How Easysearch Meets China's Financial Data Security Rules: Clause Mapping

This article maps each clause of China's 2024 financial data security regulation (金规〔2024〕24号) to Easysearch's native capabilities—including SM2/SM3/SM4 encryption, field-level masking, audit logs, high availability, and a millisecond rule engine—demonstrating compliance via three production cases: a bank's 100B-log platform, an insurer's core system replacement, and a bank's 24/7 operations contract.

Mingyi World Elasticsearch
Mingyi World Elasticsearch
Mingyi World Elasticsearch
How Easysearch Meets China's Financial Data Security Rules: Clause Mapping

Regulatory Background: 金规〔2024〕24号

On December 27, 2024, the National Financial Regulatory Administration issued the Banking and Insurance Institutions Data Security Management Measures (金规〔2024〕24号), effective immediately and replacing the 2022 regulation (银保监办发〔2022〕118号). The Measures turn responsibilities, data classification, cryptography, logging, and reporting deadlines into auditable obligations.

1. Policy Direction — Governance, Protection, Monitoring as One Obligation Set

1.1 Responsibility Elevated to Board Level

Article 10 : The Party Committee/Board bears primary responsibility ; the top executive is the first responsible person for data security.

Article 9 : Organizational structure must cover board, senior management, coordination department, and technical protection department — this work enters resource allocation and accountability.

1.2 Protection Measures Built into Systems

Article 5 : Establish a full- lifecycle security governance system; fulfill data security protection duties on top of Cybersecurity Multi-Level Protection (MLPS).

Articles 16–18 : Data classified into three tiers — Core , Important , General — with General further split into Sensitive Data and Other General Data .

Article 28 : Sensitive-and-above data must enforce "business-necessity authorization" with access audit ; simultaneously implement MLPS, Critical Information Infrastructure (CII) protection, and cryptographic protection .

Article 40 : Security measures must be synchronously planned, built, and used with information systems.

1.3 Risks Must Be Visible and Reportable

Article 7 : Improving intelligent financial services and strengthening risk prevention are coupled.

Article 50 : Models/algorithms must be verifiable, auditable, traceable .

Article 65 : Monitoring scope includes excessive authorization, privileged accounts, internal abnormal access, and sensitive data abnormal flow.

Article 69 : Incidents must be reported within 2 hours ; written report within 24 hours.

For foundational software, explicit requirements concentrate on cryptographic protection, MLPS/CII, access control, de-identification, log retention, and high availability/backup/access audit for big data platforms.

2. Four Dimensions Mapped to Easysearch

2.1 Data Security & Network Protection

Art. 44 (secure transmission of sensitive+ data): Easysearch natively supports SM2/SM3/SM4 covering transmission to storage ; built-in query rate limiting and high availability guarantee integrity, confidentiality, availability.

Art. 45 (no plaintext for identity data; anti-ransomware, disaster recovery, recoverability verification): Easysearch provides built-in authentication, authorization, audit logs , and field-level masking ; different roles see different classification levels; HA + audit traces support anti-ransomware, DR, and recoverability verification.

Art. 43 (operation logs: time, user ID, behavior type; retention: core ≥3 years, important/sensitive ≥1 year, entrusted ≥3 years; audit cycle ≤6 months): Easysearch built-in audit logs record operation time, user ID, behavior type; retention configurable by data tier; engine handles recording and retrieval to support ≤6-month audit cycles.

Art. 48 (unsensitized data principally barred from test environments): Easysearch field-level masking without secondary development ; different roles see different classification levels — customer service, developers, auditors no longer see full fields by default, aligning with the requirement.

MLPS 2.0 Level 3+ : Easysearch targets Level 3 and above; native SM2/SM3/SM4, authentication, authorization, audit logs, query rate limiting, high availability, field-level masking covering transmission to storage.

2.2 Data Governance & Classification

Art. 16 (data catalog + classification standards + differentiated protection): Easysearch indexes all data; permissions extend from cluster → index → field with native masking; classification moves beyond catalog into field-level authorization and native masking for differentiated protection, forming a classifiable, authorizable, auditable enterprise service.

Art. 17 (coverage of customer, business, operations, system, security data): A large bank replaced its stack and built a bank-wide unified log platform ingesting 100+ billion logs/day ; customer, business, operations management , system, and security data unified into Easysearch for real-time log audit and transaction behavior analysis.

Art. 21 (enterprise data architecture & asset map): Easysearch consolidates scattered logs into a unified platform covering all systems, forming a classifiable, authorizable, auditable enterprise service; cluster/index/field permissions + native masking underpin the data architecture and asset map.

