Information processing apparatus, information processing method, and program

The system addresses the challenge of understanding security-related information by receiving, storing, and calculating security scores, providing a comprehensive security risk assessment.

JP2025179535AActive Publication Date: 2025-12-10BIZREACH INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024086361
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-28
Publication Date
2025-12-10
Estimated Expiration
2044-05-28

AI Technical Summary

Technical Problem

Existing systems fail to appropriately understand and quantify security-related information, specifically the challenges of providing an effective solution for the security-related information processing device, method, and program that enable appropriate understanding of security-related information.

Method used

The system includes a receiving unit to receive answers to security questions, a memory unit to store these answers, a control unit to calculate security-related scores, and an output unit to provide security scores based on these calculations, where the security measure score increases with decreasing security risk and the security risk score increases with increasing security risk.

Benefits of technology

This system allows for the appropriate understanding and quantification of security-related information, enabling effective security risk assessment and management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025179535000001_ABST
    Figure 2025179535000001_ABST
Patent Text Reader

Abstract

To provide an information processing apparatus, an information processing method, and a program configured to properly identify the risk regarding security of a target entity.SOLUTION: An information processing apparatus includes: a receiving unit which receives an answer to a question about security, from a target entity; a control unit which calculates a security measure score regarding measures against the security, based on a result of collecting answers, and calculates, based on the security measure score, a security risk score regarding residual risk of the security; and an output unit which outputs a security score specified based on at least one of the security measure score and the security risk score. The security measure score is higher as the risk of the security is lower. The security risk score is higher as the risk of the security is higher.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing device, an information processing method, and a program. [Background technology]

[0002] BACKGROUND ART Conventionally, there is known a technique for requesting answers to security-related questions from IT service providers and the like, and for checking security and the like (for example, Patent Document 1). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent No. 6969039 Summary of the Invention [Problem to be solved by the invention]

[0004] For example, you may be asked to provide appropriate security insights based on your answers to questions.

[0005] SUMMARY OF THE INVENTION It is therefore an object of the present invention to provide an information processing device, an information processing method, and a program that enable appropriate understanding of security-related information. [Means for solving the problem]

[0006] The disclosed aspect is an information processing device comprising: a receiving unit that receives answers to security questions from a target entity; a memory unit that stores the answers in association with the target entity; a control unit that calculates a security measure score related to the security measures based on the aggregation result of the answers, and calculates a security risk score related to the residual security risk based on the security measure score; and an output unit that outputs a security score determined based on at least one of the security measure score and the security risk score, wherein the memory unit stores the security measure score and the security risk score in association with the target entity, and the security measure score is a score that increases as the security risk decreases, and the security risk score is a score that increases as the security risk increases.

[0007] The disclosed aspect is an information processing method comprising the steps of receiving answers to security questions from a target entity, storing the answers in association with the target entity, calculating a security measure score related to the security measures based on the aggregation result of the answers, and calculating a security risk score related to the residual security risk based on the security measure score, outputting a security score determined based on at least one of the security measure score and the security risk score, and storing the security measure score and the security risk score in association with the target entity, wherein the security measure score is higher the lower the security risk, and the security risk score is higher the security risk is higher.

[0008] The disclosed aspect is a program that causes a computer to execute the following steps: receiving answers to security questions from a target entity; storing the answers in association with the target entity; calculating a security measure score related to the security measures based on the aggregation result of the answers; calculating a security risk score related to the residual security risk based on the security measure score; outputting a security score determined based on at least one of the security measure score and the security risk score; and storing the security measure score and the security risk score in association with the target entity, wherein the security measure score is higher the lower the security risk, and the security risk score is higher the higher the security risk. [Effects of the Invention]

[0009] According to the present invention, it is possible to provide an information processing device and an information processing method that enable appropriate understanding of security risks of a target entity. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a diagram showing an information processing system 100 according to an embodiment. [Figure 2] FIG. 2 is a diagram showing an information processing device 10 according to the embodiment. [Figure 3] FIG. 3 is a diagram for explaining an application scene according to the embodiment. [Figure 4] FIG. 4 is a diagram illustrating a security score according to the embodiment. [Figure 5] FIG. 5 is a diagram illustrating an information processing method according to the embodiment. [Figure 6] FIG. 6 is a diagram for explaining the first embodiment. [Figure 7] FIG. 7 is a diagram for explaining the first embodiment. [Figure 8] FIG. 8 is a diagram for explaining the first embodiment. [Figure 9] FIG. 9 is a diagram for explaining the second embodiment. [Figure 10] FIG. 10 is a diagram for explaining the second embodiment. [Figure 11] FIG. 11 is a diagram for explaining the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] Hereinafter, embodiments will be described with reference to the drawings. In the following description of the drawings, the same or similar parts are denoted by the same or similar reference numerals.

[0012] However, please note that the drawings are schematic and the ratios of the dimensions may differ from those of the actual product. Therefore, the specific dimensions should be determined by taking into consideration the following explanation. Furthermore, it goes without saying that the dimensional relationships or ratios may differ between the drawings.

[0013] [Disclosure Summary] The information processing device according to the disclosure summary comprises a receiving unit that receives answers to security-related questions from a target entity; a memory unit that stores the answers in association with the target entity; a control unit that calculates a security measure score related to the security measures based on the aggregation results of the answers and calculates a security risk score related to the residual security risk based on the security measure score; and an output unit that outputs a security score determined based on at least one of the security measure score and the security risk score, wherein the memory unit stores the security measure score and the security risk score in association with the target entity, and the security measure score is a score that increases as the security risk decreases, and the security risk score is a score that increases as the security risk increases.

[0014] The information processing method according to the disclosure summary includes the steps of receiving answers to security questions from a target entity, storing the answers in association with the target entity, calculating a security measure score related to the security measures based on the aggregation result of the answers, and calculating a security risk score related to the residual security risk based on the security measure score, outputting a security score determined based on at least one of the security measure score and the security risk score, and storing the security measure score and the security risk score in association with the target entity, wherein the security measure score is higher the lower the security risk, and the security risk score is higher the higher the security risk.

[0015] The program according to the outline of the disclosure causes a computer to execute the following steps: receiving answers to security questions from a target entity; storing the answers in association with the target entity; calculating a security measure score related to the security measures based on the aggregation result of the answers; calculating a security risk score related to the residual security risk based on the security measure score; outputting a security score determined based on at least one of the security measure score and the security risk score; and storing the security measure score and the security risk score in association with the target entity, wherein the security measure score is higher the lower the security risk, and the security risk score is higher the higher the security risk.

[0016] In the summary of the disclosure, the information processing device performs an operation of calculating a security measure score related to security measures based on the aggregation result of the responses, and also an operation of calculating a security risk score related to residual security risks based on the security measure score, and stores the security measure score and the security risk score in association with the target entity. The information processing device outputs a security score determined based on at least one of the security measure score and the security risk score. With this configuration, by calculating the security measure score and the security risk score, it is possible to output security scores from different perspectives, and to appropriately grasp the security risks of the target entity.

[0017] [Embodiment] (Information Processing System) An information processing system according to an embodiment will be described below. Fig. 1 is a diagram showing an information processing system 100 according to an embodiment.

[0018] 1, the information processing system 100 includes an information processing device 10, a provision server 30, a first terminal 40, and a second terminal 50. The information processing device 10, the provision server 30, the first terminal 40, and the second terminal 50 are connected by a network 200. Although not particularly limited, the network 200 may be configured by the Internet. The network 200 may include a local area network, a mobile communication network, or a VPN (Virtual Private Network).

