Information processing system, information processing method, and program

The information processing system addresses the lack of comprehensive security management in cloud services by enabling administrators to set policies and display user-specific lists with usage permissions, ensuring secure access control.

JP2025159772AActive Publication Date: 2025-10-22BIZREACH INC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024062515
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-09
Publication Date
2025-10-22
Estimated Expiration
2044-04-09

AI Technical Summary

Technical Problem

Existing cloud service management systems lack comprehensive security management capabilities, necessitating improved methods to evaluate and control access based on security conditions.

Method used

An information processing system that includes a server device and client devices, allowing administrators to set security policies for cloud services and display user-specific lists with label information indicating usage permissions based on security evaluations.

Benefits of technology

Enables organizations to manage cloud service access securely by determining and displaying the usability of cloud services based on predefined security conditions, ensuring compliance and risk mitigation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025159772000001_ABST
    Figure 2025159772000001_ABST
Patent Text Reader

Abstract

To provide an information processing system, an information processing method and a program for allowing an administrator to set conditions on security of cloud services of an organization and confirm results of determining whether the cloud services are available or not in a list of the cloud services.SOLUTION: In an information processing system, a control unit of a server device is configured to: display a first screen for setting conditions on security of cloud services in an organization; determine whether the cloud services are available or not based on the set conditions and information on the security of the cloud services; receive a search request including search conditions on the cloud services from a client device; and control the client device to display a second screen including a list of the cloud services. Label information, which is information indicating results of determining the availability of the cloud services, is added to each of the cloud services included in the list.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing system, an information processing method, and a program. [Background technology]

[0002] Patent Document 1 discloses a method for detecting the use of cloud services. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent Publication No. 2021-77271 Summary of the Invention [Problem to be solved by the invention]

[0004] In the technique of Patent Document 1, the use of cloud services is managed based on user information, but there are cases where management based on information regarding the security of the cloud services is required. [Means for solving the problem]

[0005] According to one aspect of the present disclosure, an information processing system is provided. The information processing system has at least one or more control units. The control unit controls to display a first screen to an administrator of an organization in response to a request. The first screen is configured to allow conditions related to the security of cloud services in the organization to be set. The control unit determines whether the cloud service can be used based on the conditions set via the first screen and information related to the security of the cloud service. The control unit receives a search request from a device of a person under management of the organization. The search request includes search conditions related to the cloud service. The control unit controls to display a second screen on the device of the person under management. The second screen includes a list of cloud services. The cloud services included in the list are cloud services obtained based on the search conditions. Each cloud service included in the list is associated with and assigned label information. The label information is information indicating the result of the determination of whether the cloud service can be used. [Brief explanation of the drawings]

[0006] [Figure 1] FIG. 1 is a diagram illustrating an example of a system configuration of an information processing system. [Figure 2] FIG. 2 is a diagram illustrating an example of a hardware configuration of the server device. [Figure 3] FIG. 3 is a diagram illustrating an example of a hardware configuration of the client device. [Figure 4] FIG. 4 is a sequence diagram illustrating an example of information processing in the information processing system. [Figure 5] FIG. 5 is a diagram showing an example of the condition setting screen. [Figure 6] FIG. 6 is a diagram showing an example of the list screen. [Figure 7] FIG. 7 is a diagram showing a part of a list of cloud services. [Figure 8] FIG. 8 is a diagram showing an example of a pop-up window for editing label information. [Figure 9]FIG. 9 is a diagram showing an example of outputting OK condition information in a pop-up window for editing label information. [Figure 10] FIG. 10 is a diagram showing an example of a screen including a service ledger for a predetermined cloud service. [Figure 11] FIG. 11 is a diagram showing an example of a condition setting screen according to the third modification. [Figure 12] FIG. 12 is a diagram showing an example of a screen transition in the fourth modification. DETAILED DESCRIPTION OF THE INVENTION

[0007] Hereinafter, embodiments of the present invention will be described with reference to the drawings. Various features shown in the following embodiments can be combined with each other. The same applies to the following modified examples.

[0008] In this embodiment, the term "unit" may include, for example, a combination of hardware resources implemented by a circuit in the broad sense and software information processing that can be specifically realized by these hardware resources. Furthermore, this embodiment handles various types of information, which may be represented by, for example, physical values ​​of signal values ​​representing voltages and currents, high and low signal values ​​as a binary bit set consisting of 0 or 1, or quantum superposition (so-called quantum bits), and communication and calculations may be performed on the circuit in the broad sense.

[0009] In addition, a circuit in the broad sense is a circuit realized by at least appropriately combining a circuit, circuitry, a processor, a memory, etc. That is, it includes an application specific integrated circuit (ASIC), a programmable logic device (e.g., a simple programmable logic device (SPLD), a complex programmable logic device (CPLD), and a field programmable gate array (FPGA)), etc.

[0010] <Embodiment 1> 1. System configuration diagram FIG. 1 is a diagram illustrating an example of the system configuration of an information processing system 1000. As illustrated in FIG. 1, the information processing system 1000 includes, as a system configuration, a server device 100, a client device 110, a client device 120, and a service providing device 130 that provides cloud services. The server device 100, the client device 110, the client device 120, and the service providing device 130 are communicably connected via a network 150. The network 150 may include either or both of a WAN (Wide Area Network) and the Internet. The network 150 is configured to allow devices included in the network 150 to communicate with each other via wired and wireless connections.

[0011] The server device 100 is a server device that provides the functionality of a security evaluation platform, and executes the main processing of the first embodiment and the like.

[0012] The client device 110 is a device / terminal used by a person under management of an organization, and may be referred to as a "person under management terminal." The person under management of an organization uses the client device 110 to apply for use of cloud services provided by the service providing device 130 and to use approved cloud services. Examples of organizations include companies, individual businesses, local governments, schools, and other organizations. Persons under management of an organization are users other than the administrator, such as employees of a company, who do not have specific security-related authority. In the present specification, a company is used as an example of an organization. Persons under management of an organization may simply be referred to as first users.

