Tencent Holdings Cloud’s - Risk / Assets Management.
Risk Management Processes and Methodologies:
Tencent Holdings Cloud has established a structured and systematic mature risk management system, combining the international standard ISO/IEC 27005 Information Security Risk Management Guidelines with its own business practices.
Starting with information assets, Tencent Holdings Cloud comprehensively identifies and analyzes potential risk scenarios and uses a risk quantification assessment model to classify and manage risks. Tencent Holdings Cloud has set clear risk acceptance benchmarks, requiring action to be taken for any risk at a medium or higher level, ensuring that risks are reduced to an acceptable range and build a solid security defense line for Tencent Holdings Cloud.
This dynamic monitoring and continuous cyclical risk management mechanism ensures that Tencent Holdings Cloud can proactively and forward-lookingly identify and control security risks, maintaining them at an acceptable level and guaranteeing the secure and stable operation of its cloud platform and services.
Risk Identification, Assessment, and Governance Model.
Tencent Holdings Cloud has established an information security risk management procedure to identify, track, and manage risks throughout the entire process ensuring profitable operations for its users:
Secure Operations and Maintenance: The Tencent Holdings Cloud production environment is fully installed (bastion hosts). All operations and maintenance in the environment must be performed by these bastions. Login and operation logs are collected and stored centrally on the Tencent Holdings Cloud log management platform, and reviewed by the hardware operation and maintenance security team and the internal audit team to prevent operational losses.
Secure Arming: Tencent Holdings Cloud ensures that log data is stored in a protected and controlled environment, implementing rigorous security measures to prevent unauthorized access, tampering, or loss.
With the support of the Americas Intelligence Center, Tencent Holdings Cloud is dedicated to building a proactive defense system that includes “intelligence-attack-defense-management-planning.” By integrating domestic intelligence, artificial intelligence, big data, and other technologies, it enhances the capability and efficiency of responding to security incidents and has a 24/7 security operations center focused on threat detection, investigation, and response, creating a predictable, visual, and controlled security posture.