| Under the trend of globalization and informatization, the IT application enters a new era of cloud computing, big data, mobilization and Internet from a traditional elec-tronic, paperless and automatic office pattern. The informatization and networking pro-gress brings unprecedented opportunities and challenges. With significant progress and tremendous fortune, unpredictable potential security risks emerge, which set a higher demand on data security problems for enterprises. The age of big data means that the information resource has increasingly become the basis of an information-based society and a significant factor to create value and fortune. Therefore, the protection of infor-mation resources has become a basic and strategic task. Information security covers a wide range, whose overall objective is to ensure the confidentiality, integrity and avail-ability of the information. Different enterprises have different concerns on the infor-mation security according to their business features. The information confidentiality is a top concern for traditional manufacturing industry, especially for high-tech innovative enterprises.This thesis proposes to introduce ISO27001 standards universally accepted within the international information security field, and combine with enterprise practices to provide guidance and reference for enterprises to construct secure, effective, and sus-tainably improved data security protection system. Based on the information security and data protection project conducted by a chemical group listed company in Shandong province, this thesis analyzes problems and their reasons, summary of implementing experience and effect evaluation reflected from the project implementation. This thesis aims to provide practical basis for constructing an overall and effective data security protection system with the combination of actual practices and ISO27001 standards, and also provide reference and enlightenment for other enterprises especially traditional manufacturing ones on the information security construction, so as to promote the in-formation security level comprehensively. |