[0013] For the sake of simplicity, FIG. 1 shows only one client device 110 included in the information processing system 1000, but the information processing system 1000 may include multiple client devices 110. Also, while FIG. 1 illustrates the client device 110 as a PC (Personal Computer), the client device 110 is not limited to a PC. The client device 110 may be a smartphone or a tablet terminal. The client device 110 may be any device that can display a screen, which will be described later, and accept user selection operations, input operations, and the like. The same applies to the client device 120, which will be described later.

[0014] The client device 120 is a device / terminal used by an organization administrator, and may be called an administrator terminal. The organization administrator sets the conditions of the organization's security policy in the server device 100 and registers security evaluation information of cloud services, etc. in the server device 100. The organization administrator includes, for example, a person who has predetermined authority regarding the security of the organization, such as a security department official or a department head of a specific department, and has the authority to set conditions for whether or not to use cloud services within the organization. The organization administrator may simply be called a second user.

[0015] The service providing device 130 is a device that provides cloud services. The service providing device 130 may be configured from one server device or multiple server devices. For the sake of simplicity, only one service providing device 130 is shown in FIG. 1 , but the information processing system 1000 actually includes multiple service providing devices 130. Each of the multiple service providing devices 130 provides a different cloud service.

[0016] Here, the claimed information processing system may be comprised of multiple devices or may be comprised of a single device. When the claimed information processing system is comprised of a single device, an example of the single device is server device 100. When the claimed information processing system is comprised of a plurality of devices, the plurality of devices are, for example, a plurality of server devices that provide server device 100.

[0017] 2. Hardware Configuration (1) Hardware Configuration of Server Device 100 FIG. 2 is a diagram illustrating an example of a hardware configuration of the server device 100. As shown in FIG. 2, the server device 100 includes, as its hardware configuration, a control unit 210, a storage unit 220, a communication unit 230, and a communication bus 240. The control unit 210, the storage unit 220, and the communication unit 230 are electrically connected within the server device 100 via the communication bus 240.

[0018] The control unit 210 is, for example, a central processing unit (CPU) or the like, and performs overall processing and control of the server device 100. The control unit 210 realizes various functions related to the server device 100 by reading out predetermined programs stored in the storage unit 220. That is, information processing by software stored in the storage unit 220 is specifically realized by the control unit 210, which is an example of hardware, and can be executed as each functional unit included in the control unit 210. These will be described in further detail in the next section. Note that the control unit 210 is not limited to being single, and multiple control units 210 may be provided for each function. Alternatively, a combination of these may be used.

[0019] The storage unit 220 stores various pieces of information defined above. This may be, for example, a storage device such as an HDD (Hard Disk Drive), a ROM (Read Only Memory), a RAM (Random Access Memory), or an SSD (Solid State Drive) that stores various programs related to the server device 100 executed by the control unit 210, or a memory that stores temporarily required information (arguments, arrays, etc.) related to program calculations, or any combination thereof, and stores programs, data used when the control unit 210 executes processing based on the programs, etc. The storage unit 220 is an example of a storage medium. The program for realizing the software appearing in this embodiment may be provided as a non-transitory computer-readable medium, or may be provided so that it can be downloaded from an external server, or may be provided so that the program is started on an external computer and its functions are realized on a client terminal (so-called cloud computing).

[0020] In the present specification, data used when control unit 210 executes processing based on a program (e.g., security policy conditions for each organization, security evaluation information for each cloud service, a service ledger for each cloud service described later, etc.) is described as being stored in storage unit 220, but the data may also be stored in a storage unit of another device that can communicate with server device 100. In other words, the data may be stored in a storage unit of any device as long as it can be referenced or acquired by control unit 210. When control unit 210 executes processing based on a program stored in storage unit 220, the functions of server device 100 and the processing of server device 100 in the sequence diagram shown in FIG. 4 described later are realized.

[0021] The communication unit 250 connects the server device 100 to the network 150 and controls communication with other devices. The communication unit 250 may be a wired communication means such as USB, IEEE 1394, Thunderbolt (registered trademark), wired LAN network communication, etc., or may also include wireless LAN network communication, mobile communication such as 3G / LTE / 5G, BLUETOOTH (registered trademark) communication, etc. as needed. In other words, it is more preferable to implement the communication unit 250 as a collection of multiple communication means. In other words, the server device 100 may communicate various information from the outside via the communication unit 250 and the network 150. The number of each piece of hardware constituting the server device 100 is not limited to one, and may be multiple. The server device 100 may be in an on-premise form or in a cloud form. As a cloud-based server device 10, the above-mentioned functions and processes may be provided in the form of, for example, SaaS (Software as a Service) or cloud computing.

[0022] (2) Hardware Configuration of the Client Device 110 FIG. 3 is a diagram illustrating an example of the hardware configuration of the client device 110. As shown in FIG. As shown in FIG. 3, the client device 110 includes, as its hardware configuration, a control unit 310, a storage unit 320, an input unit 330, an output unit 340, a communication unit 350, and a communication bus 360.

[0023] The control unit 310 is, for example, a central processing unit (CPU) or the like, and performs overall processing and control related to the client device 110. The control unit 310 realizes various functions related to the client device 110 by reading out predetermined programs stored in the storage unit 320. In other words, information processing by software stored in the storage unit 320 is specifically realized by the control unit 310, which is an example of hardware, and can be executed as each functional unit included in the control unit 310. These will be described in further detail in the next section. Note that the control unit 310 is not limited to being a single unit, and multiple control units 310 may be provided for each function. A combination of these may also be used.

[0024] The storage unit 320 stores various information as defined above. This may be, for example, a storage device such as an HDD, ROM, RAM, or SSD that stores various programs related to the client device 110 executed by the control unit 310, or a memory that stores temporarily required information (arguments, arrays, etc.) related to program calculations, or any combination thereof. The storage unit 320 stores programs, data used by the control unit 310 when executing processes based on the programs, and the like. The storage unit 320 is an example of a storage medium. Although the specification describes data used by the control unit 310 when executing processes based on the programs as being stored in the storage unit 320, the data may also be stored in a storage unit of another device that can communicate with the client device 110. That is, the data may be stored in a storage unit of any device that can be accessed by the control unit 310. The control unit 310 executes processes based on the programs stored in the storage unit 320, thereby realizing the functions of the client device 110 and the processing of the client device 110 in the sequence diagram shown in FIG. 4 (described later).

