Evaluation providing apparatus, evaluation providing method, and evaluation providing program
Patent Information
- Application Number
- JP2023138074
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-08-28
- Publication Date
- 2026-01-14
AI Technical Summary
User entities face inconvenience and increased effort in obtaining security evaluations for various services, especially cloud services, due to difficulties in determining when such evaluations can be obtained.
An evaluation providing system that receives answers to security checklists from service providers, performs security evaluations, and displays a predicted delivery date for the evaluations to user entities.
Improves user convenience by allowing entities to grasp when security evaluations will be provided, reducing the effort required for obtaining them.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a rating providing device, a rating providing method, and a rating providing program. [Background technology]
[0002] In recent years, the number of cyber attacks has increased, and security evaluation against cyber attacks has attracted attention. For example, a system that manages a list of security-related questions (hereinafter, a checklist) and a system that derives a security evaluation based on answers to the checklist have been proposed (for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2003-044658 A Summary of the Invention [Problem to be solved by the invention]
[0004] By the way, it is assumed that a user entity uses various services such as SaaS (Software as a Service). In such a case, it may be troublesome for the user entity itself to obtain security evaluations of various services such as cloud services.
[0005] From the viewpoint of reducing the burden on the user entity, a rating providing system may be considered that executes a process of collecting answers to a security-related checklist from providing entities of various services on behalf of the user entity.
[0006] However, if the collection of answers to the checklist is done by a rating provision system, it may be difficult for user entities to know when they will be able to obtain a security rating, which may reduce convenience for the user entities.
[0007] Therefore, the present invention has been made to solve the above-mentioned problems, and aims to provide an evaluation providing device, an evaluation providing method, and an evaluation providing program that can improve the convenience of user entities while reducing the effort required by user entities to obtain security evaluations for various services. [Means for solving the problem]
[0008] One aspect of the present disclosure is an evaluation providing device comprising: a receiving unit that receives answers to a checklist regarding the security of a service from a providing entity that provides the service; a providing unit that provides a security evaluation regarding the service to a user entity based on the answers to the checklist; and a display unit that displays an estimated delivery date by which the security evaluation can be provided to the user entity.
[0009] One aspect of the present disclosure is a method for providing an evaluation, comprising: step A of receiving answers to a checklist regarding the security of a service from a service providing entity; step B of providing a security evaluation regarding the service to a user entity based on the answers to the checklist; and step C of displaying an estimated delivery date by which the security evaluation can be provided to the user entity.
[0010] One aspect of the present disclosure is an evaluation providing program that causes a computer to execute the steps of: step A receiving answers to a checklist regarding the security of a service from a service providing entity; step B providing a security evaluation regarding the service to a user entity based on the answers to the checklist; and step C displaying an estimated delivery date by which the security evaluation can be provided to the user entity. Effect of the Invention
[0011] According to the present invention, it is possible to provide an evaluation providing device, an evaluation providing method, and an evaluation providing program that can improve the convenience of user entities while reducing the effort required for user entities to obtain security evaluations for various services. [Brief description of the drawings]
[0012] [Figure 1] FIG. 1 is a diagram showing a rating providing system 100 according to an embodiment. [Diagram 2] FIG. 2 is a diagram showing an evaluation providing device 30 according to the embodiment. [Diagram 3] FIG. 3 is a diagram for explaining display contents according to the embodiment. [Figure 4] FIG. 4 is a diagram for explaining display contents according to the embodiment. [Diagram 5] FIG. 5 is a diagram for explaining display contents according to the embodiment. [Figure 6] FIG. 6 is a diagram for explaining the progress according to the embodiment. [Figure 7] FIG. 7 is a diagram for explaining the progress status according to the embodiment. [Figure 8] FIG. 8 is a diagram for explaining the progress according to the embodiment. [Figure 9] FIG. 9 is a diagram for explaining the progress status according to the embodiment. [Figure 10] FIG. 10 is a diagram for explaining the progress status according to the embodiment. [Figure 11] FIG. 11 is a diagram for explaining the progress according to the first modification. [Figure 12] FIG. 12 is a diagram for explaining the progress according to the second modification. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0013] Hereinafter, embodiments will be described with reference to the drawings. In the following description of the drawings, the same or similar parts are denoted by the same or similar reference numerals.
[0014] However, it should be noted that the drawings are schematic and the ratios of the dimensions may differ from the actual ones. Therefore, the specific dimensions should be determined with reference to the following explanation. In addition, the drawings may of course include parts with different dimensional relationships or ratios.