[0019] The information processing device 10 may evaluate security related to the target entity. The security related to the target entity may be security related to a product provided by the target entity to a user entity. The product provided by the target entity may be interpreted as a transaction object between the target entity and the user entity. The product provided by the target entity may be a service or an object. In this case, for example, the target entity may be a manufacturer that produces an object. Furthermore, the service may include SaaS (Software as a Service), IaaS (Infrastructure as a Service), PaaS (Platform as a Service), etc. In this case, for example, the target entity may be a SaaS provider that provides SaaS. Furthermore, the transaction object provided by the target entity may be a specific task or business. Details of the information processing device 10 will be described later (see FIG. 2).

[0020] When the product provided by the target entity is a service, the providing server 30 may be a server belonging to the target entity that provides the service via the network 200.

[0021] The first terminal 40 is a terminal used by the target entity. The first terminal 40 may have a display unit 41. The display unit 41 may be configured with a display such as a liquid crystal panel, an organic electroluminescence (EL) panel, or an LED (light emitting diode). For example, the first terminal 40 may be a personal computer, a smartphone, or a tablet terminal. The first terminal 40 may also be referred to as the target entity.

[0022] The second terminal 50 is a terminal used by a third party different from the target entity. The third party may include a user entity that uses a product provided by the target entity. The second terminal 50 may have a display unit 51. The display unit 51 may be configured with a display such as a liquid crystal panel, an organic EL panel, or an LED. For example, the second terminal 50 may be a personal computer, a smartphone, or a tablet terminal. The second terminal 50 may also be referred to as a user entity.

[0023] (Information processing device) The information processing device 10 according to the embodiment will be described below. Fig. 2 is a diagram showing the information processing device 10 according to the embodiment.

[0024] As shown in FIG. 2, the information processing device 10 includes a transmitting unit 11, a receiving unit 12, a storage unit 13, and a control unit 14.

[0025] The transmitter 11 may be configured by a communication module. The communication module may be a wireless communication module conforming to a standard such as IEEE802.11a / b / g / n / ac / ax, LTE, 5G, or 6G, or may be a wired communication module conforming to a standard such as IEEE802.3.

[0026] The transmission unit 11 may transmit various information to the first terminal 40 (target entity) and the second terminal 50 (user entity). For example, the transmission unit 11 may transmit a security question to the first terminal 40. The question may be transmitted in a list format. For example, the transmission unit 11 may transmit a security response including a security score for the target entity to the second terminal 50.

[0027] The receiver 12 may be configured by a communication module. The communication module may be a wireless communication module conforming to a standard such as IEEE802.11a / b / g / n / ac / ax, LTE, 5G, or 6G, or may be a wired communication module conforming to a standard such as IEEE802.3.

[0028] The receiving unit 12 may receive various information from the first terminal 40 (target entity) and the second terminal 50 (user entity). For example, the receiving unit 12 may receive an answer to a security question from the first terminal 40. The answer may be received in the form of a list. For example, the receiving unit 12 may receive a security request from the second terminal 50 requesting a security score for the target entity.

[0029] The storage unit 13 is configured by a storage medium such as an SSD (Solid State Drive) or an HDD (Hard Disk Drive), and stores various information.

[0030] The storage unit 13 stores answers to security questions in association with the target entities. The storage unit 13 may also store security measure scores calculated by the control unit 14 (described later) in association with the target entities. The storage unit 13 may also store security risk scores calculated by the control unit 14 (described later) in association with the target entities. The database (DB) stored in the storage unit 13 may be referred to as an entity information DB.

[0031] The control unit 14 may include at least one processor. The at least one processor may be configured by a CPU (Central Processing Unit), an MPU (Micro Processing Unit), a GPU (Graphics Processing Unit), one or more integrated circuits, one or more discrete circuits, or a combination thereof.

[0032] The control unit 14 calculates a security score for the target entity. Specifically, the control unit 14 may calculate a security measure score for security measures based on the aggregated results of answers to security questions. The control unit 14 may calculate a security risk score for residual security risks based on the security measure score. The control unit 14 may identify a security score for the target entity based on at least one of the security measure score and the security risk score. The control unit 14 may instruct the transmission unit 11 to transmit (output) the identified security score. The security score may be a security measure score, a security risk score, or both the security measure score and the security risk score.

[0033] Here, the security measure score is a score that increases as the security risk decreases. Here, the security measure score may be interpreted as a score that increases as the level of security measures increases. The security risk score is a score that increases as the security risk increases. Details of the security measure score and security risk score will be described later (see Figure 4).

[0034] In the embodiment, the receiving unit 12 constitutes a receiving unit that receives answers to security questions from target entities. The storage unit 13 constitutes a memory unit that stores the answers in association with the target entities. The control unit 14 constitutes a control unit that calculates a security measure score related to security measures based on the aggregation result of the answers, and calculates a security risk score related to residual security risks based on the security measure score. The sending unit 11 constitutes an output unit that outputs a security score determined based on at least one of the security measure score and the security risk score.

[0035] (Applicable scenes) An application scene according to the embodiment will be described below: Fig. 3 is a diagram for explaining an application scene according to the embodiment.

[0036] As shown in Fig. 3, in an application scenario, when a target entity provides a product (including goods and services) to a user entity, there is assumed to be a case where the target entity has a counterparty (a trading partner entity) with whom it transacts in providing the product. Here, the entity (including the target entity and the trading partner entity) may be an organization, group, department, individual, etc. of a company, etc. For example, the target entity may be read as the target organization or the target company, and the trading partner entity may be read as the trading partner organization or the trading partner company.

[0037] For example, as shown in FIG. 3, there may be trading partner entity #1 and trading partner entity #2 as counterparties with which the target entity conducts transactions. Trading partner entity #1 and trading partner entity #2 may be referred to as first-order trading partner entities. There may be trading partner entity #1-1 and trading partner entity #1-2 as counterparties with which trading partner entity #1 conducts transactions. Trading partner entity #1-1 and trading partner entity #1-2 may be referred to as second-order trading partner entities. There may also be nth-order trading partner entities (n is an integer greater than or equal to 1) as trading partner entities.

[0038] Here, the target entity, trading partner entity #1, trading partner entity #1-1, and trading partner entity #1-2 may be considered to constitute one supply chain. Similarly, the target entity and trading partner entity #2 may be considered to constitute one supply chain. Furthermore, trading partner entity #1 and trading partner entity #1-1 may be considered to constitute one supply chain (sub-supply chain), and trading partner entity #1 and trading partner entity #1-2 may be considered to constitute one supply chain (sub-supply chain). Note that the supply chain shown in Figure 3 is an example and is not limited to this. Here, a supply chain may be a single supply chain consisting of the flow of goods, services, etc., and is constructed by multiple organizational entities. In a supply chain, the relationship between a target entity such as a cloud service provider and trading partner entities such as its outsourced business partners is specified.

[0039] A user entity is an entity that uses a product from a target entity. If the product is a cloud service, the user entity may be a cloud service consumer. If the product is an object such as a finished product or parts, the user entity may also be a purchaser of the object. If the product (transaction object) is business or work, the user entity may also be a requesting or outsourcing company for the business or work. From the perspective of the target entity, the user entity may also be a trading company, buyer, or parent company.

[0040] The target entity is an entity that provides a product to the user entity. If the product is a cloud service, the target entity may be a cloud service provider. From the perspective of the user entity, the target entity may be a business partner, a contractor (subcontractor, sub-subcontractor), a vendor, a supplier, etc. From the perspective of the trading partner entity, the target entity may be a business partner, contractor, seller, or subsidiary.