[0025] The input unit 330 is a device that inputs information to the client device 110 in response to an operation by an operator. The input unit 330 accepts an operation input made by a user. The operation input is transferred as a command signal to the control unit 310 via the communication bus 360. The control unit 310 can execute predetermined control or calculation based on the transferred command signal as necessary. The input unit 330 may be included in the housing of the client device 110 or may be externally attached. For example, the input unit 330 may be implemented as a touch panel integrated with the output unit 340. When the input unit 330 is implemented as a touch panel, the user can input tap operations, swipe operations, etc. to the input unit 330. Instead of a touch panel, a switch button, a mouse, a trackpad, a QWERTY keyboard, etc. can be used as the input unit 330.

[0026] The output unit 340 is, for example, a display, and is a device that outputs information as a screen of a graphical user interface (GUI) that can be operated by a user. The output unit 340 may be included in the housing of the client device 110, or may be attached externally. Specifically, the output unit 340 may be implemented as a display device such as a CRT display, a liquid crystal display, an organic EL display, or a plasma display. It is preferable that these display devices are implemented by selectively using them depending on the type of client device 110.

[0027] The communication unit 350 connects the client device 110 to the network 150 and controls communication with other devices.

[0028] The hardware configuration of the client device 120 is similar to that of the client device 110 .

[0029] 3. Information Processing The information processing of the first embodiment will be described below.

[0030] (1) Overview of the process In response to a request, the control unit 210 controls the terminal of the organization administrator to display a usage permission policy setting screen for organization settings, such as that shown in FIG. 5 (described later). The usage permission policy setting screen is an example of a first screen. The usage permission policy setting screen is configured to allow the conditions of a security policy related to cloud services used by the organization to be set. The conditions of the security policy related to cloud services used by the organization are an example of conditions related to the security of cloud services in the organization. The control unit 210 determines whether a cloud service can be used based on the conditions set via the usage permission policy setting screen (also referred to as the conditions of the organization's security policy) and information related to the security of the cloud service. The information related to the security of the cloud service includes security evaluation information of the cloud service, etc. Note that the information related to the security of the cloud service is information related to the security of each of multiple cloud services. The information related to the security of the cloud service is stored in the storage unit 220 or the like in association with identification information that identifies the cloud service.

[0031] The information about the security of cloud services also includes information about security evaluations (hereinafter simply referred to as evaluation information) registered based on responses from cloud service providers to security surveys conducted by organizations using cloud services or organizations that evaluate the security of cloud services (e.g., security research companies) for the providers of the cloud services provided by the service providing device 130. The information about security evaluations includes, for example, responses to a checklist containing multiple security-related questions, such as a security checklist answered by the cloud service provider. The information about security evaluations includes information about basic items, information about security measures for the cloud service itself, and information about security measures for specific functions. The information about basic items includes the presence or absence of third-party authentication, handling of deposited data, and security incident history. The information about security measures for the cloud service itself includes information about the organizational structure for ensuring information security, access control information, encryption information, security incident management information, and the like. The information about security measures for specific functions includes information about whether the cloud service has a file upload function, whether there are external services with which deposited data is shared, and the like.

[0032] The information related to the security of cloud services also includes risk information generated by the control unit 210 automatically collecting configuration information of publicly available cloud services based on the domain information of the cloud services. The configuration information of cloud services collected based on the domain information of the cloud services includes information on related domains, related IP addresses, web access results, SSL certificate information, and other third-party sources. The risk information generated based on the configuration information of cloud services includes information on the status of security measures taken by the cloud services, information on the presence or absence of public servers that could be the source of unauthorized access, information on the presence or absence of domains that may be hijacked, information on the status of measures against email spoofing, etc.

[0033] The information relating to the security of the cloud service may include information other than the information described above, as will be described in detail later.

[0034] According to the processing of the control unit 210 described above, the administrator of an organization can set conditions relating to the security of the cloud service of the organization.

[0035] The control unit 210 receives a search request from a terminal of a person under management in the organization. The search request includes search conditions related to cloud services. The control unit 210 controls the terminal of the person under management to display a list screen. The list screen is an example of a second screen. The list screen includes a list of cloud services. The cloud services included in the list are cloud services obtained based on the search conditions. Each cloud service included in the list is associated with and assigned label information. The label information is information indicating the result of a determination as to whether the cloud service can be used.

[0036] With this configuration, it is possible to check the results of the determination as to whether or not each cloud service can be used on a list screen of search results for cloud services.

[0037] (2) Details of the processing (Security policy settings) 4 is a sequence diagram showing an example of information processing in the information processing system 1000. The server device 100 identifies whether a user who has logged in to the information processing system 1000 is a manager or a person under management of the organization by authenticating the user with the user ID and password. In sequence SQ401, the control unit of client device 120 transmits a request to server device 100 to display a condition setting screen based on a predetermined operation on a predetermined screen by an administrator of the organization.

[0038] When a request to display a condition setting screen is received from the client device 120 to which the administrator is logged in, in sequence SQ402, the control unit 210 of the server device 100 acquires the condition setting screen from the storage unit 220, etc. Note that, although the description here is given assuming that the condition setting screen is generated in advance and stored in the storage unit 220, the control unit 210 may generate the screen when a display request is received.

[0039] In sequence SQ403, control unit 210 transmits the condition setting screen to requesting client device 120. Client device 120 receives the condition setting screen from server device 100. The processing of sequences SQ402 and SQ403 is an example of a process for controlling the display of a condition setting screen on the terminal of the administrator of the organization in response to a request.

[0040] In sequence SQ404, the control unit of the client device 120 controls the output unit of the client device 120 to output the condition setting screen received from the server device 100.

[0041] In this embodiment, the server device 100 that receives the request generates a screen and transmits it to the client device that made the request. The following description is based on the assumption that the client device that received the screen displays the screen. However, the server device 100 may also acquire data necessary for generating the screen and transmit it to the client device that made the request. The client device may then generate and display the screen based on the received data. In such a case, the process of acquiring data necessary for generating the screen and transmitting it to the client device that made the request is an example of a process of controlling the display of a condition setting screen on the terminal of an organization administrator in response to a request.

