文章基于DSSCMM提出数据主权安全能力成熟度的评估方法和过程,评估后针对我国数据主权安全能力成熟度薄弱环节提出改进建议。构建并运用边际取样法确定有效样本,运用专家调查法确定关键过程域的能力维度权重,构建并运用样本赋分法计算能力维度分,进而确定关键过程域分和数据主权安全能力分。数据本地存储、数据跨境流动、数据域外管辖的能力成熟度都达到充分级,但数据域外管辖的能力成熟度实际上靠近必要级,我国数据主权安全能力成熟度达到充分级。进一步提升我国数据主权安全能力成熟度,宜从数据域外管辖的“文化教育”和数据本地存储、数据跨境流动的“技术工具”展开,尤其要重视在域外司法活动之中及时运用《数据安全法》的长臂管辖,以及引导和推广在国内网络生态系统中应用自主技术产品。
Based on DSSCMM, this paper puts forward the method and process of evaluating the maturity of data sovereignty security capability , and puts forward some suggestions to improve the weakness of our country's data sovereignty security capability.Construct and use marginal sampling method to determine effective samples, apply expert investigation method to determine the weight of capability dimension, and use sample scoring method to calculate the scores of capability dimensions, then determine the key process area score and data sovereignty security capability score.The capacity maturity of data localization, cross-border data flow and data extraterritorial jurisdiction has reached a higher level, but the capacity maturity of data extraterritorial jurisdiction actually tends to be necessary level, and the data sovereignty security capacity maturity of our country has reached a sufficient level.In order to improve the maturity of our country's data sovereignty security capability, it is suggested that we should start from "culture and education" and "technical tools" of data local storage and data cross-border flow.Particular attention shall be paid to the timely application of the long-arm jurisdiction of the Data Security Law in extraterritorial judicial activities, and guide and promote the application of independent technology products in the domestic network ecosystem.