[0015] [Disclosure Summary] According to the outline of the disclosure, there is provided a rating providing device including a receiving unit that receives an answer to a checklist regarding security of a service from a providing entity that provides the service, a providing unit that provides a security rating regarding the service to a user entity based on the answer to the checklist, and a display unit that displays a predicted delivery date by which the security rating can be provided to the user entity. In the outline of the disclosure, there may be provided a rating providing method and a rating providing program corresponding to the rating providing device.
[0016] In the summary of the disclosure, when a rating providing device acts as a proxy for collecting answers to a security checklist, the rating providing device displays a predicted delivery date by which a security rating can be provided to a user entity. With this configuration, the user entity can grasp the predicted delivery date, thereby improving convenience for the user entity.
[0017] [Embodiment] (Evaluation system) The following describes a system for providing evaluations according to an embodiment. Fig. 1 is a diagram showing a system 100 for providing evaluations according to an embodiment.
[0018] 1, the rating providing system 100 includes a first terminal 10, a second terminal 20, and a rating providing device 30. The first terminal 10, the second terminal 20, and the rating providing device 30 are connected by a network 110. Although not particularly limited, the network 110 may be configured by the Internet. The network 110 may include a local area network, a mobile communication network, or a VPN (Virtual Private Network).
[0019] The first terminal 10 is a terminal used by a user entity. The user entity is an entity that requests a risk assessment of a service provided by a providing entity. The user entity may be used as a term indicating the first terminal 10. For example, the first terminal 10 may be a personal computer, a smartphone, or a tablet terminal. In FIG. 1, the first terminal 10A and the first terminal 10B are illustrated as examples.
[0020] The second terminal 20 is a terminal used by a providing entity. The providing entity is an entity that provides a service that is the subject of risk assessment. The service may include various services such as Software as a Service (SaaS). The providing entity may be used as a term indicating the second terminal 20. For example, the second terminal 20 may be a personal computer, a smartphone, or a tablet terminal. In FIG. 1, the second terminals 20A to 20C are illustrated as examples.
[0021] The rating providing device 30 is a device that provides a security evaluation regarding a service provided by a providing entity. An entity that manages the rating providing device 30 may be referred to as a management entity. The management entity may be used as a term indicating the rating providing device 30. The rating providing device 30 may be configured by one or more servers provided on the network 110. Specifically, the rating providing device 30 collects answers to a security-related checklist from the providing entities. The rating providing device 30 provides a security evaluation regarding the service to the user entity based on the answers to the checklist. Details of the rating providing device 30 will be described later (see FIG. 2).
[0022] (Evaluation providing device) The following describes the evaluation providing device according to the embodiment. Fig. 2 is a diagram showing the evaluation providing device 30 according to the embodiment. As shown in Fig. 2, the evaluation providing device 30 has a communication unit 31, a management unit 32, and a control unit 33.
[0023] The communication unit 31 is configured by a communication module. The communication module may be a wireless communication module conforming to a standard such as IEEE802.11a / b / g / n, LTE, or 5G, or may be a wired communication module conforming to a standard such as IEEE802.3.
[0024] The communication unit 31 executes communication with the second terminal 20. For example, the communication unit 31 transmits a checklist related to the security of the service to the second terminal 20. The communication unit 31 receives a response to the checklist from the second terminal 20. The communication unit 31 may transmit a re-response request to the checklist to the second terminal 20. The communication unit 31 may receive a re-response result to the checklist from the second terminal 20.
[0025] The communication unit 31 executes communication with the first terminal 10. The communication unit 31 transmits display data related to the content to be displayed on the first terminal 10 (hereinafter, display content) to the first terminal 10. The transmission of display data related to the display content may be read as display of the display content. The display content may include the following content.
[0026] In option 1, the display content may include a security rating. Displaying the security rating may be interpreted as providing the security rating. The security rating may be provided by a system for viewing the security rating. The system for viewing the security rating may be interpreted as a system realized by the rating providing device 30.
[0027] However, the security evaluation may be provided by a method other than the system for viewing the security evaluation. The method other than the system for viewing the security evaluation may be a method using e-mail, a chat tool, a recording medium, or the like.
[0028] In option 2, the display may include an expected delivery date when the security assessment will be available to the user entity. The expected delivery date may be expressed as a period of time (e.g., 1 week, 2 weeks) from the time the expected delivery date is identified until the security assessment will be available. The expected delivery date may be expressed as a date (e.g., yyyy / mm / dd) when the security assessment will be available. The expected delivery date may be manually set by an operator of the management entity.