[0042] 5 is a diagram showing an example of a condition setting screen 500. When an organization setting tab 520 is selected and an availability policy tab 530 is selected on the organization setting screen, a display request for the condition setting screen 500 is sent from the client device 120 to the server device 100, and a condition setting area 510 is displayed. The screen including the condition setting area 510 is the condition setting screen 500.

[0043] As shown in FIG. 5, the condition setting screen 500 is configured to allow an organization to set conditions related to the security of cloud services. The conditions related to the security of cloud services can also be referred to as a security policy. A security policy is a policy and / or code of conduct for information security measures implemented by an organization. The conditions related to the security of cloud services may also be conditions that determine whether or not members of an organization, such as employees of a company, can use the cloud service. As shown in FIG. 5, the condition setting screen 500 is configured to allow multiple conditions to be combined using either or both AND and OR conditions.

[0044] More specifically, the condition setting screen 500 is configured to allow selection of multiple target items (condition setting items) for setting conditions as conditions related to the security of the cloud service. In the example of FIG. 5, "Usage history," "Investigation history," "Investigation score," "Web assessment score," "SOC2 certification," and "Items 1-15" are selected as target items. The condition setting screen 500 is also configured to allow selection of how to determine the conditions for each of the multiple target items in the "Condition" column and the "Determination" column. The determination methods (determination results) include "OK to use," "NG to use," and "OK with conditions (hereinafter simply referred to as "conditional")," as will be described later. That is, the condition setting screen 500 is configured so that the conditions "OK to use", "NG to use", and "OK with conditions" can be set.

[0045] When the administrator of the organization sets conditions on the condition setting screen 500 and selects the save button, the client device 110 transmits the set conditions to the server device 100.

[0046] Upon receiving the conditions from the client device 110, in sequence SQ406, the control unit 210 stores the received conditions in a predetermined storage area of ​​the storage unit 220. The control unit 210 stores the received conditions in the storage unit 220 in association with company information including identification information that identifies companies that meet the conditions. The company information includes information such as the company's business type, industry, information on the services and / or products that the company provides, business model, number of years since establishment, number of employees, etc.

[0047] In sequence SQ407, control unit 210 determines whether or not each of multiple cloud services can be used based on information about the security of the cloud services stored in storage unit 220, etc., and the conditions stored in sequence SQ406. The determination results include "OK to use," "NG to use," "conditions apply," "undetermined," etc., as shown in FIG. 7, which will be described later. OK to use indicates that the cloud service may be used. NG to use indicates that the cloud service may not be used. Conditions apply indicates that the cloud service may be used if certain conditions regarding the usage mode, etc. are met. Undetermined indicates that none of the set conditions are met. In other words, undetermined indicates that a determination has not been made based on the conditions as to whether or not the cloud service can be used.

[0048] The control unit 210 determines that a cloud service is "OK to use" if the information about the security of the cloud service satisfies the conditions set in the "Judgment" field on the condition setting screen 500 as the conditions for determining that the service is "OK to use." The control unit 210 determines that a cloud service is "OK to use" if the information about the security of the cloud service satisfies the conditions set in the "Judgment" field on the condition setting screen 500 as the conditions for determining that the service is "NG to use." The control unit 210 determines that a cloud service is "conditional (OK with conditions)" if the information about the security of the cloud service satisfies the conditions set in the "Judgment" field on the condition setting screen 500 as the conditions for determining that the service is "conditional." If the control unit 210 cannot determine the cloud service because there is insufficient information about the security of the cloud service, or if the cloud service does not satisfy any of the set conditions, the control unit 210 determines that the cloud service is "unassessed."

[0049] The process of sequence SQ407 is an example of a process in which control unit 210 determines whether or not a cloud service is available based on the conditions set via the condition setting screen and information related to the security of the cloud service.

[0050] The control unit 210 stores the result of the usability determination, as well as the reason for the usability determination (or the basis for the determination), in a specified storage area of ​​the storage unit 220, in association with the identification information identifying the relevant organization and the identification information identifying the cloud service.

[0051] Here, details of information relating to the security of cloud services will be explained. In this embodiment, the information relating to the security of cloud services includes information about the cloud service itself, information about the usage record of the cloud service, information about security evaluation, and information about the detection of services used by employees (managed persons) of the organization. This information is used to set conditions for determining whether or not a cloud service can be used. For example, the information relating to the security of cloud services includes the following information. Note that the information in parentheses is an example of information to be entered or selected in the "Condition" field (a field for entering or selecting under what circumstances the set condition setting item will be judged as "OK to use," "NG to use," or "OK ​​with conditions") when that information is selected as a condition setting item. ·Whether or not various certifications (ISO27001, SOC2, etc.) have been obtained Certification date Data center location Infrastructure as a Service (IaaS) providers Governing law (Japanese law, etc.) Supported languages The information related to cloud service usage records includes the following information: The usage records are records of how each cloud service is used, how it is managed, etc., and are stored in a predetermined storage area of ​​the storage unit 220 in association with identification information that identifies the cloud service. Usage history (X or more) ·Purpose of use ·Number of users (more than X people) Number of accounts used (X accounts or more) ·Using department Whether personal information is handled -Type of information assets handled (personal information, My Number, confidential information, other important information, etc.) - The degree of impact when the service is stopped (large (service stoppage causes business to stop), medium (service stoppage causes business to be delayed), small (impact is minor), etc.) Other information recorded in usage records The security evaluation information includes the following: · Investigation history (X or more cases) Survey result score (score N or above, top 1% or above, etc.) Web evaluation score (score N or above, top 1% or above, etc.) Final survey completion date - Status of implementation of specific measures (storing access logs, regular vulnerability assessments, etc.) Information regarding the detection of services used by employees (managed persons) of an organization includes the following information: User operations (number of specific operations such as logins and downloads) · Service features / functionality (file upload available, SSO not supported, etc.) Service category (IaaS, accounting system, human resources system, etc.) Number of visits in the past 30 days (more than X) Number of visitors in the past 30 days (more than X people) Last access date and time

