System

The system addresses inefficiencies in ISMS audits by using generative AI and anomaly detection to automate data analysis and feedback, ensuring timely and accurate audit reporting.

JP2026014839APending Publication Date: 2026-01-29SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024116313
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-19
Publication Date
2026-01-29

AI Technical Summary

Technical Problem

Conventional ISMS certification audits require significant human resources, are inefficient, and struggle with timely data analysis and manual report generation, making it difficult to respond quickly to audit findings.

Method used

A system that utilizes generative AI and anomaly detection algorithms to analyze information management regulations and log data, generating evaluation reports and incorporating user feedback for efficient and accurate audits.

Benefits of technology

Enables efficient and accurate ISMS certification audits by automating data analysis, report generation, and feedback incorporation, allowing for rapid response to audit results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026014839000001_ABST
    Figure 2026014839000001_ABST
Patent Text Reader

Abstract

A system is provided.SOLUTION: This system includes a means for accessing an information management database, a means for analyzing an information management regulation document, a means for analyzing log data, a means for generating an evaluation report based on an analysis result, a means for notifying the generated evaluation report, a means for collecting feedback, and a means for reflecting the collected feedback on the next process.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The technology of the present disclosure relates to a system. [Background technology]

[0002] Patent document 1 discloses a persona chatbot control method performed by at least one processor, the method including the steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to a description of the chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2022-180282 Summary of the Invention [Problem to be solved by the invention]

[0004] In conventional information management systems, conducting ISMS certification audits requires a large number of human resources, making it difficult to conduct audits efficiently. It is also difficult to effectively analyze the large amount of data generated during the audit process and make accurate evaluations. Furthermore, creating audit reports manually and incorporating feedback takes time, making it difficult to respond appropriately in situations where a quick response is required. [Means for solving the problem]

[0005] The present invention solves the above-mentioned problems by providing a system that includes a means for accessing an information management database, a means for analyzing information management regulations documents, a means for analyzing log data, a means for generating an evaluation report based on the analysis results, a means for notifying the generated evaluation report, a means for collecting feedback, and a means for incorporating the collected feedback into the next process. Specifically, the system analyzes regulations documents using a generation AI and analyzes log data using an anomaly detection algorithm, thereby conducting audits efficiently and accurately. Furthermore, the system notifies the automatically generated evaluation report and collects feedback from users to incorporate into the next audit process, enabling rapid response.

[0006] The "information management database" is a database for centrally managing data related to the information management system.

[0007] "Means of access" refers to the methods and techniques for connecting to an information management database and obtaining the required data.

[0008] An "information management regulations document" is a document that contains guidelines and policies regarding information security and management procedures.

[0009] "Means for analysis" refers to a method or device for analyzing information management regulations documents and log data using generative AI or algorithms.

[0010] "Log data" refers to data that records the operation history and event history of a system or application.

[0011] An "evaluation report" is a report that evaluates the security and management status of a system, generated based on the analysis results.

[0012] The "notification means" refers to a method or system for notifying interested parties of the generated evaluation report.

[0013] "Feedback collection means" are methods and techniques for gathering opinions and additional information from users.

[0014] "Means of incorporating feedback into the next process" refers to the methods and techniques used to incorporate the collected feedback into the next audit or evaluation process.

[0015] "Generative AI" is an artificial intelligence technology that analyzes regulatory documents and log data and generates evaluation reports.

[0016] An "anomaly detection algorithm" is a mathematical method for analyzing log data to detect abnormal behavior or unauthorized access. [Brief explanation of the drawings]

[0017] [Figure 1] 1 is a conceptual diagram showing an example of the configuration of a data processing system according to a first embodiment. [Figure 2] 1 is a conceptual diagram showing an example of main functions of a data processing device and a smart device according to a first embodiment. [Figure 3] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a second embodiment. [Figure 4] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and smart glasses according to a second embodiment. [Figure 5] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a third embodiment. [Figure 6] FIG. 11 is a conceptual diagram showing an example of main functions of a data processing device and a headset-type terminal according to a third embodiment. [Figure 7] FIG. 10 is a conceptual diagram showing an example of the configuration of a data processing system according to a fourth embodiment. [Figure 8] FIG. 10 is a conceptual diagram showing an example of main functions of a data processing device and a robot according to a fourth embodiment. [Figure 9] 1 shows an emotion map onto which multiple emotions are mapped. [Figure 10]1 shows an emotion map onto which multiple emotions are mapped. [Figure 11] FIG. 3 is a sequence diagram showing a processing flow of the data processing system according to the first embodiment. [Figure 12] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 1. [Figure 13] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system according to the second embodiment when an emotion engine is combined. [Figure 14] FIG. 10 is a sequence diagram showing the flow of processing in the data processing system in Application Example 2 when an emotion engine is combined. DETAILED DESCRIPTION OF THE INVENTION

[0018] An example of an embodiment of a system according to the technology of the present disclosure will be described below with reference to the accompanying drawings.

[0019] First, the terms used in the following description will be explained.

[0020] In the following embodiments, a coded processor (hereinafter simply referred to as a "processor") may be a single arithmetic device or a combination of multiple arithmetic devices. Furthermore, a processor may be a single type of arithmetic device or a combination of multiple types of arithmetic devices. Examples of arithmetic devices include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), and an APU (Accelerated Processing Unit).

[0021] In the following embodiments, a coded RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a working memory by a processor.

[0022] In the following embodiments, the coded storage is one or more non-volatile storage devices that store various programs, various parameters, etc. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), and magnetic tapes.

[0023] In the following embodiments, a communication I / F (Interface) with a symbol is an interface including a communication processor, an antenna, etc. The communication I / F controls communication between multiple computers. Examples of communication standards applied to the communication I / F include wireless communication standards including 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.

[0024] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." In other words, "A and / or B" means that it may be only A, only B, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" is also applied when three or more things are expressed connected by "and / or."

[0025] [First embodiment]

[0026] FIG. 1 shows an example of the configuration of a data processing system 10 according to the first embodiment.

[0027] 1, a data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0028] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0029] The smart device 14 includes a computer 36, a reception device 38, an output device 40, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The reception device 38, the output device 40, and the camera 42 are also connected to the bus 52.

[0030] The reception device 38 includes a touch panel 38A, a microphone 38B, and the like, and receives user input. The touch panel 38A detects contact with an indicator (for example, a pen or a finger) to receive user input by the touch of the indicator. The microphone 38B detects the user's voice to receive user input by voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0031] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form of expression that the user 20 can perceive (for example, audio and / or text). The display 40A displays visible information such as text and images in accordance with instructions from the processor 46. The speaker 40B outputs audio in accordance with instructions from the processor 46. The camera 42 is a compact digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0032] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 control the exchange of various information between the processor 46 and the processor 28 via the network 54.

[0033] FIG. 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0034] 2, in the data processing device 12, a specific process is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific process is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0035] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0036] In the smart device 14, the processor 46 performs the reception output process. The storage 50 stores a reception output program 60. The reception output program 60 is used in conjunction with the specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0037] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0038] This invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, and generates and notifies an evaluation report based on the analysis results. This system utilizes generative AI and anomaly detection algorithms to efficiently conduct ISMS audits and reflect user feedback in the next process.

[0039] System program processing description

[0040] The program processing flow of this system is shown below. The system is mainly composed of three components: the server, the user, and the terminal.

[0041] Server Processing

[0042] Accessing the database

[0043] The server accesses the information management database and connects using the necessary authentication information to extract data such as security guidelines, procedures, and access logs related to the company's ISMS certification.

[0044] Analysis of information management regulations documents

[0045] The server uses a generative AI to analyze information management policy documents extracted from the database. The generative AI checks whether the documents comply with the latest laws and regulations and best practices. For example, it analyzes "information protection policies" and "risk assessment reports" and evaluates whether their contents are appropriate.

[0046] Analyzing log data

[0047] The server analyzes the log data using anomaly detection algorithms. It analyzes access logs and system logs to check for abnormal access or unauthorized behavior. For example, it evaluates whether a specific user is accessing the site at an abnormal time.

[0048] Generate an assessment report

[0049] An evaluation report is generated based on the analysis results. The server uses the generation AI to create a comprehensive evaluation report based on the information obtained from the analysis. The report contains a detailed evaluation of the maintenance and operational status.

[0050] Evaluation report notification

[0051] The server will then send the generated assessment report to the auditor and company administrator via email, with the assessment report attached for immediate review.

[0052] User Action

[0053] Review the assessment report

[0054] The user receives an email from the server and checks the assessment report, which clearly shows the current status of the company's information security management and areas for improvement.

[0055] Providing feedback

[0056] The user may provide feedback based on the evaluation report as needed, for example, to add supplementary information to the report or to indicate matters requiring further confirmation.

[0057] Terminal handling

[0058] Send Feedback

[0059] The terminal sends the feedback entered by the user to the server, which receives the feedback and prepares it for the next audit process.

[0060] Specific examples

[0061] Company A's information management database stores the latest security guidelines, procedures, and access logs. The server accesses the database, extracts the necessary information, and begins analysis. The generation AI analyzes the regulation documents and checks whether their contents comply with the latest laws and regulations. In parallel, the anomaly detection algorithm analyzes the access logs and checks for any abnormal behavior. Based on the analysis results, the server generates a comprehensive evaluation report and notifies the auditor and company administrator. The user reviews the evaluation report and sends any necessary feedback to the server via their device. The server receives this feedback and reflects it in the next audit process.

[0062] As described above, by using this system, ISMS certification audits can be carried out effectively and efficiently.

[0063] The processing flow will be explained below.

[0064] Step 1:

[0065] The server accesses the information management database, connects to the database using the necessary authentication information, and extracts data related to the company's ISMS certification (security guidelines, procedures, access logs, etc.).

[0066] Step 2:

[0067] The server launches a generation AI to analyze information management regulations documents. The generation AI analyzes documents such as "information protection policies" and "risk assessment reports" to verify that their contents comply with the latest laws, regulations, and best practices.

[0068] Step 3:

[0069] The server analyzes the log data using anomaly detection algorithms, which examine access logs and system logs to check for unusual access or unauthorized behavior, such as detecting abnormal access patterns from a particular IP address.

[0070] Step 4:

[0071] The server generates an evaluation report based on the analysis results. Using the generation AI, the report details the maintenance and operational status. The report includes any issues discovered and suggestions for improvement.

[0072] Step 5:

[0073] The server notifies the auditor and company administrator of the generated assessment report by sending an email with the assessment report attached for immediate review.

[0074] Step 6:

[0075] The user receives an email sent from the server, checks the assessment report, and understands the current state of security management and areas for improvement.

[0076] Step 7:

[0077] The user provides feedback based on the evaluation report, adding supplementary information to the contents of the evaluation report or providing additional confirmation.

[0078] Step 8:

[0079] The device sends the feedback entered by the user to the server, which transmits the feedback to the server in near real time.

[0080] Step 9:

[0081] The server receives the feedback sent from the device, analyzes the feedback, and prepares to incorporate it into the next audit process. For example, items that require additional inspection may be included in the next audit.

[0082] By following the above steps, this system can efficiently and accurately conduct ISMS certification audits and immediately reflect feedback.

[0083] Example 1

[0084] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0085] In modern companies, maintaining the robustness of their information security management requires efficient and effective ISMS (Information Security Management System) audits. However, many conventional systems require a lot of manual work, such as data analysis, report generation, anomaly detection, and feedback utilization, which is time-consuming and costly. Another problem is that audit results are not fully utilized in the next audit process. To address this issue, a system is needed that streamlines the entire process of database access and analysis, evaluation report generation and notification, and feedback collection and reuse.

[0086] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0087] In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document, means for analyzing log data, means for generating an evaluation report based on the analysis results, means for notifying the evaluation report, means for collecting feedback from users, and means for reflecting the collected feedback in the next process. This makes it possible to streamline the ISMS audit process, reduce manual work, and effectively reflect the obtained feedback in the next and subsequent processes.

[0088] An "information management database" is a database that allows companies and organizations to centrally store and manage data related to information security management.

[0089] An "information management regulations document" is a document that describes information security policies, procedures, and other information security guidelines.

[0090] "Log data" refers to data that records the operation history of a system or network, and includes access logs and system event logs.

[0091] "Analysis" is the process of collecting data and examining and evaluating its contents in detail.

[0092] "Generative AI" is a system that uses artificial intelligence technology to automatically generate new information and documents.

[0093] An "anomaly detection algorithm" is an algorithm that analyzes system and network log data to detect unusual behavior or unauthorized access.

[0094] An "evaluation report" is a report that summarizes the current state of information security management and areas for improvement based on the results of data analysis.

[0095] "Feedback" refers to information such as opinions and improvement suggestions provided by users.

[0096] "Reflecting in the next process" means incorporating the collected feedback into the next work or analysis to achieve continuous improvement.

[0097] "Notification" is the process of informing interested parties of generated evaluation reports and information through communication means.

[0098] This invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, and generates and notifies an evaluation report based on the analysis results. This system utilizes generative AI and anomaly detection algorithms to efficiently conduct ISMS audits and reflect user feedback in the next process.

[0099] Server Processing

[0100] The server first accesses the information management database, which stores information such as security guidelines, procedures, and access logs related to ISMS certification. The server connects to the database using the necessary authentication information and extracts the necessary data.

[0101] Next, the server uses a generative AI (for example, Azure OpenAI) to analyze the information management policy document. A prompt such as "Analyze our information protection policy and check whether it complies with the latest regulations" is input to the generative AI. Based on this prompt, the generative AI analyzes the document and evaluates whether it complies with regulations and best practices.

[0102] In parallel, the server analyzes the log data using an anomaly detection algorithm (e.g., Kibana), analyzing access logs and system logs to detect any abnormal access or unauthorized behavior.

[0103] Once the analysis is complete, the server uses generative AI to create a comprehensive assessment report that details the state of information management, operational status, and areas for improvement. The assessment report is saved in PDF format and sent to auditors and company administrators via email (e.g., SendGrid or Amazon SES).

[0104] User Action

[0105] The user receives an email from the server and checks the assessment report, which clearly shows the current state of the company's information security management and areas for improvement.

[0106] When users provide feedback, they access a dedicated form based on the evaluation report and enter their feedback. Specifically, they can add supplementary information to the report or indicate matters requiring further confirmation.

[0107] Terminal handling

[0108] The device collects the feedback entered by the user and sends it to the server, which receives the feedback and prepares it for the next audit process.

[0109] Specific examples

[0110] Company A's information management database stores the latest security guidelines, procedures, and access logs. The server accesses the database, extracts the necessary information, and begins analysis. For example, it inputs a prompt to the generation AI, such as, "Analyze this information protection policy and confirm that it complies with the latest laws and regulations." In parallel, an anomaly detection algorithm uses Kibana to analyze the access logs and check for any abnormal behavior.

[0111] Based on the analysis results, the server generates a comprehensive evaluation report and notifies the auditor and company administrator. The user can review the evaluation report and send any necessary feedback to the server via their device. The server will then prepare to incorporate this feedback into the next audit process.

[0112] In this way, by using this system, ISMS certification audits can be carried out effectively and efficiently.

[0113] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0114] Step 1: Access the Database

[0115] The server obtains connection information to access the information management database. The connection information includes the database URL, user name, password, etc. The server uses this authentication information to connect to the database. If the connection is successful, the server extracts the necessary data from the database, such as security guidelines, procedures, and access logs related to ISMS certification. The input is the authentication information and database URL, and the output is the extracted data set. With this step, the server is ready to access the information management database and retrieve the necessary data.

[0116] Step 2: Analyze the information management policy document

[0117] The server inputs the extracted information management regulations document into the generation AI. The input data includes security guidelines and procedures. The server sets specific questions as prompts for the generation AI, such as, "Please confirm whether this information protection policy complies with the latest laws and regulations." The generation AI analyzes the document based on these prompts and evaluates whether it complies with laws and regulations and best practices. The analysis results are returned to the server, and the evaluation results and points for improvement are obtained as output. This step allows the server to use the generation AI to analyze the document.

[0118] Step 3: Analyze the log data

[0119] The server analyzes the log data using an anomaly detection algorithm (e.g., Kibana). Input data includes access logs and system logs. The server inputs the log data into the anomaly detection algorithm to detect abnormal access or unauthorized behavior. For example, it evaluates whether a specific user is accessing the system at an abnormal time. The analysis results output details of any abnormal events or unauthorized access detected by the anomaly detection algorithm. Through this step, the server identifies abnormal system behavior and reduces security risks.

[0120] Step 4: Generate an assessment report

[0121] The server generates an assessment report based on the analysis results of the information management regulations document and the log data. These analysis results are input, and the server uses a generation AI to create the assessment report. The generation AI compiles the analysis results into a report that details the maintenance status, operational status, and areas for improvement. The assessment report is saved in PDF format or other common formats, and a comprehensive assessment report is obtained as output. With this step, the server is ready to compile the audit results and provide them to the relevant parties.