Art. 47 (identity management, anonymization, behavior monitoring, log audit componentized for consistent enforcement): Easysearch's unified log platform carries capabilities for identity management , anonymization, behavior monitoring, log audit ; permissions to field level, native masking, real-time log audit and transaction analysis ensure consistent security standards across systems.

2.3 Risk Monitoring & Business Risk Control

Chapter 7 Data Security Risk : Easysearch rule engine targets high-concurrency, low-latency queries; rule compilation to millisecond level; supports multiple simultaneous rule hits — used for automated monitoring and query in data security risk scenarios.

Art. 7 (risk prevention enhancement): Rule engine scenarios cover banking transactions, anti-money laundering, account security, credit, and insurance claims — same query capability powers risk prevention.

Art. 50 (automated decision traceability): Easysearch provides rule-hit verification for traceability; fairness of rules and model explainability remain the institution's model governance responsibility.

Art. 65 (abnormal access monitoring): Easysearch performs business rule hit verification with millisecond compilation and multi-rule simultaneous hits.

2.4 Core System Controllability & Smooth Migration

Art. 31 (no outsourcing of IT management responsibility, data security primary responsibility, core competitiveness functions): Easysearch is developed by INFINI Labs based on Apache Lucene with self-contained core code ; cryptographic algorithms self-implemented; permissions and audit do not depend on external commercial modules ; core queries run on this engine with national crypto, field permissions, and audit all enabled — supporting the non-outsourcing of core competitiveness functions.

Art. 49 (big data platform HA design, hardening, backup; dynamic access authorization, monitoring, audit): Easysearch fits massive storage/compute/analysis platforms; supports HA design, hardening, access audit; national crypto, field permissions, audit can be enabled simultaneously ; access authorization mechanism built into the engine ; backup paired with deployment plan.

3. Three Production Financial Scenarios

3.1 Unified Logs — Aligned with Traceability & Reporting Deadlines

A major bank built a bank-wide unified log platform: 100+ billion logs/day , second-level alerting and second-level traceback for suspicious operations. This maps to Art. 43 (operation logs), Art. 49 (access monitoring), and Art. 69 (2-hour reporting). At 100B scale, response shifts from "find which system holds the logs" to "directly view alerts and operation context."

Unified log platform dashboard showing second-level alert and traceback
Unified log platform dashboard showing second-level alert and traceback

3.2 Core Business Replacement — Aligned with Least Privilege

Guoren Insurance deployed Easysearch for intelligent customer service, underwriting, reserve funds core systems, completing search engine localization. These systems process customer and business data requiring Art. 28 authorization and Art. 48 masking before test entry. Field permissions and masking are native to the engine , eliminating the need for a separate masking middleware during replacement.

Guoren Insurance core system architecture with Easysearch
Guoren Insurance core system architecture with Easysearch

3.3 Financial-Grade Operations — Aligned with High Availability & Emergency Response

INFINI Labs won Zheshang Bank's 2026–2028 log management platform maintenance (3 years), covering 7×24 online assistance, fault analysis & emergency response, Elasticsearch cluster inspection & health checks, disaster recovery switchover, performance optimization . Art. 49 and Art. 68 requirements for HA, backup, contingency plans, and incident handling become continuous service. Inspection objects include in-use Elasticsearch clusters, indicating the current path: first contain operational risks, then leverage API compatibility for phased replacement . The rule engine shares the same capabilities: millisecond compilation, multi-rule hits; anti-money laundering, account security, claims investigation share one low-latency query; permissions and audit maintain a single standard.

Zheshang Bank operations maintenance scope
Zheshang Bank operations maintenance scope

4. Summary

The Measures codify responsibility, classification, cryptography, logs, and reporting deadlines as checkable obligations. Easysearch's aligned capabilities are national cryptography (SM2/SM3/SM4), field-level permissions & masking, audit, high availability, and Elasticsearch API compatibility on domestic CPUs and operating systems . Institutions need to run core queries, logs, and risk control on a system that can trace, classify, and explain within two hours .

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

Rule EngineAudit LoggingFinancial Data SecurityEasysearchChinese CryptographyField-Level Masking
Mingyi World Elasticsearch
Written by

Mingyi World Elasticsearch

The leading WeChat public account for Elasticsearch fundamentals, advanced topics, and hands‑on practice. Join us to dive deep into the ELK Stack (Elasticsearch, Logstash, Kibana, Beats).

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.