[0029] In option 3, the display may include notices regarding the provision of security evaluations to the user entity. The notices may include at least one of matters regarding the availability of security evaluations and matters regarding conditions that may be imposed on the user entity in providing security evaluations.
[0030] In option 4, the display content may include a progress status until a security assessment can be provided to the user entity. The progress status may include a first progress status belonging to a first hierarchical level and a second progress status belonging to a second hierarchical level lower than the first hierarchical level. The second progress status may include an initial answer to the checklist, a review of the initial answer to the checklist, a second or subsequent re-answer to the checklist, and a second or subsequent re-review of the checklist.
[0031] Two or more options selected from Option 1 to Option 4 may be combined.
[0032] The management unit 32 is configured with a storage medium such as a non-volatile memory, a hard disk drive (HDD), a solid state drive (SSD), or a magnetic tape.
[0033] For example, the management unit 32 stores past security evaluations in association with the providing entity. The management unit 32 may store checklists used in past security evaluations in association with the providing entity, and may store answers to the checklists used in past security evaluations in association with the providing entity. The management unit 32 may store a history of communication between the providing entity and the management entity regarding past security evaluations. The management unit 32 may store the frequency of answers by the providing entity to the checklists used in past security evaluations.
[0034] The control unit 33 may include at least one processor. The at least one processor may be configured by a single integrated circuit, or may be configured by a plurality of circuits (such as integrated circuits and / or discrete circuits) communicatively connected to each other.
[0035] For example, the control unit 33 generates display data related to the display contents. The display contents may include one or more options selected from the above-mentioned options 1 to 4. Here, the generation of the display data may be interpreted as the display of the display contents.
[0036] The control unit 33 may generate display data for displaying an expected delivery time when a past security assessment is associated with the providing entity.
[0037] In an embodiment, the communication unit 31 constitutes a receiving unit for receiving answers to a checklist relating to the security of the service from a providing entity.
[0038] In an embodiment, the communication unit 31 constitutes a provider that provides a security assessment of the service to the user entity based on the answers to the checklist.
[0039] In an embodiment, at least one of the communication unit 31 and the control unit 33 configures a display unit that displays a predicted delivery date by which a security assessment can be provided to a user entity.
[0040] In an embodiment, the management unit 32 configures a database that stores past security assessments regarding the service in association with the providing entity.
[0041] (Display content) Display contents according to the embodiment will be described below. In the following, the providing entity may be referred to as a vendor. The service provided by the providing entity may be referred to as a cloud service.
[0042] First, the display contents related to the above-mentioned options 2 and 3 will be mainly described with reference to Fig. 3. The display contents shown in Fig. 3 may be displayed on the first terminal 10 by the evaluation providing device 30.
[0043] 3, the display contents include a list of cloud services that the user entity plans to use, cloud services that the user entity is considering using, or cloud services that the user entity is currently using. For example, the list of services includes cloud services A to D.
[0044] When past security evaluations of cloud services are stored in association with the vendor, a predicted delivery date 51 is displayed together with an icon "disclose investigation results," as shown for cloud services A to C. For example, a predicted delivery date 51 of within about one week is displayed for cloud service A, a predicted delivery date 51 of within about two weeks is displayed for cloud service B, and a predicted delivery date 51 of within about one week is displayed for cloud service C.
[0045] On the other hand, if no past security evaluations of the cloud service are stored in association with the vendor, an icon "Request a new investigation" is displayed, as shown for cloud service D. In such a case, information 52 such as "No investigation history" indicating that no security evaluation has been conducted in the past may be displayed together with the icon.
[0046] If there are any precautions regarding the provision of the security evaluation to the user entity, an icon 53 indicating the presence of the precautions is displayed. In Fig. 3, a case where there are precautions for cloud services B to D is illustrated as an example.
[0047] As shown in Figure 4, the notes may include types such as "individual investigation," "third-party privacy policy," "contract plan," "usage status," "paid response," "NDA required," "competing product," "no contact," and "other (general purpose)."