[0122] Step 5: Notification of the evaluation report

[0123] The server notifies the relevant parties of the generated assessment report. The inputs are the generated assessment report and the relevant parties' email addresses. The server uses an email sending system (for example, SendGrid or Amazon SES) to send the assessment report to the auditor and company administrator. The assessment report is attached to the email, so that the relevant parties can immediately check the contents. The output is the sent notification email. This step ensures that the analysis results are communicated to the relevant parties quickly.

[0124] Step 6: Review the assessment report

[0125] The user receives an email sent from the server. The input is the email, and the user opens the assessment report attached to the email. The assessment report clearly shows the current state of the company's information security management and areas for improvement, so the user can review it and provide feedback or instructions to each department as necessary. The output is the contents of the assessment report reviewed by the user. This step allows the user to understand the audit results and take any necessary actions.

[0126] Step 7: Provide feedback

[0127] The user provides feedback based on the evaluation report. The input is the contents of the evaluation report and the user's feedback. The user accesses a dedicated input form and enters their opinions on the evaluation report, suggestions for improvement, and further confirmation items. Once the input is complete, the feedback is sent to the server by clicking the send button. The output is the feedback information provided by the user. This step allows the user to contribute to system improvements based on the evaluation report.

[0128] Step 8: Submit your feedback

[0129] The terminal collects the feedback entered by the user and sends it to the server. The input is the feedback entered by the user. The terminal communicates to consolidate the feedback and send it to the server. The server receives the feedback and prepares to reflect it in the next audit process. The output is the feedback sent to the server. This step allows the feedback provided by the user to be used in the next audit process, ensuring continuous improvement of the system.

[0130] In this way, the servers, users, and terminals work together to efficiently carry out the audit and improvement process of information security management.

[0131] (Application example 1)

[0132] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0133] Currently, auditing a company's information security management system (ISMS) requires manual checking of information management databases and analysis of documents and log data, which is time-consuming and laborious. The process for users to review assessment reports and provide feedback is also cumbersome. This reduces the efficiency of ISMS audits. Furthermore, access from mobile devices is difficult, limiting the location and time at which audit work can be performed. The purpose of this invention is to solve these issues and provide a more efficient and user-friendly ISMS audit system.

[0134] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0135] In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document, means for analyzing log data, means for generating an evaluation report based on the analysis results, means for notifying the generated evaluation report, means for collecting feedback, means for reflecting the collected feedback in the next process, means for securely accessing the information management database from a mobile device, and means for checking the evaluation report and providing feedback on the mobile device. This enables ISMS audits to be conducted efficiently and quickly, and enables users to check the evaluation report on their mobile devices and provide feedback.

[0136] An "information management database" is a database for collecting and managing data related to the information management of a company or organization.

[0137] An "information management regulations document" is a document in which a company or organization lists rules and procedures regarding information security and information management.

[0138] "Log data" refers to data that records the operating status of a system or application, and includes access history and system operation records.

[0139] An "evaluation report" is a report that summarizes the evaluation of a system or process, created based on the results of document analysis and log data analysis.

[0140] "Generative AI" is a technology or program that uses artificial intelligence to automatically analyze documents and data and generate results.

[0141] An "anomaly detection algorithm" is an algorithm that automatically detects unusual patterns or abnormal behavior from data.

[0142] A "mobile device" is a portable electronic device such as a smartphone or tablet.

[0143] "Feedback" refers to the act and content of providing evaluations, opinions, and areas for improvement.

[0144] "Means of notification" refers to the methods or functions used by the system to notify the user of specific information.

[0145] "Means of reflection" are the methods and functions for incorporating collected information and feedback into the next operation of a process or system.

[0146] The embodiment of the present invention will be described below: The system mainly consists of three components: a server, a user, and a mobile device.

[0147] Server Processing

[0148] The server accesses the information management database and extracts necessary data. Specifically, the server accesses the database using a security protocol to collect data such as security guidelines, procedures, and access logs.

[0149] The information management policy document is then analyzed using a generative AI, such as OpenAI's GPT-3 model, to ensure that the document complies with the latest regulations and best practices.

[0150] The server then analyzes the log data using anomaly detection algorithms, such as Isolation Forest and k-means clustering.

[0151] To generate an evaluation report based on the analysis results, the server uses a report generation library such as Python's ReportLab to create a comprehensive evaluation report.

[0152] The generated evaluation report is sent to the user via email using the SMTP protocol and the Python smtplib library.

[0153] Mobile Device Handling

[0154] Users use their mobile devices to access the server and check the assessment report. The HTTPS protocol is used to securely access the information management database from mobile devices.

[0155] After reviewing the evaluation report, the user can provide feedback if necessary. The feedback is entered directly from the mobile device and sent to the server.

[0156] User Action

[0157] The user checks the evaluation report sent from the server, understands the current situation and areas for improvement, and provides feedback based on the contents of the evaluation report, which is then sent back to the server.

[0158] The feedback may include specific improvements to the evaluation report or additional points to be checked, and will be reflected in the next audit process.

[0159] Specific examples

[0160] Specific examples are shown below.

[0161] When Company B uses the Mobile Security Audit Assistant, the server accesses the information management database and extracts the latest security guidelines and access logs.

[0162] The generative AI uses the following prompt to analyze the "Information Security Policy" document and ensure it complies with regulations:

[0163] Please confirm that the contents of your "Information Security Policy" document comply with the latest laws and regulations. Also, review the following seven aspects: 1. Advanced security measures 2. Appropriate management of information assets 3. Employee education and training 4. Risk assessment 5. Access control 6. Continuous improvement 7. Detection of abnormal login attempts.

[0164] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0165] Step 1:

[0166] The server accesses the information management database. It uses security authentication information and the database URL as input to retrieve data such as security guidelines, procedures, and access logs from the database. It obtains the extracted data as output. This process is securely accessed using the HTTPS protocol.

[0167] Step 2:

[0168] The server uses a generative AI model to analyze the information management regulations document. Using the extracted regulations document as input, the generative AI model (e.g., GPT-3) is given a prompt to analyze it. As a specific example, a prompt to confirm whether the contents of the "Information Security Policy" document comply with the latest laws and regulations is input to the generative AI. The analysis results are obtained as output.

[0169] Step 3:

[0170] The server analyzes the log data using an anomaly detection algorithm. Using the acquired log data as input, it applies an anomaly detection algorithm such as Isolation Forest or k-means clustering. The output is anomaly detection results. Specific operations include detecting unauthorized access and abnormal login attempts.

[0171] Step 4:

[0172] The server generates an evaluation report based on the analysis results. It uses the analysis results of the information management regulations document and the anomaly detection results from the log data as input, and creates the evaluation report using a report generation library such as Python's ReportLab. The generated evaluation report is obtained as output. Specifically, the report includes an evaluation of the current security measures and areas for improvement.

[0173] Step 5:

[0174] The server notifies the user of the evaluation report. Using the generated evaluation report and the user's email address as input, the server sends the report by email using the SMTP protocol. The server obtains the evaluation report that is notified to the user as output. Specifically, the email is sent using Python's smtplib library.

[0175] Step 6:

[0176] The user checks the evaluation report using a mobile device. Using the received evaluation report as input, the user views the report using the viewer function of the mobile device. The user receives the evaluation report as output. The user checks the report contents to understand the current situation and areas for improvement.

[0177] Step 7:

[0178] The user provides feedback from their mobile device. The evaluation report contents and any additional comments from the user are used as input and sent to the server via the feedback function within the application. The collected feedback is obtained as output. The feedback may include specific improvements or further considerations.

[0179] Step 8:

[0180] The server reflects the collected feedback in the next process. It uses the feedback provided by the user as input and saves and manages it as data to be reflected in the next audit process. It obtains feedback to be reflected in the next audit as output. Specifically, it saves the feedback content in a database and uses it as reference for the next analysis.

[0181] Furthermore, an emotion engine that estimates the user's emotion may be combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59 and perform identification processing using the user's emotion.

[0182] This invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, and generates and notifies an evaluation report based on the analysis results. By combining this system with an emotion engine, it collects and evaluates feedback from users more precisely and reflects the results in the next process.

[0183] System program processing description

[0184] The program processing flow of this system is shown below. The system is mainly composed of three components: the server, the user, and the terminal.

[0185] Server Processing

[0186] Accessing the database

[0187] The server accesses the information management database and connects to it using the necessary authentication information to extract data such as security guidelines, procedures, and access logs related to the company's ISMS certification.

[0188] Analysis of information management regulations documents

[0189] The server uses a generative AI to analyze information management policy documents extracted from the database. The generative AI checks whether the documents comply with the latest laws and regulations and best practices. Specifically, it analyzes "information protection policies" and "risk assessment reports" and evaluates whether their contents are appropriate.

[0190] Analyzing log data

[0191] The server analyzes the log data using anomaly detection algorithms, which examine access logs and system logs to check for abnormal access or unauthorized behavior, specifically detecting abnormal access patterns from specific IP addresses.

[0192] Generate an assessment report

[0193] An evaluation report is generated based on the analysis results. The server uses the generation AI to create an evaluation report that details the maintenance and operational status. The report includes any issues discovered and suggestions for improvement.

[0194] Evaluation report notification

[0195] The server notifies the auditor and company administrator of the generated assessment report by sending an email with the assessment report attached for immediate review.

[0196] User Action

[0197] Review the assessment report

[0198] The user receives an email sent from the server, checks the assessment report, and understands the current state of security management and areas for improvement.

[0199] Providing feedback

[0200] The user provides feedback based on the evaluation report. The user may add supplementary information or provide additional confirmations. The emotion engine also analyzes the user's emotional state.

[0201] Terminal handling

[0202] Send Feedback

[0203] The device sends the feedback entered by the user to the server, including the user's emotions.

[0204] Emotion Engine Operation

[0205] The emotion engine analyzes the emotion of the user based on the feedback, for example, identifying whether the user is dissatisfied or satisfied based on the content of the feedback.

[0206] Rating and categorizing feedback

[0207] Evaluate and categorize feedback content based on emotional data collected using an emotion engine, for example generating an alert for negative feedback requiring immediate attention.

[0208] Generate and send follow-ups

[0209] The server automatically generates and sends follow-up communications based on the user's emotions recognized by the emotion engine, for example, if the user is dissatisfied, it sends a follow-up email to offer additional support.

[0210] Specific examples

[0211] Company B's information management database stores the latest security guidelines, procedures, and access logs. The server accesses the database, extracts the necessary information, and begins analysis. The generation AI analyzes the regulation documents and checks whether their contents comply with the latest laws and regulations. In parallel, the anomaly detection algorithm analyzes the access logs and checks for any abnormal behavior. The server generates an evaluation report based on the analysis results and notifies the auditor and company administrator. The user checks the evaluation report and sends any necessary feedback to the server via their device. The feedback also includes the user's emotions, which are analyzed by the emotion engine. The server evaluates the feedback based on the emotion data and automatically generates and sends follow-up emails as necessary.

[0212] As described above, by using this system, ISMS certification audits can be carried out efficiently and accurately, and feedback that takes user feelings into consideration can be reflected immediately.

[0213] The processing flow will be explained below.

[0214] Step 1:

[0215] The server accesses the information management database, connecting using the necessary authentication information to extract data such as security guidelines, procedures, and access logs related to the company's ISMS certification.

[0216] Step 2:

[0217] The server launches a generation AI to analyze information management regulations documents. The generation AI analyzes documents such as "information protection policies" and "risk assessment reports" to verify that their contents comply with the latest laws, regulations, and best practices.

[0218] Step 3:

[0219] The server analyzes the log data using an anomaly detection algorithm. It analyzes access logs and system logs to check for abnormal access or unauthorized behavior. Specifically, it detects abnormal access patterns from specific IP addresses.

[0220] Step 4:

[0221] The server generates an evaluation report based on the analysis results. Using the generation AI, the report details the maintenance and operational status. The report includes any issues discovered and suggestions for improvement.

[0222] Step 5:

[0223] The server notifies the auditor and company administrator of the generated assessment report by sending an email with the assessment report attached for immediate review.

[0224] Step 6:

[0225] The user receives an email sent from the server and checks the evaluation report to understand the current state of security management and areas for improvement.

[0226] Step 7:

[0227] The user provides feedback based on the evaluation report. For example, the user may add supplementary information to the contents of the evaluation report or provide additional confirmation items. Here, the user may input feedback including their feelings.

[0228] Step 8:

[0229] The terminal transmits the feedback input by the user to the server, and the terminal transmits the feedback to the server in near real time.

[0230] Step 9:

[0231] The server receives the feedback sent from the device. The feedback includes the user's emotional data, which is then analyzed by the emotion engine. For example, the content and expressions of the sentences are used to measure the user's dissatisfaction or satisfaction.

[0232] Step 10:

[0233] The server evaluates and classifies the feedback content based on the user's emotions recognized by the emotion engine, for example, generating an alert indicating that negative feedback requires immediate attention.

[0234] Step 11:

[0235] The server generates follow-up communications based on the emotion engine's analysis, and if the user is dissatisfied, generates and sends a follow-up email to provide additional support or clarification.

[0236] Step 12:

[0237] The server then incorporates the feedback and sentiment analysis results into the next audit process. For example, if any issues are identified, specific steps and measures to resolve them can be added to the next audit plan.

[0238] Through these steps, this system can efficiently and accurately conduct ISMS certification audits and instantly reflect feedback that takes into account the user's feelings.

[0239] Example 2

[0240] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0241] Modern companies must manage large amounts of information and operate in compliance with laws and industry best practices. Appropriate document management and log analysis are essential, particularly for Information Security Management System (ISMS) certification. However, these tasks require time and effort when performed manually, and there is a high risk of human error. Furthermore, collecting and incorporating feedback after creating an evaluation report is cumbersome, making it difficult to properly reflect user sentiment and opinions. To address these challenges, a system that achieves advanced automation and sophisticated sentiment analysis is needed.

[0242] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document using a generative AI model, means for analyzing log data using an anomaly detection algorithm, means for generating an evaluation report based on the analysis results, means for notifying the generated evaluation report by email, means for collecting feedback from the user, means for analyzing the user's emotional state using an emotion engine, and means for reflecting the collected feedback and the analyzed emotional state in the next process. This makes it possible to improve the efficiency of the information management and evaluation processes related to ISMS certification and accurately reflect the user's emotions and opinions.

[0243] An "information management database" is a system that centrally stores and manages data used by companies and organizations for information security management.

[0244] A "generative AI model" is an artificial intelligence algorithm that uses natural language processing and machine learning techniques to analyze and generate text data.

[0245] An "information management regulations document" is a document that clearly states the procedures and policies regarding the operation and management of information security.

[0246] An "anomaly detection algorithm" is an algorithm that analyzes log data and the like to detect abnormal access or behavior that deviates from normal patterns.

[0247] An "evaluation report" is a report summarizing the results of the analysis, detailing the current state of security management and areas for improvement.

[0248] "Email" is a means of communication for sending documents and files to other parties via the Internet.

[0249] "Users" are people involved in information security management, such as employees and managers of companies that use the system.

[0250] "Feedback" refers to user opinions and comments provided in response to an evaluation report.

[0251] The "emotion engine" is an artificial intelligence algorithm that analyzes feedback content and identifies the user's emotional state.

[0252] This invention relates to a system that enables companies and organizations to manage information security efficiently and precisely. This system accesses an information management database, analyzes information management regulations documents and log data using generative AI models and anomaly detection algorithms, and generates and notifies evaluation reports based on the analysis results. It also collects feedback from users and uses an emotion engine to reflect the feedback in the next process.

[0253] Hardware and Software Configuration

[0254] This system is mainly composed of three components: the server, the terminal, and the user. The hardware and software for each component are as follows:

[0255] server

[0256] Hardware: The server is a server machine equipped with a powerful processor, ample memory space, and large storage capacity.

[0257] software:

[0258] Database Management System (DBMS): Used to manage information management databases.

[0259] Generative AI model: Used to analyze information management policy documents.

[0260] Anomaly detection algorithms: Used to analyze log data.

[0261] SMTP Server: Used for email notification of assessment reports.

[0262] Terminal

[0263] Hardware: Terminal devices such as PCs and tablets that accept user input.

[0264] software:

[0265] Web browser: Used by users to view evaluation reports and provide feedback.

[0266] HTTP client: Used to send feedback data to the server.

[0267] Emotion engine: Used to analyze feedback content and determine the user's emotional state.

[0268] User

[0269] Role: The user is responsible for using the system to review the evaluation reports and provide feedback.

[0270] System Operation

[0271] 1. Access to the database

[0272] The server connects to the information management database using authentication information and extracts the necessary data (security guidelines, procedures, access logs, etc.).

[0273] 2. Analysis of information management regulations documents

[0274] The server uses the generative AI model to analyze the extracted information management regulations document. For example, analysis can be performed by inputting the following prompt sentence into the generative AI model:

[0275] "Analyze this document for compliance with the latest regulations."

