ICBC Software Center Deploys Data‑Driven Security Monitoring and Traceability System

The Industrial and Commercial Bank of China’s Software Development Center has built a proactive, data‑driven security architecture that combines intelligent sensitive data identification, unified log collection, real‑time data lake ingestion, and automated traceability to achieve zero‑trust protection, comprehensive monitoring, and rapid incident response across its banking operations.

BanTech Think Tank
BanTech Think Tank
BanTech Think Tank
ICBC Software Center Deploys Data‑Driven Security Monitoring and Traceability System

Background and Current Challenges

With the rapid growth of large‑scale data usage, inclusive data services, and cross‑institution data sharing, the bank faces increasing risks of data leakage, misuse, and unauthorized access. The lack of transparency in data usage and difficulty in tracing leaks have become critical security concerns.

To address these issues, the Software Development Center aligned its efforts with China’s Data Security Law and Personal Information Protection Law, establishing a complete classification‑based security framework and launching an enterprise‑level data security technology platform.

Four‑in‑One Data Security Framework

The center first built foundational capabilities such as data identification, data control, data desensitization, and data watermarking. These enabled a "data‑driven security" model that provides proactive protection, systematic monitoring, and traceability (see Figure 1).

Key components include:

Intelligent Sensitive Data Identification – Models detect personal identifiers (name, ID number, phone, address, card number) in real time via the data security gateway, extracting and storing transaction time, parties, and detailed data features.

Unified Log Collection Standards – Revised technical specifications (e.g., "Data Lifecycle Security Technical Specification", "Application Log Technical Specification") define uniform formats for sensitive operation logs and data records. Spring Boot‑compatible components automatically capture these logs.

Real‑Time Data Lake Ingestion – A PB‑scale processing pipeline stores raw sensitive information and usage logs in a real‑time data warehouse, creating a unified data security view and 34 anomaly‑monitoring models (IP, domain, interface count, sensitive field access, risk events, etc.).

Automated Traceability Mechanism – Leveraging big‑data and distributed search engines, the system provides hour‑level traceability for six key customer data elements, supporting single or combined trace scenarios, automatic sample authenticity verification, and rapid source identification.

Zero‑Trust Data Security Gateway

The gateway establishes a unified entry‑exit point for data access and distribution, acting as the "throat" that blocks risk exposure. It monitors traffic, identifies sensitive data streams, and enforces control policies.

Full Lifecycle Protection and Emergency Response

The platform delivers overall security posture awareness, real‑time anomaly detection, and automated alert handling for nearly a thousand applications exposing personal customer data. It provides a unified view of usage behavior, supports pre‑identification, in‑process control, and post‑incident traceability, and defines a ten‑step traceability workflow (see Figure 9).

Emergency procedures cover alert confirmation, incident verification, response execution, and post‑mortem handling, reducing manual effort and cost while strengthening deterrence against data breaches.

Conclusion and Outlook

The center will continue to deepen intelligent risk control, reinforce digital security per national strategies, and evolve the "monitor‑trace‑prevent" integrated shield. By advancing digital platforms, it aims to shift risk management from reactive to proactive, supporting high‑quality development and the bank’s role in China’s modernisation.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

monitoringBig Datadata securityzero trusttraceabilitybanking
BanTech Think Tank
Written by

BanTech Think Tank

Tracks major fintech trends, focusing on fintech management, technology development, IT operations, information security, indigenous innovation, data governance, and business innovation. Aims to promote integrated industry‑academia‑research‑application development, offering a sharing platform for tech practitioners and valuable insights for institutional decision‑makers.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.