Information management system
The information management system addresses the challenge of evaluating security measures across multiple organizations by enabling flexible subgrouping and generating statistical information, ensuring robust security assessments and efficient implementation.
Patent Information
- Application Number
- JP2023216140
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-07-03
AI Technical Summary
Existing security evaluation systems provide individual evaluations for organizations, failing to assess the sufficiency of security measures across multiple organizations in a supply chain, and do not adapt to dynamic changes in cooperation among them.
An information management system that includes a database for security measure evaluations, allows for hierarchical subgrouping of organizations, and generates statistical information on selected subgroups, enabling flexible quantitative evaluations across multiple organizations.
Facilitates flexible and accurate quantitative evaluations of security measures across a plurality of organizations, allowing for dynamic adjustments and efficient implementation of strong security measures.
Smart Images

Figure 2025099461000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information management system.
Background Art
[0002] In many organizations such as companies and local governments, information security is recognized as one of the important issues in organizational operation. In order to objectively grasp whether the planned or implemented security measures are sufficient, it is desirable to provide an index that quantitatively shows the appropriateness of the security measures. However, since security measures include not only technical measures but also strategic and institutional measures, it is difficult to automatically evaluate the appropriateness of such measures.
[0003] Patent Document 1 discloses a security evaluation system that calculates an evaluation score based on answer information received in a question-and-answer (QA) format in order to provide a quantitative index of whether security measures taken from various viewpoints are sufficient. The security evaluation system of Patent Document 1 enables a user to find improvement points of security measures and avoid excessive security investment by providing a relative evaluation of the score of an individual organization with respect to the scores of many organizations.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] Recently, cyberattacks on supply chains involving multiple organizations have become a problem. If there are vulnerable points in the security measures within the supply chain, the entire supply chain may be exposed to security risks as a result of cyberattacks on those points. Since the security evaluation system of Patent Document 1 provides individual evaluation results for each organization, it does not facilitate the determination of whether the security measures for a collection of multiple organizations such as a supply chain are sufficient.
[0006] The validity of security measures is preferably monitored regularly as long as business activities continue. However, the way of cooperation among organizations in the supply chain can change dynamically according to changes in the business environment. Therefore, in order to timely notice the problems in security measures across the entire supply chain, it is required to be able to flexibly provide a quantitative evaluation across multiple organizations.
[0007] In view of the above problems, an object of the present invention is to realize a mechanism that can flexibly provide a quantitative evaluation regarding information security measures across multiple organizations.
Means for Solving the Problems
[0008] According to one aspect, an information management system for managing evaluation information regarding security measures for a group including a plurality of organizations is provided. The information management system includes a database that holds evaluation information regarding the security measures of each organization, and one or more subgroups that form a hierarchical structure, where at least one organization is directly or indirectly associated with each subgroup, and a setting unit that sets the one or more subgroups within the group, and an information output unit that generates statistical information regarding the security measures of the first subgroup among the one or more subgroups based on the evaluation information held in the database when the first subgroup is selected by a user, and outputs the generated statistical information.
Effects of the Invention
[0009] According to the present invention, it becomes possible to flexibly provide a quantitative evaluation regarding security measures across a plurality of organizations.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Mode for Carrying Out the Invention
[0011] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims, and not all combinations of the features described in the embodiments are essential for the invention. Two or more of the plurality of features described in the embodiments may be arbitrarily combined. Also, the same or similar configurations are given the same reference numerals, and redundant descriptions are omitted.
[0012] <1. Overview of the System> FIG. 1 is a schematic diagram showing an overview of an information management system 1 according to an embodiment. The information management system 1 is a system for managing evaluation information regarding security measures for a group including a plurality of organizations. In this specification, an “organization” refers to any organization that conducts business activities or other social activities, such as a company, a local government, a public institution, or a school. Each organization takes various information security measures for the purpose of preventing leakage of confidential information, protecting the information system from computer viruses and unauthorized access, and data preservation against disasters.
[0013] The information management system 1 provides a mechanism for quantitatively evaluating the validity of the security measures of each organization. In this embodiment, the evaluation of the security measures is performed in a QA format. Specifically, for a set of questions prepared in advance regarding security measures, the person in charge of each organization answers based on the actual situation of the organization, and an evaluation score is calculated based on the submitted answers. Typically, the higher the evaluation score, the stronger the security measures of the organization can be judged. In this specification, the set of questions assigned to each organization and the answers thereto (including those in a blank state, i.e., unanswered) are collectively referred to as “security diagnosis” or simply “diagnosis”.
[0014] In modern society, it is common for multiple organizations to conduct activities while exchanging information via a network. A supply chain, which means the chain between companies from the procurement of product materials and parts to the sales of products, is an example of a framework involving multiple organizations. If there are vulnerable points in security measures within the supply chain, as a result of a cyber-attack on such points, the entire supply chain may be exposed to security risks. In order to enable accurate analysis and understanding of such risks, the information management system 1 provides information that not only evaluates the security measures for each organization under its management but also facilitates the determination of whether the security measures are sufficient for a set of multiple organizations.
[0015] In FIG. 1, six organizations B1, B2, B3, B4, B5, and B6 are shown. Each organization may be, for example, a company, factory, logistics base, or store involved in one supply chain. In this specification, the entire set of these organizations under the management of the information management system 1 is referred to as a "group", and a selected subset of organizations set within the group is referred to as a "sub-group".
[0016] In the example of FIG. 1, the group G1 corresponds to the entire set of six organizations B1 to B6. The sub-group SG1 is the set of organizations B1, B3, B4, and B5. The sub-group SG2 is the set of organizations B2 and B6. The sub-group SG3 is the set of organizations B3 and B4. The sub-groups SG1, SG2, and SG3 constitute a hierarchical structure together with the group G1. That is, the group G1 includes the sub-groups SG1 and SG2, and the sub-group SG1 includes the sub-group SG3.
[0017] How to set sub-groups within the group is left to the judgment of the user (for example, the system administrator). For example, the following list is an example of the perspective of setting sub-groups: · Sub-groups by region (e.g., North America / Europe / Asia / Oceania, etc.) · Sub-groups by country (e.g., United States / Canada / France / Germany / Japan, etc.) ·Sub - groups by business segment (e.g., automotive / power / chemicals / natural resources, etc.) ·Sub - groups by product item (e.g., passenger cars / buses / trucks, etc.) Sub - groups by country may be positioned below sub - groups by region. Also, sub - groups by product item may be positioned below sub - groups by business segment. However, from the perspective of subgroup setting, these are not limited to the examples.
[0018] The information management system 1 includes one or more user terminals 10 and a management server 100. The user terminal 10 and the management server 100 are interconnected via a network 5. The network 5 may be any combination of networks such as, for example, the Internet, an intranet, and a cloud network.
[0019] The user terminal 10 may be any type of terminal device such as, for example, a personal computer (PC) or a smartphone. The user terminal 10 has components similar to those of a general terminal device, such as a processor, a memory, a storage, an input device, an output device, and a communication interface. Although only one user terminal 10 is shown in FIG. 1, in reality, additional user terminals are available in each organization. User U1 is a system administrator who manages settings, programs, and data in the information management system 1. User U1 may be, for example, a member of a department responsible for information security in the head office of a corporate group. User U1 can access various management functions of the information management system 1 using the user terminal 10. Some of the management functions provided by the information management system 1 will be described in detail later.
[0020] User U2 is a member in charge of answering the set of diagnostic questions assigned to group B1. User U2 may be, for example, a member belonging to a business company within an enterprise group. User U2 accesses the answer input screen using some user terminal (not shown), inputs an answer, and sends it to the management server 100. Similarly, standard or individual diagnoses are assigned to other groups B2 to B6, and answers are given by their respective members in charge.