[0041] A business partner entity is an entity involved in the merchandise provided by a target entity to a user entity. From the perspective of the target entity, a business partner entity may be a business partner, a contractor (subcontractor, sub-subcontractor, sub-sub-subcontractor, etc.), a vendor, a supplier, etc.

[0042] Here, the above-mentioned storage unit 13 (entity information DB) stores trading partner entities related to a target entity in association with the target entity. The storage unit 13 (entity information DB) stores hierarchical relationships of a supply chain configured by trading partner entities and target entities having one or more hierarchical levels. Information about such a supply chain may be registered by a user entity or a target entity. The target entity may register all information about the supply chain including itself, or a trading partner entity included in the supply chain may register other trading partner entities that are at a lower hierarchical level (downstream) than itself. The storage unit 13 (entity information DB) stores trading partner security measure scores related to security measures related to trading partner entities in association with the trading partner entities. The storage unit 13 (entity information DB) stores trading partner security risk scores related to security measures related to trading partner entities in association with the trading partner entities.

[0043] Note that, when viewed from the target entity, the related trading partner entity may be a trading partner entity with which there is a trading relationship, a consignment relationship, a contract relationship, a buying / selling relationship, a group company relationship, etc. The above-mentioned storage unit 13 (entity information DB) may store other trading partner entities related to the trading partner entity in association with the trading partner entity.

[0044] Specifically, the entity information DB may store information about entities that make up the supply chain. The information about the entities may include identification information about the entities and company information about the entities (capital, president, risk information, service information, base information, etc.). The information about the entities may include information about the transaction hierarchy to which the entities belong in the supply chain, information about entities that are higher in the supply chain than the entities, and information about entities that are lower in the supply chain than the entities. The information about the entities may include information about the products (services or goods) provided by the entities, information about the transaction amounts of the entities, risk assessment information about the entities, etc. The risk assessment information may include a security measure score and a security risk score. The risk assessment information may include a business partner security measure score and a business partner security risk score, which will be described later.

[0045] (security score) The security score according to the embodiment will be described below. FIG. 4 is a diagram for explaining the security score according to the embodiment. As shown in FIG. 4, several methods for the security score are possible. For the sake of simplicity, FIG. 4 illustrates a case where there is one trading partner entity.

[0046] In method 1, the information processing device 10 calculates a security measure score related to security measures based on the results of tallying answers to security-related questions. For example, the information processing device 10 may calculate a security measure score according to the number of questions included in a security checklist that are answered with a predetermined answer (e.g., "Yes"). When the questions are classified by item, the information processing device 10 may tally the number for each item. The information processing device 10 manages a weighting value for each item and may calculate the security measure score after correcting the numerical value for each item based on the weighting value. The security measure score is a score that increases as the security risk decreases. The information processing device 10 stores a business partner security measure score related to security measures related to a business partner entity. The business partner security measure score is a score that increases as the security risk decreases.

[0047] Here, in Method 1, the security measure score may be quantified or indexed so that the upper limit is a base score (for example, 100) common to each entity, so that the security measure scores of each entity can be compared.

[0048] For example, the information processing device 10 may output 70 / 100 as the security measure score of the target entity, and 40 / 100 as the business partner security measure score of the business partner entity.

[0049] In method 1, the information processing device 10 may output the security measure score of the target entity (e.g., 70) as the security score for the target entity. The information processing device 10 may output the business partner security measure score of the business partner entity (e.g., 40) as the business partner security score for the business partner entity.

[0050] In method 1, the information processing device 10 may identify the highest risk score included in the supplier security scores of the supplier entities that make up the supply chain, and output the highest risk score in association with the supplier entity having the highest risk score. The highest risk score is the supplier security measure score with the lowest score.

[0051] In method 2, the information processing device 10 determines a security risk score related to residual security risk based on the security measure score. The higher the security risk, the higher the security risk. The information processing device 10 stores a business partner security risk score related to security risk related to a business partner entity. The higher the security risk, the higher the business partner security risk score.

[0052] Here, in Method 2, the security measure scores may be quantified or indexed so that a different base score for each entity is the upper limit. For example, the base score of the target entity may be 150, and the base score of the trading partner entity may be 100. The base score of the target entity may be set based at least on the data handled by the target entity. The base score of the trading partner entity may be set based at least on the data handled by the trading partner entity.

[0053] For example, the base score of an entity that handles personal information may be higher than the base score of an entity that does not handle personal information. The base score of an entity that handles sensitive information may be higher than the base score of an entity that does not handle sensitive information.

[0054] For example, when the security measure score of the target entity is 110, the information processing device 10 may output 40 (150-110) as the security risk score of the target entity, which is obtained by subtracting the security measure score from the base score. The information processing device 10 may output 60 (100-40) as the trading partner security risk score of the trading partner entity.

[0055] In other words, the security risk score is the score obtained by subtracting the security measure score from the base score of the target entity. Similarly, the trading partner security risk score is the score obtained by subtracting the trading partner security measure score from the base score of the trading partner entity. By subtracting the security measure score, which indicates the level of security measures, from the base score, which is the basic value of the security risk held by the entity, the actual security risk held by the entity can be grasped using a score.

[0056] In method 2, the information processing device 10 may output the security risk score of the target entity (e.g., 40) as the security score for the target entity. The information processing device 10 may output the trading partner security risk score of the trading partner entity (e.g., 60) as the trading partner security score for the trading partner entity.

[0057] In method 2, the information processing device 10 may identify the highest risk score included in the supplier security scores of the supplier entities that make up the supply chain, and output the highest risk score in association with the supplier entity having the highest risk score. The highest risk score is the score with the highest supplier security risk score.

[0058] In Method 3, the information processing device 10 calculates a supply chain security score for the entire supply chain based on the security score, the supplier security score, and the hierarchical relationship. The supply chain may include the sub-supply chain described above. In other words, the supply chain may be read as the sub-supply chain.

[0059] Here, in Method 3, the information processing device 10 may calculate the supply chain security score based on coefficients between entities that make up the supply chain. For example, the information processing device 10 may calculate the supply chain security score by multiplying at least one of the security score and the supplier security score by a coefficient. The following options are possible as the coefficient:

[0060] In option 1, the coefficient may be set based on a dependency coefficient between entities that make up the supply chain, and the dependency coefficient may be set based on the proportion that each entity contributes to the provision of the commodity.

[0061] For example, the higher the contribution of an entity to the provision of a commercial product, the larger the value of the dependency coefficient of the entity may be set.The larger the dependency coefficient, the larger the value of the coefficient may be set.

[0062] In option 2, the coefficient may be set based on weighting coefficients set for the entities that make up the supply chain. The weighting coefficient is set based on information about the entities that make up the supply chain, and is set based on at least one of the following information: personal information deposit, important information deposit, number of data handled, contract amount, business form, country of location, and technology used. Note that personal information deposit, important information deposit, number of data handled, contract amount, business form, country of location, and technology used may be examples of information about the entities.

[0063] The weighting coefficient, which is set based on information such as the deposit of personal information, deposit of important information, number of data handled, contract amount, business type, country of location, and technology used, may be set to a larger value as the expected damage or loss in the event of a security incident such as an information leak is greater.

[0064] For example, the weighting factor for entities with personal information embezzlement may be greater than the weighting factor for entities without personal information embezzlement.

[0065] For example, the weighting factor for an entity with material information deposition may be greater than the weighting factor for an entity without material information deposition.

[0066] For example, the larger the amount of data handled by an entity, the larger the value set as the weighting coefficient of the entity.