[0048] "Individual investigation" is a condition that may require individual action to be taken regarding the providing entity because the providing entity does not accept security investigations and does not support the scheme of sending a checklist and receiving a response to the checklist. If "individual investigation" exists as a caution based on past investigation results, a display message associated with "individual investigation" may be displayed by selecting (clicking) the icon 53. Here, the display message is a message that explains the details of the caution to the user entity. The display message may also include a message of advice to the user entity regarding the caution. For example, the display message may be "There have been cases where investigations have been declined because security investigations are not accepted due to policy or resource / cost issues. If you enter the person in charge information, it may be possible to disclose the information."
[0049] The "third-party mediated privacy policy" is a condition under which the providing entity may not permit the intervention of the evaluation providing device 30 (third party). When the "third-party mediated privacy policy" exists as a notice, a display message associated with the "third-party mediated privacy policy" may be displayed by selecting (clicking) the icon 53. The display message may be, for example, "There have been cases where investigations have been refused because, according to policies, information cannot be provided to third parties who do not have a contract for the company's services. If you enter the person in charge information or contact us in advance, we may be able to disclose the information."
[0050] The "contract plan" is a condition under which the providing entity may refuse to provide a security evaluation depending on the contract plan, scale of use (number of accounts, etc.), contract amount, etc. of the service provided by the providing entity. When the "contract plan" is present as a note, a display message associated with the "contract plan" may be displayed by selecting (clicking) the icon 53. The display message may be, for example, "The business entity decides whether or not to respond to an investigation based on the contract plan, scale of use (number of accounts, etc.), contract amount, etc., and there have been cases where the investigation request was declined because the criteria were not met. When making this request, please be sure to enter the plan you are planning to contract / currently contracted for."
[0051] "Usage status" is a condition under which the providing entity may refuse to provide a security evaluation if the user is not currently using or under contract with the service provided by the providing entity. When "usage status" is present as a caution, a display message associated with "usage status" may be displayed by selecting (clicking) icon 53. For example, the display message may be, "There have been cases where an investigation was refused because security investigations are not accepted without the use or contract of the service. Therefore, if you request an investigation at the introduction consideration stage before use, your request may be refused. Please be aware of this before making your request."
[0052] "Paid service" is a condition under which a providing entity may refuse to provide a security evaluation if the security evaluation of the service provided by the providing entity is not paid for. When "Paid service" is present as a notice, a display message associated with "Paid service" may be displayed by selecting (clicking) icon 53. The display message may be, for example, "There have been cases where security investigations have required a fee. Please be aware of this before placing your order."
[0053] "NDA Required" is a condition that may require a non-disclosure agreement when providing a security evaluation. When "NDA Required" is present as a notice, a display message associated with "NDA Required" may be displayed by selecting (clicking) the icon 53. The display message may be, for example, "There have been cases where a non-disclosure agreement was required for security investigation. Please be aware of this before making a request."
[0054] "Competitive product" is a condition under which the providing entity may refuse to provide a security evaluation because the service provided by the providing entity is competitive with a service that may be provided by the management entity. The services that may be provided by the management entity may include services realized by the evaluation providing device 30, and may include other services provided by the management entity that are other than the services realized by the evaluation providing device 30. When the "competitive product" is present as a notice, a display message associated with the "competitive product" may be displayed by selecting (clicking) the icon 53. Services that fall under the "competitive product" are difficult for the management entity to obtain a security evaluation for, so they may not be displayed in the list of services. The display message may be, for example, "There have been cases where investigations have been refused due to competing services."
[0055] "No contact" is a condition in which it may be impossible to contact the providing entity. If "No contact" is present as a caution, a display message associated with "No contact" may be displayed by selecting (clicking) icon 53. The display message may be, for example, "This is a company that we have contacted many times after receiving the request, but have been unable to get in touch with or communicate with. If you enter the contact information, they may be able to disclose the information."
[0056] "Other (generic)" is a condition for which a security evaluation may not be obtained for reasons other than those described above. If "Other (generic)" is present as a caution, a display message associated with "Other (generic)" may be displayed by selecting (clicking) icon 53. The display message may be, for example, "There have been cases in the past where we were unable to investigate."
[0057] Here, "individual survey", "third-party privacy policy", "competitive product", "no contact", and "other (general purpose)" may be considered as examples of items related to the availability of security evaluations. "contract plan", "usage status", "paid support", and "NDA required" may be considered as examples of items related to conditions that may be imposed on user entities when providing security evaluations.
[0058] The type of condition and the display wording of the precautions are selected based on past security evaluations stored by the management unit 32 in association with the providing entity, the history of communication between the providing entity and the management entity, and the frequency of responses from the providing entity.