[0021] Figure 2 shows an example of the configuration of a screen for inputting answers to security-related questions. Referring to Figure 2, the answer input screen 30 includes a question display area 31, a save button 32, and a submit button 33. The question display area 31 is an area for displaying a list of questions included in one diagnosis and options for answers to each question. Typically, the questions are pre-classified into a plurality of categories, and a list of questions can be displayed for each category. The answer options do not necessarily have to be common throughout all questions. The user can temporarily save (locally or on the server) the data of the input answers by operating the button 32 during the answer operation. Also, when the answer operation is completed, the user can submit the answer to the management server 100 by operating the button 33.
[0022] The management server 100 is a server device that provides various functions for the management of security diagnoses. The management server 100 may be implemented as an application server, a web server, or a cloud server using a high-performance general-purpose computer. Although Figure 1 shows a single management server 100, the functions of the management server 100 described below may also be realized by the cooperation of a plurality of devices.
[0023] The management server 100 generates evaluation information regarding security measures based on the answers to the security diagnosis submitted by the responsible members of each organization. FIG. 3 shows an example of the configuration of a screen for displaying the diagnosis results. Referring to FIG. 3, the diagnosis result screen 40 includes a result display area 41 and a report output button 42. The result display area 41 is an area for displaying the evaluation information as the diagnosis result. In the example of FIG. 3, as the quantitative evaluation indicators for the security measures, the overall score, the deviation value of the score of the target organization with respect to the diagnosis results of all organizations, the scores of the four countermeasure categories, and the deviation values of the scores of those categories are displayed in the result display area 41. The report output button 42 is a button for outputting the report of the evaluation information as a data file or to a printer.
[0024] In the present embodiment, the management server 100 can generate not only the evaluation information for each organization as exemplified in FIG. 3, but also the statistical information of the evaluation in units of groups or subgroups composed of a plurality of organizations. The system administrator can freely set subgroups within a group. Thereby, the information management system 1 flexibly provides a quantitative evaluation regarding information security measures across a plurality of organizations under management. An example of the configuration of the management server 100 for such subgroup setting, as well as the generation and provision of statistical information, will be described in detail in the next section.
[0025] <2. Configuration of the Management Server> <2-1. Example of Basic Configuration> FIG. 4 is a block diagram showing an example of the configuration of the management server 100 according to an embodiment. Referring to FIG. 4, the management server 100 includes a communication interface 101, a memory 103, a processing circuit 105, an input device 107, an output device 109, and a database 110.
[0026] The communication interface 101 is an interface for the management server 100 to communicate with other devices via the network 5. The communication interface 101 may be a wired communication interface or a wireless communication interface.
[0027] The memory 103 may be any combination of a volatile memory and a non-volatile memory. The volatile memory (e.g., random access memory (RAM)) provides a temporary storage area for operations to the processing circuit 105. The non-volatile memory (e.g., read-only memory (ROM) and hard disk) stores one or more computer programs and various data.
[0028] The processing circuit 105 includes one or more processors (e.g., central processing unit (CPU)) capable of executing a computer program stored by the memory 103. In the present embodiment, the processing circuit 105 functions as a setting unit 121, an evaluation unit 122, and an information output unit 123. Details of these functional modules will be described later.
[0029] The input device 107 is a device for the management server 100 to receive user input. The input device 107 may include, for example, one or more of a keyboard, a touch panel, a pointing device, a button, a switch, and a microphone. The output device 109 is a device for the management server 100 to output information. The output device 109 may include, for example, one or more of a display and a speaker.
[0030] The database 110 is a set of tables that holds data used for managing information related to security measures. FIG. 4 shows an example in which the management server 100 includes the database 110, but the database 110 may be realized as a database server separate from the management server 100.
[0031] <2-2. Configuration Example of Database> In the present embodiment, the database 110 includes a group table 111, a group table 112, a group-group table 113, a user table 114, a template table 115, a question table 116, a diagnosis assignment table 117, an answer table 118, and an evaluation result table 119.
[0032] The group table 111 is a table that holds information related to each group under the management of the system. The group table 111 may include data items such as the following: · "Group ID" · "Group name" · "Responsible member" · Any one or more group attributes "Group ID" is an identifier that uniquely identifies each group. "Group name" represents the name of each group. "Responsible member" identifies the responsible member, who is the user who should answer the security diagnosis, by the user ID in the user table 114 when the responsible member is set at the group level. It may be possible to set more than one responsible member for one group. Group attributes may include, for example, representative address, representative name, and group type.
[0033] The group table 112 is a table that defines the hierarchical structure of groups and subgroups. The group table 112 may include data items such as the following: · "Group ID" · "Parent group" · "Group name" · "Responsible member" · "Administrative member" "Group ID" is an identifier that uniquely identifies each group / subgroup. "Parent group" identifies, by its group ID, the group or subgroup corresponding to the parent of each subgroup in the hierarchical structure. "Group name" represents the name of each group / subgroup. "Responsible member" is identified by the user ID in user table 114 when a responsible member who has the responsibility for answering security diagnosis is set for each subgroup. The responsible member of a subgroup may answer the security diagnosis of the organization belonging to the subgroup by themselves, or may request an answer from the responsible member of each organization. It may be possible to set more than one responsible member for one subgroup. "Administrative member" is identified by the user ID in user table 114 when the authority to perform security diagnosis-related settings is granted to a user other than the system administrator. It may be possible to set more than one administrative member for one subgroup. The authority of each member may be set individually for functions such as further addition (invitation) of members, association of organizations with subgroups, creation of templates, assignment of diagnoses to organizations, input of answers, approval of the input answers, viewing of evaluation information for each organization, and viewing of statistical information for each subgroup.
[0034] The organization-group table 113 is a table that defines the association between subgroups and organizations. The organization-group table 113 may include data items such as the following: · "Related subgroup" · "Organization" "Related subgroup" identifies one of the subgroups registered in the group table 112 by its group ID. "Organization" identifies the organization associated with the subgroup identified by the "related subgroup" by its organization ID. Thus, one record in the organization-group table 113 defines the association of one organization with one subgroup. In the present embodiment, it is assumed that at least one organization is directly or indirectly associated with each subgroup (i.e., each subgroup has at least one organization under it).
[0035] The user table 114 is a table that holds information about users involved in the operation of the information management system 1. The user table 114 may include data items such as the following: · "User ID" · "User name" · "Affiliated organization" · Any one or more user attributes "User ID" is an identifier that uniquely identifies each user. "User name" represents the name of each user. "Affiliated organization" identifies the organization to which each user belongs by its organization ID. User attributes may include, for example, an email address and the language used.
[0036] The template table 115 is a table that holds information about templates for security diagnosis. The template table 115 may include data items such as the following: · "Template ID" · "Template name" · "Related group" · "Author" "Template ID" is an identifier that uniquely identifies each template. "Template Name" represents the name of each template. In this embodiment, each security diagnosis may be either a standard diagnosis consisting of a standard set of questions or a customized diagnosis consisting of a set of questions created uniquely by the user. "Related Group" identifies the target subgroup by its group ID when the customized diagnosis is created for a specific subgroup. "Creator" identifies the user who created the customized diagnosis by their user ID.
[0037] Question table 116 is a table that holds a set of security-related questions that make up each template of the security diagnosis registered in template table 115. Question table 116 may include data items such as the following: · "Related Template" · "Question Number" · "Category" · "Question Text" · "Option Type" "Related Template" identifies the template to which each question belongs by its template ID. "Question Number" is a number that uniquely identifies each question. "Category" identifies the category into which each question is classified among a plurality of predefined category candidates. Just an example, in this embodiment, it is assumed that four category candidates, namely "Strategy", "People and Organization", "Technology", and "Emergency Response", are predefined. Note that multi-level category classification such as "major category" and "medium category" may be performed. Also, it may be possible for the user to define their own category candidates in advance. "Question Text" defines the text of each question displayed on the answer input screen. "Option Type" represents the type of options for the answer to each question. For example, one option type may be "Yes / No", another option type may be "Documented / Defined / No", and yet another option type may be "Performed / Documented / Defined / No".