[0276] 3. Log data analysis

[0277] The server analyzes the log data using anomaly detection algorithms, for example, to detect abnormal access patterns from specific IP addresses.

[0278] 4. Generate an evaluation report

[0279] The generative AI model generates an evaluation report based on the analysis results. The evaluation report includes any issues found and suggestions for improvement. An example of a prompt is as follows:

[0280] "Please prepare an evaluation report based on the analysis results. Please include any issues and suggestions for improvement."

[0281] 5. Notification of Evaluation Report

[0282] The server will notify the auditor or company administrator of the generated assessment report via email.

[0283] 6. Feedback Collection and Analysis

[0284] Users use their devices to check the evaluation reports and provide feedback, which is then sent to the server and analyzed by the emotion engine.

[0285] For example, the server analyzes security guidelines, procedures, and access logs obtained from a company's information management database, generates an evaluation report, and notifies the administrator. The user (administrator) checks the evaluation report and enters feedback into the system. The emotion engine analyzes the user's emotional state from the feedback and reflects it in the next process.

[0286] By using this system, companies can efficiently and accurately manage information related to ISMS certification, and can instantly reflect feedback that takes user emotions into consideration.

[0287] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0288] Step 1:

[0289] The server accesses the information management database. Specifically, it connects to the database management system (DBMS) using authentication information (user ID and password) set by the administrator. At this time, the server executes the necessary queries and extracts data such as "security guidelines," "procedures," and "access logs." The input is the authentication information, and the output is the extracted data set.

[0290] Step 2:

[0291] The server uses a generative AI model to analyze the information management regulations document. The input data is the "information management regulations document" extracted from the database. Specifically, the analysis is performed by inputting the following prompt into the generative AI model: "Please analyze whether this document complies with the latest laws and regulations." The generative AI model analyzes the document content and outputs whether it complies with the regulations and any necessary improvements.

[0292] Step 3:

[0293] The server analyzes the log data using an anomaly detection algorithm. The input data is the "access log" and "system log." The server uses pattern matching technology to detect abnormal access patterns or unauthorized behavior from a specific IP address. For example, it detects "multiple invalid login attempts from a specific IP address." The output is the anomaly detection results and their details.

[0294] Step 4:

[0295] The server generates an evaluation report based on the analysis results. The input data are the "analysis results of the regulations document" and the "analysis results of the log data." Using the generative AI model, the server creates an evaluation report that includes issues and improvement suggestions. As a specific example, the following prompt is input to the generative AI model: "Please create an evaluation report based on the analysis results. Please include issues and improvement suggestions." The output is the created evaluation report.

[0296] Step 5:

[0297] The server will notify the generated assessment report by email. The input data is the "assessment report". The server will attach the assessment report to an email and send it to the designated auditor and company administrator using the SMTP protocol. The output is the sent email and a confirmation of its delivery.

[0298] Step 6:

[0299] The user checks the evaluation report using a terminal. The input data is the "email sent from the server." The user opens the evaluation report in an email client to understand the current state of security management and areas for improvement. The output is a review of the evaluation report and an understanding of its contents.

[0300] Step 7:

[0301] The user provides feedback based on the content of the evaluation report. The input data is the "evaluation report." The user uses the feedback form to enter supplementary information or additional confirmations. The feedback also includes an emotional state that can be analyzed by the emotion engine. The output is the written feedback.

[0302] Step 8:

[0303] The terminal sends the feedback entered by the user to the server. The input data is "user feedback". The terminal sends an HTTP POST request to send the feedback to the server. The output is the sent feedback data.

[0304] Step 9:

[0305] The emotion engine analyzes the user's feedback content. The input data is the "feedback content." The emotion engine uses text analysis technology to determine the user's emotion from the feedback content. For example, it identifies "dissatisfied" or "satisfied." The output is the analyzed emotion data.

[0306] Step 10:

[0307] The server evaluates and classifies the feedback content using the emotional data analyzed by the emotion engine. The input data is the analyzed emotional data and the feedback content. For example, an alert is generated indicating that negative feedback requires immediate action. The output is the evaluated and classified feedback data.

[0308] Step 11:

[0309] The server generates and sends follow-up communications based on the user's emotions recognized by the emotion engine. The input data is the "evaluated and classified feedback data and analyzed emotion data." For example, if the user is dissatisfied, a follow-up email offering additional support is automatically generated and sent using the SMTP protocol. The output is the sent follow-up email and its confirmation of delivery.

[0310] (Application example 2)

[0311] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart device 14 will be referred to as a "terminal."

[0312] Traditional information management systems mainly focus on functions such as document analysis and log data monitoring, but lack the ability to analyze feedback sentiment and generate follow-up communications and notifications based on it. This makes it difficult to improve user satisfaction and take prompt and effective action. As a result, the quality of information security management may decline and users may lose trust.

[0313] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 2 is realized by the following means.

[0314] In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document, means for analyzing log data, means for generating an evaluation report based on the analysis results, means for notifying the generated evaluation report, means for collecting feedback, means for reflecting the collected feedback in the next process, means for analyzing the emotions of the feedback using an emotion engine, and means for generating and notifying follow-up communication based on the analyzed emotions. This enables emotion analysis based on user feedback and rapid follow-up accordingly, thereby improving the quality of information security management and increasing user satisfaction and trust.

[0315] An "information management database" is a database that centrally manages data related to information security management for companies and organizations.

[0316] An "information management regulations document" is a document that contains guidelines and best practices regarding information security.

[0317] "Log data" refers to data that records system behavior and access history.

[0318] An "evaluation report" is a report generated based on the results of analysis of information management regulations documents and log data.

[0319] "Means of notification" refers to the means of transmitting the evaluation report and follow-up communications.

[0320] "Feedback" refers to the user's opinions and thoughts on the evaluation report.

[0321] An "emotion engine" is a system for analyzing emotions based on user feedback.

[0322] "Follow-up communications" are additional messages or support generated based on sentiment analysis.

[0323] "Generative AI" refers to artificial intelligence that analyzes natural language and automatically generates documents and reports.

[0324] An "anomaly detection algorithm" is an algorithm that analyzes log data to detect abnormal behavior or unauthorized access.

[0325] The present invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, generates and notifies evaluation reports, collects feedback and analyzes emotions, and generates and notifies follow-up communications. A specific embodiment of this system is described below.

[0326] Key Components of the System

[0327] It consists of three components: server, user, and terminal.

[0328] Server Processing

[0329] 1. Access to the database:

[0330] The server uses appropriate authentication information (e.g., tokens) to access the information management database and extracts data such as security guidelines and access logs. The hardware used is a high-performance server, and the software may utilize a REST API.

[0331] 2. Analysis of information management regulations documents:

[0332] The server uses a generative AI model (e.g., GPT-3) to analyze information management policy documents extracted from the database, using libraries such as AutoTokenizer and AutoModelForSeq2SeqLM to ensure that the document content complies with the latest regulations.

[0333] 3. Log data analysis:

[0334] The server analyzes the log data using an anomaly detection algorithm (e.g., IsolationForest), processes the log data in a tabular format, and detects anomalous access patterns from specific IP addresses.

[0335] 4. Evaluation report generation and notification:

[0336] Based on the analysis results, an assessment report is generated using a generative AI model, which includes a detailed assessment and improvement suggestions based on the analyzed data, and the generated assessment report is notified to the auditor and company management via email.

[0337] User Action

[0338] 1. Review the assessment report:

[0339] The user receives the email sent from the server and checks the evaluation report. The user understands the contents of the report and confirms the current state of security management and any necessary improvements.

[0340] 2. Providing Feedback:

[0341] Users provide feedback on the evaluation report, including their opinions and thoughts entered through a feedback form.

[0342] Terminal handling

[0343] 1. Feedback submission and sentiment analysis:

[0344] The device sends the user-entered feedback to the server, which then uses an emotion engine to analyze the user's emotions from the feedback content. It uses libraries such as TextBlob to classify the emotions of the feedback text as positive, neutral, or negative.

[0345] 2. Follow-up generation and notification:

[0346] The server automatically generates follow-up communications based on the analyzed sentiment data: if the user provides negative feedback, a follow-up email is sent to offer additional support.

[0347] Specific examples

[0348] A company with multiple departments is using this system. One day, the company's security team receives a weekly security assessment report. The report was generated using a generative AI model (e.g., GPT-3) and includes the latest security guidelines and access log analysis results. Security team members review the report and provide feedback within the app. The device analyzes this feedback with an emotion engine and detects positive emotions, such as "Please enter your feedback: The contents of this report were very helpful." Based on the analysis results, the server automatically generates a follow-up message, such as "Thank you for using our service," and notifies the user, thereby improving satisfaction.

[0349] Prompt Sentence Examples

[0350] "Analyze the document and assess its compliance with modern security standards: 'All employees must comply with company security policies...'"

[0351] As described above, the embodiment of the present invention provides an integrated system for efficiently and effectively managing corporate information security.

[0352] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0353] Step 1:

[0354] The server accesses the information management database. The inputs are the database URL and authentication token. Based on this, data such as security guidelines and access logs are extracted using a REST API. The output is the extracted data. Specifically, a GET request is sent using the requests library. The required data is returned as a response to this request.

[0355] Step 2:

[0356] The server analyzes the information management regulations document. The input is the text of the information management regulations document extracted in step 1. This text is passed to a generative AI model (e.g., GPT-3), which analyzes the document content. The output is an evaluation as the analysis result. Specifically, the text is tokenized using AutoTokenizer, and then the generation process is performed by the model using AutoModelForSeq2SeqLM.

[0357] Step 3:

[0358] The server analyzes the log data. The input is the log data, such as the access log obtained in step 1. This data is passed to an anomaly detection algorithm (e.g., Isolation Forest) to detect abnormal access patterns. The output is the anomaly detection results. Specifically, the log data is converted into a table format using the pandas library, and anomalies are detected using Isolation Forest.

[0359] Step 4:

[0360] The server generates an evaluation report based on the analysis results. The inputs are the analysis results from steps 2 and 3. These results are combined and passed to a generative AI model to generate an evaluation report. The output is the generated evaluation report. Specifically, the generative AI uses an evaluation report template to generate a report containing detailed descriptions.

[0361] Step 5:

[0362] The server notifies the user of the generated evaluation report. The input is the evaluation report and the user's contact information. An email is generated based on this information and the notification is sent. The output is the sent notification email. Specifically, the server uses an SMTP server to send an email with the evaluation report attached.

[0363] Step 6:

[0364] The user receives the evaluation report and checks its contents. The input is the email containing the evaluation report sent from the server. The output is a confirmation of the evaluation report. The user opens the report and understands the current state of security management.

[0365] Step 7:

[0366] The user provides feedback on the evaluation report. The input is the user's opinion or impression on the evaluation report. This is entered through a feedback form and sent. The output is the entered feedback. Specifically, the user enters text into the feedback form and presses the "Submit" button.

[0367] Step 8:

[0368] The terminal sends the feedback entered by the user to the server. The input is the feedback text entered by the user. The terminal sends this data to the server. The output is the sent feedback data. The specific operation is to send the feedback data to the server using an HTTP POST request.

[0369] Step 9:

[0370] The server uses an emotion engine to analyze the sentiment of the feedback. The input is the feedback text, which is passed to an emotion analysis library (e.g., TextBlob) to classify the sentiment as positive, neutral, or negative. The output is the analyzed emotion data. Specifically, it uses TextBlob to calculate the sentiment score of the text and classifies it based on that.

[0371] Step 10:

[0372] The server generates and notifies follow-up communications based on the analyzed emotional data. The input is the emotional analysis results and the user's contact information. A follow-up message is generated based on this information and a notification email is sent. The output is the generated follow-up message and the sent notification email. The specific operation is that the generation AI generates a follow-up message and sends the email using the SMTP server.

[0373] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0374] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0375] In the above embodiment, an example in which the specific process is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific process may be performed by the smart device 14.

[0376] [Second embodiment]

[0377] FIG. 3 shows an example of the configuration of a data processing system 210 according to the second embodiment.

[0378] 3, the data processing system 210 includes the data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0379] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0380] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication I / F 44. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, and the camera 42 are also connected to the bus 52.

[0381] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0382] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0383] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0384] Fig. 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Fig. 4, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0385] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0386] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0387] In the smart glasses 214, the reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0388] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal."

[0389] This invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, and generates and notifies an evaluation report based on the analysis results. This system utilizes generative AI and anomaly detection algorithms to efficiently conduct ISMS audits and reflect user feedback in the next process.

[0390] System program processing description

[0391] The program processing flow of this system is shown below. The system is mainly composed of three components: the server, the user, and the terminal.

[0392] Server Processing

[0393] Accessing the database

[0394] The server accesses the information management database and connects using the necessary authentication information to extract data such as security guidelines, procedures, and access logs related to the company's ISMS certification.

[0395] Analysis of information management regulations documents

[0396] The server uses a generative AI to analyze information management policy documents extracted from the database. The generative AI checks whether the documents comply with the latest laws and regulations and best practices. For example, it analyzes "information protection policies" and "risk assessment reports" and evaluates whether their contents are appropriate.

[0397] Analyzing log data

[0398] The server analyzes the log data using anomaly detection algorithms. It analyzes access logs and system logs to check for abnormal access or unauthorized behavior. For example, it evaluates whether a specific user is accessing the site at an abnormal time.

[0399] Generate an assessment report

[0400] An evaluation report is generated based on the analysis results. The server uses the generation AI to create a comprehensive evaluation report based on the information obtained from the analysis. The report contains a detailed evaluation of the maintenance and operational status.

[0401] Evaluation report notification

[0402] The server will then send the generated assessment report to the auditor and company administrator via email, with the assessment report attached for immediate review.

[0403] User Action

[0404] Review the assessment report

[0405] The user receives an email from the server and checks the assessment report, which clearly shows the current status of the company's information security management and areas for improvement.

[0406] Providing feedback

[0407] The user may provide feedback based on the evaluation report as needed, for example, to add supplementary information to the report or to indicate matters requiring further confirmation.

[0408] Terminal handling

[0409] Send Feedback

[0410] The terminal sends the feedback entered by the user to the server, which receives the feedback and prepares it for the next audit process.

[0411] Specific examples

[0412] Company A's information management database stores the latest security guidelines, procedures, and access logs. The server accesses the database, extracts the necessary information, and begins analysis. The generation AI analyzes the regulation documents and checks whether their contents comply with the latest laws and regulations. In parallel, the anomaly detection algorithm analyzes the access logs and checks for any abnormal behavior. Based on the analysis results, the server generates a comprehensive evaluation report and notifies the auditor and company administrator. The user reviews the evaluation report and sends any necessary feedback to the server via their device. The server receives this feedback and reflects it in the next audit process.

[0413] As described above, by using this system, ISMS certification audits can be carried out effectively and efficiently.

[0414] The processing flow will be explained below.

[0415] Step 1:

[0416] The server accesses the information management database, connects to the database using the necessary authentication information, and extracts data related to the company's ISMS certification (security guidelines, procedures, access logs, etc.).

[0417] Step 2:

[0418] The server launches a generation AI to analyze information management regulations documents. The generation AI analyzes documents such as "information protection policies" and "risk assessment reports" to verify that their contents comply with the latest laws, regulations, and best practices.

[0419] Step 3:

[0420] The server analyzes the log data using anomaly detection algorithms, which examine access logs and system logs to check for unusual access or unauthorized behavior, such as detecting abnormal access patterns from a particular IP address.

[0421] Step 4:

[0422] The server generates an evaluation report based on the analysis results. Using the generation AI, the report details the maintenance and operational status. The report includes any issues discovered and suggestions for improvement.

[0423] Step 5:

[0424] The server notifies the auditor and company administrator of the generated assessment report by sending an email with the assessment report attached for immediate review.

[0425] Step 6:

[0426] The user receives an email sent from the server, checks the assessment report, and understands the current state of security management and areas for improvement.

[0427] Step 7:

[0428] The user provides feedback based on the evaluation report, adding supplementary information to the contents of the evaluation report or providing additional confirmation.

[0429] Step 8:

[0430] The device sends the feedback entered by the user to the server, which transmits the feedback to the server in near real time.

[0431] Step 9:

[0432] The server receives the feedback sent from the device, analyzes the feedback, and prepares to incorporate it into the next audit process. For example, items that require additional inspection may be included in the next audit.

[0433] By following the above steps, this system can efficiently and accurately conduct ISMS certification audits and immediately reflect feedback.

[0434] Example 1

[0435] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0436] In modern companies, maintaining the robustness of their information security management requires efficient and effective ISMS (Information Security Management System) audits. However, many conventional systems require a lot of manual work, such as data analysis, report generation, anomaly detection, and feedback utilization, which is time-consuming and costly. Another problem is that audit results are not fully utilized in the next audit process. To address this issue, a system is needed that streamlines the entire process of database access and analysis, evaluation report generation and notification, and feedback collection and reuse.