[0059] Secondly, the display content relating to the above-mentioned option 4 will be mainly described with reference to Fig. 5. The display content shown in Fig. 5 may be displayed on the first terminal 10 by the evaluation providing device 30.
[0060] As shown in FIG. 5, the display contents include a list of cloud services for which the user entity has requested an investigation. For example, the list of services includes cloud services A to D. The display contents may include items such as the service name, request date, completion date, investigation status, and re-investigation. The investigation status is an example of the progress status until a security evaluation can be provided to the user entity. The list of services may also include both cloud services that have been investigated in the past and for which a request has been made to disclose the investigation results, and cloud services that have not been investigated in the past and for which a request has been made to investigate for the first time.
[0061] The progress status may include a first progress status belonging to a first hierarchical level and a second progress status belonging to a second hierarchical level lower than the first hierarchical level. Although not particularly limited, the second progress status may be displayed in the investigation status field shown in FIG.
[0062] For example, as shown in Figures 6 to 10, the first progress status may include statuses such as "request sent", "confirmed by other party", "answer", and "completed". "Request sent" is a status in which a request for a security evaluation investigation is received from a user entity and the providing entity is requested to investigate the security evaluation. "Confirmed by other party" is a status in which the providing entity confirms whether or not to accept the security evaluation investigation. "Answer" is a status in which a checklist is sent to the providing entity, a reply to the checklist is received from the providing entity, and the reply to the checklist is reviewed by the management entity. "Completed" is a status in which the security evaluation investigation is completed.
[0063] The second progress status may include "Request Sent" which is lower in level than "Request Sent" of the first progress status. As shown in FIG. 6, "Request Sent" of the second progress status is a status in which a user entity requests an investigation of a security evaluation and the management entity confirms the request. When the management entity completes confirmation of the request and requests the providing entity to investigate the security evaluation, "Request Sent" of the second progress status is completed (e.g., a black circle), and "Request Sent" of the first progress status is also completed (e.g., a check). In this way, the status of the first progress status and the second progress status may be displayed by different icons.
[0064] The second progress status may include "response by person in charge" and "answer negotiation", which are lower than the first progress status "confirmation by other party". As shown in the left column of FIG. 7, "response by person in charge" of the second progress status is a status of waiting for a reply from the providing entity. When there is a reply from the providing entity, "response by person in charge" of the second progress status is completed (e.g., a black circle). As shown in the right column of FIG. 7, "answer negotiation" is a status of negotiating between the management entity and the providing entity regarding a request for a security evaluation investigation. When the negotiation is completed, "answer negotiation" of the second progress status is completed (e.g., a black circle), and "confirmation by other party" of the first progress status is also completed (e.g., a check).
[0065] The second progress status may include "Response Start", "Response", and "Review" that are lower than "Response" of the first progress status. As shown in the upper left column of FIG. 8, "Response Start" of the second progress status is a status in which a checklist is sent to a providing entity, and the providing entity starts responding to the checklist. When the checklist is sent to the providing entity, "Response Start" of the second progress status ends (e.g., a black circle). As shown in the upper right column of FIG. 8, "Response" of the second progress status is a status in which the providing entity is responding to the checklist. When a response to the checklist is received from the providing entity, "Response" of the second progress status ends (e.g., a black circle). As shown in the lower left column of FIG. 8, "Review" of the second progress status is a status in which the management entity reviews the response to the checklist. If there is no problem with the response to the checklist, "Review" of the second progress status ends (e.g., a black circle), and "Response" of the first progress status also ends (e.g., a check).
[0066] Here, if there is an error in the response to the checklist, as shown in FIG. 9, the items "Re-Response" and "Re-Review" are added as a second progress status lower than "Response" of the first progress status. As shown in the left column of FIG. 9, "Re-Response" of the second progress status is a status in which the providing entity is re-responding to the checklist. When a re-response to the checklist is received from the providing entity, "Re-Response" of the second progress status is completed (e.g., a black circle). As shown in the right column of FIG. 9, "Re-Review" of the second progress status is a status in which the management entity re-reviews the re-response to the checklist. If there is no error in the re-response to the checklist, "Re-Review" of the second progress status is completed (e.g., a black circle), and "Response" of the first progress status is also completed (e.g., a check).
[0067] If there is any deficiency in the re-answer to the checklist, the items "Re-answer" and "Re-review" are further added as a second progress status lower than "Answer" in the first progress status, and a re-answer to the checklist and a re-review of the re-answer to the checklist are performed in the same procedure as in Fig. 9. The same procedure as in Fig. 9 may be repeated until there are no deficiencies in the re-answer to the checklist.