[0038] The diagnosis assignment table 117 is a table that holds information related to the assignment of diagnoses to each group. The diagnosis assignment table 117 may include data items such as the following: · "Diagnosis ID" · "Target group" · "Template" · "Assignment date" · "Response date" "Diagnosis ID" is an identifier that uniquely identifies each security diagnosis assigned to a group. "Target group" specifies the group to which each diagnosis is assigned by its group ID. "Template" specifies the template used for each diagnosis by its template ID. "Assignment date" represents the date on which a security diagnosis was assigned to a group. "Response date" represents the date on which a response was submitted for each diagnosis.
[0039] The response table 118 is a table that holds information on responses submitted to questions of security diagnoses assigned to each group. The response table 118 may include data items such as the following: · "Diagnosis ID" · "Question number" · "Response" "Diagnosis ID" specifies the security diagnosis that is the subject of the response by its diagnosis ID. "Question number" specifies each question that makes up each diagnosis by the question number in the question table 116. "Response" represents the number of the option selected as the response to each question. The "Response" for questions that have not been answered is blank.
[0040] The evaluation result table 119 is a table that holds evaluation information generated based on responses submitted for each diagnosis. The evaluation result table 119 may include data items such as the following: · "Target diagnosis" · "Rank" · "Total score" · "Total standard score" · "Category score 1" to "Category score N" · "Category standard score 1" to "Category standard score N" "Target diagnosis" identifies the security diagnosis to be evaluated by its diagnosis ID. "Rank" represents the rank determined by the evaluation unit 122 described below in each evaluation. The rank may be represented by an alphabet such as, for example, "S", "A", "B", "C", or "D", where "S" is the highest rank (the strongest security measure) and "D" is the lowest rank (the weakest security measure). "Overall score" represents the overall score calculated across multiple categories in each evaluation. "Overall deviation value" represents the deviation value calculated for the overall score. "Category score 1" to "Category score N" represent the scores calculated for each category in each evaluation. When four category candidates are predefined as described above, N = 4. "Category deviation value 1" to "Category deviation value N" represent the deviation values calculated for the category scores.
[0041] Note that the configuration of the database 110 described in this section is just an example. Each table in the database 110 may have additional data items or may not have some of the described data items. One described table may be divided into multiple tables, or multiple described tables may be integrated into one table.
[0042] <2-3. Typical work flow> Figure 5 is a sequence diagram showing a typical work flow of security diagnosis in the information management system 1 along an exemplary scenario. The sequence shown in Figure 5 is roughly divided into three stages: a setting stage S10, an evaluation stage S20, and an information output stage S30.
[0043] (1) Setting stage In the setting stage S10, the setting unit 121 of the management server 100 accepts user input for various settings related to security diagnosis in the information management system 1, and registers the settings in the database 110 according to the accepted user input. In particular, in this embodiment, the setting unit 121 sets one or more subgroups constituting a hierarchical structure within a group including multiple organizations under the management of the system. The subgroup-related setting items may include, for example, at least one of the following: Adding a subgroup · Associating an entity to a subgroup -Rename subgroups -Adding attributes to subgroups
[0044] For example, the system administrator selects a parent group or subgroup on a group setting screen provided by the setting unit 121 and instructs the addition of a new subgroup. In response to the instruction to add a subgroup, the setting unit 121 registers a record including the group ID, group name, and group ID of the parent group of the new subgroup in the group table 112. In addition, the system administrator selects a parent subgroup and an organization to be associated with the subgroup on the group setting screen and instructs the association of the organization with the subgroup. In response to the instruction to associate the organization, the setting unit 121 registers a record including the group ID of the selected subgroup and the organization ID of the selected organization in the organization-group table 113. It may also be possible to change the name of a subgroup, delete a subgroup, and cancel the association of an organization.
[0045] In the group setting screen, it may be possible to assign some attributes to a subgroup. The attributes of the subgroup may be selected by the user and stored in the data items of the group table 112. Additionally or alternatively, the attributes of the subgroup may be tagged to the subgroup as user tags that can be arbitrarily set by the user. Additionally or alternatively, the attributes of the subgroup may be automatically assigned based on the group attributes of the subordinate groups. By assigning attributes to the subgroup, it becomes possible to statistically analyze the evaluation information based on the attributes.
[0046] In the scenario of FIG. 5, in step S11, user U1 adds subgroup SG3 as a new subgroup to the group hierarchy and associates groups B3 and B4 with subgroup SG3.
[0047] Also, the setting unit 121 can set, for each subgroup, a responsible member who is responsible for the answering work regarding the security diagnosis assigned to the groups subordinate to the subgroup. For example, the system administrator designates, on the group setting screen, the user who should be the responsible member of each subgroup. The setting unit 121 registers the user ID of the designated user in the "responsible member" of the record of the corresponding subgroup in the group table 112 according to the designation of the responsible member. In this way, by enabling the setting of the responsible member for promoting the answering work regarding the security diagnosis on a subgroup-by-subgroup basis, the workload for setting the responsible member can be reduced. Note that the responsible member may be set on a group basis instead of a subgroup basis.
[0048] Furthermore, the setting unit 121 can set, for each subgroup, a management member who manages security diagnosis-related settings. For example, the system administrator designates, on the group setting screen, the user who should be the management member of each subgroup. The setting unit 121 registers the user ID of the designated user in the "management member" of the record of the corresponding subgroup in the group table 112 according to the designation of the management member. In this way, by enabling the system administrator who manages the settings of the entire group to delegate the setting work to the management members who manage the settings for each subgroup, it is possible to obtain the support of the management members who are expected to be more familiar with the actual situation on site, reduce the workload of the system administrator, and streamline the security management operations within a large-scale group.
[0049] In the scenario of FIG. 5, in step S12, the user U1 sets the user U3 as the person in charge for the subgroup SG3. Since the groups B3 and B4 are associated with the subgroup SG3, the user U3 will have the role of answering the security diagnosis assigned to the group B3 and the security diagnosis assigned to the group B4.
[0050] Furthermore, the setting unit 121 can set, for each subgroup, a common template for the security diagnosis to be assigned to the groups under the subgroup. The template here can be selected from one or more templates prepared in advance for standard diagnosis and one or more templates created by the system administrator or management member for customized diagnosis. As an example, a template based on the information security guidelines defined in the relevant industry may be set for a subgroup set up from the perspective of business segments. As another example, a template based on the regulations defined in the region may be set for a subgroup set up from the perspective of the region. In this way, by enabling the retention of a common template for each subgroup, it becomes possible to achieve both the setup of security diagnosis in line with the actual situation of each subgroup and the improvement of management efficiency through the reuse of the question set.
[0051] For example, a system administrator selects a certain subgroup on the group setting screen and specifies a security diagnosis template to be set for the selected subgroup. In response to the specification of the template, the setting unit 121 assigns security diagnoses based on the specified template to all organizations under the selected subgroup in a batch. The assignment of security diagnoses can be performed by registering a record including the organization ID and the template ID in the diagnosis assignment table 117. Note that the assignment of security diagnoses may be performed on a per-organization basis instead of on a per-subgroup basis.
[0052] In the scenario of FIG. 5, at step S13, user U1 creates a set of questions for a template for customized diagnosis (this step is omitted when standard diagnosis is used). Next, at step S14, user UI sets a specific template (for example, the template created at step S13 or the template for standard diagnosis) for subgroup SG3. As a result, security diagnoses based on a common template (i.e., having the same set of questions) are automatically assigned to organizations B3 and B4 belonging to subgroup SG3, respectively.