[0067] For example, the larger the contract amount of an entity, the larger the value set as the weighting coefficient of the entity.

[0068] For example, an entity that is a corporation may have a higher weighting factor than an entity that is an individual.

[0069] For example, the weighting factor for an entity located in a country with a relatively high geopolitical risk may be greater than the weighting factor for an entity located in a country with a relatively low geopolitical risk.

[0070] For example, the weighting factor of an entity whose technology is a technology that should be protected from a security perspective or is important (e.g., AI technology, military technology, etc.) may be higher than the weighting factor of an entity whose technology is not a technology that should be protected from a security perspective.

[0071] Option 3 may combine options 1 and 2.

[0072] In Method 3, Method 1 (security measure score and business partner security measure score) may be used to calculate the supply chain security score, or Method 2 (security risk score and business partner security risk score) may be used.

[0073] For example, when Method 1 is used, if the security measure score is 70, the business partner security measure score is 40, and the relationship between the coefficients of the target entity and the business partner entity is 20:80, the information processing device 10 may output 46 (70*0.2+40*0.8) as the supply chain security score. In such a case, the supply chain security score increases as the security risk decreases.

[0074] For example, when Method 2 is used, if the security risk score is 40, the trading partner security risk score is 60, and the relationship between the coefficients of the target entity and the trading partner entity is 20:80, the information processing device 10 may output 56 (40*0.2+40*0.8) as the supply chain security score. In such a case, the supply chain security score increases as the security risk increases.

[0075] In method 3, the information processing device 10 may identify the highest risk score included in the supplier security scores of the supplier entities that make up the supply chain, and output the score in association with the supplier entity having the highest risk score.

[0076] In method 3, when a supply chain includes multiple sub-supply chains, the information processing device 10 may identify the highest risk score included in the supply chain security score for each sub-supply chain, and output it in association with the sub-supply chain having the highest risk score.

[0077] (Information processing method) The information processing method according to the embodiment will be described below. Fig. 5 is a diagram showing the information processing method according to the embodiment.

[0078] As shown in FIG. 5, in step S10, the information processing device 10 transmits a security question to the target entity (first terminal 40).

[0079] In step S11, the information processing device 10 receives an answer to a security question from the target entity (first terminal 40). The information processing device 10 may also receive information about entities that make up a supply chain from the target entity (first terminal 40).

[0080] In step S12, the information processing device 10 stores the answer to the security question in association with the target entity. The information processing device 10 may store a trading partner entity related to the target entity in association with the target entity based on information about the entity. The information processing device 10 may store a hierarchical relationship of a supply chain made up of trading partner entities having one or more hierarchical levels and the target entity based on information about the entity.

[0081] In step S13, the information processing device 10 calculates a security score for the target entity. For example, the information processing device 10 calculates a security measure score and a security risk score.

[0082] If there is a business partner entity related to the target entity, the information processing device 10 may store a business partner security score for the business partner entity. For example, the information processing device 10 may store a business partner security measure score and a business partner security risk score.

[0083] The information processing device 10 may calculate a supply chain security score for the entire supply chain based on the security score, the supplier security score, and the hierarchical relationship.

[0084] In step S21, the information processing device 10 receives a score request from a user entity (second terminal 50). The score request may include a type of score requested by the user entity. The score type may include a security measure score and a business partner security measure score (method 1), a security risk score and a business partner security risk score (method 2), a supply chain security score based on method 1 (method 3), a supply chain security score based on method 2 (method 3), etc.

[0085] In step S22, the information processing device 10 transmits a score response to the score request to the user entity (the second terminal 50). The score response may include the score of the type requested by the score request.

[0086] In step S23, the user entity (second terminal 50) displays the security-related score based on the score response received from the information processing device 10.

[0087] (Example of operation) An example of operation relating to the above-described embodiment will be described below.

[0088] First, the information processing device 10 may send a signal (e.g., a URL of an input form) to the first entity requesting input of information about a second entity that is lower in the hierarchy than the first entity in response to input or selection of information (identification information, company name, products handled, etc.) about a first entity that is lower in the hierarchy than the target entity.

[0089] For example, cloud service provider A, which is a target entity, may input information about provider B, which is a first-tier trading partner entity, to information processing device 10. Information processing device 10 may send a signal to provider B requesting that provider B input information about entities (subcontractors, sub-subcontractors, etc.) that are lower in the hierarchy than provider B. Provider B may input information about providers D, E, and F that are connected to it in the supply chain to information processing device 10.

[0090] Alternatively, the cloud service provider A, which is the target entity, may input information about all entities that make up the supply chain (the provider B, the providers D, E, and F) into the information processing device 10.

[0091] Second, the information processing device 10 retrieves risk assessment information for the input / selected entity. The risk assessment information may be calculated based on the latest security checklist and answers to security questions stored in association with the entity.

[0092] Third, the target entity or the trading partner entity inputs coefficients such as a dependency coefficient or a weight coefficient to the information processing device 10. Alternatively, the information processing device 10 may set coefficients such as a dependency coefficient or a weight coefficient based on information about the entities constituting the supply chain (personal information deposit, important information deposit, number of data handled, contract amount, business form, country of location, and technology used). For example, the information processing device 10 may identify a weight coefficient from information about the entity using a table that defines the relationship between information about the entity and the weight coefficient. The table may be stored in the storage unit 13.

[0093] For example, if a supply chain is made up of N entities, risk assessment information for entities 1 to N may be stored in the storage unit 13, and coefficients such as dependency coefficients or weight coefficients may be set for nodes connecting each hierarchy. Alternatively, the information processing device 10 may set coefficients such as dependency coefficients or weight coefficients based on information about the entities from entity 1 to entity N.

[0094] Fourth, the information processing device 10 may calculate a supply chain security score based on the risk assessment information and the coefficients. The information processing device 10 may identify the highest risk score included in the supplier security scores of the supplier entities that make up the supply chain, and output the highest risk score in association with the supplier entity having the highest risk score.

[0095] Fifth, when a supply chain includes multiple sub-supply chains, the information processing device 10 may calculate a supply chain security score for each sub-supply chain. The information processing device 10 may identify the highest risk score included in the supply chain security score for each sub-supply chain, and output the highest risk score in association with the sub-supply chain having the highest risk score.

[0096] With this configuration, the security risk associated with commercial products can be improved by taking measures such as suspending use of the sub-supply chain with the highest risk or reviewing the trading partner entity with the highest risk score.

[0097] (Use Case) Use cases of the embodiment will be described below.

[0098] For example, a use case may be a case in which a cloud service user wants to understand the risks in the supply chain of a cloud service provider. The cloud service user is an example of a user entity, and the cloud service provider is an example of a target entity.

[0099] For example, a use case may be one in which a parent company evaluates the risk of a group of companies linked to its subsidiaries, sub-subsidiaries, etc. The parent company is an example of a user entity, and the subsidiaries, sub-subsidiaries, etc. are examples of target entities and business partner entities.

[0100] For example, a use case may involve an outsourcing company assessing supply chain risks not only for its outsourcee but also for its subcontractors, sub-subcontractors, etc. The outsourcing company is an example of a user entity, the outsourcee is an example of a target entity, and the subcontractors, sub-sub-subcontractors, etc. are examples of trading partner entities. In such a case, the user entity may be a cloud service consumer, the target entity may be a cloud service provider (the outsourcing company is the target entity), and the trading partner entity may be an outsourcing company that does business with the cloud service provider (the first-tier outsourcing company is the trading partner entity). Here, if there are outsourcing companies at a lower level, second-tier outsourcing companies, third-tier outsourcing companies, etc., n-tier outsourcing companies may also be trading partner entities.

