4.2.1 Security Management of Storage Media
Data storage media, including physical objects like magnetic or hard disks, and virtual ones like containers or virtual
disks, can also be used for temporary data transmission. To ensure data security and prevent leaks, ProBio sets clear
security standards for the usage of storage media, such as:
Classifying the storage media.
Grading storage media and defining specific requirements for each grade regarding data storage.
Defining media usage standards and establishing media application and user registration policies.
Establishing criteria, such as authority and access, for data cleaning and purging.
Specifying labeling requirements for storage media, such as expiration dates.
Regularly reviewing media usage and conducting inspections to prevent data loss.
4.2.2 Logical Storage Security Management
ProBio's security standards for storage containers and architecture encompass various aspects including authentication,
access control, log management, communication protocols, and malware. We have outlined logical storage
guidelines, which include:
Defining logical storage systems and devices, such as cloud storage objects, block storage, and distributed
storage.
Establishing rules for logical security configurations, covering authentication, access control, and requirements for
configuration changes and releases.
Implementing measures for logical multi-tenant isolation and authorization management.
Enforcing security management rules and operating procedures for storage equipment, including standards,
maintenance, and emergency protocols.
Specifying requirements for storage system accounts and rights, log management, encryption management,
version upgrades, and other relevant aspects.
4.2.3 Data Storage Encryption Management
To ensure the confidentiality and integrity of data in storage, ProBio uses encryption technologies to encrypt and store
data, preventing security risks such as interception, forgery, and tampering of authorized data, and ensuring the security
of data in storage. Targeted encryption protection is carried out based on different categories and levels of data,
especially for sensitive business data such as personal information and important data. ProBio can guarantee the security
of sensitive data, regardless of whether data is leaked internally or externally, intentionally or unintentionally.
According to the requirements of national laws and regulations, requirements of service data for confidentiality and
integrity, and data classification and grading, data is encrypted and stored in the scenarios demanding encryption and
storage, and data storage scenarios involving sensitive service data or with high requirements for confidentiality and
integrity. This includes:
System data classified as confidential or above should be stored using encryption;
Passwords should be stored after being encrypted using an approved one-way encryption algorithm;
Important data should generally not be stored in the DMZ zone. If it is necessary to store important data in
the DMZ zone, the data must be encrypted using an approved encryption method before storage.
ProBioCDMO.com
6