[0053] FIG. 6 is an explanatory diagram showing an example of the configuration of a group setting screen according to an embodiment. Referring to FIG. 6, the group setting screen 50 includes a navigation area 51a and a setting area 51b.
[0054] In the navigation area 51a, a list of configured groups and subgroups constituting a hierarchical structure is displayed in a tree form (in the initial state, only the top-level group). The system administrator can find the target subgroup by entering the group name (or a part thereof) in the search field 52. Buttons 53a, 53b, 53c, and 53d are buttons for switching the display state of the list of subgroups and organizations under the corresponding node between display and non-display.
[0055] The setting area 51b is an area that accepts operations for various settings regarding the subgroup selected in the navigation area 51a. In the setting area 51b, the name of the selected subgroup, a list of subordinate organizations, a list of group members (person in charge and administrator), and several setting-related UI objects are displayed. In the example of FIG. 6, the subgroup SG3 is selected. The system administrator can call up a further screen for adding a new subgroup with the subgroup SG3 as the parent group by operating the button 54. Also, the system administrator can call up a further screen for associating an organization (for example, organization B4) with the subgroup SG3 by operating the button 55. Also, the system administrator can call up a further screen for setting a person in charge or an administrator at the subgroup level for the subgroup SG3 by operating the button 56. Also, the system administrator can call up a further screen for batch-assigning security diagnoses at the subgroup level to the subgroup SG3 by operating the button 57. Since the configuration of these further screens can be designed by those skilled in the art based on ordinary knowledge, a detailed description thereof is omitted.
[0056] In one embodiment, the setting unit 121 is assumed to be able to associate the same organization with a plurality of different subgroups. For example, the organization B6 associated with the subgroup SG2 in FIG. 1 may be substantially the same organization as the organization B3 associated with the subgroup SG3. By allowing duplicate registration of the same organization in this way, it becomes possible to form a hierarchical structure of groups so that security measures for a common set of organizations can be evaluated from different perspectives, such as evaluation by business segment and evaluation by region.
[0057] (2) Evaluation stage In the evaluation stage S20, the evaluation unit 122 of the management server 100 requests the person in charge of each group to answer regarding the security diagnosis assigned to the group. When an answer to a question constituting the security diagnosis is submitted in response to the request, the evaluation unit 122 quantitatively evaluates the security measures for each group based on the submitted answer.
[0058] In the present embodiment, in addition to being able to accept requests for answers regarding security diagnosis on a group basis, requests for answers can also be accepted on a subgroup basis. Specifically, as described above, the database 110 of the management server 100 holds templates for security-related questions to be applied to specific subgroups. When the evaluation unit 122 selects this specific subgroup and is instructed to request answers, it collectively requests answers from one or more groups associated with the subgroup. Then, the evaluation unit 122 generates evaluation information based on the answers submitted from each of those groups. By enabling requests for answers to be made collectively on a subgroup basis in this way, the workload of the system administrator or management member is further reduced.
[0059] For example, the system administrator selects a target subgroup on the diagnosis selection screen and instructs a request for answers. In response to the instruction for the request for answers, the evaluation unit 122 sends a request for answers message (e.g., an email) to the corresponding person in charge, requesting an answer to the security diagnosis assigned to the groups under the selected subgroup. The request for answers message may describe a URL (Uniform Resource Locator) for accessing the answer input screen as described with reference to FIG. 2. In response to receiving the request for answers message, the person in charge accesses the answer input screen for the security diagnosis assigned to the group they are in charge of. The person in charge enters answers for each question displayed on the screen based on the actual situation of the group they are in charge of, and submits the answers when the work is completed. The evaluation unit 122 generates evaluation information regarding the security measures for each group based on the answers submitted in this way.
[0060] In the scenario of FIG. 5, in step S21, user U1 selects subgroup SG3 and instructs management server 100 to request the person in charge to answer the security diagnosis assigned to the organization associated with subgroup SG3. At this time, organizations B3 and B4 are associated with subgroup SG3. Also, a security diagnosis based on the template set for subgroup SG3 in step S14 of the setting stage S10 is assigned to organizations B3 and B4. In step S22, evaluation unit 122 requests user U3, who is the person in charge of subgroup SG3, to answer the security diagnosis of organization B3 and the security diagnosis of organization B4. Note that in step S22, a message notifying that the request for an answer to the security diagnosis has been sent to the persons in charge of organizations B3 and B4 may be sent to user U3.
[0061] In step S23a, user U3 (or the person in charge of organization B3) accesses the answer input screen for organization B3 and enters an answer to the displayed question. When the answer operation is completed, user U3 performs an operation to submit the answer, and in response, in step S24a, the answer information is sent from user U3's terminal to management server 100. In response to receiving the answer information, in step S25a, evaluation unit 122 generates evaluation information regarding the security measures of organization B3. Then, in step S26a, evaluation unit 122 sends an end notification message indicating that the security diagnosis for organization B3 has been completed to user U1.
[0062] Similarly, in step S23b, user U3 (or the person in charge of group B4) accesses the response input screen for group B4 and inputs a response to the displayed question. When the response operation is completed, user U3 performs an operation to submit the response, and accordingly, in step S24b, the response information is transmitted from user U3's terminal to management server 100. In response to receiving the response information, evaluation unit 122 generates evaluation information regarding the security measures of group B4 in step S25b. Then, in step S26b, evaluation unit 122 transmits an end notification message indicating that the security diagnosis for group B4 has been completed to user U1.
[0063] After receiving the instruction for the response request, evaluation unit 122 may provide a diagnosis status screen that displays the diagnosis status for each subgroup and each individual group until responses are submitted from all the target groups.
[0064] FIG. 7 is an explanatory diagram showing an example of the configuration of a diagnosis status screen according to an embodiment. Referring to FIG. 7, diagnosis status screen 60 includes a summary area 61a and an individual group area 61b.
[0065] In summary area 61a, information indicating the overall diagnosis status for the selected subgroup is displayed. In the example of FIG. 7, the template name of the target security diagnosis, subgroup name, progress rate, start date (the date when the response request was sent), end target date, and a pie chart of the submission status for each group are displayed in summary area 61a. Here, the progress rate may be, for example, the ratio of the number of questions for which responses have been input to the total number of questions.
[0066] In the group individual area 61b, information indicating the diagnosis status of each group associated with the selected subgroup is displayed. In the example of FIG. 7, the group name, submission status, and progress rate for each group are displayed in the group individual area 61b. The icon 62 displayed in the group individual area 61b is an object for calling up the diagnosis result screen 40 for the group B1 for which the answer has been submitted. Since groups B3, B4, and B5 have not submitted their answers, similar icons are not displayed for these groups. Note that an icon for calling up a browsing screen that allows the user to view the content in progress for a group that has not submitted an answer may be provided in the group individual area 61b.
[0067] The generation of evaluation information based on the answers to the security-related questions for each diagnosis may be performed according to any method for QA-form security evaluation. For example, Patent Document 1 describes a method of calculating a total score of 1000 points with 250 points for each of four categories. In the method described in Patent Document 1, a score is assigned in advance to each of the options prepared for each question. As an example, the score for an option of the type "yes / no" may be 1 point for "yes" and 0 points for "no". The score for an option of the type "documented / defined / no" may be 1.0 point for "documented", 0.5 point for "defined", and 0 points for "no". In this example, the maximum score for each question is all 1 point and is uniform. As another example, a non-uniform score using weighting may be adopted. For example, the scores may be weighted among a plurality of questions using a weight correlated with the average value of known scores in a set of related groups, or a weight arbitrarily set by the system administrator. The evaluation unit 122 calculates a total score by aggregating the scores of the answers submitted from each group according to such uniform or non-uniform scores.