[0068] In addition, if the deadline for the security evaluation is delayed, for example because a re-response by the providing entity or a re-review by the management entity is required, a message to the effect that the deadline will be delayed may be displayed together with the display of the first progress status and the second progress status.
[0069] That is, as shown in Figures 9 and 10, the display content regarding progress may include a first response to the checklist, a review of the first response to the checklist, a second or subsequent re-response to the checklist, and a re-review of the second or subsequent responses to the checklist.
[0070] The second progress status may include a "Complete" that is lower in level than the "Complete" of the first progress status. As shown in Fig. 10, the second progress status "Complete" is a status indicating that the provision of the security evaluation is completed. When the provision of the security evaluation is completed, the "Complete" of the second progress status becomes completed (e.g., a black circle), and the "Complete" of the first progress status also becomes completed (e.g., a check).
[0071] 5 illustrates an example in which the second progress status is displayed in the investigation status field, but the first progress status may be displayed in the investigation status field, and the second progress status may be displayed in response to the selection of the first progress status. Alternatively, both the first progress status and the second progress status may be displayed in the investigation status field.
[0072] (Action and Effects) In the embodiment, when the evaluation providing device 30 collects answers to a security checklist on behalf of a user entity, the evaluation providing device 30 displays a predicted delivery date by which a security evaluation can be provided to the user entity. With this configuration, the user entity can know the predicted delivery date, thereby improving the convenience of the user entity.
[0073] In the embodiment, the evaluation providing device 30 displays a notice regarding the provision of a security evaluation to a user entity. With such a configuration, the user entity can know the notice in advance, thereby improving the convenience of the user entity.
[0074] In the embodiment, the evaluation providing device 30 displays the progress status until a security evaluation can be provided to a user entity. With such a configuration, even when a security evaluation is collected on behalf of a management entity, the user entity can grasp the progress between the management entity and the providing entity, thereby improving the convenience of the user entity.
[0075] [Change Example 1] Modification 1 of the embodiment will be described below. Differences from the embodiment will be mainly described below.
[0076] In the first modification example, the display content may include the reason why the user entity's request for providing a security evaluation was canceled by the user entity (in FIG. 11, "Reason for cancellation"), as shown in the left column of FIG. 11. Although not particularly limited, the reason for cancellation may be that the user entity has determined that it is difficult to obtain a security evaluation from the providing entity. Here, the left column of FIG. 11 illustrates an example in which the request is canceled at the "Request sent" stage of the first progress status, but the request may be canceled at another first progress status or second progress status.
[0077] In the first modification, the display contents may include the reason why the providing entity cannot provide a security evaluation (NG reason in FIG. 11), as shown in the right column of FIG. 11. Although not particularly limited, the NG reason may be a reason such as the providing entity not accepting individual support for the security evaluation. Here, the right column of FIG. 11 illustrates an example of a case where it is determined that a security evaluation cannot be provided at the "Request Submission" stage of the first progress status, but it may also be determined that a security evaluation cannot be provided in another first progress status or second progress status.
[0078] (Action and Effects) In the first modification, the evaluation providing device 30 displays at least one of the cancellation reason and the NG reason. With this configuration, the user entity can properly understand the reason why the security evaluation was not obtained.
[0079] [Change Example 2] Modification 2 of the embodiment will be described below. Differences from the embodiment will be mainly described below.
[0080] In the second modification, the display content may include a message indicating that the security evaluation has been delivered by a method other than the system for viewing the security evaluation, as shown in Fig. 12. In cases where the providing entity refuses delivery via the management entity or prefers delivery by e-mail or the like, the security evaluation may be delivered by a method other than the system for viewing the security evaluation. The method other than the system for viewing the security evaluation may be a method using e-mail, a chat tool, a recording medium, or the like.
[0081] In such a case, the managing entity may manually change the "Completed" of the second progress status to Completed. The "Completed" of the first progress status may be manually changed to Completed by the managing entity, or may be changed to Completed at the same time that the "Completed" of the second progress status is changed to Completed.
[0082] (Action and Effects) In the second modification, the evaluation providing device 30 displays that the security evaluation has been delivered by a method other than the system for viewing security evaluations. With this configuration, even if the security evaluation has been delivered by a method other than the system for viewing security evaluations, the user entity can properly grasp whether or not the security evaluation has been obtained.