[0437] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0438] In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document, means for analyzing log data, means for generating an evaluation report based on the analysis results, means for notifying the evaluation report, means for collecting feedback from users, and means for reflecting the collected feedback in the next process. This makes it possible to streamline the ISMS audit process, reduce manual work, and effectively reflect the obtained feedback in the next and subsequent processes.

[0439] An "information management database" is a database that allows companies and organizations to centrally store and manage data related to information security management.

[0440] An "information management regulations document" is a document that describes information security policies, procedures, and other information security guidelines.

[0441] "Log data" refers to data that records the operation history of a system or network, and includes access logs and system event logs.

[0442] "Analysis" is the process of collecting data and examining and evaluating its contents in detail.

[0443] "Generative AI" is a system that uses artificial intelligence technology to automatically generate new information and documents.

[0444] An "anomaly detection algorithm" is an algorithm that analyzes system and network log data to detect unusual behavior or unauthorized access.

[0445] An "evaluation report" is a report that summarizes the current state of information security management and areas for improvement based on the results of data analysis.

[0446] "Feedback" refers to information such as opinions and improvement suggestions provided by users.

[0447] "Reflecting in the next process" means incorporating the collected feedback into the next work or analysis to achieve continuous improvement.

[0448] "Notification" is the process of informing interested parties of generated evaluation reports and information through communication means.

[0449] This invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, and generates and notifies an evaluation report based on the analysis results. This system utilizes generative AI and anomaly detection algorithms to efficiently conduct ISMS audits and reflect user feedback in the next process.

[0450] Server Processing

[0451] The server first accesses the information management database, which stores information such as security guidelines, procedures, and access logs related to ISMS certification. The server connects to the database using the necessary authentication information and extracts the necessary data.

[0452] Next, the server uses a generative AI (for example, Azure OpenAI) to analyze the information management policy document. A prompt such as "Analyze our information protection policy and check whether it complies with the latest regulations" is input to the generative AI. Based on this prompt, the generative AI analyzes the document and evaluates whether it complies with regulations and best practices.

[0453] In parallel, the server analyzes the log data using an anomaly detection algorithm (e.g., Kibana), analyzing access logs and system logs to detect any abnormal access or unauthorized behavior.

[0454] Once the analysis is complete, the server uses generative AI to create a comprehensive assessment report that details the state of information management, operational status, and areas for improvement. The assessment report is saved in PDF format and sent to auditors and company administrators via email (e.g., SendGrid or Amazon SES).

[0455] User Action

[0456] The user receives an email from the server and checks the assessment report, which clearly shows the current state of the company's information security management and areas for improvement.

[0457] When users provide feedback, they access a dedicated form based on the evaluation report and enter their feedback. Specifically, they can add supplementary information to the report or indicate matters requiring further confirmation.

[0458] Terminal handling

[0459] The device collects the feedback entered by the user and sends it to the server, which receives the feedback and prepares it for the next audit process.

[0460] Specific examples

[0461] Company A's information management database stores the latest security guidelines, procedures, and access logs. The server accesses the database, extracts the necessary information, and begins analysis. For example, it inputs a prompt to the generation AI, such as, "Analyze this information protection policy and confirm that it complies with the latest laws and regulations." In parallel, an anomaly detection algorithm uses Kibana to analyze the access logs and check for any abnormal behavior.

[0462] Based on the analysis results, the server generates a comprehensive evaluation report and notifies the auditor and company administrator. The user can review the evaluation report and send any necessary feedback to the server via their device. The server will then prepare to incorporate this feedback into the next audit process.

[0463] In this way, by using this system, ISMS certification audits can be carried out effectively and efficiently.

[0464] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0465] Step 1: Access the Database

[0466] The server obtains connection information to access the information management database. The connection information includes the database URL, user name, password, etc. The server uses this authentication information to connect to the database. If the connection is successful, the server extracts the necessary data from the database, such as security guidelines, procedures, and access logs related to ISMS certification. The input is the authentication information and database URL, and the output is the extracted data set. With this step, the server is ready to access the information management database and retrieve the necessary data.

[0467] Step 2: Analyze the information management policy document

[0468] The server inputs the extracted information management regulations document into the generation AI. The input data includes security guidelines and procedures. The server sets specific questions as prompts for the generation AI, such as, "Please confirm whether this information protection policy complies with the latest laws and regulations." The generation AI analyzes the document based on these prompts and evaluates whether it complies with laws and regulations and best practices. The analysis results are returned to the server, and the evaluation results and points for improvement are obtained as output. This step allows the server to use the generation AI to analyze the document.

[0469] Step 3: Analyze the log data

[0470] The server analyzes the log data using an anomaly detection algorithm (e.g., Kibana). Input data includes access logs and system logs. The server inputs the log data into the anomaly detection algorithm to detect abnormal access or unauthorized behavior. For example, it evaluates whether a specific user is accessing the system at an abnormal time. The analysis results output details of any abnormal events or unauthorized access detected by the anomaly detection algorithm. Through this step, the server identifies abnormal system behavior and reduces security risks.

[0471] Step 4: Generate an assessment report

[0472] The server generates an assessment report based on the analysis results of the information management regulations document and the log data. These analysis results are input, and the server uses a generation AI to create the assessment report. The generation AI compiles the analysis results into a report that details the maintenance status, operational status, and areas for improvement. The assessment report is saved in PDF format or other common formats, and a comprehensive assessment report is obtained as output. With this step, the server is ready to compile the audit results and provide them to the relevant parties.

[0473] Step 5: Notification of the evaluation report

[0474] The server notifies the relevant parties of the generated assessment report. The inputs are the generated assessment report and the relevant parties' email addresses. The server uses an email sending system (for example, SendGrid or Amazon SES) to send the assessment report to the auditor and company administrator. The assessment report is attached to the email, so that the relevant parties can immediately check the contents. The output is the sent notification email. This step ensures that the analysis results are communicated to the relevant parties quickly.

[0475] Step 6: Review the assessment report

[0476] The user receives an email sent from the server. The input is the email, and the user opens the assessment report attached to the email. The assessment report clearly shows the current state of the company's information security management and areas for improvement, so the user can review it and provide feedback or instructions to each department as necessary. The output is the contents of the assessment report reviewed by the user. This step allows the user to understand the audit results and take any necessary actions.

[0477] Step 7: Provide feedback

[0478] The user provides feedback based on the evaluation report. The input is the contents of the evaluation report and the user's feedback. The user accesses a dedicated input form and enters their opinions on the evaluation report, suggestions for improvement, and further confirmation items. Once the input is complete, the feedback is sent to the server by clicking the send button. The output is the feedback information provided by the user. This step allows the user to contribute to system improvements based on the evaluation report.

[0479] Step 8: Submit your feedback

[0480] The terminal collects the feedback entered by the user and sends it to the server. The input is the feedback entered by the user. The terminal communicates to consolidate the feedback and send it to the server. The server receives the feedback and prepares to reflect it in the next audit process. The output is the feedback sent to the server. This step allows the feedback provided by the user to be used in the next audit process, ensuring continuous improvement of the system.

[0481] In this way, the servers, users, and terminals work together to efficiently carry out the audit and improvement process of information security management.

[0482] (Application example 1)

[0483] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0484] Currently, auditing a company's information security management system (ISMS) requires manual checking of information management databases and analysis of documents and log data, which is time-consuming and laborious. The process for users to review assessment reports and provide feedback is also cumbersome. This reduces the efficiency of ISMS audits. Furthermore, access from mobile devices is difficult, limiting the location and time at which audit work can be performed. The purpose of this invention is to solve these issues and provide a more efficient and user-friendly ISMS audit system.

[0485] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0486] In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document, means for analyzing log data, means for generating an evaluation report based on the analysis results, means for notifying the generated evaluation report, means for collecting feedback, means for reflecting the collected feedback in the next process, means for securely accessing the information management database from a mobile device, and means for checking the evaluation report and providing feedback on the mobile device. This enables ISMS audits to be conducted efficiently and quickly, and enables users to check the evaluation report on their mobile devices and provide feedback.

[0487] An "information management database" is a database for collecting and managing data related to the information management of a company or organization.

[0488] An "information management regulations document" is a document in which a company or organization lists rules and procedures regarding information security and information management.

[0489] "Log data" refers to data that records the operating status of a system or application, and includes access history and system operation records.

[0490] An "evaluation report" is a report that summarizes the evaluation of a system or process, created based on the results of document analysis and log data analysis.

[0491] "Generative AI" is a technology or program that uses artificial intelligence to automatically analyze documents and data and generate results.

[0492] An "anomaly detection algorithm" is an algorithm that automatically detects unusual patterns or abnormal behavior from data.

[0493] A "mobile device" is a portable electronic device such as a smartphone or tablet.

[0494] "Feedback" refers to the act and content of providing evaluations, opinions, and areas for improvement.

[0495] "Means of notification" refers to the methods or functions used by the system to notify the user of specific information.

[0496] "Means of reflection" are the methods and functions for incorporating collected information and feedback into the next operation of a process or system.

[0497] The embodiment of the present invention will be described below: The system mainly consists of three components: a server, a user, and a mobile device.

[0498] Server Processing

[0499] The server accesses the information management database and extracts necessary data. Specifically, the server accesses the database using a security protocol to collect data such as security guidelines, procedures, and access logs.

[0500] The information management policy document is then analyzed using a generative AI, such as OpenAI's GPT-3 model, to ensure that the document complies with the latest regulations and best practices.

[0501] The server then analyzes the log data using anomaly detection algorithms, such as Isolation Forest and k-means clustering.

[0502] To generate an evaluation report based on the analysis results, the server uses a report generation library such as Python's ReportLab to create a comprehensive evaluation report.

[0503] The generated evaluation report is sent to the user via email using the SMTP protocol and the Python smtplib library.

[0504] Mobile Device Handling

[0505] Users use their mobile devices to access the server and check the assessment report. The HTTPS protocol is used to securely access the information management database from mobile devices.

[0506] After reviewing the evaluation report, the user can provide feedback if necessary. The feedback is entered directly from the mobile device and sent to the server.

[0507] User Action

[0508] The user checks the evaluation report sent from the server, understands the current situation and areas for improvement, and provides feedback based on the contents of the evaluation report, which is then sent back to the server.

[0509] The feedback may include specific improvements to the evaluation report or additional points to be checked, and will be reflected in the next audit process.

[0510] Specific examples

[0511] Specific examples are shown below.

[0512] When Company B uses the Mobile Security Audit Assistant, the server accesses the information management database and extracts the latest security guidelines and access logs.

[0513] The generative AI uses the following prompt to analyze the "Information Security Policy" document and ensure it complies with regulations:

[0514] Please confirm that the contents of your "Information Security Policy" document comply with the latest laws and regulations. Also, review the following seven aspects: 1. Advanced security measures 2. Appropriate management of information assets 3. Employee education and training 4. Risk assessment 5. Access control 6. Continuous improvement 7. Detection of abnormal login attempts.

[0515] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0516] Step 1:

[0517] The server accesses the information management database. It uses security authentication information and the database URL as input to retrieve data such as security guidelines, procedures, and access logs from the database. It obtains the extracted data as output. This process is securely accessed using the HTTPS protocol.

[0518] Step 2:

[0519] The server uses a generative AI model to analyze the information management regulations document. Using the extracted regulations document as input, the generative AI model (e.g., GPT-3) is given a prompt to analyze it. As a specific example, a prompt to confirm whether the contents of the "Information Security Policy" document comply with the latest laws and regulations is input to the generative AI. The analysis results are obtained as output.

[0520] Step 3:

[0521] The server analyzes the log data using an anomaly detection algorithm. Using the acquired log data as input, it applies an anomaly detection algorithm such as Isolation Forest or k-means clustering. The output is anomaly detection results. Specific operations include detecting unauthorized access and abnormal login attempts.

[0522] Step 4:

[0523] The server generates an evaluation report based on the analysis results. It uses the analysis results of the information management regulations document and the anomaly detection results from the log data as input, and creates the evaluation report using a report generation library such as Python's ReportLab. The generated evaluation report is obtained as output. Specifically, the report includes an evaluation of the current security measures and areas for improvement.

[0524] Step 5:

[0525] The server notifies the user of the evaluation report. Using the generated evaluation report and the user's email address as input, the server sends the report by email using the SMTP protocol. The server obtains the evaluation report that is notified to the user as output. Specifically, the email is sent using Python's smtplib library.

[0526] Step 6:

[0527] The user checks the evaluation report using a mobile device. Using the received evaluation report as input, the user views the report using the viewer function of the mobile device. The user receives the evaluation report as output. The user checks the report contents to understand the current situation and areas for improvement.

[0528] Step 7:

[0529] The user provides feedback from their mobile device. The evaluation report contents and any additional comments from the user are used as input and sent to the server via the feedback function within the application. The collected feedback is obtained as output. The feedback may include specific improvements or further considerations.

[0530] Step 8:

[0531] The server reflects the collected feedback in the next process. It uses the feedback provided by the user as input and saves and manages it as data to be reflected in the next audit process. It obtains feedback to be reflected in the next audit as output. Specifically, it saves the feedback content in a database and uses it as reference for the next analysis.

[0532] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[0533] This invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, and generates and notifies an evaluation report based on the analysis results. By combining this system with an emotion engine, it collects and evaluates feedback from users more precisely and reflects the results in the next process.

[0534] System program processing description

[0535] The program processing flow of this system is shown below. The system is mainly composed of three components: the server, the user, and the terminal.

[0536] Server Processing

[0537] Accessing the database

[0538] The server accesses the information management database and connects to it using the necessary authentication information to extract data such as security guidelines, procedures, and access logs related to the company's ISMS certification.

[0539] Analysis of information management regulations documents

[0540] The server uses a generative AI to analyze information management policy documents extracted from the database. The generative AI checks whether the documents comply with the latest laws and regulations and best practices. Specifically, it analyzes "information protection policies" and "risk assessment reports" and evaluates whether their contents are appropriate.

[0541] Analyzing log data

[0542] The server analyzes the log data using anomaly detection algorithms, which examine access logs and system logs to check for abnormal access or unauthorized behavior, specifically detecting abnormal access patterns from specific IP addresses.

[0543] Generate an assessment report

[0544] An evaluation report is generated based on the analysis results. The server uses the generation AI to create an evaluation report that details the maintenance and operational status. The report includes any issues discovered and suggestions for improvement.

[0545] Evaluation report notification

[0546] The server notifies the auditor and company administrator of the generated assessment report by sending an email with the assessment report attached for immediate review.

[0547] User Action

[0548] Review the assessment report

[0549] The user receives an email sent from the server, checks the assessment report, and understands the current state of security management and areas for improvement.

[0550] Providing feedback

[0551] The user provides feedback based on the evaluation report. The user may add supplementary information or provide additional confirmations. The emotion engine also analyzes the user's emotional state.

[0552] Terminal handling

[0553] Send Feedback

[0554] The device sends the feedback entered by the user to the server, including the user's emotions.

[0555] Emotion Engine Operation

[0556] The emotion engine analyzes the emotion of the user based on the feedback, for example, identifying whether the user is dissatisfied or satisfied based on the content of the feedback.

[0557] Rating and categorizing feedback

[0558] Evaluate and categorize feedback content based on emotional data collected using an emotion engine, for example generating an alert for negative feedback requiring immediate attention.

[0559] Generate and send follow-ups

[0560] The server automatically generates and sends follow-up communications based on the user's emotions recognized by the emotion engine, for example, if the user is dissatisfied, it sends a follow-up email to offer additional support.

[0561] Specific examples

[0562] Company B's information management database stores the latest security guidelines, procedures, and access logs. The server accesses the database, extracts the necessary information, and begins analysis. The generation AI analyzes the regulation documents and checks whether their contents comply with the latest laws and regulations. In parallel, the anomaly detection algorithm analyzes the access logs and checks for any abnormal behavior. The server generates an evaluation report based on the analysis results and notifies the auditor and company administrator. The user checks the evaluation report and sends any necessary feedback to the server via their device. The feedback also includes the user's emotions, which are analyzed by the emotion engine. The server evaluates the feedback based on the emotion data and automatically generates and sends follow-up emails as necessary.

[0563] As described above, by using this system, ISMS certification audits can be carried out efficiently and accurately, and feedback that takes user feelings into consideration can be reflected immediately.

[0564] The processing flow will be explained below.

[0565] Step 1:

[0566] The server accesses the information management database, connecting using the necessary authentication information to extract data such as security guidelines, procedures, and access logs related to the company's ISMS certification.

[0567] Step 2:

[0568] The server launches a generation AI to analyze information management regulations documents. The generation AI analyzes documents such as "information protection policies" and "risk assessment reports" to verify that their contents comply with the latest laws, regulations, and best practices.