[0068] For each security diagnosis, the evaluation unit 122 generates evaluation information including at least the above-described overall score. The evaluation information generated by the evaluation unit 122 may further include one or more of the rank of the overall score, the deviation value of the overall score (overall deviation value), the score for each category, and the deviation value of the score for each category (category-specific deviation value). The rank of the overall score can be determined based on which pre-defined range the calculated overall score falls into (for example, "S" if 780 points or more, "A" if 640 points or more and less than 780 points, "B" if 500 points or more and less than 640 points, etc.). The evaluation unit 122 stores the generated evaluation information in the evaluation result table 119 in association with the diagnosis ID of the corresponding security diagnosis.
[0069] (3) Information output stage In the information output stage S30, the information output unit 123 of the management server 100 outputs the result of the security diagnosis via a user interface (UI). In this embodiment, in addition to being able to output the evaluation information generated by the evaluation unit 122 as the diagnosis result for an individual group, the information output unit 123 can output statistical information generated based on the evaluation information of one or more groups associated with a subgroup selected by the user as the diagnosis result regarding security measures for the subgroup unit.
[0070] The diagnosis result for an individual group may be output in a form of displaying the evaluation information on the diagnosis result screen 40 described with reference to FIG. 3, for example. Additionally or alternatively, a report describing the evaluation information may be output as a data file and downloaded to the user terminal, or may be printed by a printer. These also apply to the diagnosis results for the subgroup unit.
[0071] On the diagnosis selection screen provided by the information output unit 123, when the system administrator (or another user with viewing authority) selects the first subgroup and instructs the output of statistical information, the information output unit 123 generates statistical information regarding the security measures of the first subgroup based on the evaluation information held in the database 110 for one or more organizations (subordinate organizations) associated with the first subgroup. The statistical information regarding the security measures here may include at least one of the following information elements: · Statistical value of the scores regarding security measures aggregated for the subordinate organizations · Relative evaluation regarding security measures in the population including other organizations within the same group that are different from the subordinate organizations · Relative evaluation regarding security measures in the population including organizations outside the group that are different from the subordinate organizations
[0072] The statistical value of the scores in the statistical information at the subgroup level may include, for example, the average value, the maximum value, the minimum value, and the number of organizations by rank (rank distribution) of the scores of the subordinate organizations. By referring to such statistical values at the subgroup level, the user can efficiently determine, for example, whether the security measures in the supply chain of an individual region or business segment are sufficient, or whether there are variations in the security measures among the organizations within the supply chain.
[0073] The population including other organizations within the same group may mean, for example, a population spanning multiple subgroups (e.g., multiple regions or multiple business segments) within the same corporate group. The relative evaluation may include, for example, the deviation value or rank of the average score of each subgroup in such a population. By referring to such relative evaluations within the group, the user can efficiently determine, for example, in which region or business segment of the supply chain the security measures should be focused on for investment.
[0074] The population including groups outside the group may, for example, mean a population spanning multiple corporate groups. The population here may include as many groups as possible, or may include only some groups (for example, groups with similar attributes) selected based on the attributes of the first subgroup. By referring to such cross-group relative evaluations, the user can objectively grasp how strong (or weak) the security measures in the individual supply chain of the group to which the user belongs are compared to the measures of other groups. In particular, when the population is selected based on the attributes of the subgroup, more appropriate mutual comparisons become possible.
[0075] In the scenario of FIG. 5, in step S31, user U1 selects subgroup SG3 and instructs the output of statistical information on the diagnosis selection screen provided by information output unit 123. Then, in step S32, a statistical information request targeting subgroup SG3 is transmitted from user terminal 10 to management server 100. In response to the reception of the statistical information request, in step S33, information output unit 123 generates statistical information regarding the security measures of the selected subgroup SG3 based on the evaluation information about groups B3 and B4 under subgroup SG3. Then, in step S34, information output unit 123 causes the generated statistical information to be displayed on the display of user terminal 10.
[0076] Figures 8 and 9 are explanatory diagrams showing an example of the configuration of a diagnosis selection screen according to an embodiment. Referring to these figures, the diagnosis selection screen 70 includes a first tab 71a and a second tab 71b. Figure 8 shows a state in which the first tab 71a is selected. The first tab 71a includes a tree-like list consisting of groups, subgroups, and organizations. An icon 72 is displayed near the name of each organization. Also, an icon 73 is displayed near the group name of each subgroup, and an icon 74 is displayed near the group name of the top-level group. The icon 72 is an object for instructing the output of evaluation information about an individual organization (for example, when the icon 72 is operated, the diagnosis result screen 40 is called). The icon 73 is an object for instructing the output of statistical information in units of subgroups. The icon 74 is an object for instructing the output of statistical information for the entire group. When one of the icons 73 in the first tab 71a is operated, the information output unit 123 calls a statistical display screen 80 described later.
[0077] Figure 9 shows a state in which the second tab 71b is selected. The second tab 71b includes a flat list of a plurality of organizations under the group G1. An icon 72 is displayed near the name of each organization. In the prior art, such a flat list of security diagnoses was provided, but with such a simple list, it was difficult to grasp at a glance which organizations constituted a set such as a supply chain, and statistical information in units of subgroups was not output either. In contrast, in the present embodiment, the user can flexibly access security diagnoses in units of subgroups that can be set from various viewpoints according to a tree-like list as in the example of Figure 8, and can also view statistical information in units of subgroups.
[0078] FIG. 10 and FIG. 11 are explanatory diagrams showing an example of the configuration of a statistical display screen according to an embodiment. Referring to these figures, the statistical display screen 80 includes a first tab 81a and a second tab 81b. FIG. 10 shows a state where the first tab 81a is selected. The first tab 81a displays statistical information generated by the information output unit 123 for the selected subgroup "European region". The "European region" has 15 organizations under it, and security diagnoses have been completed for 14 of these organizations. In the illustrated example, as statistical information, the average score, the average score of other groups as a comparison criterion, the average deviation value, the highest score, the organization name that recorded the highest score, the organization name that recorded the lowest score, and a pie chart of the rank distribution are displayed on the first tab 81a. Of course, the statistical information generated and displayed by the information output unit 123 is not limited to the illustrated example. For example, a more detailed distribution of the scores of the organizations under it may be displayed in an arbitrary graph format. By browsing such statistical information, the user can recognize, for example, that although the security measures are at a high level as a whole for the set of organizations constituting the supply chain in the European region, there are organizations within the region whose scores are below the average of other groups.
[0079] FIG. 11 shows a state where the second tab 81b is selected. The second tab 81b displays a list of subgroups and organizations under the selected subgroup "European region". Each record includes, as display items, the name of the subgroup or organization, the rank, the score, and an icon for accessing the individual diagnosis result. By browsing such list-formatted information, the user can easily compare and consider the diagnosis results among the subgroups or organizations under the same subgroup.
[0080] <2-4. Flow of Statistical Output Processing> FIG. 12 is a flowchart showing an example of the flow of statistical output processing that can be executed by the information output unit 123 of the management server 100. The statistical output processing here may correspond to steps S32 to S34 of the information output stage S30 in FIG. 5.
[0081] First, in step S101, the information output unit 123 receives a statistical information request from the user terminal via the communication interface 101. The statistical information request may include a group ID that identifies a subgroup selected by the user.
[0082] Next, in step S102, the information output unit 123 identifies one or more organizations directly or indirectly associated with the selected subgroup, i.e., subordinate organizations, according to the settings registered in the group table 112 and the organization-group table 113 of the database 110.
