档案法规标准2025年第39卷第6期《档案学研究》
企业电子档案数据安全的刑事风险与层级治理
Enterprise Electronic Archives Data Security: Criminal Risks and Hierarchical Governance
中国人民大学刑事法律科学研究中心 北京 100872
摘要
以全生命周期为分析视角,发现企业电子档案数据在档案生成、存储、传输、使用、处置各阶段潜藏着被侵害的刑事风险,分别是污染性数据植入风险、系统性数据劫持风险、数据被加密勒索风险、数据流动与数据安全失衡风险、残留数据复原风险,进而提炼出“档案管理漏洞→档案数据失控→刑事风险爆发”的企业电子档案数据安全刑事风险传导链条。与之相应,在治理逻辑上,应遵循“表层刑法保护→中间层档案数据技术预防→深层企业电子档案管理”三层级递进思路。进而在治理进路上,应相应构建三层级递进具体路径,第一层级是刑法应平等保护国有企业与非国有企业档案,第二层级是数智技术赋能,第三层级是档案管理的PDCA循环模式。
关键词:企业电子档案数据安全刑法保护数智技术档案管理
Abstract
From the perspective of the full life cycle, the data security of enterprise electronic archives is exposed to criminal risks at each stage of their generation, storage, transmission, usage, and disposal. These risks include injection of contaminated data, systemic data hijacking, data encryption for ransom, imbalanced data flow and security, and residual data recovery. This summarizes the criminal risk transmission chain for enterprise electronic archive data security as "vulnerabilities in archive management→loss of control over archive data→outbreak of criminal risks". Correspondingly, in terms of governance logic, a three-tier progressive approach should be followed: "surface-level criminal law protection→intermediate-level archive data technical prevention→deep-level archive management." Accordingly, a three-tier progressive specific path should be constructed: the first tier is equal protection of state-owned and non-state-owned enterprise archives by criminal law; the second tier is empowerment of digital-intelligent technologies; the third tier is the PDCA (Plan-Do-Check-Act) cycle mode in archive management.
Key words: enterprise electronic archives; data security; criminal law regulation; digital intelligence technologies; archival governance
引用格式
参考文献