[0569] Step 3:

[0570] The server analyzes the log data using an anomaly detection algorithm. It analyzes access logs and system logs to check for abnormal access or unauthorized behavior. Specifically, it detects abnormal access patterns from specific IP addresses.

[0571] Step 4:

[0572] The server generates an evaluation report based on the analysis results. Using the generation AI, the report details the maintenance and operational status. The report includes any issues discovered and suggestions for improvement.

[0573] Step 5:

[0574] The server notifies the auditor and company administrator of the generated assessment report by sending an email with the assessment report attached for immediate review.

[0575] Step 6:

[0576] The user receives an email sent from the server and checks the evaluation report to understand the current state of security management and areas for improvement.

[0577] Step 7:

[0578] The user provides feedback based on the evaluation report. For example, the user may add supplementary information to the contents of the evaluation report or provide additional confirmation items. Here, the user may input feedback including their feelings.

[0579] Step 8:

[0580] The terminal transmits the feedback input by the user to the server, and the terminal transmits the feedback to the server in near real time.

[0581] Step 9:

[0582] The server receives the feedback sent from the device. The feedback includes the user's emotional data, which is then analyzed by the emotion engine. For example, the content and expressions of the sentences are used to measure the user's dissatisfaction or satisfaction.

[0583] Step 10:

[0584] The server evaluates and classifies the feedback content based on the user's emotions recognized by the emotion engine, for example, generating an alert indicating that negative feedback requires immediate attention.

[0585] Step 11:

[0586] The server generates follow-up communications based on the emotion engine's analysis, and if the user is dissatisfied, generates and sends a follow-up email to provide additional support or clarification.

[0587] Step 12:

[0588] The server then incorporates the feedback and sentiment analysis results into the next audit process. For example, if any issues are identified, specific steps and measures to resolve them can be added to the next audit plan.

[0589] Through these steps, this system can efficiently and accurately conduct ISMS certification audits and instantly reflect feedback that takes into account the user's feelings.

[0590] Example 2

[0591] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0592] Modern companies must manage large amounts of information and operate in compliance with laws and industry best practices. Appropriate document management and log analysis are essential, particularly for Information Security Management System (ISMS) certification. However, these tasks require time and effort when performed manually, and there is a high risk of human error. Furthermore, collecting and incorporating feedback after creating an evaluation report is cumbersome, making it difficult to properly reflect user sentiment and opinions. To address these challenges, a system that achieves advanced automation and sophisticated sentiment analysis is needed.

[0593] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document using a generative AI model, means for analyzing log data using an anomaly detection algorithm, means for generating an evaluation report based on the analysis results, means for notifying the generated evaluation report by email, means for collecting feedback from the user, means for analyzing the user's emotional state using an emotion engine, and means for reflecting the collected feedback and the analyzed emotional state in the next process. This makes it possible to improve the efficiency of the information management and evaluation processes related to ISMS certification and accurately reflect the user's emotions and opinions.

[0594] An "information management database" is a system that centrally stores and manages data used by companies and organizations for information security management.

[0595] A "generative AI model" is an artificial intelligence algorithm that uses natural language processing and machine learning techniques to analyze and generate text data.

[0596] An "information management regulations document" is a document that clearly states the procedures and policies regarding the operation and management of information security.

[0597] An "anomaly detection algorithm" is an algorithm that analyzes log data and the like to detect abnormal access or behavior that deviates from normal patterns.

[0598] An "evaluation report" is a report summarizing the results of the analysis, detailing the current state of security management and areas for improvement.

[0599] "Email" is a means of communication for sending documents and files to other parties via the Internet.

[0600] "Users" are people involved in information security management, such as employees and managers of companies that use the system.

[0601] "Feedback" refers to user opinions and comments provided in response to an evaluation report.

[0602] The "emotion engine" is an artificial intelligence algorithm that analyzes feedback content and identifies the user's emotional state.

[0603] This invention relates to a system that enables companies and organizations to manage information security efficiently and precisely. This system accesses an information management database, analyzes information management regulations documents and log data using generative AI models and anomaly detection algorithms, and generates and notifies evaluation reports based on the analysis results. It also collects feedback from users and uses an emotion engine to reflect the feedback in the next process.

[0604] Hardware and Software Configuration

[0605] This system is mainly composed of three components: the server, the terminal, and the user. The hardware and software for each component are as follows:

[0606] server

[0607] Hardware: The server is a server machine equipped with a powerful processor, ample memory space, and large storage capacity.

[0608] software:

[0609] Database Management System (DBMS): Used to manage information management databases.

[0610] Generative AI model: Used to analyze information management policy documents.

[0611] Anomaly detection algorithms: Used to analyze log data.

[0612] SMTP Server: Used for email notification of assessment reports.

[0613] Terminal

[0614] Hardware: Terminal devices such as PCs and tablets that accept user input.

[0615] software:

[0616] Web browser: Used by users to view evaluation reports and provide feedback.

[0617] HTTP client: Used to send feedback data to the server.

[0618] Emotion engine: Used to analyze feedback content and determine the user's emotional state.

[0619] User

[0620] Role: The user is responsible for using the system to review the evaluation reports and provide feedback.

[0621] System Operation

[0622] 1. Access to the database

[0623] The server connects to the information management database using authentication information and extracts the necessary data (security guidelines, procedures, access logs, etc.).

[0624] 2. Analysis of information management regulations documents

[0625] The server uses the generative AI model to analyze the extracted information management regulations document. For example, analysis can be performed by inputting the following prompt sentence into the generative AI model:

[0626] "Analyze this document for compliance with the latest regulations."

[0627] 3. Log data analysis

[0628] The server analyzes the log data using anomaly detection algorithms, for example, to detect abnormal access patterns from specific IP addresses.

[0629] 4. Generate an evaluation report

[0630] The generative AI model generates an evaluation report based on the analysis results. The evaluation report includes any issues found and suggestions for improvement. An example of a prompt is as follows:

[0631] "Please prepare an evaluation report based on the analysis results. Please include any issues and suggestions for improvement."

[0632] 5. Notification of Evaluation Report

[0633] The server will notify the auditor or company administrator of the generated assessment report via email.

[0634] 6. Feedback Collection and Analysis

[0635] Users use their devices to check the evaluation reports and provide feedback, which is then sent to the server and analyzed by the emotion engine.

[0636] For example, the server analyzes security guidelines, procedures, and access logs obtained from a company's information management database, generates an evaluation report, and notifies the administrator. The user (administrator) checks the evaluation report and enters feedback into the system. The emotion engine analyzes the user's emotional state from the feedback and reflects it in the next process.

[0637] By using this system, companies can efficiently and accurately manage information related to ISMS certification, and can instantly reflect feedback that takes user emotions into consideration.

[0638] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0639] Step 1:

[0640] The server accesses the information management database. Specifically, it connects to the database management system (DBMS) using authentication information (user ID and password) set by the administrator. At this time, the server executes the necessary queries and extracts data such as "security guidelines," "procedures," and "access logs." The input is the authentication information, and the output is the extracted data set.

[0641] Step 2:

[0642] The server uses a generative AI model to analyze the information management regulations document. The input data is the "information management regulations document" extracted from the database. Specifically, the analysis is performed by inputting the following prompt into the generative AI model: "Please analyze whether this document complies with the latest laws and regulations." The generative AI model analyzes the document content and outputs whether it complies with the regulations and any necessary improvements.

[0643] Step 3:

[0644] The server analyzes the log data using an anomaly detection algorithm. The input data is the "access log" and "system log." The server uses pattern matching technology to detect abnormal access patterns or unauthorized behavior from a specific IP address. For example, it detects "multiple invalid login attempts from a specific IP address." The output is the anomaly detection results and their details.

[0645] Step 4:

[0646] The server generates an evaluation report based on the analysis results. The input data are the "analysis results of the regulations document" and the "analysis results of the log data." Using the generative AI model, the server creates an evaluation report that includes issues and improvement suggestions. As a specific example, the following prompt is input to the generative AI model: "Please create an evaluation report based on the analysis results. Please include issues and improvement suggestions." The output is the created evaluation report.

[0647] Step 5:

[0648] The server will notify the generated assessment report by email. The input data is the "assessment report". The server will attach the assessment report to an email and send it to the designated auditor and company administrator using the SMTP protocol. The output is the sent email and a confirmation of its delivery.

[0649] Step 6:

[0650] The user checks the evaluation report using a terminal. The input data is the "email sent from the server." The user opens the evaluation report in an email client to understand the current state of security management and areas for improvement. The output is a review of the evaluation report and an understanding of its contents.

[0651] Step 7:

[0652] The user provides feedback based on the content of the evaluation report. The input data is the "evaluation report." The user uses the feedback form to enter supplementary information or additional confirmations. The feedback also includes an emotional state that can be analyzed by the emotion engine. The output is the written feedback.

[0653] Step 8:

[0654] The terminal sends the feedback entered by the user to the server. The input data is "user feedback". The terminal sends an HTTP POST request to send the feedback to the server. The output is the sent feedback data.

[0655] Step 9:

[0656] The emotion engine analyzes the user's feedback content. The input data is the "feedback content." The emotion engine uses text analysis technology to determine the user's emotion from the feedback content. For example, it identifies "dissatisfied" or "satisfied." The output is the analyzed emotion data.

[0657] Step 10:

[0658] The server evaluates and classifies the feedback content using the emotional data analyzed by the emotion engine. The input data is the analyzed emotional data and the feedback content. For example, an alert is generated indicating that negative feedback requires immediate action. The output is the evaluated and classified feedback data.

[0659] Step 11:

[0660] The server generates and sends follow-up communications based on the user's emotions recognized by the emotion engine. The input data is the "evaluated and classified feedback data and analyzed emotion data." For example, if the user is dissatisfied, a follow-up email offering additional support is automatically generated and sent using the SMTP protocol. The output is the sent follow-up email and its confirmation of delivery.

[0661] (Application example 2)

[0662] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the smart glasses 214 will be referred to as a "terminal."

[0663] Traditional information management systems mainly focus on functions such as document analysis and log data monitoring, but lack the ability to analyze feedback sentiment and generate follow-up communications and notifications based on it. This makes it difficult to improve user satisfaction and take prompt and effective action. As a result, the quality of information security management may decline and users may lose trust.

[0664] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 2 is realized by the following means.

[0665] In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document, means for analyzing log data, means for generating an evaluation report based on the analysis results, means for notifying the generated evaluation report, means for collecting feedback, means for reflecting the collected feedback in the next process, means for analyzing the emotions of the feedback using an emotion engine, and means for generating and notifying follow-up communication based on the analyzed emotions. This enables emotion analysis based on user feedback and rapid follow-up accordingly, thereby improving the quality of information security management and increasing user satisfaction and trust.

[0666] An "information management database" is a database that centrally manages data related to information security management for companies and organizations.

[0667] An "information management regulations document" is a document that contains guidelines and best practices regarding information security.

[0668] "Log data" refers to data that records system behavior and access history.

[0669] An "evaluation report" is a report generated based on the results of analysis of information management regulations documents and log data.

[0670] "Means of notification" refers to the means of transmitting the evaluation report and follow-up communications.

[0671] "Feedback" refers to the user's opinions and thoughts on the evaluation report.

[0672] An "emotion engine" is a system for analyzing emotions based on user feedback.

[0673] "Follow-up communications" are additional messages or support generated based on sentiment analysis.

[0674] "Generative AI" refers to artificial intelligence that analyzes natural language and automatically generates documents and reports.

[0675] An "anomaly detection algorithm" is an algorithm that analyzes log data to detect abnormal behavior or unauthorized access.

[0676] The present invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, generates and notifies evaluation reports, collects feedback and analyzes emotions, and generates and notifies follow-up communications. A specific embodiment of this system is described below.

[0677] Key Components of the System

[0678] It consists of three components: server, user, and terminal.

[0679] Server Processing

[0680] 1. Access to the database:

[0681] The server uses appropriate authentication information (e.g., tokens) to access the information management database and extracts data such as security guidelines and access logs. The hardware used is a high-performance server, and the software may utilize a REST API.

[0682] 2. Analysis of information management regulations documents:

[0683] The server uses a generative AI model (e.g., GPT-3) to analyze information management policy documents extracted from the database, using libraries such as AutoTokenizer and AutoModelForSeq2SeqLM to ensure that the document content complies with the latest regulations.

[0684] 3. Log data analysis:

[0685] The server analyzes the log data using an anomaly detection algorithm (e.g., IsolationForest), processes the log data in a tabular format, and detects anomalous access patterns from specific IP addresses.

[0686] 4. Evaluation report generation and notification:

[0687] Based on the analysis results, an assessment report is generated using a generative AI model, which includes a detailed assessment and improvement suggestions based on the analyzed data, and the generated assessment report is notified to the auditor and company management via email.

[0688] User Action

[0689] 1. Review the assessment report:

[0690] The user receives the email sent from the server and checks the evaluation report. The user understands the contents of the report and confirms the current state of security management and any necessary improvements.

[0691] 2. Providing Feedback:

[0692] Users provide feedback on the evaluation report, including their opinions and thoughts entered through a feedback form.

[0693] Terminal handling

[0694] 1. Feedback submission and sentiment analysis:

[0695] The device sends the user-entered feedback to the server, which then uses an emotion engine to analyze the user's emotions from the feedback content. It uses libraries such as TextBlob to classify the emotions of the feedback text as positive, neutral, or negative.

[0696] 2. Follow-up generation and notification:

[0697] The server automatically generates follow-up communications based on the analyzed sentiment data: if the user provides negative feedback, a follow-up email is sent to offer additional support.

[0698] Specific examples

[0699] A company with multiple departments is using this system. One day, the company's security team receives a weekly security assessment report. The report was generated using a generative AI model (e.g., GPT-3) and includes the latest security guidelines and access log analysis results. Security team members review the report and provide feedback within the app. The device analyzes this feedback with an emotion engine and detects positive emotions, such as "Please enter your feedback: The contents of this report were very helpful." Based on the analysis results, the server automatically generates a follow-up message, such as "Thank you for using our service," and notifies the user, thereby improving satisfaction.

[0700] Prompt Sentence Examples

[0701] "Analyze the document and assess its compliance with modern security standards: 'All employees must comply with company security policies...'"

[0702] As described above, the embodiment of the present invention provides an integrated system for efficiently and effectively managing corporate information security.

[0703] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[0704] Step 1:

[0705] The server accesses the information management database. The inputs are the database URL and authentication token. Based on this, data such as security guidelines and access logs are extracted using a REST API. The output is the extracted data. Specifically, a GET request is sent using the requests library. The required data is returned as a response to this request.

[0706] Step 2:

[0707] The server analyzes the information management regulations document. The input is the text of the information management regulations document extracted in step 1. This text is passed to a generative AI model (e.g., GPT-3), which analyzes the document content. The output is an evaluation as the analysis result. Specifically, the text is tokenized using AutoTokenizer, and then the generation process is performed by the model using AutoModelForSeq2SeqLM.

[0708] Step 3:

[0709] The server analyzes the log data. The input is the log data, such as the access log obtained in step 1. This data is passed to an anomaly detection algorithm (e.g., Isolation Forest) to detect abnormal access patterns. The output is the anomaly detection results. Specifically, the log data is converted into a table format using the pandas library, and anomalies are detected using Isolation Forest.

[0710] Step 4:

[0711] The server generates an evaluation report based on the analysis results. The inputs are the analysis results from steps 2 and 3. These results are combined and passed to a generative AI model to generate an evaluation report. The output is the generated evaluation report. Specifically, the generative AI uses an evaluation report template to generate a report containing detailed descriptions.

[0712] Step 5:

[0713] The server notifies the user of the generated evaluation report. The input is the evaluation report and the user's contact information. An email is generated based on this information and the notification is sent. The output is the sent notification email. Specifically, the server uses an SMTP server to send an email with the evaluation report attached.

[0714] Step 6:

[0715] The user receives the evaluation report and checks its contents. The input is the email containing the evaluation report sent from the server. The output is a confirmation of the evaluation report. The user opens the report and understands the current state of security management.

[0716] Step 7:

[0717] The user provides feedback on the evaluation report. The input is the user's opinion or impression on the evaluation report. This is entered through a feedback form and sent. The output is the entered feedback. Specifically, the user enters text into the feedback form and presses the "Submit" button.

[0718] Step 8:

[0719] The terminal sends the feedback entered by the user to the server. The input is the feedback text entered by the user. The terminal sends this data to the server. The output is the sent feedback data. The specific operation is to send the feedback data to the server using an HTTP POST request.

[0720] Step 9:

[0721] The server uses an emotion engine to analyze the sentiment of the feedback. The input is the feedback text, which is passed to an emotion analysis library (e.g., TextBlob) to classify the sentiment as positive, neutral, or negative. The output is the analyzed emotion data. Specifically, it uses TextBlob to calculate the sentiment score of the text and classifies it based on that.