[0083] Next, in step S103, the information output unit 123 obtains evaluation information regarding security measures for the identified organizations from the database 110. The evaluation information obtained here is information generated by the evaluation unit 122 based on the answers submitted by each organization to the questions constituting the security diagnosis.
[0084] Next, in step S104, the information output unit 123 generates statistical information regarding security measures for the selected subgroup by aggregating the evaluation information obtained from the database 110.
[0085] Next, in step S105, the information output unit 123 causes a statistical display screen showing the generated statistical information regarding security measures to be displayed on the display of the user terminal that is the source of the statistical information request.
[0086] <2-5. Summary> So far, the main embodiments of the present invention have been described. In the above-described embodiments, in an information management system that manages evaluation information regarding security measures for a group including a plurality of organizations, the evaluation information regarding the security measures for each organization is held in a database. Also, within the above group, one or more subgroups that constitute a hierarchical structure are set. Further, at least one organization is directly or indirectly associated with each subgroup. Then, when a first subgroup is selected by a user, statistical information regarding the security measures of the first subgroup is generated and output based on the evaluation information held in the above database. According to such a configuration, a quantitative evaluation regarding information security measures across a plurality of organizations can be flexibly provided. For example, even if the way of cooperation among organizations in a supply chain dynamically changes in accordance with changes in the business environment, the user can add or change the setting of subgroups in accordance with the changes and view statistical information at the subgroup level that conforms to the latest situation. In addition, accurate judgments for improving security measures are made by users who have viewed and considered statistical information from various viewpoints, making it possible to efficiently implement strong security measures at the group level.
[0087] <3. Modification Example> <3-1. First Modification Example> Various modification examples can be envisioned for the above-described embodiments. In a first modification example, after the evaluation unit 122 requests an answer to a security-related question from a first organization among the organizations within the group, it may wait for approval by at least one approver for the answer submitted from the first organization. The request for an answer here may be each of the requests for answers to a plurality of organizations made in units of subgroups, or may be a single request for an answer to an individual organization. The evaluation unit 122 generates evaluation information for the first organization on the condition that approval by an approver has been obtained for the answer input by the member in charge of the first organization. In this case, the evaluation unit 122 selects at least one approver to give approval based on the hierarchical structure of the group.
[0088] FIG. 13 is a sequence diagram showing an example of the workflow of security diagnosis according to the first modification. The sequence shown in FIG. 13 consists of a setting stage S60, an evaluation stage S70, and an information output stage S80.
[0089] The workflow in the setting stage S60 may be the same as the setting stage S10 in the sequence diagram of FIG. 5. However, in the scenario of FIG. 13, in step S61, the user U1 adds the subgroup SG3 to the group hierarchy with the subgroup SG1 as the parent group. The group B1 is directly associated with the subgroup SG1. The group B3 is directly associated with the subgroup SG3 (and as a result, indirectly associated with the subgroup SG1). Also, in step S62, the user U1 sets the user U3 as the person in charge of the security diagnosis of the group associated with the subgroup SG3, and sets the user U2 as the approver of the security diagnosis of the group associated with the subgroup SG1. Since the subgroup SG1 is a higher-level group than the subgroup SG3, the user U2 will be requested to approve the security diagnosis of the groups under the subgroup SG3. In step S64, the user UI sets a template for the subgroup SG3, and as a result, a security diagnosis based on the set template is assigned to the group B3 belonging to the subgroup SG3.
[0090] In the evaluation stage S70, in step S71, user U1 selects subgroup SG3 and instructs management server 100 to request an answer to the security diagnosis for the organization associated with subgroup SG3. In step S72, evaluation unit 122 requests user U3, who is a member in charge of subgroup SG3, to answer the security diagnosis for organization B3. Incidentally, to repeat, a message notifying that a request for an answer to the security diagnosis has been sent to the member in charge of organization B3 may be sent to user U3. In step S73, user U3 (or the member in charge of organization B3) accesses the answer input screen for organization B3 and inputs an answer to the displayed questions. When the answering operation is completed, user U3 performs an operation for submitting the answer, and accordingly, in step S74, answer information is sent from user U3's terminal to management server 100.
[0091] In response to receiving the answer information, in step S75, evaluation unit 122 requests user U2 to approve the answer input for the security diagnosis of organization B3. In step S76, user U2 accesses the screen displaying the answer to the security diagnosis of organization B3, checks the accuracy of the input answer, and performs an operation for approval if there are no problems. In response to that operation, in step S77, a message indicating that the answer has been approved is sent from user U2's terminal to management server 100. In response to receiving this message, in step S78, evaluation unit 122 generates evaluation information regarding the security measures of organization B3. Then, in step S79, evaluation unit 122 sends an end notification message indicating that the security diagnosis for organization B3 has been completed to user U1. Incidentally, if user U2 rejects the approval for reasons such as the input answer not being consistent with the actual situation of organization B3, evaluation unit 122 requests user U3 to answer again.
[0092] In addition, when a request for an answer is sent to the member in charge of Group B3 in step S72, in addition to user U2 in subgroup SG1, user U3 in subgroup SG3 may be set as an approver. In this case, the evaluation unit 122 first requests user U3 to approve the answer input by the member in charge of Group B3 regarding the security diagnosis of Group B3. User U3 checks the input answer and performs an operation for approval if there is no problem (primary approval). In response to the primary approval being performed, the evaluation unit 122 further requests user U2 to approve the answer input by the member in charge of Group B3. User U2 checks the input answer and performs an operation for approval if there is no problem (secondary approval). In response to the secondary approval being performed, the evaluation unit 122 generates evaluation information regarding the security measures of Group B3. The evaluation unit 122 can select approvers for such two-stage or more approvals based on the hierarchical structure of the group.
[0093] The workflow in the information output stage S80 may be the same as the information output stage S30 in the sequence diagram of FIG. 5. In step S81, user U1 selects subgroup SG3 on the diagnosis selection screen provided by the information output unit 123 and instructs the output of statistical information. Then, in step S82, a statistical information request targeting subgroup SG3 is sent from the user terminal 10 to the management server 100. In response to the reception of the statistical information request, the information output unit 123 generates statistical information regarding the security measures of the selected subgroup SG3 in step S83. Then, in step S84, the information output unit 123 causes the generated statistical information to be displayed on the display of the user terminal 10.
[0094] As in the first modification example, by making the condition for generating evaluation information that approval by an approver selected based on the hierarchical structure of the group is obtained for the answer to the security diagnosis, it is possible to prevent the generation of low-reliability evaluation information and statistical information due to inaccurate answers. In addition, in this case, since there is no need to individually select and set an approver for each security diagnosis, the workload of the system administrator or management member is reduced.
[0095] <3-2. Second Modification Example> In addition to quantitative evaluation regarding security measures, information security is improved by reviewing the measures based on the evaluation and steadily implementing the measures. Generally, since the security measures to be implemented differ for each organization, what measures should be implemented by when is defined as a task for each organization, and the progress of the task is managed by the administrator of each organization.
[0096] However, in order to achieve and maintain the required security level for a collection of multiple organizations such as a supply chain, it is desirable to provide a task management mechanism that spans multiple organizations. Therefore, in the second modification example, the management server 100 of the information management system 1 is capable of outputting not only statistical information on the evaluation regarding security measures in units of subgroups but also task information regarding security measures in units of subgroups.
[0097] FIG. 14 is a block diagram showing an example of the configuration of the management server 100 according to the second modification example. Referring to FIG. 14, the management server 100 includes a communication interface 101, a memory 103, a processing circuit 205, an input device 107, an output device 109, and a database 210.
[0098] The processing circuit 205 includes one or more processors (e.g., a CPU) capable of executing a computer program stored by the memory 103. In this modification example, the processing circuit 205 functions as a setting unit 221, an evaluation unit 122, an information output unit 223, and a task generation unit 224.