[0052] Here, the importance of information assets handled (deposited) by cloud services may be determined and evaluated in terms of confidentiality, integrity, and availability, and may be stored as information related to the security of the cloud services. Confidentiality is an indicator of whether information is accessible only to authorized users, and is determined and evaluated from the perspective of whether the information is required by law to be managed securely (personal information, specific personal information, etc.), whether it is subject to confidentiality obligations (information provided in confidence by a business partner, etc.), or whether it should be managed as an internal trade secret (a company's proprietary technology or know-how, etc.). Integrity is an indicator of whether the information and the way it is processed are required to be accurate and complete, and is judged and evaluated from the perspective of whether tampering would have a serious impact on the company, business partners, etc. Availability is an indicator of whether information is accessible to designated users when needed, and is judged and evaluated from the perspective of whether its unavailability would have a serious impact on the company, business partners, etc. Using these perspectives, the importance of the information assets handled may be evaluated and determined, stored, and used to set conditions for determining whether or not to allow cloud services to be used. For example, a condition may be set such as "Use is OK as long as information whose secure management is required by law is not handled." Furthermore, using these perspectives, the importance of information may be scored and used to set conditions for determining whether or not to allow cloud services to be used. For example, the higher the confidentiality, the higher the score, the higher the required integrity, and the higher the required availability, the higher the score. A condition may be set such that "Use is OK if the score of the importance of the information handled is below a specified value."

[0053] In addition, in the following explanation, it is assumed that in addition to information regarding the security of the cloud service, the memory unit 220 of the server device 100 also stores information regarding the cloud service, such as the name of the cloud service, the name of the company providing the cloud service, and the category (service category) of the cloud service, in association with the information regarding the security of the cloud service.

[0054] In sequence SQ408, control unit 210 stores the determination result as a result of availability in the organization in a predetermined storage area such as storage unit 220. More specifically, control unit 210 stores the result of availability of each of a plurality of cloud services in association with information about each cloud service in a predetermined storage area such as storage unit 220.

[0055] (Search for cloud services) In sequence SQ409, the control unit 310 of the client device 110 sends a request to the server device 100 to display a cloud service list screen based on a predetermined operation on a predetermined screen by the person under management. The request to display the cloud service list screen includes search conditions for cloud services, as will be described later. The request to display the cloud service list screen is an example of a search condition for cloud services.

[0056] When a request to display a list screen of cloud services is received from the client device 110 to which the person being managed is logged in, in sequence SQ410, the control unit 210 of the server device 100 searches the cloud service information for the relevant cloud service based on the search conditions included in the display request and obtains the search results.

[0057] In sequence SQ411, control unit 210 generates a list screen including a list of relevant cloud service information, etc. as the search results. The list screen is an example of a second screen.

[0058] In sequence SQ412, control unit 210 transmits the list screen to requesting client device 110. Client device 110 receives the list screen from server device 100.

[0059] The processing of sequence SQ411 and sequence SQ412 is an example of a process for controlling the display of a list screen on the terminal of a person under management in an organization in response to a request.

[0060] In sequence SQ413, the control unit 310 of the client device 110 controls the output unit 340 of the client device 110 to output the list screen received from the server device 100.

[0061] FIG. 6 is a diagram showing an example of a list screen 600. When the service search tab 620 is selected and a search condition (e.g., a free word, a service category, etc.) is selected in the display area 610, a request to display a cloud service list screen is sent from the client device 110 to the server device 100, and a list of cloud services is displayed in the display area 610. Examples of free words include the name of a company providing a cloud service and the name of a cloud service. The list screen 600 is a screen that includes a list of cloud services. The list screen 600 displays a list of summary information for each cloud service that matches the search condition. The summary information includes information such as the service name, the cloud service provider (e.g., the vendor), and the type of service. In other words, the list screen 600 includes a list of cloud services.

[0062] On the list screen 600, when security evaluation information related to cloud services is stored in association with the cloud services and cloud service providers, an icon 640 labeled "Disclose investigation results" and an estimated delivery date 650 are displayed in association with cloud services A to C and cloud service E. For example, for cloud service A, an estimated delivery date 650 of approximately one week is displayed, and for cloud service B, an estimated delivery date 650 of approximately two weeks is displayed. When the person under management selects (e.g., clicks) the icon 640 labeled "Disclose investigation results," a request is sent to the server device 100 to transmit the security evaluation information of the cloud services stored in the storage unit 220 or the like to the client device 110 or the client device 120. An icon is a small picture or symbol image displayed on the screen that represents a process or function that is performed when selected, and is designed to be intuitively operable by the user.

[0063] On the other hand, if no past security evaluations for the cloud service are stored, an icon 660 saying "Request a new investigation" is displayed, as shown for cloud service D. In such a case, information such as "No investigation history" indicating that no past security evaluations have been investigated may be displayed together with the icon.

[0064] Here, Fig. 7 shows an enlarged view of area 630, which is part of the list of cloud services. Fig. 7 is a diagram showing part of the list of cloud services. Each cloud service included in the list of cloud services is associated with label information and assigned to the cloud service. The label information is information indicating the result of a determination as to whether or not the cloud service can be used.

[0065] The types of label information include at least information indicating that the cloud service may be used (in the example of Figure 7, label information 710 indicates "OK to use") and information indicating that the cloud service may not be used (in the example of Figure 7, label information 740 indicates "NG to use").

[0066] The types of label information further include information indicating that the cloud service may be used conditionally (in the example of FIG. 7, label information 720 "conditional").

[0067] The types of label information further include information indicating that it is not possible to evaluate whether or not the cloud service is permitted to be used (in the example of FIG. 7, label information 730 "unable to determine").

[0068] In this way, different types of label information (labels with different wordings) may be attached to the cloud service list screen. In other words, the label information that can be attached to the cloud service list screen may be selected from a variety of patterns depending on the availability determination result.

[0069] A person under management who is planning to use a cloud service can check whether the desired cloud service is available in their organization by referring to the label information for each cloud service included in the list screen shown in Figure 7.

[0070] According to the processing of the first embodiment, an administrator of an organization can set security conditions for the organization's cloud services. Furthermore, according to the processing of the first embodiment, it is possible to display cloud services that are available to the organization, cloud services that are unavailable, or cloud services that are available under certain conditions based on the set conditions. Furthermore, according to the processing of the first embodiment, it is possible to display a label indicating whether or not a cloud service is available in terms of security for each cloud service.

[0071] <Variation 1> The following describes Modification 1 of Embodiment 1. Modification 1 is included in Embodiment 1, but is not a different embodiment from Embodiment 1. Configurations and processes not described in Modification 1 are the same as those in Embodiment 1.

