we proposed a set of embedded Internet services security management system based on the experience of mobile Internet service operation. The system covers the whole lifecycle of Internet services and achieves a set of embedded business risk control
which wholy implements "three simultaneous" of the network and information security. The management system described in this paper achieved dual security auditing of the business process and the coding audit
and ensures the comprehensiveness and accuracy of the risk investigation. The use of automatic compliance verification mechanism and manual penetration testing improved the efficiency and accuracy of risk investigation. Risk sharing mechanism significantly reduces the probability of services security risks recurring.