[0099] The database 210 is a set of tables that holds data used for managing information related to security measures. In this modified example, the database 210 includes a group table 111, a group table 112, a group-group table 113, a user table 114, a template table 115, a question table 216, a diagnosis assignment table 117, an answer table 118, an evaluation result table 119, and a task table 220.
[0100] The question table 216 is a table that holds a set of security-related questions that make up each of the templates of the security diagnosis registered in the template table 115, similar to the question table 116 described above. The question table 216 may include data items such as the following: · "Related template" · "Question number" · "Category" · "Question text" · "Option type" · "Task generation option" · "Answer trigger task" · "Trigger type" "Related template", "Question number", "Category", "Question text", and "Option type" are the same data items as those described in relation to the question table 116. "Task generation option" indicates an option for an answer that triggers the generation of task items by the task generation unit 224 described later. For example, for a question with an option type of "Yes / No" asking whether a certain action has been performed, the "task generation option" indicates "No". When a person in charge of a certain group selects "No" for this question and submits an answer to the security diagnosis, the performance of the said action can be generated as a new task item and registered in the task table 220. As will be described later, new task items based on the answers to the security diagnosis may be automatically generated, or may be generated after being proposed to the user and approved by the user. "Answer trigger task" is a set of information defining the content of task items (such as title, detailed description, priority, and period, etc.) generated based on the answers to each question. "Trigger type" indicates whether the generation of task items of the answer trigger task is automatically performed (answer trigger task of the first type) or is performed after approval by the user (answer trigger task of the second type).
[0101] The task table 220 is a table that holds task information related to task items generated by the task generation unit 224. The task table 220 may include, for example, the following data items: · "Task ID" · "Related group" · "Title" · "Detailed description" · "Priority" · "Generation date" · "Due date" · "Person in charge" · "Related question" · "Status" "Task ID" is an identifier that uniquely identifies each task item. "Related organization" specifies the organization associated with each task item by its organization ID. "Title" is a short string that concisely represents the content of each task item. "Detailed description" is text that elaborately explains the content of each task item. "Priority" represents the priority set for each task item and indicates one of a plurality of predefined candidate values such as "Low", "Medium", "High", and "Urgent". "Generation date" represents the date on which each task item was generated and registered in the task table 220. "Due date" represents the date by which the action corresponding to each task item should be carried out. The default value of the due date may be the date obtained by adding a predetermined period to the generation date. "Responsible member" specifies the user responsible for carrying out the action corresponding to each task item by the user ID in the user table 114. "Related question" identifies the question that triggered the generation of a task item generated based on the answer to the security diagnosis. "Status" represents the progress status of the action corresponding to each task item and indicates one of a plurality of predefined candidate values such as "Not started", "In progress", "On hold", and "Completed".
[0102] The setting unit 221 provides the same setting function as the above-described setting unit 121. Further, in this modification example, the setting unit 221 accepts the setting of the answer trigger task by the management member on the setting screen of the template for the security diagnosis. FIG. 15 is an explanatory diagram showing an example of the configuration of the template setting screen according to this modification example. Referring to FIG. 15, the template setting screen 250 includes a question list area 251 and a question setting area 252.
[0103] The question list area 251 is an area for displaying a list of questions included in the template to be set. The question setting area 252 is an area for accepting settings for the question selected in the question list area 251. In the example of FIG. 15, the question with the question number "Q3" is selected.
[0104] The question setting area 252 includes a question text field 253, a pull-down menu 254, radio buttons 255, a pull-down menu 256, check boxes 257, and a detailed setting button 258. The question text field 253 is a field for accepting the input of the question text of the selected question. The pull-down menu 254 is an object for accepting the setting of the option type of the answer to the question. The radio buttons 255 are objects for accepting the setting of whether to generate a task based on the answer to the question. The pull-down menu 256 is an object for accepting the setting of the option that triggers the generation of a task among a plurality of options of the option type set in the pull-down menu 254 when the generation of a task based on the answer is enabled. The check boxes 257 are objects for accepting the setting of the type of answer trigger task. In the example of FIG. 15, when the check box 257 is off, the type of answer trigger task is set to the first type (i.e., automatic generation), and when the check box 257 is on, the type of answer trigger task is set to the second type (i.e., generation after user approval). The detailed setting button 258 is a button for calling up a further screen for accepting the setting of the content of the task items to be generated (such as headings, detailed descriptions, priorities, and periods, etc.) when the generation of a task based on the answer is enabled. It may be possible to set a plurality of answer trigger tasks for one question. Here, the plurality of answer trigger tasks may be associated with the same option or different options. Also, although not shown in FIG. 15, in the question setting area 252, a list of tasks already set for each question may be further displayed. The setting unit 221 accepts the setting of the answer trigger task via such a setting screen and registers the accepted setting in the question table 216.
[0105] The task generation unit 224 generates task information regarding the security measures of each organization. Specifically, when an answer to the security diagnosis of an organization is submitted, the task generation unit 224 generates task items of the answer trigger task based on the submitted answer.
[0106] As an example, assume that for one or more questions for which a first type of answer trigger task is set, an option to trigger task generation in the submitted answer is selected. In this case, the task generation unit 224 generates task items of those answer trigger tasks according to the setting of the answer trigger tasks in the question table 216, and registers corresponding records in the task table 220.
[0107] As another example, assume that for one or more questions for which a second type of answer trigger task is set, an option to trigger task generation in the submitted answer is selected. In this case, the task generation unit 224 proposes to the user to generate task items of the answer trigger task on a screen that may be displayed after the answer is submitted, according to the setting of the answer trigger task in the question table 216. On this screen, the text of the message proposing the generation of task items may change according to the priority of the task items (or other task-related information). Then, when an operation for instructing the generation of task items (i.e., approval of generation) is performed by the user, the task generation unit 224 generates those task items and registers corresponding records in the task table 220. When the task generation unit 224 proposes to the user to generate a plurality of task items, only some of the task items selected according to the user input (e.g., on the screen) among the task items included in the proposal may be generated. The task items to be generated may be selected individually, or may be selected collectively by specifying attributes such as the category or priority of related questions. When the user defers the generation of current task items at the time of answer submission, the task generation unit 224 may additionally provide a screen that enables the user to instruct the generation of those task items later.
[0108] In any case, the due date of the newly generated task item may be a default due date, and the status may be set to "not started". Also, on the screen that may be displayed after the submission of the answer to the security diagnosis, the user may be able to set or change information such as the due date, priority, and person in charge of each answer trigger task. When an answer to the security diagnosis is resubmitted, the task generation unit 224 may update the status in the task table 220 of the task items that have been generated in the past based on the resubmitted answer.
[0109] The task generation unit 224 may be able to generate a new task item according to user input on the screen (for example, a task generation screen not shown) without depending on the answer to the security diagnosis. That is, the task item in this modification example may include one or both of the task items generated based on the answer to the security diagnosis and the task items generated by the user. The task items generated by the user may or may not be associated with a specific question of the security diagnosis.
[0110] The task generation unit 224 may further provide a task management screen for accepting the editing of existing task items. For example, the management member may be able to edit the heading or detailed description of each task item, change the priority, change the due date, assign the person in charge, and change the status on the task management screen.
[0111] The information output unit 223 provides the same information output function as the information output unit 123 described above. Further, in this modification example, the information output unit 223 outputs the task information registered in the task table 220 via the UI. In particular, in addition to being able to output task information in units of groups, the information output unit 223 is also able to output task information in units of subgroups.
[0112] FIG. 16 is an explanatory diagram showing an example of the configuration of a task display screen according to this modified example that can be provided by the information output unit 223. Referring to FIG. 16, the task display screen 260 includes a group selection menu 261, a condition selection menu 262, a list display area 263, and a display switching button 264.