[0083] [Change Example 3] The third modification of the embodiment will be described below. Differences from the embodiment will be mainly described below.
[0084] In the embodiment, the case where the predicted delivery date is manually set by the operator of the management entity has been exemplified. In contrast, in the modified example 3, the predicted delivery date is specified by the control unit 33 based on information managed by the management unit 32. The information used to specify the predicted delivery date is as follows.
[0085] In option 3-1, the control unit 33 determines the predicted delivery time based on the actual delivery time required to provide a past security evaluation. The actual delivery time is the period required for the past security evaluation from receiving a request for the security evaluation to providing the security evaluation.
[0086] In option 3-2, the control unit 33 specifies the expected delivery date based on the version of the checklist used in the past security evaluation. For example, the control unit 33 may specify a longer delivery date as the expected delivery date for an older version of the checklist.
[0087] In option 3-3, the control unit 33 specifies the predicted delivery date based on the sufficiency of the answers in the checklist used in the past security evaluation. For example, the control unit 33 may specify a longer delivery date as the predicted delivery date as the sufficiency of the answers in the checklist used in the past security evaluation is lower.
[0088] In option 3-4, the control unit 33 determines the expected delivery time based on a history of communication with the providing entity regarding past security evaluations. For example, the control unit 33 may determine a longer delivery time as the expected delivery time when the providing entity is slow in responding to an inquiry to the providing entity.
[0089] In option 3-5, the control unit 33 determines the expected delivery time based on the response frequency of the providing entity to the checklist used in the past security evaluation. For example, the control unit 33 may determine a longer delivery time as the expected delivery time as the response frequency is lower.
[0090] Two or more options selected from Option 3-1 to Option 3-5 may be combined. In addition, if any of the options specifies a delivery time that is longer than the actual delivery time in the past, a notice to that effect may be displayed.
[0091] (Action and Effects) In the third modification, the evaluation providing device 30 specifies the predicted delivery date based on at least one of options 3-1 to 3-5. With this configuration, the predicted delivery date can be appropriately specified while reducing the effort of the management entity.
[0092] [Other embodiments] Although the present invention has been described by the above-mentioned embodiment, the description and drawings forming a part of this disclosure should not be understood as limiting the present invention. From this disclosure, various alternative embodiments, examples and operating techniques will become apparent to those skilled in the art.
[0093] Although not particularly limited thereto, a security evaluation survey may be read as a security survey.
[0094] Although not specifically mentioned in the embodiment, a program may be provided that causes a computer to execute each process performed by the evaluation providing device 30. The program may also be recorded in a computer-readable medium. Using the computer-readable medium, it is possible to install the program in a computer. Here, the computer-readable medium on which the program is recorded may be a non-transient recording medium. The non-transient recording medium is not particularly limited, and may be, for example, a recording medium such as a CD-ROM or a DVD-ROM.
[0095] Alternatively, a chip may be provided that is configured by a memory that stores a program for executing each process performed by the rating providing device 30 and a processor that executes the program stored in the memory.
[0096] [Note] The above disclosure may be expressed as follows:
[0097] A first feature is an evaluation providing device comprising: a receiving unit that receives answers to a checklist regarding the security of a service from a providing entity that provides the service; a providing unit that provides a security evaluation regarding the service to a user entity based on the answers to the checklist; and a display unit that displays a predicted delivery date by which the security evaluation can be provided to the user entity.
[0098] A second feature is the evaluation providing device according to the first feature, wherein the display unit displays a notice regarding providing the security evaluation to the user entity.
[0099] A third feature is the rating providing device of the second feature, wherein the notes include at least one of matters related to the possibility of providing the security rating and matters related to conditions that may be imposed on the user entity when providing the security rating.
[0100] A fourth feature is a rating providing device in at least one of the first to third features, wherein the display unit displays a progress status until the security rating can be provided to the user entity.
[0101] A fifth feature is the evaluation providing device of the fourth feature, wherein the progress status includes a first progress status belonging to a first hierarchy and a second progress status belonging to a second hierarchy lower than the first hierarchy.
[0102] A sixth feature is the evaluation providing device of the fifth feature, wherein the second progress status includes a first response to the checklist, a review of the first response to the checklist, a second or subsequent re-response to the checklist, and a re-review of the second or subsequent responses to the checklist.