[0072] In the above description, the cloud service list screen is described as being displayed on the output unit 340 of the managed client device 110. However, the cloud service list screen can also be displayed on the output unit of the administrator's client device 120. More specifically, when the control unit 210 of Modification 1 receives a request to display the cloud service list screen from the administrator's client device 120, it generates a cloud service list screen configured to allow editing of label information associated with the cloud services, and transmits the cloud service list screen to the administrator's client device 120.

[0073] When the control unit 210 receives an operation to select label information from the client device 120 (for example, when it receives an operation to select label information 730 in FIG. 7), it causes the client device 120 to display a pop-up window 800 for editing the label information (label information "Conditional" in FIG. 7). This process is an example of a process in which the control unit 210 controls the display of a list screen on the administrator's terminal in response to a request.

[0074] 8 is a diagram showing an example of a pop-up window 800 for editing label information. The administrator can edit label information individually via the pop-up window 800. More specifically, the administrator can individually input and edit whether or not a cloud service is available and the reason for the decision via the pop-up window 800 that appears when the administrator selects, by clicking or otherwise, label information displayed in association with a cloud service. In other words, the list screen displayed to the administrator is configured to allow editing of label information for cloud services.

[0075] If the availability is "conditionally OK," the control unit 210 may allow the user to input and edit the "OK" conditions (additional conditions for availability) via a pop-up window for editing label information. The additional conditions input here supplement the security-related conditions for the cloud service set on the condition setting screen 500. FIG. 9 is a diagram showing an example of inputting and editing "OK" condition information 910 in the pop-up window 900 for editing label information. In the example of FIG. 9, the "OK" condition information 910 includes "no personal information," "usage by fewer than 10 people," and "spot use for less than six months." If all the "OK" conditions are met, the associated cloud service is available for use. In this way, "conditionally OK" is used when the determination of availability of a cloud service varies depending on the usage pattern within an organization. Usage patterns include, for example, the type of information handled (whether it contains important information such as personal information or confidential information), the number of users, the usage period, the department using the service, etc. These availability conditions may be referred to as additional or supplementary conditions. That is, if the label information is "conditionally OK," the pop-up window 900 is configured to allow input of additional conditions for determining whether the cloud service is permitted to be used.

[0076] The control unit 210 stores the edited label information and condition information in a predetermined storage area of ​​the storage unit 220 in association with the identification information identifying the relevant organization and the identification information identifying the cloud service. The control unit 210 also stores the edited result of the usability determination, as well as the reason for the usability determination (or the basis for the determination), in association with the identification information identifying the relevant organization and the identification information identifying the cloud service in a predetermined storage area of ​​the storage unit 220. For example, if a cloud service that was determined to be "not usable" based on the conditions related to the security of the cloud service set on the condition setting screen is edited to be "usable," the control unit 210 stores a phrase such as "individually determined" as the reason for the determination (or the basis for the determination).

[0077] On the other hand, the label information displayed on the output unit 340 of the managed client device 110 is controlled so that it cannot be edited by the managed user. In other words, the control unit 210 controls whether the label information can be edited depending on the attributes and authority of the user who uses the client device or terminal that displays the label information. This makes it possible to restrict the editing of label information for users who are not desired to edit label information, such as users who do not have predetermined authority related to security in the organization.

[0078] According to Variation 1, the administrator can input and edit label information for each cloud service individually based on the results of individual investigations and reviews of the cloud service. Furthermore, if the label information is "conditionally OK," the administrator can input and edit additional information, such as information about the conditions under which the cloud service can be used, such as the type of usage. This allows administrators to not only set conditions for determining whether cloud services can be used in bulk, but also to set the results of the use eligibility determination and additional conditions according to individual circumstances and review results.

[0079] <Variation 2> The following describes Modification 2 of Embodiment 1. Modification 2 is included in Embodiment 1, and is not a different embodiment from Embodiment 1. Configurations and processes not described in Modification 2 are the same as those in Embodiment 1.

[0080] 10 is a diagram showing an example of a screen 1010 including a service ledger for a predetermined cloud service. For example, when an administrator or a person under management of an organization selects a predetermined cloud service on a screen displayed on a client device 110 and performs an operation to select the service ledger, the control unit 210 of Modification 2 generates the screen 1010, transmits it to the client device 110, and controls the screen 1010 to be displayed on the output unit 340. Here, the service ledger is registered information on cloud services currently being used or under consideration for use within an organization, and is a digital ledger that centrally manages individual information (such as the department using the service, the intended use, etc.) and evaluation information for each cloud service. The administrator may register a cloud service in the service ledger.

[0081] As shown in FIG. 10 , screen 1010 includes label information ("OK to Use") indicating whether the cloud service is available, as well as information 1030 indicating the reason for the determination of availability. In the example of FIG. 10 , the reason for the determination of availability for a cloud service named "Human Resources Cloud Service A" is listed as "Because the survey score is 70 points or more (determined based on the availability policy)." The reason for the determination may be displayed together with the label information indicating availability, or may be displayed in a manner that is distinguishable from the label information. For example, control unit 210 may display the reason for the determination by changing the shape, color, size, etc. of the label or text from the label information indicating availability. The reason for the determination of availability may be, for example, "Determined based on the availability policy" if the cloud service satisfies the security requirements for the organization's cloud service set on the condition setting screen, or "Determined based on individual editing" if the label information is individually edited by an administrator via a pop-up window and the usage is approved. Furthermore, the reason for the determination of whether or not the service is usable may not only be displayed on screen 1010 including the service ledger, but may also be displayed together with label information indicating whether or not the service is usable on cloud service list screen 600 viewed by the administrator or the person under management, as shown in Fig. 6. Furthermore, when the user places the cursor on the label information on cloud service list screen 600 or performs an operation such as pressing, the reason for the determination of whether or not the service is usable may be displayed in a form such as a pop-up.

[0082] The above-described process is an example of a process in which the control unit 210 outputs the reason for determining whether or not the cloud service is available in response to a request.

[0083] According to the second modification, in addition to the result of the determination as to whether or not the cloud service can be used, the reason for the determination can be known.