[0101] For example, a use case may be one in which a first-tier subcontractor assesses the supply chain risks of second-tier, third-tier, etc. The first-tier subcontractor is an example of a user entity, and the second-tier, third-tier, etc. subcontractors are examples of target entities and trading partner entities. In such a case, the user entity may be a cloud service consumer, the target entity may be a cloud service provider, and the trading partner entities may be the cloud service provider's subcontractor (first-tier subcontractor), second-tier subcontractor, third-tier, etc.

[0102] For example, a user entity may be a person viewing a risk assessment (eg, an IT department representative, manager, etc. of an entity).

[0103] For example, the supply chain may be a supplier-manufacturer-wholesale-retailer supply chain, a cloud service provider-business partner-secondary business partner supply chain, a system developer-contractor-subcontractor supply chain, or a manufacturer-subcontractor-sub-subcontractor supply chain.

[0104] (Display mode) The display mode of the embodiment is described below. The display mode is a mode displayed on the second terminal 50 (user entity) and is a mode displayed based on data transmitted from the information processing device 10.

[0105] For example, the display manner may include a manner in which dependency coefficients, weight coefficients, and scores are displayed on the supply chain diagram.

[0106] For example, the display manner may include a manner in which the manner of characters (color, thickness, brightness) is changed depending on the magnitude of the coefficient or score.

[0107] For example, the display manner may include displaying high-risk companies in the supply chain (low security measure scores, high security risk scores) in a distinctive manner (color, font, size, etc.) that is distinguishable from others.

[0108] (others) Other variations of the embodiment will be described below.

[0109] For example, because risk assessments may vary depending on the products offered by the same company, risk assessments may generally be performed for each product. However, risk assessments may also be performed for each entity. For example, if cloud service provider A offers multiple cloud services as products, risk assessments may be performed for each cloud service, or risk assessments may be performed collectively for cloud service provider A.

[0110] For example, the calculation of the supply chain assessment (supply chain security score) may include the target entity, or may not include the target entity and only include the trading partner entity.

[0111] For example, countermeasures to reduce risk may be presented in accordance with the risk assessment. The countermeasures may include reviewing high-risk entities (such as substituting other entities) or reviewing high-risk chains (such as substituting other chains). The countermeasures may be stored in a table in association with the scores. The risk assessment may be input to AI and the countermeasures may be output from the AI.

[0112] To generate a countermeasure, a countermeasure creation model that has been trained to be able to input at least one risk assessment and output a countermeasure may be used. In this case, the control unit 14 may input risk assessments (such as scores and comments related to risks) and information about other entities into the countermeasure creation model and cause the countermeasure creation model to output a countermeasure. The countermeasure creation model is a learning model for outputting a countermeasure for the risk assessment of an entity. The countermeasure creation model may be a learning model that has been trained using training risk assessments and corresponding countermeasure data as training data.

[0113] The countermeasure generation model may be, for example, an AI (Artificial Intelligence) equipped with a language model such as a Transformer (including GPT (Generative Pretrained Transformer, including GPT-1, GPT-2, GPT-3, and GPT-4)), a Bidirectional Encoder Representations from Transformers (BERT), a Bidirectional and Auto-regressive Transformer (BART), or a Recurrent Neural Network (RNN), and may be a generative AI including a large-scale language model. In other words, the language model may not only be one trained for a specific task, but also a general-purpose model that can be used for a wide range of tasks. Examples of artificial intelligence include general-purpose natural language processing learning models such as Large Language Models (LLMs) that have learned massive amounts of data. In this case, the control unit may input risk assessments, entity information, etc., and input prompts including instructions to output countermeasures to the countermeasure generation model, causing the countermeasure generation model to output the countermeasures. In addition to the instruction to generate and output a countermeasure and the risk assessment, the control unit may input a prompt containing, as input and output samples, for example, one or more risk assessment samples and one or more corresponding countermeasure samples to the countermeasure generation model. The countermeasure generation model may output a countermeasure based on the risk assessment in accordance with the input prompt.

[0114] The AI ​​may be an external component of the provision server 30. In this case, the external component, the artificial intelligence, is provided, for example, by an artificial intelligence service server, and is configured to receive input from each functional unit of the provision server 30, receive requests to execute the artificial intelligence service, and return the instructed output as a processing result to the provision server 30. The artificial intelligence service server may be a server that provides a service using a language model as a learning model, or a server that executes language processing tasks using a language model. The artificial intelligence service server may be constructed by an LLM. The artificial intelligence service server receives input of prompts in the form of text, images, voice, etc., and generates and responds to the prompts.

[0115] For example, a risk assessment after countermeasures have been implemented may be displayed together with the current risk assessment. For example, the risk assessment after countermeasures have been implemented may be specified assuming countermeasures such as changing a weighting coefficient or a dependency coefficient, or changing a specific entity to another entity included in the DB.

[0116] For example, the weighting coefficient and the dependency coefficient may be set as separate coefficients, or may be set as a single coefficient reflecting the weighting coefficient and the dependency coefficient.

[0117] For example, the information processing device 10 may generate an alert notification when an entity whose security measure score or business partner security measure score is equal to or less than a predetermined value (e.g., 30 points) is included in the supply chain. Alternatively, the information processing device 10 may generate an alert notification when an entity whose security risk score or business partner security risk score is equal to or greater than a predetermined value (e.g., 70 points) is included in the supply chain.

[0118] (Action and effect) In the embodiment, the information processing device 10 performs an operation of calculating a security measure score related to security measures based on the aggregation result of the responses, and also an operation of calculating a security risk score related to residual security risks based on the security measure score, and stores the security measure score and the security risk score in association with the target entity. The information processing device outputs a security score determined based on at least one of the security measure score and the security risk score. With this configuration, by calculating the security measure score and the security risk score, it is possible to output security scores from different perspectives, and to appropriately grasp the security risks of the target entity.

[0119] In an embodiment, the information processing device 10 may output a supplier security score (supplier security measure score, supplier security risk score) when there is a supplier entity related to the target entity. With this configuration, it is possible to grasp the supplier security score, and therefore it is possible to appropriately grasp the risks that may be involved in the supply chain due to the supplier entity.

[0120] In an embodiment, the information processing device 10 may calculate a supply chain security score for the entire supply chain based on the security score, the supplier security score, and the hierarchical relationship, and output the calculated supply chain security score. With this configuration, it is possible to appropriately grasp the risks in the entire supply chain.

[0121] [Change Example 1] Modification 1 will be described below, focusing mainly on the differences from the embodiment.

[0122] In Modification Example 1, we consider a case in which the information processing device 10 has already received an answer to a security question from a specific entity, for example, when a specific entity is a trading partner entity in one supply chain and the specific entity is a target entity in another supply chain.

[0123] In a first modification, the information processing device 10 may calculate a supplier security score using at least a portion of a response received from a supplier entity (a target entity in another supply chain) in a risk assessment related to the supply chain of a certain product. At least a portion of the response received from the supplier entity may include an answer to a security-related question that is common between the certain product and another product.

[0124] [Change Example 2] The following describes Modification Example 2. The following mainly describes the differences from the embodiment.

[0125] In a second modification, the information processing device 10 may output, in response to a request from a user entity, a supply chain security score calculated based on the selection result of the user entity that selects either the security measure score or the security risk score.

[0126] For example, when a supply chain security score according to Method 1 is requested in the score request, the information processing device 10 may output a supply chain security score calculated based on the security measure score and the supplier security measure score.

