开放教育数据安全能力体系构建——以国家开放大学为例
Building a Data Security Capability Framework for Open Education—A Case Study of The Open University of China
DOI: 10.12677/jsst.2026.143011, PDF,    科研立项经费支持
作者: 马伟娜, 宋 星, 吴淑苹:国家开放大学数字化部,北京;魏顺平:中央民族大学教育学院,北京
关键词: 开放教育数据安全数字教育隐私数据Open Education Data Security Digital Education Private Data
摘要: 自《数据安全法》颁布实施以来,数据安全问题日益受到关注。开放教育场景下,校务数据治理、数据共享与开放应用伴随大量师生个人隐私等敏感信息,其安全保障直接关系高校办学稳定与长远发展。当前,制度漏洞、技术短板、环境风险等多重因素交织叠加,高校数据安全面临的威胁持续加剧。大模型、云计算及智能终端的广泛应用推动数据深度集成与高频交互,大数据的存储、共享与应用暴露出数据泄露与隐私外溢等问题,给师生个人权益、高校办学安全乃至国家信息安全带来潜在风险。本文结合开放教育数据特征与学校数据安全现实困境,基于数据生命周期理论,围绕在线教育数据的采集、传输、存储、共享、销毁等全流程,从制度、技术、环境等多维度对高校数据安全风险进行溯源,构建覆盖数据全生命周期、融合制度规范与技术防护的开放教育数据安全预警监测与防护体系,为开放教育数据安全治理提供实践参考。
Abstract: Since the promulgation and implementation of the Data Security Law, data security has drawn increasing attention. In open education settings, the governance of institutional data and the sharing and open application of data involve a large volume of sensitive information, such as the personal privacy of teachers and students; safeguarding such data bears directly on the operational stability and long-term development of higher education institutions. At present, multiple factors—institutional loopholes, technological shortcomings, and environmental risks—are interwoven and superimposed, and the threats confronting data security in higher education continue to intensify. The widespread application of large models, cloud computing, and intelligent terminals has driven the deep integration and high-frequency interaction of data, while the storage, sharing, and application of big data have exposed problems such as data breaches and privacy leakage, posing potential risks to the individual rights and interests of teachers and students, the operational security of institutions, and even national information security. Drawing on the characteristics of open education data and the real-world dilemmas of data security in universities, and grounded in data lifecycle theory, this paper traces the sources of data security risks in higher education from the multiple dimensions of institution, technology, and environment across the full process of online education data—collection, transmission, storage, sharing, and destruction. It constructs an early-warning, monitoring, and protection system for open education data security that spans the full data lifecycle and integrates institutional and technical safeguards, thereby providing a practical reference for the governance of open education data security.
文章引用:马伟娜, 宋星, 吴淑苹, 魏顺平. 开放教育数据安全能力体系构建——以国家开放大学为例[J]. 安防技术, 2026, 14(3): 105-114. https://doi.org/10.12677/jsst.2026.143011

参考文献

[1] 教育部关于加强新时代教育管理信息化工作的通知[EB/OL].
http://www.moe.gov.cn/srcsite/A16/s3342/202103/t20210322_521669.html, 2021-03-10.
[2] 教育部等七部门关于加强教育系统数据安全工作的通知[EB/OL].
https://xxzx.hebcm.edu.cn/col/1559021415599/2023/05/16/1684228560091.html, 2023-05-16.
[3] 教育部等九部门关于加快推进教育数字化的意见[EB/OL].
https://www.gov.cn/zhengce/zhengceku/202504/content_7019045.htm, 2025-04-11.
[4] 魏顺平, 袁亚兴, 吴淑苹, 等. 基于云服务的教育信息化精准扶贫模式研究——以国家开放大学扶贫实践为例[J]. 中国电化教育, 2020(9): 74-81.
[5] European Parliament and Council of the European Union (2026) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data, and Repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA Relevance).
https://eur-lex.europa.eu/eli/reg/2016/679/oj
[6] 中关村网络安全与信息化产业联盟数据安全治理专业委员会. 数据安全治理白皮书5.0 [R]. 北京: 中关村网络安全与信息化产业联盟, 2023.
[7] International Organization for Standardization (2022) Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements: ISO/IEC 27001:2022. International Organization for Standardization.
[8] 全国信息安全标准化技术委员会. GB/T 37988-2019信息安全技术 数据安全能力成熟度模型[S]. 北京: 中国标准出版社, 2019.
[9] 吴信东, 董丙冰, 堵新政, 等. 数据治理技术[J]. 软件学报, 2019, 30(9): 2830-2856.