[0113] The group selection menu 261 is an object that accepts a selection of one of a subgroup or an organization as the range of task information displayed in the list display area 263. For example, a management member or a person in charge of a subgroup can select, in the group selection menu 261, a subgroup for which the person has viewing authority or an organization under the subgroup. The condition selection menu 262 is an object that accepts a selection of filtering conditions for the task information displayed in the list display area 263. For example, one or more of the following filtering conditions may be applicable: · All task items · Task items associated with questions in a specific category · Task items whose priority indicates a specific value · Task items whose creation date belongs to a specific period · Task items whose due date belongs to a specific period · Task items for which the person in charge is a specific member · Task items whose status indicates a specific value In the example of FIG. 16, “Italian region” is selected as the subgroup, and “Category - Technology” is selected as the filtering condition. As a result, a list of task items associated with the questions in the “Technology” category of the organizations associated with the “Italian region” is displayed in the list display area 263. The list display area 263 displays the organization name, task heading, status, priority, and due date of these task items. However, what data items are displayed in the list display area 263 is not limited to the example of FIG. 16. The data items displayed in the list display area 263 may be set by the management member. When a specific task item is selected in the list display area 263, the information output unit 223 displays a task details screen (not shown) that displays the detailed content of the selected task item. In the task display screen 260 or the task details screen, the status of each task item may be updatable.
[0114] The display switching button 264 is a button for changing the screen display from the task display screen 260 to the statistical display screen 80 described with reference to FIGS. 10 and 11. A button for transitioning from the statistical display screen 80 to the task display screen 260 may be added. Alternatively, a third tab for displaying task information similar to the task display screen 260 may be added to the statistical display screen 80.
[0115] In the screen as exemplified above, when a specific subgroup (the first subgroup) is selected by the user and a first user operation for requesting output of statistical information is performed, the information output unit 223 outputs the above-described statistical information regarding the first subgroup to the screen. Also, when the first subgroup is selected by the user and a second user operation for requesting output of task information is performed, the information output unit 223 outputs task information regarding the first subgroup. The task information regarding the first subgroup may include, for example, a list of task items for each of at least one organization associated with the first subgroup.
[0116] In this way, in this modified example, by providing task information in units of subgroups, it is possible to efficiently manage efforts to maintain or improve the information security of a supply chain consisting of multiple organizations. Since the setting of subgroups can be flexibly changed, even if the organizations constituting the supply chain change dynamically, task management can quickly adapt to the change.
[0117] Also, in this modified example, on a series of screens, statistical information in units of subgroups based on evaluation information regarding security measures and task information in units of subgroups regarding security measures are provided. Therefore, a user who manages the information security of the supply chain can objectively grasp the achievement level of the current information security of the supply chain and efficiently and seamlessly confirm the implementation status of the security measures.
[0118] Furthermore, in this modified example, the task information regarding the security measures of each organization includes task items generated based on the answers submitted by the organization to security-related questions. In this way, by using the answers to security-related questions as a trigger for generating task items, tasks that contribute to maintaining or improving the information security of the supply chain or individual organizations can be efficiently added to the scope of task management. When task items are automatically generated based on the answers to security-related questions, it is possible to reliably prevent important task items from being omitted from task management. Also, when task items are generated through proposals to the user and approval by the user, task items recognized as necessary by the user can be efficiently or selectively included in task management.
[0119] <3-3. Other Modified Examples> To reiterate, the content of the evaluation information and the statistical information is not limited to the examples described in this specification. In a certain modification, the evaluation information may include the ratio of specific options selected for a set of security diagnosis questions. For example, the evaluation unit 122 may calculate the "implementation rate" as the ratio of the questions for which "implemented" or "yes" was actually selected among all the questions asking whether any action (for example, each action recommended to be implemented in a given security guideline) was implemented. The statistical information may include the average value of such implementation rates across the organizations under each subgroup. In another modification, instead of being generated based on the answers to security-related questions, the evaluation information may be generated by automatically diagnosing the vulnerability of the information system of each organization.
[0120] The invention is not limited to the above embodiments, and various modifications and changes are possible within the scope of the gist of the invention.
Explanation of Reference Numerals
[0121] 1... Information management system, 10... User terminal, 30... Answer input screen, 40... Diagnosis result screen, 50... Group setting screen, 60... Diagnosis status screen, 70... Diagnosis selection screen, 80... Statistical display screen, 100... Management server, 110, 210... Database, 121, 221... Setting unit, 122... Evaluation unit, 123, 222... Information output unit, 224... Task generation unit, 250... Template setting screen, 260... Task display screen, G1... Group, SG1 to SG3... Subgroups, B1 to B6... Organizations, U1 to U3... Users, S10, S60... Setting stages, S20, S70... Evaluation stages, S30, S80... Information output stages
Claims
1. An information management system for managing evaluation information on security measures for a group including a plurality of organizations, comprising: a database that holds evaluation information on security measures for each organization; a setting unit that sets in the group one or more subgroups that form a hierarchical structure, with at least one organization directly or indirectly associated with each subgroup; an information output unit that, when a first subgroup among the one or more subgroups is selected by a user, generates statistical information on security measures for the first subgroup based on the evaluation information held in the database and outputs the generated statistical information; The information management system comprising.
2. The information management system according to claim 1, further comprising an evaluation unit that generates the evaluation information based on responses submitted by each organization to security-related questions.
3. The information management system according to claim 1, wherein the setting unit can associate the same organization with a plurality of different subgroups.
4. The database further holds templates of security-related questions to be applied to a specific subgroup, and the evaluation information for the organizations associated with the specific subgroup is generated based on responses to security-related questions based on the templates. The information management system according to claim 2.
5. The evaluation unit: requests a response to a security-related question from a first organization among the plurality of organizations; awaits approval by at least one approver for the response submitted by the first organization; generates the evaluation information for the first organization after the approval is obtained; wherein the at least one approver is selected based on the hierarchical structure. The information management system according to claim 2.
6. The statistical information on security measures for the first subgroup is: a statistical value of scores related to security measures aggregated for one or more organizations associated with the first subgroup; a relative evaluation of security measures in a population including other organizations within the group, different from the one or more organizations associated with the first subgroup; and A relative evaluation regarding security measures in a population including groups outside the group, different from the one or more groups associated with the first subgroup, The information management system according to claim 1, including at least one of them.
7. The information management system according to claim 6, wherein the population is selected based on attributes assigned to the first subgroup.
8. The database further holds task information regarding security measures for each group, The information output unit, When the first subgroup is selected by the user and a first user operation is performed, outputs the statistical information generated based on the evaluation information, When the first subgroup is selected by the user and a second user operation different from the first user operation is performed, outputs the task information of at least one group associated with the first subgroup. The information management system according to claim 1.
9. The task information regarding security measures for each group includes task items generated based on answers submitted by the group to security-related questions. The information management system according to claim 8.
10. The information management system, A generation unit that automatically generates the task items based on the submitted answer when the answer is submitted to a security-related question, The information management system according to claim 9, further including.
11. The information management system, When the answer is submitted to a security-related question, proposes to the user to generate the task items based on the submitted answer, and generates the task items when the generation of the task items is instructed by the user. A generation unit, The information management system according to claim 9, further including.
12. The generation unit according to claim 11 is capable of generating the task items selected according to user input among the task items included in the proposal. The information management system according to claim 11.
13. The task information of the at least one group associated with the first subgroup includes a list of task items generated for each of the at least one group. The information management system according to any one of claims 8 to 12.
Citation Information
Patent Citations
Security evaluation system and security evaluation method
JP7026475B2
Cited By
Information processing system, information processing method and program
JP7792041B1