[0127] For example, when a supply chain security score according to method 2 is requested in the score request, the information processing device 10 may output a supply chain security score calculated based on the security risk score and the business partner security risk score.

[0128] According to the second modification, it is possible to output a score calculated in a manner that meets the intention of the user entity.

[0129] [Change Example 3] The following describes Modification 3. The following mainly focuses on the differences from the embodiment.

[0130] In modified example 3, we consider a case in which the entities that make up the supply chain include entities that do not authorize the provision of information to the user entity (unauthorized entities) and entities that make up the supply chain that authorize the provision of information to the user entity (authorized entities).

[0131] In such a case, in response to a request from a user entity, the information processing device 10 may output a security score corresponding to an unauthorized entity in association with the unauthorized entity, but may output a security score corresponding to an authorized entity in association with the authorized entity. Similarly, in response to a request from a user entity, the information processing device 10 may output a business partner security score corresponding to an unauthorized entity in association with the authorized entity, but may not output a business partner security score corresponding to an unauthorized entity in association with the unauthorized entity.

[0132] Furthermore, the information processing device 10 may output a supply chain security score even if it does not output a security score corresponding to an unauthorized entity in association with the unauthorized entity. Similarly, the information processing device 10 may output a supply chain security score even if it does not output a supplier security score corresponding to an unauthorized entity in association with the unauthorized entity.

[0133] According to modification example 3, it is possible to prevent risk assessments from being disclosed by unauthorized entities to user entities that have not authorized disclosure, while disclosing risks throughout the supply chain and assisting user entities in understanding risks in the supply chain.

[0134] [Change Example 4] Modification 4 will be described below, focusing mainly on the differences from the embodiment.

[0135] In Modification Example 4, a method for setting a base score will be described. The base score may be set from the same perspective as the weighting coefficient described above. Specifically, the base score may be set based on at least one of the following information: personal information deposit, important information deposit, number of data handled, contract amount, business form, country of location, and technology used. Note that personal information deposit, important information deposit, number of data handled, contract amount, business form, country of location, and technology used may be examples of information about an entity. In Modification Example 4, for each of the above-mentioned information, the base score may be set to be higher for situations with higher risk.

[0136] For example, the base score for an entity with personal information embezzlement may be greater than the base score for an entity without personal information embezzlement.

[0137] For example, the base score for an entity with a material information deposit may be greater than the base score for an entity without a material information deposit.

[0138] For example, the larger the amount of data handled by an entity, the larger the value set as the entity's base score.

[0139] For example, the larger the contract amount of an entity, the larger the value set as the entity's base score.

[0140] For example, the base score for an entity that is a corporation may be greater than the base score for an entity that is an individual.

[0141] For example, the base score for an entity located in a country with relatively high geopolitical risk may be greater than the base score for an entity located in a country with relatively low geopolitical risk.

[0142] For example, the base score of an entity whose technology is one that should be protected from a security perspective (e.g., AI technology, military technology, etc.) may be higher than the base score of an entity whose technology is not one that should be protected from a security perspective.

[0143] Although not particularly limited, when a different base score is used for each entity in calculating the supply chain security score, the weighting coefficients described above do not need to be used. Alternatively, when the weighting coefficients described above are used in calculating the supply chain security score, a common base score for each entity may be used.

[0144] [Example] An example will be described below. In the example, a supply chain security score (method 3) based on method 1 will be described. In the example, it is assumed that the entity is a company, and the coefficients are set by the dependency coefficient and weight coefficient described above.

[0145] In the following, constituent companies are the names of the companies that make up the supply chain, number of constituent companies is the number of companies that make up the supply chain, coefficient is a preset value, security score is the supply chain security score, low score companies are companies with the lowest trading partner security measure scores, and lowest score is the lowest trading partner security measure score in the supply chain.

[0146] The lowest supplier security measure score is an example of the highest risk score. The company's (single) security score is the company's security measure score or supplier security measure score.

[0147] Example 1 In the first embodiment, as shown in FIG. 6, a case will be illustrated in which a target company A-1, a business partner company B, a business partner company E, a business partner company F, and a business partner company H are included in the supply chain.

[0148] As shown in Figure 6, Company A-1 (standalone) has a score of 100 points, Company B (standalone) has a score of 95 points, Company E (standalone) has a score of 50 points, Company F (standalone) has a score of 90 points, and Company H (standalone) has a score of 30 points. Between Company A-1 and Company B, the coefficient of Company A-1 is 0.1, and the coefficient of Company B is 0.9. This indicates, for example, that in a transaction between Company A-1 and Company B, Company A-1's degree of dependence on itself is 0.1, and its degree of dependence on Company B is 0.9. Between Company B, Company E, and Company F, the coefficient of Company B is 0.2, the coefficient of Company E is 0.5, and the coefficient of Company F is 0.3. This indicates that Company B does business with multiple companies, Company E and Company F, in this supply chain, and Company A's degree of dependence on Company B, 0.9, is divided into Company A's degree of self-dependence on Company B itself, its degree of dependence on Company E, and its degree of dependence on Company F. Of Company B's coefficient of 0.2, 0.1 is allocated to Company E and 0.1 is allocated to Company F, for a total of 0.2. Similarly, between Company E and Company H, Company E's coefficient (e.g., self-dependence) is 0.4, and Company H's coefficient (e.g., dependence) is 0.6.

[0149] Under these assumptions, the supply chain for company A-1 can be decomposed into supply chain 1-1 (A-1, B, E, H, F), supply chain 1-2 (B, E, H, F), supply chain 1-3 (B, E, H), supply chain 1-4 (E, H), supply chain 1-5 (H), supply chain 1-6 (B, F), and supply chain 1-7 (F), as shown in Figure 7.

[0150] Here, the security measure score of company A-1 (standalone) is calculated based on the answers to security-related questions. The business partner security measure scores of companies B, E, F, and H (standalone) may be obtained from company A-1 or may be calculated based on answers to security-related questions obtained in the past. As mentioned above, the coefficients are set in advance based on the degree of dependency, workload, level of security risk, etc.

[0151] Under these assumptions, the information processing device 10 calculates a supply chain security score based on the security measure score, the supplier security measure score, and the coefficient. Specifically, the information processing device 10 calculates the supply chain security score by multiplying the security score of each entity by the corresponding coefficient, starting from the lowest tier in the supply chain, and summing the products (Σ(coefficient × security score)). In the example shown in FIG. 7, the information processing device 10 calculates the supply chain security score starting from supply chains 1-7. For example, since supply chain 1-7 includes only company F, the supply chain security score of supply chain 1-7 is 1*90 points=90 points, which matches the security score of company F itself. Next, the information processing device 10 calculates the supply chain security scores in the order of supply chains 1-6 to 1-1. At this time, the calculated supply chain security scores for the lower levels are used to calculate the supply chain scores for the higher levels. The calculation method for the supply chain security score for each supply chain is as shown in FIG. 8. Note that the value of Σ(coefficient × score) may be divided by the sum of the coefficients to ensure that the security scores reach a perfect score (here, 100 points).

[0152] Next, the information processing device 10 outputs the supply chain security score of each supply chain as supply chain information related to company A-1, as well as the company with the lowest supplier security measure score (company H in the first embodiment) and the lowest supplier security measure score (30 in the first embodiment), as shown in Fig. 7. The information shown in Fig. 7 may be considered to be an example of information output to a user entity.