[0084] <Variation 3> The following describes Modification 3 of Embodiment 1. Modification 3 is included in Embodiment 1, and is not a different embodiment from Embodiment 1. Configurations and processes not described in Modification 3 are the same as those in Embodiment 1.

[0085] FIG. 11 is a diagram showing an example of a condition setting screen 500 according to Modification 3. The control unit 210 according to Modification 3 controls the condition setting screen 500 to output information on the average setting values ​​of organizations in the same industry as the organization as reference information. More specifically, the control unit 210 acquires the conditions of organizations in the same industry as the organization on the condition setting screen 500 from the storage unit 220 or the like. Here, organizations in the same industry refer to organizations in the same industry, organizations that provide similar products or services, or organizations with the same business model. Organizations in the same industry may be, for example, companies that compete in business. Note that the control unit 210 may acquire setting values ​​of organizations in the same industry that have been established for a similar number of years as the organization or organizations in the same industry that have a similar number of employees, and calculate the average value.

[0086] 11, the condition setting screen 500 includes reference information 1110 indicating that the condition regarding the survey score is an average of 75 points or more in the same industry, and reference information 1120 indicating that the condition regarding the web evaluation score is an average of 80 points or more in the same industry. Note that the conditions of other organizations displayed alongside the set conditions on the condition setting screen are not limited to conditions of organizations in the same industry, etc., but may be conditions related to conditions other than the company's own organization; for example, conditions of an industry, business type, or organization (such as a company) previously set by the administrator may be retrieved from the storage unit 220, etc., and displayed.

[0087] As shown in FIG. 11, the condition setting screen includes, as reference information, conditions for organizations other than the relevant organization.

[0088] 11, for the sake of simplicity, the control unit 210 is shown outputting reference information for some of the conditions among the multiple items. However, the control unit 210 may be configured to output reference information for each of the conditions of all of the items.

[0089] The control unit 210 may output the average value of the entire organization (or all companies) instead of the average value of the same industry as reference information. The control unit 210 may output other values, such as the mode value, instead of the average value, as reference information.

[0090] According to the third modification, conditions of other organizations can be used as reference when setting conditions.

[0091] As another example, when the input conditions differ from the average values, etc. of the conditions of other organizations other than the relevant organization, the control unit 210 may output the average values, etc. of the conditions of the other organizations as reference information on the condition setting screen. With this configuration, when the input conditions differ from the average values, etc. of the conditions of the other organizations, the average values, etc. of the conditions of the other organizations are output, and this value can be used as a reference.

[0092] <Variation 4> The following describes Modification 4 of Embodiment 1. Modification 4 is included in Embodiment 1, and is not a different embodiment from Embodiment 1. Configurations and processes not described in Modification 4 are the same as those in Embodiment 1.

[0093] FIG. 12 is a diagram showing an example of a screen transition in the fourth modification. When conditions are set on the condition setting screen 500 and the Save button is selected, the control unit 210 of the fourth modification searches for cloud services that satisfy the conditions set on the condition setting screen 500. If a cloud service that satisfies the conditions is found, the control unit 210 generates a confirmation screen 1200 including information on at least the cloud services that satisfy the conditions and the number of cloud services that satisfy the conditions, and controls the output unit of the client device 120 to output the confirmation screen 1200. Here, a cloud service that satisfies the conditions refers to a cloud service whose label information is "OK to use." This process is an example of a process in which the control unit 210 outputs information including the number of cloud services whose security information satisfies the conditions set via the condition setting screen. Alternatively, the control unit 210 may search for cloud services that satisfy the set conditions when the conditions are input and set on the condition setting screen 500 (without selecting the Save button). In this case, if a cloud service that satisfies the conditions is found as a result of the search, the control unit 210 may control the condition setting screen 500 to display information regarding the number of cloud services that satisfy the conditions. This allows the user to check the number of cloud services that satisfy the entered conditions without transitioning to a separate confirmation screen, thereby enabling efficient review of the conditions.

[0094] When a registration button 1210 included in the confirmation screen 1200 is selected, the control unit 210 registers the conditions set on the condition setting screen 500 by storing them in a predetermined storage area such as the storage unit 220. On the other hand, when a correction button 1220 included in the confirmation screen 1200 is selected, the control unit 210 transitions the screen display to the condition setting screen 500 and prompts the user to correct the conditions.

[0095] According to the fourth modification, it is possible to display the number of cloud services that satisfy the conditions that the administrator is trying to set. For example, if the conditions are too strict and the number of cloud services that satisfy the conditions is 0 or 1, the administrator can review the conditions by looking at this number.

[0096] <Other> In the above embodiment, cloud services have been used as an example, but this is not limited to this and the present invention can also be widely applied to determining whether or not services, applications, software, etc. that are provided in other formats such as download or installation are available.

[0097] In the above embodiment, the server device 100 performs various storage and control operations, but multiple external devices may be used instead of the server device 100. That is, various information and programs may be distributed and stored in multiple external devices using block chain technology or the like.

[0098] The aspect of the present embodiment is not limited to the information processing system 1000, and may be an information processing method or a program. The information processing method includes each step executed by the information processing system 1000. The program causes a computer to execute each step of the information processing system 1000.

[0099] <Additional Notes> (Appendix 1) An information processing system, having at least one or more control units, The control unit Controlling the display of the first screen on the terminal of the administrator of the organization in response to a request; the first screen is configured to allow the organization to set conditions related to security of cloud services; determining whether or not the cloud service is available based on the conditions set via the first screen and information related to the security of the cloud service; receiving a search request from a terminal of a person under management in the organization; the search request includes search conditions related to the cloud service; Controlling the terminal of the person to be managed to display a second screen; the second screen includes a list of cloud services; the cloud services included in the list are cloud services acquired based on the search criteria; Each cloud service included in the list is assigned label information, and The label information is information indicating a result of a determination as to whether the cloud service is available. Information processing system.

[0100] (Appendix 2) 10. The information processing system of claim 1, The types of the label information include at least information indicating that the cloud service is permitted to be used and information indicating that the cloud service is not permitted to be used. Information processing system.

[0101] (Appendix 3) 10. The information processing system according to claim 2, The type of the label information further includes information indicating that the cloud service may be used under certain conditions. Information processing system.