[0103] A seventh feature is a rating providing device in at least one of the first to sixth features, wherein the display unit displays at least one of the reason why the user entity's request for the provision of the security rating was canceled by the user entity and the reason why the security rating cannot be provided.
[0104] An eighth feature is an evaluation providing device in at least one of the first to seventh features, wherein the display unit displays that the security evaluation has been delivered by a method other than a system for viewing the security evaluation.
[0105] A ninth feature is a rating providing device that, in at least one of the first to eighth features, includes a database that stores past security ratings for the service in correspondence with the providing entity, and the display unit displays the predicted delivery date when the past security ratings are stored in correspondence with the providing entity.
[0106] A tenth feature is the evaluation providing device of the ninth feature, further comprising a control unit that determines the predicted delivery date based on at least one of the actual delivery date required for the past security evaluation to be able to be provided, the version of the checklist used in the past security evaluation, the satisfaction of the answers to the checklist used in the past security evaluation, the history of communication with the providing entity regarding the past security evaluation, and the frequency of answers by the providing entity to the checklist used in the past security evaluation.
[0107] An eleventh feature is a method for providing an evaluation, comprising: a step A of receiving answers to a checklist regarding the security of a service from a service providing entity; a step B of providing a security evaluation regarding the service to a user entity based on the answers to the checklist; and a step C of displaying an estimated delivery date by which the security evaluation can be provided to the user entity.
[0108] A twelfth feature is an evaluation providing program that causes a computer to execute the steps of: receiving, from a service providing entity, an answer to a checklist regarding security of the service; providing, to a user entity, a security evaluation regarding the service based on the answer to the checklist; and displaying, to the user entity, an estimated delivery date when the security evaluation can be provided to the user entity. [Explanation of symbols]
[0109] 10...first terminal, 20...second terminal, 30...rating providing device, 31...communication unit, 32...management unit, 33...control unit, 100...rating providing system, 110...network
Claims
1. a receiving unit for receiving an answer to a checklist regarding security of a service from a providing entity that provides the service; a provider that provides a security assessment of the service to a user entity based on an answer to the checklist; a database storing information indicating the progress of the security assessment until it is available for provision to the user entity; a control unit that identifies the progress status based on the information stored in the database and generates display data for displaying the progress status; a display unit that displays the progress status based on the display data generated by the control unit.
2. The evaluation providing device according to claim 1 , wherein the display unit displays a notice regarding the provision of the security evaluation to the user entity.
3. The rating providing device of claim 2 , wherein the notice includes at least one of matters regarding the possibility of providing the security rating and matters regarding conditions that may be imposed on the user entity when providing the security rating.
4. The evaluation providing device according to claim 1 , wherein the progress status includes a first progress status belonging to a first hierarchical level and a second progress status belonging to a second hierarchical level lower than the first hierarchical level.
5. The evaluation providing device described in Claim 4, wherein the first progress status includes at least one of a status of requesting the providing entity to investigate the security evaluation, a status of confirming whether the providing entity will undergo the security evaluation investigation, a status of reviewing responses to the checklist, or a status of completing the security evaluation investigation.
6. The evaluation providing device of claim 4, wherein the second progress status includes a first response to the checklist, a review of the first response to the checklist, a second or subsequent re-response to the checklist, and a re-review of the second or subsequent responses to the checklist.
7. The evaluation providing device of claim 1 , wherein the display unit displays at least one of the reason why the user entity's request for providing the security evaluation was canceled by the user entity and the reason why the providing entity cannot provide the security evaluation.
8. The evaluation providing device according to claim 1 , wherein the display unit displays that the security evaluation has been delivered by a method other than a system for viewing the security evaluation.
9. A step A in which an evaluation providing device receives answers to a checklist regarding security of a service from a providing entity that provides the service; Step B: the rating providing device provides a security rating for the service to the user entity based on the answers to the checklist; C. storing information indicating the progress of the rating providing device until the security rating can be provided to the user entity; a step D in which the evaluation providing device identifies the progress status based on the information stored in the database and generates display data for displaying the progress status; A rating providing method comprising: a step E in which the rating providing device displays the progress status based on the display data generated in the step D.
10. A step A of receiving an answer to a checklist regarding security of a service from a providing entity that provides said service; Step B: providing a security assessment of the service to a user entity based on the answers to the checklist; C. storing information indicating the progress of said security assessment until it is available for provision to said user entity; a step D of identifying the progress status based on the information stored in the database and generating display data for displaying the progress status; and step E of displaying the progress status based on the display data generated in step D.