[0153] With this configuration, the user entity can understand that company H poses the highest risk, and can improve the security risk associated with the merchandise by taking measures such as reviewing company H. Even if company H is an unauthorized entity and information about company H (e.g., business partner security measure score) is not provided to the user entity, the user entity can understand that the supply chain security score of supply chain 1-2 (companies B, E, H, F) is lower than the supply chain security score of supply chain 1-6 (companies B and F), and can improve the security risk associated with the merchandise by taking measures such as reviewing supply chain 1-2.

[0154] Example 2 In Example 2, as shown in Figure 9, an example is given of a case in which target company A-2, trading company B, trading company C, trading company F, trading company G, trading company I, trading company J, trading company K, and trading company L are included in the supply chain.

[0155] As shown in Figure 9, the score for Company A-2 (standalone) is 100 points, the score for Company B (standalone) is 70 points, the score for Company C (standalone) is 60 points, the score for Company J (standalone) is 90 points, the score for Company F (standalone) is 90 points, the score for Company G (standalone) is 60 points, the score for Company K (standalone) is 60 points, the score for Company I (standalone) is 60 points, and the score for Company L (standalone) is 60 points. Between Company A-2 and Company B, the coefficient for Company A-2 is 0.1 and the coefficient for Company B is 0.9. Between Company A-2 and Company C, the coefficient for Company A-2 is 0.1 and the coefficient for Company B is 0.9. Between Company A-2 and Company J, the coefficient for Company A-2 is 0.1 and the coefficient for Company B is 0.9. Between Company B and Company F, the coefficient for Company B is 0.2 and the coefficient for Company F is 0.8. Between Company C and Company G, the coefficient for Company C is 0.1 and the coefficient for Company G is 0.9. Between Company G and Company I, the coefficient for Company G is 0.1 and the coefficient for Company I is 0.9. Between Company J and Company K, the coefficient for Company J is 0.1 and the coefficient for Company K is 0.9. Between Company K and Company L, the coefficient for Company K is 0.7 and the coefficient for Company L is 0.3.

[0156] Under these assumptions, the supply chain for company A-2 can be decomposed into supply chain 1-1 (A-2, B, F), supply chain 1-2 (B, F), supply chain 1-3 (F), supply chain 2-1 (A-2, C, G, I), supply chain 2-2 (C, G, I), supply chain 2-3 (G, I), supply chain 2-4 (I), supply chain 3-1 (A-2, J, K, L), supply chain 3-2 (J, K, L), supply chain 3-3 (K, L), and supply chain 3-4 (L), as shown in Figure 10.

[0157] Here, the security measure score of company A-2 (standalone) is calculated based on the answers to security-related questions. The business partner security measure scores of companies B, C, F, G, I, J, K, and L (standalone) may be obtained from company A-2 or may be calculated based on answers to security-related questions obtained in the past. The coefficients are assumed to be set in advance, as described above.

[0158] Under these assumptions, the information processing device 10 calculates the supply chain security score based on the security measure score, supplier security measure score, and coefficient. The information processing device 10 calculates Σ (coefficient × score) for each layer in turn, starting from the lowest layer in the supply chain. The calculation method is the same as in Example 1. The calculation method for the supply chain security score for each supply chain is as shown in Figure 11.

[0159] Next, the information processing device 10 outputs the supply chain security score of each supply chain as supply chain information related to company A-2, as well as the company with the lowest supplier security measure score (company H in the second embodiment) and the lowest trading partner security measure score (30 in the second embodiment), as shown in Fig. 10. The information shown in Fig. 11 may be considered to be an example of information output to a user entity.

[0160] With this configuration, the user entity can determine that company L poses the highest risk, and can improve the security risk associated with the merchandise by taking measures such as reviewing company L. Alternatively, the user entity can determine that supply chain 2-1 (companies A2, C(, G, I)) poses a high risk, and can improve the security risk associated with the merchandise by taking measures such as suspending use of supply chain 2-1 (companies A2, C(, G, I)). Furthermore, the user entity is provided with information to determine whether to prioritize addressing company L or supply chain 2-1.

[0161] [Other embodiments] Although the present invention has been described by the above-mentioned embodiments, the descriptions and drawings that form part of this disclosure should not be understood to limit the present invention. From this disclosure, various alternative embodiments, examples, and operating techniques will become apparent to those skilled in the art.

[0162] In the above disclosure, the customer security score may be determined based on at least one of the customer security measure score and the customer security risk score. The customer security score may be the customer security measure score, the customer security risk score, or both the customer security measure score and the customer security risk score.

[0163] In the above disclosure, the trading partner entity's trading partner security score (trading partner security measure score, trading partner security risk score) may be input by the target entity and stored in the information processing device 10, or may be input by the trading partner entity and stored in the information processing device 10. Alternatively, as described in Modification Example 1, the trading partner entity's trading partner security score may be calculated using at least a portion of the response received from the trading partner entity (a target entity in the supply chain of another commodity).

[0164] In the above disclosure, the hierarchical relationship of the supply chain may be input by the target entity and stored in the information processing device 10, or may be input by the trading partner entity and stored in the information processing device 10.

[0165] In the above disclosure, the dependency coefficient may be input by the target entity and stored in the information processing device 10, or may be input by the trading partner entity and stored in the information processing device 10.

[0166] In the above disclosure, the weighting coefficient may be input by the target entity and stored in the information processing device 10, or may be input by the trading partner entity and stored in the information processing device 10. Alternatively, the weighting coefficient may be set based on information about the entity (at least one of information about personal information deposit, important information deposit, number of data handled, contract amount, business form, country of location, and technology used).

[0167] Although not specifically mentioned in the above disclosure, the information processing device 10 may have a display unit that displays risk assessments (security risk score, business partner security score, and supply chain security score). The display unit may be configured with a display such as a liquid crystal panel, an organic EL panel, or an LED.

[0168] Although not specifically mentioned in the embodiments, a program may be provided that causes a computer to execute each process performed by the information processing device 10, the first terminal 40, and the second terminal 50. The program may also be recorded on a computer-readable medium. Using the computer-readable medium, the program can be installed on a computer. Here, the computer-readable medium on which the program is recorded may be a non-transitory recording medium. The non-transitory recording medium is not particularly limited, and may be, for example, a recording medium such as a CD-ROM or a DVD-ROM.

[0169] Alternatively, a chip may be provided that is configured by a memory that stores programs for executing the processes performed by the information processing device 10, the first terminal 40, and the second terminal 50, and a processor that executes the programs stored in the memory.

[0170] [Note] The above disclosure may be expressed as follows:

[0171] A first feature of the information processing device is that it includes a receiving unit that receives answers to security questions from a target entity; a memory unit that stores the answers in association with the target entity; a control unit that calculates a security measure score related to the security measures based on the aggregation results of the answers, and calculates a security risk score related to the residual security risk based on the security measure score; and an output unit that outputs a security score determined based on at least one of the security measure score and the security risk score, wherein the memory unit stores the security measure score and the security risk score in association with the target entity, and the security measure score is a score that increases as the security risk decreases, and the security risk score is a score that increases as the security risk increases.

[0172] A second feature is the method of the first feature, wherein the security risk score is a score obtained by subtracting the security measure score from the security-related base score; The base score is set based on at least the data handled by the target entity by an information processing device.

[0173] A third feature is the first or second feature, wherein the storage unit stores a trading partner entity related to the target entity in association with the target entity, and the storage unit stores a trading partner security measure score related to security measures for the trading partner entity and a trading partner security risk score related to security risks for the trading partner entity in association with the trading partner entity; The output unit is an information processing device that outputs a supplier security score that is specified based on at least one of the supplier security measure score and the supplier security risk score, in association with the security score.