[0102] (Appendix 4) 10. The information processing system according to claim 2, The type of the label information further includes information indicating that it has not yet been determined whether or not the cloud service is permitted to be used. Information processing system.

[0103] (Appendix 5) 10. The information processing system of claim 1, The control unit Controlling the administrator's terminal to display the second screen in response to a request; the second screen displayed on the terminal of the administrator is configured to allow editing of the label information of the cloud service; The label information is updated according to the editing result. Information processing system.

[0104] (Appendix 6) 6. The information processing system according to claim 5, When the label information before editing is information indicating that the cloud service may be used under certain conditions, the second screen is configured to allow input of predetermined conditions; The predetermined condition is an additional condition for determining whether the cloud service is permitted to be used. Information processing system.

[0105] (Appendix 7) 10. The information processing system of claim 1, The control unit outputting a reason for determining whether or not the cloud service is available in association with the label information; Information processing system.

[0106] (Appendix 8) 10. The information processing system according to claim 1, further comprising: The first screen includes the conditions of organizations other than the organization as reference information. Information processing system.

[0107] (Appendix 9) 10. The information processing system according to any one of claims 1 to 8, The first screen is configured so that the plurality of conditions can be combined using either or both of AND conditions and OR conditions. Information processing system.

[0108] (Appendix 10) 10. The information processing system according to any one of claims 1 to 9, The control unit Searching for cloud services based on the conditions set via the first screen regarding security, and acquiring and outputting information including the number of cloud services that satisfy the conditions. Information processing system.

[0109] (Appendix 11) An information processing method executed by an information processing system, Controlling the display of the first screen on the terminal of the administrator of the organization in response to a request; the first screen is configured to allow the organization to set conditions related to security of cloud services; determining whether or not the cloud service can be used based on the conditions set via the first screen and information related to the security of the cloud service; receiving a search request from a terminal of a person under management in the organization; the search request includes search conditions related to the cloud service; Controlling the terminal of the person to be managed to display a second screen; the second screen includes a list of cloud services; the cloud services included in the list are cloud services acquired based on the search criteria; Each cloud service included in the list is assigned label information, and The label information is information indicating a result of a determination as to whether the cloud service is available. Information processing methods.

[0110] (Appendix 12) A program, Computer, A program for causing the information processing system according to any one of claims 1 to 10 to function as such.

[0111] Finally, while various embodiments of the present invention have been described, these are presented by way of example only and are not intended to limit the scope of the invention. The novel embodiments may be embodied in various other forms, and various omissions, substitutions, and modifications may be made without departing from the spirit of the invention. The embodiments and their modifications are intended to be included within the scope and spirit of the invention, as well as within the scope of the inventions and their equivalents as defined in the appended claims.

[0112] Any of the variations may be implemented in combination with each other. [Explanation of symbols]

[0113] 100 Server Devices 110 Client device 120 Client Device 130 Service providing device 150 Network 210 Control Unit 220 Storage section 230 Communications Department

Claims

1. An information processing system, having at least one or more control units, The control unit Controlling the display of the first screen on the terminal of the administrator of the organization in response to a request; the first screen is configured to allow the organization to set conditions related to security of cloud services; determining whether or not the cloud service is available based on the conditions set via the first screen and information related to the security of the cloud service; receiving a search request from a terminal of a person under management in the organization; the search request includes search conditions related to the cloud service; Controlling the terminal of the person to be managed to display a second screen; the second screen includes a list of cloud services; the cloud services included in the list are cloud services acquired based on the search criteria; Each cloud service included in the list is assigned label information, and The label information is information indicating a result of a determination as to whether the cloud service is available. Information processing system.

2. 2. The information processing system according to claim 1, The types of the label information include at least information indicating that the cloud service is permitted to be used and information indicating that the cloud service is not permitted to be used. Information processing system.

3. 3. The information processing system according to claim 2, The type of the label information further includes information indicating that the cloud service may be used under certain conditions. Information processing system.

4. 3. The information processing system according to claim 2, The type of the label information further includes information indicating that it has not yet been determined whether or not the cloud service is permitted to be used. Information processing system.

5. 2. The information processing system according to claim 1, The control unit Controlling the manager's terminal to display the second screen in response to a request; the second screen displayed on the terminal of the administrator is configured to allow editing of the label information of the cloud service; The label information is updated according to the editing result. Information processing system.

6. 6. The information processing system according to claim 5, When the label information before editing is information indicating that the cloud service may be used under certain conditions, the second screen is configured to allow input of predetermined conditions, The predetermined condition is an additional condition for determining whether the cloud service is permitted to be used. Information processing system.

7. 2. The information processing system according to claim 1, The control unit outputting a reason for determining whether or not the cloud service is available in association with the label information; Information processing system.

8. 2. The information processing system according to claim 1, The first screen includes the conditions of organizations other than the organization as reference information. Information processing system.

9. 2. The information processing system according to claim 1, The first screen is configured so that the plurality of conditions can be combined using either or both of an AND condition and an OR condition. Information processing system.

10. 2. The information processing system according to claim 1, The control unit Searching for cloud services based on the conditions set via the first screen regarding security, and acquiring and outputting information including the number of cloud services that satisfy the conditions. Information processing system.

11. An information processing method executed by an information processing system, Controlling the display of the first screen on the terminal of the administrator of the organization in response to a request; the first screen is configured to allow the organization to set conditions related to security of cloud services; determining whether or not the cloud service can be used based on the conditions set via the first screen and information related to the security of the cloud service; receiving a search request from a terminal of a person under management in the organization; the search request includes search conditions related to the cloud service; Controlling the terminal of the person to be managed to display a second screen; the second screen includes a list of cloud services; the cloud services included in the list are cloud services acquired based on the search criteria; Each cloud service included in the list is assigned label information, and The label information is information indicating a result of a determination as to whether the cloud service is available. Information processing methods.

12. A program, Computer, A program for causing the information processing system according to any one of claims 1 to 10 to function.

Citation Information

Patent Citations

  • Management device, control method, and program

    JP2015018338A

  • Method for determining availability of public cloud

    JP2017058985A

  • Information processing apparatus and method

    JP2023106709A

  • Data processing route management system and data processing route management method

    JP2024008735A

  • Method and apparatus for managing risk, such as compliance risk, in an organization

    US20080033775A1