[0722] Step 10:

[0723] The server generates and notifies follow-up communications based on the analyzed emotional data. The input is the emotional analysis results and the user's contact information. A follow-up message is generated based on this information and a notification email is sent. The output is the generated follow-up message and the sent notification email. The specific operation is that the generation AI generates a follow-up message and sends the email using the SMTP server.

[0724] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0725] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0726] In the above embodiment, an example in which the specific processing is performed by the data processing device 12 has been given, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the smart glasses 214.

[0727] [Third embodiment]

[0728] FIG. 5 shows an example of the configuration of a data processing system 310 according to the third embodiment.

[0729] 5, the data processing system 310 includes the data processing device 12 and a headset type terminal 314. An example of the data processing device 12 is a server.

[0730] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0731] The headset type terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a display 343. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the display 343 are also connected to the bus 52.

[0732] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[0733] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[0734] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[0735] Fig. 6 shows an example of the main functions of the data processing device 12 and the headset type terminal 314. As shown in Fig. 6, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[0736] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0737] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0738] In the headset type terminal 314, a reception output process is performed by the processor 46. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[0739] Next, a description will be given of the identification process performed by the identification processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as the "server" and the headset type terminal 314 will be referred to as the "terminal."

[0740] This invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, and generates and notifies an evaluation report based on the analysis results. This system utilizes generative AI and anomaly detection algorithms to efficiently conduct ISMS audits and reflect user feedback in the next process.

[0741] System program processing description

[0742] The program processing flow of this system is shown below. The system is mainly composed of three components: the server, the user, and the terminal.

[0743] Server Processing

[0744] Accessing the database

[0745] The server accesses the information management database and connects using the necessary authentication information to extract data such as security guidelines, procedures, and access logs related to the company's ISMS certification.

[0746] Analysis of information management regulations documents

[0747] The server uses a generative AI to analyze information management policy documents extracted from the database. The generative AI checks whether the documents comply with the latest laws and regulations and best practices. For example, it analyzes "information protection policies" and "risk assessment reports" and evaluates whether their contents are appropriate.

[0748] Analyzing log data

[0749] The server analyzes the log data using anomaly detection algorithms. It analyzes access logs and system logs to check for abnormal access or unauthorized behavior. For example, it evaluates whether a specific user is accessing the site at an abnormal time.

[0750] Generate an assessment report

[0751] An evaluation report is generated based on the analysis results. The server uses the generation AI to create a comprehensive evaluation report based on the information obtained from the analysis. The report contains a detailed evaluation of the maintenance and operational status.

[0752] Evaluation report notification

[0753] The server will then send the generated assessment report to the auditor and company administrator via email, with the assessment report attached for immediate review.

[0754] User Action

[0755] Review the assessment report

[0756] The user receives an email from the server and checks the assessment report, which clearly shows the current status of the company's information security management and areas for improvement.

[0757] Providing feedback

[0758] The user may provide feedback based on the evaluation report as needed, for example, to add supplementary information to the report or to indicate matters requiring further confirmation.

[0759] Terminal handling

[0760] Send Feedback

[0761] The terminal sends the feedback entered by the user to the server, which receives the feedback and prepares it for the next audit process.

[0762] Specific examples

[0763] Company A's information management database stores the latest security guidelines, procedures, and access logs. The server accesses the database, extracts the necessary information, and begins analysis. The generation AI analyzes the regulation documents and checks whether their contents comply with the latest laws and regulations. In parallel, the anomaly detection algorithm analyzes the access logs and checks for any abnormal behavior. Based on the analysis results, the server generates a comprehensive evaluation report and notifies the auditor and company administrator. The user reviews the evaluation report and sends any necessary feedback to the server via their device. The server receives this feedback and reflects it in the next audit process.

[0764] As described above, by using this system, ISMS certification audits can be carried out effectively and efficiently.

[0765] The processing flow will be explained below.

[0766] Step 1:

[0767] The server accesses the information management database, connects to the database using the necessary authentication information, and extracts data related to the company's ISMS certification (security guidelines, procedures, access logs, etc.).

[0768] Step 2:

[0769] The server launches a generation AI to analyze information management regulations documents. The generation AI analyzes documents such as "information protection policies" and "risk assessment reports" to verify that their contents comply with the latest laws, regulations, and best practices.

[0770] Step 3:

[0771] The server analyzes the log data using anomaly detection algorithms, which examine access logs and system logs to check for unusual access or unauthorized behavior, such as detecting abnormal access patterns from a particular IP address.

[0772] Step 4:

[0773] The server generates an evaluation report based on the analysis results. Using the generation AI, the report details the maintenance and operational status. The report includes any issues discovered and suggestions for improvement.

[0774] Step 5:

[0775] The server notifies the auditor and company administrator of the generated assessment report by sending an email with the assessment report attached for immediate review.

[0776] Step 6:

[0777] The user receives an email sent from the server, checks the assessment report, and understands the current state of security management and areas for improvement.

[0778] Step 7:

[0779] The user provides feedback based on the evaluation report, adding supplementary information to the contents of the evaluation report or providing additional confirmation.

[0780] Step 8:

[0781] The device sends the feedback entered by the user to the server, which transmits the feedback to the server in near real time.

[0782] Step 9:

[0783] The server receives the feedback sent from the device, analyzes the feedback, and prepares to incorporate it into the next audit process. For example, items that require additional inspection may be included in the next audit.

[0784] By following the above steps, this system can efficiently and accurately conduct ISMS certification audits and immediately reflect feedback.

[0785] Example 1

[0786] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[0787] In modern companies, maintaining the robustness of their information security management requires efficient and effective ISMS (Information Security Management System) audits. However, many conventional systems require a lot of manual work, such as data analysis, report generation, anomaly detection, and feedback utilization, which is time-consuming and costly. Another problem is that audit results are not fully utilized in the next audit process. To address this issue, a system is needed that streamlines the entire process of database access and analysis, evaluation report generation and notification, and feedback collection and reuse.

[0788] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[0789] In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document, means for analyzing log data, means for generating an evaluation report based on the analysis results, means for notifying the evaluation report, means for collecting feedback from users, and means for reflecting the collected feedback in the next process. This makes it possible to streamline the ISMS audit process, reduce manual work, and effectively reflect the obtained feedback in the next and subsequent processes.

[0790] An "information management database" is a database that allows companies and organizations to centrally store and manage data related to information security management.

[0791] An "information management regulations document" is a document that describes information security policies, procedures, and other information security guidelines.

[0792] "Log data" refers to data that records the operation history of a system or network, and includes access logs and system event logs.

[0793] "Analysis" is the process of collecting data and examining and evaluating its contents in detail.

[0794] "Generative AI" is a system that uses artificial intelligence technology to automatically generate new information and documents.

[0795] An "anomaly detection algorithm" is an algorithm that analyzes system and network log data to detect unusual behavior or unauthorized access.

[0796] An "evaluation report" is a report that summarizes the current state of information security management and areas for improvement based on the results of data analysis.

[0797] "Feedback" refers to information such as opinions and improvement suggestions provided by users.

[0798] "Reflecting in the next process" means incorporating the collected feedback into the next work or analysis to achieve continuous improvement.

[0799] "Notification" is the process of informing interested parties of generated evaluation reports and information through communication means.

[0800] This invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, and generates and notifies an evaluation report based on the analysis results. This system utilizes generative AI and anomaly detection algorithms to efficiently conduct ISMS audits and reflect user feedback in the next process.

[0801] Server Processing

[0802] The server first accesses the information management database, which stores information such as security guidelines, procedures, and access logs related to ISMS certification. The server connects to the database using the necessary authentication information and extracts the necessary data.

[0803] Next, the server uses a generative AI (for example, Azure OpenAI) to analyze the information management policy document. A prompt such as "Analyze our information protection policy and check whether it complies with the latest regulations" is input to the generative AI. Based on this prompt, the generative AI analyzes the document and evaluates whether it complies with regulations and best practices.

[0804] In parallel, the server analyzes the log data using an anomaly detection algorithm (e.g., Kibana), analyzing access logs and system logs to detect any abnormal access or unauthorized behavior.

[0805] Once the analysis is complete, the server uses generative AI to create a comprehensive assessment report that details the state of information management, operational status, and areas for improvement. The assessment report is saved in PDF format and sent to auditors and company administrators via email (e.g., SendGrid or Amazon SES).

[0806] User Action

[0807] The user receives an email from the server and checks the assessment report, which clearly shows the current state of the company's information security management and areas for improvement.

[0808] When users provide feedback, they access a dedicated form based on the evaluation report and enter their feedback. Specifically, they can add supplementary information to the report or indicate matters requiring further confirmation.

[0809] Terminal handling

[0810] The device collects the feedback entered by the user and sends it to the server, which receives the feedback and prepares it for the next audit process.

[0811] Specific examples

[0812] Company A's information management database stores the latest security guidelines, procedures, and access logs. The server accesses the database, extracts the necessary information, and begins analysis. For example, it inputs a prompt to the generation AI, such as, "Analyze this information protection policy and confirm that it complies with the latest laws and regulations." In parallel, an anomaly detection algorithm uses Kibana to analyze the access logs and check for any abnormal behavior.

[0813] Based on the analysis results, the server generates a comprehensive evaluation report and notifies the auditor and company administrator. The user can review the evaluation report and send any necessary feedback to the server via their device. The server will then prepare to incorporate this feedback into the next audit process.

[0814] In this way, by using this system, ISMS certification audits can be carried out effectively and efficiently.

[0815] The flow of the identification process in the first embodiment will be described with reference to FIG.

[0816] Step 1: Access the Database

[0817] The server obtains connection information to access the information management database. The connection information includes the database URL, user name, password, etc. The server uses this authentication information to connect to the database. If the connection is successful, the server extracts the necessary data from the database, such as security guidelines, procedures, and access logs related to ISMS certification. The input is the authentication information and database URL, and the output is the extracted data set. With this step, the server is ready to access the information management database and retrieve the necessary data.

[0818] Step 2: Analyze the information management policy document

[0819] The server inputs the extracted information management regulations document into the generation AI. The input data includes security guidelines and procedures. The server sets specific questions as prompts for the generation AI, such as, "Please confirm whether this information protection policy complies with the latest laws and regulations." The generation AI analyzes the document based on these prompts and evaluates whether it complies with laws and regulations and best practices. The analysis results are returned to the server, and the evaluation results and points for improvement are obtained as output. This step allows the server to use the generation AI to analyze the document.

[0820] Step 3: Analyze the log data

[0821] The server analyzes the log data using an anomaly detection algorithm (e.g., Kibana). Input data includes access logs and system logs. The server inputs the log data into the anomaly detection algorithm to detect abnormal access or unauthorized behavior. For example, it evaluates whether a specific user is accessing the system at an abnormal time. The analysis results output details of any abnormal events or unauthorized access detected by the anomaly detection algorithm. Through this step, the server identifies abnormal system behavior and reduces security risks.

[0822] Step 4: Generate an assessment report

[0823] The server generates an assessment report based on the analysis results of the information management regulations document and the log data. These analysis results are input, and the server uses a generation AI to create the assessment report. The generation AI compiles the analysis results into a report that details the maintenance status, operational status, and areas for improvement. The assessment report is saved in PDF format or other common formats, and a comprehensive assessment report is obtained as output. With this step, the server is ready to compile the audit results and provide them to the relevant parties.

[0824] Step 5: Notification of the evaluation report

[0825] The server notifies the relevant parties of the generated assessment report. The inputs are the generated assessment report and the relevant parties' email addresses. The server uses an email sending system (for example, SendGrid or Amazon SES) to send the assessment report to the auditor and company administrator. The assessment report is attached to the email, so that the relevant parties can immediately check the contents. The output is the sent notification email. This step ensures that the analysis results are communicated to the relevant parties quickly.

[0826] Step 6: Review the assessment report

[0827] The user receives an email sent from the server. The input is the email, and the user opens the assessment report attached to the email. The assessment report clearly shows the current state of the company's information security management and areas for improvement, so the user can review it and provide feedback or instructions to each department as necessary. The output is the contents of the assessment report reviewed by the user. This step allows the user to understand the audit results and take any necessary actions.

[0828] Step 7: Provide feedback

[0829] The user provides feedback based on the evaluation report. The input is the contents of the evaluation report and the user's feedback. The user accesses a dedicated input form and enters their opinions on the evaluation report, suggestions for improvement, and further confirmation items. Once the input is complete, the feedback is sent to the server by clicking the send button. The output is the feedback information provided by the user. This step allows the user to contribute to system improvements based on the evaluation report.

[0830] Step 8: Submit your feedback

[0831] The terminal collects the feedback entered by the user and sends it to the server. The input is the feedback entered by the user. The terminal communicates to consolidate the feedback and send it to the server. The server receives the feedback and prepares to reflect it in the next audit process. The output is the feedback sent to the server. This step allows the feedback provided by the user to be used in the next audit process, ensuring continuous improvement of the system.

[0832] In this way, the servers, users, and terminals work together to efficiently carry out the audit and improvement process of information security management.

[0833] (Application example 1)

[0834] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[0835] Currently, auditing a company's information security management system (ISMS) requires manual checking of information management databases and analysis of documents and log data, which is time-consuming and laborious. The process for users to review assessment reports and provide feedback is also cumbersome. This reduces the efficiency of ISMS audits. Furthermore, access from mobile devices is difficult, limiting the location and time at which audit work can be performed. The purpose of this invention is to solve these issues and provide a more efficient and user-friendly ISMS audit system.

[0836] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[0837] In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document, means for analyzing log data, means for generating an evaluation report based on the analysis results, means for notifying the generated evaluation report, means for collecting feedback, means for reflecting the collected feedback in the next process, means for securely accessing the information management database from a mobile device, and means for checking the evaluation report and providing feedback on the mobile device. This enables ISMS audits to be conducted efficiently and quickly, and enables users to check the evaluation report on their mobile devices and provide feedback.

[0838] An "information management database" is a database for collecting and managing data related to the information management of a company or organization.

[0839] An "information management regulations document" is a document in which a company or organization lists rules and procedures regarding information security and information management.

[0840] "Log data" refers to data that records the operating status of a system or application, and includes access history and system operation records.

[0841] An "evaluation report" is a report that summarizes the evaluation of a system or process, created based on the results of document analysis and log data analysis.

[0842] "Generative AI" is a technology or program that uses artificial intelligence to automatically analyze documents and data and generate results.

[0843] An "anomaly detection algorithm" is an algorithm that automatically detects unusual patterns or abnormal behavior from data.

[0844] A "mobile device" is a portable electronic device such as a smartphone or tablet.

[0845] "Feedback" refers to the act and content of providing evaluations, opinions, and areas for improvement.

[0846] "Means of notification" refers to the methods or functions used by the system to notify the user of specific information.

[0847] "Means of reflection" are the methods and functions for incorporating collected information and feedback into the next operation of a process or system.

[0848] The embodiment of the present invention will be described below: The system mainly consists of three components: a server, a user, and a mobile device.

[0849] Server Processing

[0850] The server accesses the information management database and extracts necessary data. Specifically, the server accesses the database using a security protocol to collect data such as security guidelines, procedures, and access logs.

[0851] The information management policy document is then analyzed using a generative AI, such as OpenAI's GPT-3 model, to ensure that the document complies with the latest regulations and best practices.

[0852] The server then analyzes the log data using anomaly detection algorithms, such as Isolation Forest and k-means clustering.

[0853] To generate an evaluation report based on the analysis results, the server uses a report generation library such as Python's ReportLab to create a comprehensive evaluation report.

[0854] The generated evaluation report is sent to the user via email using the SMTP protocol and the Python smtplib library.

[0855] Mobile Device Handling

[0856] Users use their mobile devices to access the server and check the assessment report. The HTTPS protocol is used to securely access the information management database from mobile devices.

[0857] After reviewing the evaluation report, the user can provide feedback if necessary. The feedback is entered directly from the mobile device and sent to the server.

[0858] User Action

[0859] The user checks the evaluation report sent from the server, understands the current situation and areas for improvement, and provides feedback based on the contents of the evaluation report, which is then sent back to the server.

[0860] The feedback may include specific improvements to the evaluation report or additional points to be checked, and will be reflected in the next audit process.

[0861] Specific examples

[0862] Specific examples are shown below.

[0863] When Company B uses the Mobile Security Audit Assistant, the server accesses the information management database and extracts the latest security guidelines and access logs.

[0864] The generative AI uses the following prompt to analyze the "Information Security Policy" document and ensure it complies with regulations:

[0865] Please confirm that the contents of your "Information Security Policy" document comply with the latest laws and regulations. Also, review the following seven aspects: 1. Advanced security measures 2. Appropriate management of information assets 3. Employee education and training 4. Risk assessment 5. Access control 6. Continuous improvement 7. Detection of abnormal login attempts.

[0866] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[0867] Step 1:

[0868] The server accesses the information management database. It uses security authentication information and the database URL as input to retrieve data such as security guidelines, procedures, and access logs from the database. It obtains the extracted data as output. This process is securely accessed using the HTTPS protocol.

