commercial Cryptography Product Model Certificate from China's State Cryptography Administration, the first to meet the national confidentiality standard Technical Requirements for Security Database Products in Systems Handling State Secrets and obtain the Classified Information System Product Testing Certificate, and it conforms to the Level 4 technical requirements of the national standard (GB/T 20273-2019 Information security technology — Technical requirements for security of database management systems).
GBase 8s is primarily suited for classified information systems, systems rated Level 3 and above under China’s information system security classified protection requirements, core information systems of pillar industries of the national economy, and other areas with demanding data management security needs.
GBase 8s has been widely deployed in core business systems across industries such as finance, energy, government, transportation, and manufacturing. Going forward, it will continue to energize the industry by providing secure protection for sensitive data in all types of information systems, while delivering more efficient access and more stable, reliable operations.