[0174] A fourth feature is an information processing device according to the third feature, wherein the memory unit stores a hierarchical relationship of a supply chain composed of the trading partner entity and the target entity having one or more hierarchies, the control unit calculates a supply chain security score for the entire supply chain based on the security score, the trading partner security score, and the hierarchical relationship, and the output unit outputs the supply chain security score.

[0175] A fifth feature is the information processing device according to the fourth feature, wherein the control unit calculates the supply chain security score based on at least one of a dependency coefficient between entities that make up the supply chain and a weight coefficient set for the entities that make up the supply chain.

[0176] A sixth feature is the information processing device according to the fifth feature, wherein the control unit calculates the supply chain security score by multiplying at least one of the security score and the trading partner security score by at least one of the dependency coefficient and the weighting coefficient.

[0177] A seventh feature is an information processing device according to the fifth or sixth feature, wherein the weighting coefficient is information about the entities that make up the supply chain, and is set based on at least one of the following information: personal information deposit, important information deposit, number of data handled, contract amount, business form, country of location, and technology used.

[0178] An eighth feature is an information processing device in which, in at least one of the third to seventh features, the control unit determines the customer security score using at least a portion of an answer received from the customer entity as an answer to the security question.

[0179] A ninth feature is an information processing device in which, in at least one of the third to eighth features, the output unit outputs the highest risk score included in the business partner security score in association with the business partner entity having the highest risk score.

[0180] A tenth feature is an information processing device in which, in at least one of the fourth to seventh features, the output unit outputs the supply chain security score calculated based on a selection result of the user entity that selects either the security measure score or the security risk score in response to a request from the user entity.

[0181] An eleventh feature is an information processing device that, in at least one of the fourth to seventh features, in response to a request from a user entity, the output unit outputs a security score or a trading partner security score corresponding to an unauthorized entity in association with the authorized entity, without outputting a security score or a trading partner security score corresponding to the unauthorized entity in association with the unauthorized entity; the output unit outputs the supply chain security score even when the output unit does not output the security score or the trading partner security score corresponding to the unauthorized entity in association with the unauthorized entity; the unauthorized entity is an entity that constitutes the supply chain that has not authorized the provision of information to the user entity, and the authorizing entity is an entity that constitutes the supply chain that has authorized the provision of information to the user entity.

[0182] A twelfth feature is an information processing method comprising the steps of receiving an answer to a security question from a target entity, storing the answer in association with the target entity, calculating a security measure score related to the security measure based on a compilation result of the answers, and calculating a security risk score related to the residual security risk based on the security measure score, outputting a security score determined based on at least one of the security measure score and the security risk score, and storing the security measure score and the security risk score in association with the target entity, wherein the security measure score is higher as the security risk is lower, and the security risk score is higher as the security risk is higher.

[0183] A thirteenth feature is a program that causes a computer to execute the following steps: receiving answers to security questions from a target entity; storing the answers in association with the target entity; calculating a security measure score related to the security measures based on a compilation result of the answers; calculating a security risk score related to the residual security risk based on the security measure score; outputting a security score determined based on at least one of the security measure score and the security risk score; and storing the security measure score and the security risk score in association with the target entity, wherein the security measure score is higher as the security risk is lower, and the security risk score is higher as the security risk is higher. [Explanation of symbols]

[0184] 10...information processing device, 11...transmission unit, 12...reception unit, 13...storage unit, 14...control unit, 30...providing server, 40...first terminal, 50...second terminal, 100...information processing system, 200...network

Claims

1. a receiver for receiving an answer to the security question from the target entity; a storage unit that stores the answer in association with the target entity; a control unit that calculates a security measure score related to the security measures based on the aggregation result of the responses, and calculates a security risk score related to the residual security risk based on the security measure score; an output unit that outputs a security score determined based on at least one of the security measure score and the security risk score, the storage unit stores the security measure score and the security risk score in association with the target entity; the security measure score is a score that increases as the security risk decreases, An information processing device, wherein the security risk score is a score that increases as the security risk increases.

2. the security risk score is a score obtained by subtracting the security measure score from the security-related base score, The information processing device according to claim 1 , wherein the base score is set based on at least data handled by the target entity.

3. the storage unit stores a trading partner entity related to the target entity in association with the target entity; the storage unit stores a supplier security measure score related to security measures for the supplier entity and a supplier security risk score related to security risks for the supplier entity in association with the supplier entity; The information processing device according to claim 1 , wherein the output unit outputs a supplier security score identified based on at least one of the supplier security measure score and the supplier security risk score, in association with the security score.

4. the storage unit stores a hierarchical relationship of a supply chain configured by the trading partner entity and the target entity, the supply chain having one or more hierarchical levels; the control unit calculates a supply chain security score for the entire supply chain based on the security score, the supplier security score, and the hierarchical relationship; The information processing device according to claim 3 , wherein the output unit outputs the supply chain security score.

5. The information processing device according to claim 4 , wherein the control unit calculates the supply chain security score based on at least one of a dependency coefficient between entities that make up the supply chain and a weight coefficient set for the entities that make up the supply chain.

6. The information processing device according to claim 5 , wherein the control unit calculates the supply chain security score by multiplying at least one of the security score and the supplier security score by at least one of the dependency coefficient and the weighting coefficient.

7. 6. The information processing device according to claim 5, wherein the weighting coefficient is set based on information about entities that make up the supply chain, the information being at least one of personal information deposit, important information deposit, number of data handled, contract amount, business form, country of location, and technology used.

8. The information processing device according to claim 3 , wherein the control unit determines the customer security score using at least a part of a response received from the customer entity as a response to the security question.

9. The information processing device according to claim 3 , wherein the output unit outputs the highest risk score included in the supplier security score in association with the supplier entity having the highest risk score.

10. The information processing device according to claim 4 , wherein the output unit outputs the supply chain security score calculated based on a selection result of the user entity that selects either the security measure score or the security risk score in response to a request from the user entity.

11. the output unit, in response to a request from a user entity, does not output a security score or a customer security score corresponding to an unlicensed entity in association with the unlicensed entity, but outputs a security score or a customer security score corresponding to an authorized entity in association with the authorized entity; the output unit outputs the supply chain security score even when the security score or trading partner security score corresponding to the unauthorized entity is not output in association with the unauthorized entity; The unauthorized entity is an entity that is not authorized to provide information to the user entity among the entities that make up the supply chain, The information processing device according to claim 4 , wherein the licensing entity is an entity that licenses the provision of information to the user entity among the entities that make up the supply chain.

12. receiving an answer to a security question from the target entity; storing the answer in association with the target entity; calculating a security measure score related to the security measures based on the aggregation result of the responses, and calculating a security risk score related to the residual security risk based on the security measure score; outputting a security score determined based on at least one of the security measure score and the security risk score; and storing the security measure score and the security risk score in association with the target entity; the security measure score is a score that increases as the security risk decreases, An information processing method, wherein the security risk score is a score that increases as the security risk increases.

13. receiving an answer to a security question from the target entity; storing the answer in association with the target entity; calculating a security measure score related to the security measures based on the aggregation result of the responses, and calculating a security risk score related to the residual security risk based on the security measure score; outputting a security score determined based on at least one of the security measure score and the security risk score; storing the security measure score and the security risk score in association with the target entity; the security measure score is a score that increases as the security risk decreases, The security risk score is a score that increases as the security risk increases.

Citation Information

Patent Citations

  • Risk evaluation support system

    JP2022057956A

  • Information processing system and information processing method

    JP7448293B1

  • Question list management method, device, and program

    JP6969039B1