[0869] Step 2:

[0870] The server uses a generative AI model to analyze the information management regulations document. Using the extracted regulations document as input, the generative AI model (e.g., GPT-3) is given a prompt to analyze it. As a specific example, a prompt to confirm whether the contents of the "Information Security Policy" document comply with the latest laws and regulations is input to the generative AI. The analysis results are obtained as output.

[0871] Step 3:

[0872] The server analyzes the log data using an anomaly detection algorithm. Using the acquired log data as input, it applies an anomaly detection algorithm such as Isolation Forest or k-means clustering. The output is anomaly detection results. Specific operations include detecting unauthorized access and abnormal login attempts.

[0873] Step 4:

[0874] The server generates an evaluation report based on the analysis results. It uses the analysis results of the information management regulations document and the anomaly detection results from the log data as input, and creates the evaluation report using a report generation library such as Python's ReportLab. The generated evaluation report is obtained as output. Specifically, the report includes an evaluation of the current security measures and areas for improvement.

[0875] Step 5:

[0876] The server notifies the user of the evaluation report. Using the generated evaluation report and the user's email address as input, the server sends the report by email using the SMTP protocol. The server obtains the evaluation report that is notified to the user as output. Specifically, the email is sent using Python's smtplib library.

[0877] Step 6:

[0878] The user checks the evaluation report using a mobile device. Using the received evaluation report as input, the user views the report using the viewer function of the mobile device. The user receives the evaluation report as output. The user checks the report contents to understand the current situation and areas for improvement.

[0879] Step 7:

[0880] The user provides feedback from their mobile device. The evaluation report contents and any additional comments from the user are used as input and sent to the server via the feedback function within the application. The collected feedback is obtained as output. The feedback may include specific improvements or further considerations.

[0881] Step 8:

[0882] The server reflects the collected feedback in the next process. It uses the feedback provided by the user as input and saves and manages it as data to be reflected in the next audit process. It obtains feedback to be reflected in the next audit as output. Specifically, it saves the feedback content in a database and uses it as reference for the next analysis.

[0883] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[0884] This invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, and generates and notifies an evaluation report based on the analysis results. By combining this system with an emotion engine, it collects and evaluates feedback from users more precisely and reflects the results in the next process.

[0885] System program processing description

[0886] The program processing flow of this system is shown below. The system is mainly composed of three components: the server, the user, and the terminal.

[0887] Server Processing

[0888] Accessing the database

[0889] The server accesses the information management database and connects to it using the necessary authentication information to extract data such as security guidelines, procedures, and access logs related to the company's ISMS certification.

[0890] Analysis of information management regulations documents

[0891] The server uses a generative AI to analyze information management policy documents extracted from the database. The generative AI checks whether the documents comply with the latest laws and regulations and best practices. Specifically, it analyzes "information protection policies" and "risk assessment reports" and evaluates whether their contents are appropriate.

[0892] Analyzing log data

[0893] The server analyzes the log data using anomaly detection algorithms, which examine access logs and system logs to check for abnormal access or unauthorized behavior, specifically detecting abnormal access patterns from specific IP addresses.

[0894] Generate an assessment report

[0895] An evaluation report is generated based on the analysis results. The server uses the generation AI to create an evaluation report that details the maintenance and operational status. The report includes any issues discovered and suggestions for improvement.

[0896] Evaluation report notification

[0897] The server notifies the auditor and company administrator of the generated assessment report by sending an email with the assessment report attached for immediate review.

[0898] User Action

[0899] Review the assessment report

[0900] The user receives an email sent from the server, checks the assessment report, and understands the current state of security management and areas for improvement.

[0901] Providing feedback

[0902] The user provides feedback based on the evaluation report. The user may add supplementary information or provide additional confirmations. The emotion engine also analyzes the user's emotional state.

[0903] Terminal handling

[0904] Send Feedback

[0905] The device sends the feedback entered by the user to the server, including the user's emotions.

[0906] Emotion Engine Operation

[0907] The emotion engine analyzes the emotion of the user based on the feedback, for example, identifying whether the user is dissatisfied or satisfied based on the content of the feedback.

[0908] Rating and categorizing feedback

[0909] Evaluate and categorize feedback content based on emotional data collected using an emotion engine, for example generating an alert for negative feedback requiring immediate attention.

[0910] Generate and send follow-ups

[0911] The server automatically generates and sends follow-up communications based on the user's emotions recognized by the emotion engine, for example, if the user is dissatisfied, it sends a follow-up email to offer additional support.

[0912] Specific examples

[0913] Company B's information management database stores the latest security guidelines, procedures, and access logs. The server accesses the database, extracts the necessary information, and begins analysis. The generation AI analyzes the regulation documents and checks whether their contents comply with the latest laws and regulations. In parallel, the anomaly detection algorithm analyzes the access logs and checks for any abnormal behavior. The server generates an evaluation report based on the analysis results and notifies the auditor and company administrator. The user checks the evaluation report and sends any necessary feedback to the server via their device. The feedback also includes the user's emotions, which are analyzed by the emotion engine. The server evaluates the feedback based on the emotion data and automatically generates and sends follow-up emails as necessary.

[0914] As described above, by using this system, ISMS certification audits can be carried out efficiently and accurately, and feedback that takes user feelings into consideration can be reflected immediately.

[0915] The processing flow will be explained below.

[0916] Step 1:

[0917] The server accesses the information management database, connecting using the necessary authentication information to extract data such as security guidelines, procedures, and access logs related to the company's ISMS certification.

[0918] Step 2:

[0919] The server launches a generation AI to analyze information management regulations documents. The generation AI analyzes documents such as "information protection policies" and "risk assessment reports" to verify that their contents comply with the latest laws, regulations, and best practices.

[0920] Step 3:

[0921] The server analyzes the log data using an anomaly detection algorithm. It analyzes access logs and system logs to check for abnormal access or unauthorized behavior. Specifically, it detects abnormal access patterns from specific IP addresses.

[0922] Step 4:

[0923] The server generates an evaluation report based on the analysis results. Using the generation AI, the report details the maintenance and operational status. The report includes any issues discovered and suggestions for improvement.

[0924] Step 5:

[0925] The server notifies the auditor and company administrator of the generated assessment report by sending an email with the assessment report attached for immediate review.

[0926] Step 6:

[0927] The user receives an email sent from the server and checks the evaluation report to understand the current state of security management and areas for improvement.

[0928] Step 7:

[0929] The user provides feedback based on the evaluation report. For example, the user may add supplementary information to the contents of the evaluation report or provide additional confirmation items. Here, the user may input feedback including their feelings.

[0930] Step 8:

[0931] The terminal transmits the feedback input by the user to the server, and the terminal transmits the feedback to the server in near real time.

[0932] Step 9:

[0933] The server receives the feedback sent from the device. The feedback includes the user's emotional data, which is then analyzed by the emotion engine. For example, the content and expressions of the sentences are used to measure the user's dissatisfaction or satisfaction.

[0934] Step 10:

[0935] The server evaluates and classifies the feedback content based on the user's emotions recognized by the emotion engine, for example, generating an alert indicating that negative feedback requires immediate attention.

[0936] Step 11:

[0937] The server generates follow-up communications based on the emotion engine's analysis, and if the user is dissatisfied, generates and sends a follow-up email to provide additional support or clarification.

[0938] Step 12:

[0939] The server then incorporates the feedback and sentiment analysis results into the next audit process. For example, if any issues are identified, specific steps and measures to resolve them can be added to the next audit plan.

[0940] Through these steps, this system can efficiently and accurately conduct ISMS certification audits and instantly reflect feedback that takes into account the user's feelings.

[0941] Example 2

[0942] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[0943] Modern companies must manage large amounts of information and operate in compliance with laws and industry best practices. Appropriate document management and log analysis are essential, particularly for Information Security Management System (ISMS) certification. However, these tasks require time and effort when performed manually, and there is a high risk of human error. Furthermore, collecting and incorporating feedback after creating an evaluation report is cumbersome, making it difficult to properly reflect user sentiment and opinions. To address these challenges, a system that achieves advanced automation and sophisticated sentiment analysis is needed.

[0944] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document using a generative AI model, means for analyzing log data using an anomaly detection algorithm, means for generating an evaluation report based on the analysis results, means for notifying the generated evaluation report by email, means for collecting feedback from the user, means for analyzing the user's emotional state using an emotion engine, and means for reflecting the collected feedback and the analyzed emotional state in the next process. This makes it possible to improve the efficiency of the information management and evaluation processes related to ISMS certification and accurately reflect the user's emotions and opinions.

[0945] An "information management database" is a system that centrally stores and manages data used by companies and organizations for information security management.

[0946] A "generative AI model" is an artificial intelligence algorithm that uses natural language processing and machine learning techniques to analyze and generate text data.

[0947] An "information management regulations document" is a document that clearly states the procedures and policies regarding the operation and management of information security.

[0948] An "anomaly detection algorithm" is an algorithm that analyzes log data and the like to detect abnormal access or behavior that deviates from normal patterns.

[0949] An "evaluation report" is a report summarizing the results of the analysis, detailing the current state of security management and areas for improvement.

[0950] "Email" is a means of communication for sending documents and files to other parties via the Internet.

[0951] "Users" are people involved in information security management, such as employees and managers of companies that use the system.

[0952] "Feedback" refers to user opinions and comments provided in response to an evaluation report.

[0953] The "emotion engine" is an artificial intelligence algorithm that analyzes feedback content and identifies the user's emotional state.

[0954] This invention relates to a system that enables companies and organizations to manage information security efficiently and precisely. This system accesses an information management database, analyzes information management regulations documents and log data using generative AI models and anomaly detection algorithms, and generates and notifies evaluation reports based on the analysis results. It also collects feedback from users and uses an emotion engine to reflect the feedback in the next process.

[0955] Hardware and Software Configuration

[0956] This system is mainly composed of three components: the server, the terminal, and the user. The hardware and software for each component are as follows:

[0957] server

[0958] Hardware: The server is a server machine equipped with a powerful processor, ample memory space, and large storage capacity.

[0959] software:

[0960] Database Management System (DBMS): Used to manage information management databases.

[0961] Generative AI model: Used to analyze information management policy documents.

[0962] Anomaly detection algorithms: Used to analyze log data.

[0963] SMTP Server: Used for email notification of assessment reports.

[0964] Terminal

[0965] Hardware: Terminal devices such as PCs and tablets that accept user input.

[0966] software:

[0967] Web browser: Used by users to view evaluation reports and provide feedback.

[0968] HTTP client: Used to send feedback data to the server.

[0969] Emotion engine: Used to analyze feedback content and determine the user's emotional state.

[0970] User

[0971] Role: The user is responsible for using the system to review the evaluation reports and provide feedback.

[0972] System Operation

[0973] 1. Access to the database

[0974] The server connects to the information management database using authentication information and extracts the necessary data (security guidelines, procedures, access logs, etc.).

[0975] 2. Analysis of information management regulations documents

[0976] The server uses the generative AI model to analyze the extracted information management regulations document. For example, analysis can be performed by inputting the following prompt sentence into the generative AI model:

[0977] "Analyze this document for compliance with the latest regulations."

[0978] 3. Log data analysis

[0979] The server analyzes the log data using anomaly detection algorithms, for example, to detect abnormal access patterns from specific IP addresses.

[0980] 4. Generate an evaluation report

[0981] The generative AI model generates an evaluation report based on the analysis results. The evaluation report includes any issues found and suggestions for improvement. An example of a prompt is as follows:

[0982] "Please prepare an evaluation report based on the analysis results. Please include any issues and suggestions for improvement."

[0983] 5. Notification of Evaluation Report

[0984] The server will notify the auditor or company administrator of the generated assessment report via email.

[0985] 6. Feedback Collection and Analysis

[0986] Users use their devices to check the evaluation reports and provide feedback, which is then sent to the server and analyzed by the emotion engine.

[0987] For example, the server analyzes security guidelines, procedures, and access logs obtained from a company's information management database, generates an evaluation report, and notifies the administrator. The user (administrator) checks the evaluation report and enters feedback into the system. The emotion engine analyzes the user's emotional state from the feedback and reflects it in the next process.

[0988] By using this system, companies can efficiently and accurately manage information related to ISMS certification, and can instantly reflect feedback that takes user emotions into consideration.

[0989] The flow of the identification process in the second embodiment will be described with reference to FIG.

[0990] Step 1:

[0991] The server accesses the information management database. Specifically, it connects to the database management system (DBMS) using authentication information (user ID and password) set by the administrator. At this time, the server executes the necessary queries and extracts data such as "security guidelines," "procedures," and "access logs." The input is the authentication information, and the output is the extracted data set.

[0992] Step 2:

[0993] The server uses a generative AI model to analyze the information management regulations document. The input data is the "information management regulations document" extracted from the database. Specifically, the analysis is performed by inputting the following prompt into the generative AI model: "Please analyze whether this document complies with the latest laws and regulations." The generative AI model analyzes the document content and outputs whether it complies with the regulations and any necessary improvements.

[0994] Step 3:

[0995] The server analyzes the log data using an anomaly detection algorithm. The input data is the "access log" and "system log." The server uses pattern matching technology to detect abnormal access patterns or unauthorized behavior from a specific IP address. For example, it detects "multiple invalid login attempts from a specific IP address." The output is the anomaly detection results and their details.

[0996] Step 4:

[0997] The server generates an evaluation report based on the analysis results. The input data are the "analysis results of the regulations document" and the "analysis results of the log data." Using the generative AI model, the server creates an evaluation report that includes issues and improvement suggestions. As a specific example, the following prompt is input to the generative AI model: "Please create an evaluation report based on the analysis results. Please include issues and improvement suggestions." The output is the created evaluation report.

[0998] Step 5:

[0999] The server will notify the generated assessment report by email. The input data is the "assessment report". The server will attach the assessment report to an email and send it to the designated auditor and company administrator using the SMTP protocol. The output is the sent email and a confirmation of its delivery.

[1000] Step 6:

[1001] The user checks the evaluation report using a terminal. The input data is the "email sent from the server." The user opens the evaluation report in an email client to understand the current state of security management and areas for improvement. The output is a review of the evaluation report and an understanding of its contents.

[1002] Step 7:

[1003] The user provides feedback based on the content of the evaluation report. The input data is the "evaluation report." The user uses the feedback form to enter supplementary information or additional confirmations. The feedback also includes an emotional state that can be analyzed by the emotion engine. The output is the written feedback.

[1004] Step 8:

[1005] The terminal sends the feedback entered by the user to the server. The input data is "user feedback". The terminal sends an HTTP POST request to send the feedback to the server. The output is the sent feedback data.

[1006] Step 9:

[1007] The emotion engine analyzes the user's feedback content. The input data is the "feedback content." The emotion engine uses text analysis technology to determine the user's emotion from the feedback content. For example, it identifies "dissatisfied" or "satisfied." The output is the analyzed emotion data.

[1008] Step 10:

[1009] The server evaluates and classifies the feedback content using the emotional data analyzed by the emotion engine. The input data is the analyzed emotional data and the feedback content. For example, an alert is generated indicating that negative feedback requires immediate action. The output is the evaluated and classified feedback data.

[1010] Step 11:

[1011] The server generates and sends follow-up communications based on the user's emotions recognized by the emotion engine. The input data is the "evaluated and classified feedback data and analyzed emotion data." For example, if the user is dissatisfied, a follow-up email offering additional support is automatically generated and sent using the SMTP protocol. The output is the sent follow-up email and its confirmation of delivery.

[1012] (Application example 2)

[1013] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the headset type terminal 314 will be referred to as a "terminal."

[1014] Traditional information management systems mainly focus on functions such as document analysis and log data monitoring, but lack the ability to analyze feedback sentiment and generate follow-up communications and notifications based on it. This makes it difficult to improve user satisfaction and take prompt and effective action. As a result, the quality of information security management may decline and users may lose trust.

[1015] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 2 is realized by the following means.

[1016] In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document, means for analyzing log data, means for generating an evaluation report based on the analysis results, means for notifying the generated evaluation report, means for collecting feedback, means for reflecting the collected feedback in the next process, means for analyzing the emotions of the feedback using an emotion engine, and means for generating and notifying follow-up communication based on the analyzed emotions. This enables emotion analysis based on user feedback and rapid follow-up accordingly, thereby improving the quality of information security management and increasing user satisfaction and trust.

[1017] An "information management database" is a database that centrally manages data related to information security management for companies and organizations.

[1018] An "information management regulations document" is a document that contains guidelines and best practices regarding information security.

[1019] "Log data" refers to data that records system behavior and access history.

[1020] An "evaluation report" is a report generated based on the results of analysis of information management regulations documents and log data.

[1021] "Means of notification" refers to the means of transmitting the evaluation report and follow-up communications.

[1022] "Feedback" refers to the user's opinions and thoughts on the evaluation report.

[1023] An "emotion engine" is a system for analyzing emotions based on user feedback.

[1024] "Follow-up communications" are additional messages or support generated based on sentiment analysis.

[1025] "Generative AI" refers to artificial intelligence that analyzes natural language and automatically generates documents and reports.

[1026] An "anomaly detection algorithm" is an algorithm that analyzes log data to detect abnormal behavior or unauthorized access.

[1027] The present invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, generates and notifies evaluation reports, collects feedback and analyzes emotions, and generates and notifies follow-up communications. A specific embodiment of this system is described below.

[1028] Key Components of the System

[1029] It consists of three components: server, user, and terminal.

[1030] Server Processing

[1031] 1. Access to the database:

[1032] The server uses appropriate authentication information (e.g., tokens) to access the information management database and extracts data such as security guidelines and access logs. The hardware used is a high-performance server, and the software may utilize a REST API.

[1033] 2. Analysis of information management regulations documents:

[1034] The server uses a generative AI model (e.g., GPT-3) to analyze information management policy documents extracted from the database, using libraries such as AutoTokenizer and AutoModelForSeq2SeqLM to ensure that the document content complies with the latest regulations.

[1035] 3. Log data analysis:

[1036] The server analyzes the log data using an anomaly detection algorithm (e.g., IsolationForest), processes the log data in a tabular format, and detects anomalous access patterns from specific IP addresses.

[1037] 4. Evaluation report generation and notification:

[1038] Based on the analysis results, an assessment report is generated using a generative AI model, which includes a detailed assessment and improvement suggestions based on the analyzed data, and the generated assessment report is notified to the auditor and company management via email.

[1039] User Action

[1040] 1. Review the assessment report:

[1041] The user receives the email sent from the server and checks the evaluation report. The user understands the contents of the report and confirms the current state of security management and any necessary improvements.

[1042] 2. Providing Feedback:

[1043] Users provide feedback on the evaluation report, including their opinions and thoughts entered through a feedback form.

[1044] Terminal handling

[1045] 1. Feedback submission and sentiment analysis:

[1046] The device sends the user-entered feedback to the server, which then uses an emotion engine to analyze the user's emotions from the feedback content. It uses libraries such as TextBlob to classify the emotions of the feedback text as positive, neutral, or negative.

[1047] 2. Follow-up generation and notification:

[1048] The server automatically generates follow-up communications based on the analyzed sentiment data: if the user provides negative feedback, a follow-up email is sent to offer additional support.

[1049] Specific examples

[1050] A company with multiple departments is using this system. One day, the company's security team receives a weekly security assessment report. The report was generated using a generative AI model (e.g., GPT-3) and includes the latest security guidelines and access log analysis results. Security team members review the report and provide feedback within the app. The device analyzes this feedback with an emotion engine and detects positive emotions, such as "Please enter your feedback: The contents of this report were very helpful." Based on the analysis results, the server automatically generates a follow-up message, such as "Thank you for using our service," and notifies the user, thereby improving satisfaction.

[1051] Prompt Sentence Examples

[1052] "Analyze the document and assess its compliance with modern security standards: 'All employees must comply with company security policies...'"

[1053] As described above, the embodiment of the present invention provides an integrated system for efficiently and effectively managing corporate information security.

[1054] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1055] Step 1:

[1056] The server accesses the information management database. The inputs are the database URL and authentication token. Based on this, data such as security guidelines and access logs are extracted using a REST API. The output is the extracted data. Specifically, a GET request is sent using the requests library. The required data is returned as a response to this request.

[1057] Step 2:

[1058] The server analyzes the information management regulations document. The input is the text of the information management regulations document extracted in step 1. This text is passed to a generative AI model (e.g., GPT-3), which analyzes the document content. The output is an evaluation as the analysis result. Specifically, the text is tokenized using AutoTokenizer, and then the generation process is performed by the model using AutoModelForSeq2SeqLM.

[1059] Step 3:

[1060] The server analyzes the log data. The input is the log data, such as the access log obtained in step 1. This data is passed to an anomaly detection algorithm (e.g., Isolation Forest) to detect abnormal access patterns. The output is the anomaly detection results. Specifically, the log data is converted into a table format using the pandas library, and anomalies are detected using Isolation Forest.

[1061] Step 4:

[1062] The server generates an evaluation report based on the analysis results. The inputs are the analysis results from steps 2 and 3. These results are combined and passed to a generative AI model to generate an evaluation report. The output is the generated evaluation report. Specifically, the generative AI uses an evaluation report template to generate a report containing detailed descriptions.

[1063] Step 5:

[1064] The server notifies the user of the generated evaluation report. The input is the evaluation report and the user's contact information. An email is generated based on this information and the notification is sent. The output is the sent notification email. Specifically, the server uses an SMTP server to send an email with the evaluation report attached.

[1065] Step 6:

[1066] The user receives the evaluation report and checks its contents. The input is the email containing the evaluation report sent from the server. The output is a confirmation of the evaluation report. The user opens the report and understands the current state of security management.

[1067] Step 7:

[1068] The user provides feedback on the evaluation report. The input is the user's opinion or impression on the evaluation report. This is entered through a feedback form and sent. The output is the entered feedback. Specifically, the user enters text into the feedback form and presses the "Submit" button.

[1069] Step 8:

[1070] The terminal sends the feedback entered by the user to the server. The input is the feedback text entered by the user. The terminal sends this data to the server. The output is the sent feedback data. The specific operation is to send the feedback data to the server using an HTTP POST request.

[1071] Step 9:

[1072] The server uses an emotion engine to analyze the sentiment of the feedback. The input is the feedback text, which is passed to an emotion analysis library (e.g., TextBlob) to classify the sentiment as positive, neutral, or negative. The output is the analyzed emotion data. Specifically, it uses TextBlob to calculate the sentiment score of the text and classifies it based on that.

[1073] Step 10:

[1074] The server generates and notifies follow-up communications based on the analyzed emotional data. The input is the emotional analysis results and the user's contact information. A follow-up message is generated based on this information and a notification email is sent. The output is the generated follow-up message and the sent notification email. The specific operation is that the generation AI generates a follow-up message and sends the email using the SMTP server.

[1075] The specific processing unit 290 transmits the result of the specific processing to the headset type terminal 314. In the headset type terminal 314, the control unit 46A causes the speaker 240 and the display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating a user input regarding the result of the specific processing. The control unit 46A transmits audio data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[1076] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1077] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the headset type terminal 314.

[1078] [Fourth embodiment]

[1079] FIG. 7 shows an example of the configuration of a data processing system 410 according to the fourth embodiment.

[1080] 7, a data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[1081] The data processing device 12 includes a computer 22, a database 24, and a communication I / F 26. The computer 22 is an example of a "computer" according to the technology of the present disclosure. The computer 22 includes a processor 28, a RAM 30, and a storage 32. The processor 28, the RAM 30, and the storage 32 are connected to a bus 34. The database 24 and the communication I / F 26 are also connected to the bus 34. The communication I / F 26 is connected to a network 54. Examples of the network 54 include a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1082] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication I / F 44, and a control target 443. The computer 36 includes a processor 46, a RAM 48, and a storage 50. The processor 46, the RAM 48, and the storage 50 are connected to a bus 52. The microphone 238, the speaker 240, the camera 42, and the control target 443 are also connected to the bus 52.

[1083] The microphone 238 receives instructions and the like from the user 20 by receiving voice uttered by the user 20. The microphone 238 captures the voice uttered by the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio in accordance with instructions from the processor 46.

[1084] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an imaging element such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the surroundings of user 20 (for example, an imaging range defined by an angle of view equivalent to the field of vision of a typical healthy person).

[1085] The communication I / F 44 is connected to a network 54. The communication I / Fs 44 and 26 are responsible for the exchange of various information between the processor 46 and the processor 28 via the network 54. The exchange of various information between the processor 46 and the processor 28 using the communication I / Fs 44 and 26 is carried out in a secure state.

[1086] The control object 443 includes a display device, LEDs in the eyes, and motors for driving the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the emotions of the robot 414 can be expressed by controlling these motors. In addition, the facial expressions of the robot 414 can also be expressed by controlling the light emission state of the LEDs in the eyes of the robot 414.

[1087] Fig. 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Fig. 8, in the data processing device 12, a specific process is performed by the processor 28. A specific process program 56 is stored in the storage 32.

[1088] The specific processing program 56 is an example of a "program" according to the technology of the present disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1089] The storage 32 stores a data generation model 58 and an emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1090] In the robot 414, the processor 46 performs the reception output process. A reception output program 60 is stored in the storage 50. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output process is realized by the processor 46 operating as the control unit 46A in accordance with the reception output program 60 executed on the RAM 48.

[1091] Next, a description will be given of the specific processing performed by the specific processing unit 290 of the data processing device 12. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1092] This invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, and generates and notifies an evaluation report based on the analysis results. This system utilizes generative AI and anomaly detection algorithms to efficiently conduct ISMS audits and reflect user feedback in the next process.

[1093] System program processing description

[1094] The program processing flow of this system is shown below. The system is mainly composed of three components: the server, the user, and the terminal.

[1095] Server Processing

[1096] Accessing the database

[1097] The server accesses the information management database and connects using the necessary authentication information to extract data such as security guidelines, procedures, and access logs related to the company's ISMS certification.

[1098] Analysis of information management regulations documents

[1099] The server uses a generative AI to analyze information management policy documents extracted from the database. The generative AI checks whether the documents comply with the latest laws and regulations and best practices. For example, it analyzes "information protection policies" and "risk assessment reports" and evaluates whether their contents are appropriate.

[1100] Analyzing log data

[1101] The server analyzes the log data using anomaly detection algorithms. It analyzes access logs and system logs to check for abnormal access or unauthorized behavior. For example, it evaluates whether a specific user is accessing the site at an abnormal time.

[1102] Generate an assessment report

[1103] An evaluation report is generated based on the analysis results. The server uses the generation AI to create a comprehensive evaluation report based on the information obtained from the analysis. The report contains a detailed evaluation of the maintenance and operational status.

[1104] Evaluation report notification

[1105] The server will then send the generated assessment report to the auditor and company administrator via email, with the assessment report attached for immediate review.

[1106] User Action

[1107] Review the assessment report

[1108] The user receives an email from the server and checks the assessment report, which clearly shows the current status of the company's information security management and areas for improvement.

[1109] Providing feedback

[1110] The user may provide feedback based on the evaluation report as needed, for example, to add supplementary information to the report or to indicate matters requiring further confirmation.

[1111] Terminal handling

[1112] Send Feedback

[1113] The terminal sends the feedback entered by the user to the server, which receives the feedback and prepares it for the next audit process.

[1114] Specific examples

[1115] Company A's information management database stores the latest security guidelines, procedures, and access logs. The server accesses the database, extracts the necessary information, and begins analysis. The generation AI analyzes the regulation documents and checks whether their contents comply with the latest laws and regulations. In parallel, the anomaly detection algorithm analyzes the access logs and checks for any abnormal behavior. Based on the analysis results, the server generates a comprehensive evaluation report and notifies the auditor and company administrator. The user reviews the evaluation report and sends any necessary feedback to the server via their device. The server receives this feedback and reflects it in the next audit process.

[1116] As described above, by using this system, ISMS certification audits can be carried out effectively and efficiently.

[1117] The processing flow will be explained below.

[1118] Step 1:

[1119] The server accesses the information management database, connects to the database using the necessary authentication information, and extracts data related to the company's ISMS certification (security guidelines, procedures, access logs, etc.).

[1120] Step 2:

[1121] The server launches a generation AI to analyze information management regulations documents. The generation AI analyzes documents such as "information protection policies" and "risk assessment reports" to verify that their contents comply with the latest laws, regulations, and best practices.

[1122] Step 3:

[1123] The server analyzes the log data using anomaly detection algorithms, which examine access logs and system logs to check for unusual access or unauthorized behavior, such as detecting abnormal access patterns from a particular IP address.

[1124] Step 4:

[1125] The server generates an evaluation report based on the analysis results. Using the generation AI, the report details the maintenance and operational status. The report includes any issues discovered and suggestions for improvement.

[1126] Step 5:

[1127] The server notifies the auditor and company administrator of the generated assessment report by sending an email with the assessment report attached for immediate review.

[1128] Step 6:

[1129] The user receives an email sent from the server, checks the assessment report, and understands the current state of security management and areas for improvement.

[1130] Step 7:

[1131] The user provides feedback based on the evaluation report, adding supplementary information to the contents of the evaluation report or providing additional confirmation.

[1132] Step 8:

[1133] The device sends the feedback entered by the user to the server, which transmits the feedback to the server in near real time.

[1134] Step 9:

[1135] The server receives the feedback sent from the device, analyzes the feedback, and prepares to incorporate it into the next audit process. For example, items that require additional inspection may be included in the next audit.

[1136] By following the above steps, this system can efficiently and accurately conduct ISMS certification audits and immediately reflect feedback.

[1137] Example 1

[1138] Next, a description will be given of Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1139] In modern companies, maintaining the robustness of their information security management requires efficient and effective ISMS (Information Security Management System) audits. However, many conventional systems require a lot of manual work, such as data analysis, report generation, anomaly detection, and feedback utilization, which is time-consuming and costly. Another problem is that audit results are not fully utilized in the next audit process. To address this issue, a system is needed that streamlines the entire process of database access and analysis, evaluation report generation and notification, and feedback collection and reuse.

[1140] The specific processing by the specific processing unit 290 of the data processing device 12 in the first embodiment is realized by the following means.

[1141] In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document, means for analyzing log data, means for generating an evaluation report based on the analysis results, means for notifying the evaluation report, means for collecting feedback from users, and means for reflecting the collected feedback in the next process. This makes it possible to streamline the ISMS audit process, reduce manual work, and effectively reflect the obtained feedback in the next and subsequent processes.

[1142] An "information management database" is a database that allows companies and organizations to centrally store and manage data related to information security management.

[1143] An "information management regulations document" is a document that describes information security policies, procedures, and other information security guidelines.

[1144] "Log data" refers to data that records the operation history of a system or network, and includes access logs and system event logs.

[1145] "Analysis" is the process of collecting data and examining and evaluating its contents in detail.

[1146] "Generative AI" is a system that uses artificial intelligence technology to automatically generate new information and documents.

[1147] An "anomaly detection algorithm" is an algorithm that analyzes system and network log data to detect unusual behavior or unauthorized access.

[1148] An "evaluation report" is a report that summarizes the current state of information security management and areas for improvement based on the results of data analysis.

[1149] "Feedback" refers to information such as opinions and improvement suggestions provided by users.

[1150] "Reflecting in the next process" means incorporating the collected feedback into the next work or analysis to achieve continuous improvement.

[1151] "Notification" is the process of informing interested parties of generated evaluation reports and information through communication means.

[1152] This invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, and generates and notifies an evaluation report based on the analysis results. This system utilizes generative AI and anomaly detection algorithms to efficiently conduct ISMS audits and reflect user feedback in the next process.

[1153] Server Processing

[1154] The server first accesses the information management database, which stores information such as security guidelines, procedures, and access logs related to ISMS certification. The server connects to the database using the necessary authentication information and extracts the necessary data.

[1155] Next, the server uses a generative AI (for example, Azure OpenAI) to analyze the information management policy document. A prompt such as "Analyze our information protection policy and check whether it complies with the latest regulations" is input to the generative AI. Based on this prompt, the generative AI analyzes the document and evaluates whether it complies with regulations and best practices.

[1156] In parallel, the server analyzes the log data using an anomaly detection algorithm (e.g., Kibana), analyzing access logs and system logs to detect any abnormal access or unauthorized behavior.

[1157] Once the analysis is complete, the server uses generative AI to create a comprehensive assessment report that details the state of information management, operational status, and areas for improvement. The assessment report is saved in PDF format and sent to auditors and company administrators via email (e.g., SendGrid or Amazon SES).

[1158] User Action

[1159] The user receives an email from the server and checks the assessment report, which clearly shows the current state of the company's information security management and areas for improvement.

[1160] When users provide feedback, they access a dedicated form based on the evaluation report and enter their feedback. Specifically, they can add supplementary information to the report or indicate matters requiring further confirmation.

[1161] Terminal handling

[1162] The device collects the feedback entered by the user and sends it to the server, which receives the feedback and prepares it for the next audit process.

[1163] Specific examples

[1164] Company A's information management database stores the latest security guidelines, procedures, and access logs. The server accesses the database, extracts the necessary information, and begins analysis. For example, it inputs a prompt to the generation AI, such as, "Analyze this information protection policy and confirm that it complies with the latest laws and regulations." In parallel, an anomaly detection algorithm uses Kibana to analyze the access logs and check for any abnormal behavior.

[1165] Based on the analysis results, the server generates a comprehensive evaluation report and notifies the auditor and company administrator. The user can review the evaluation report and send any necessary feedback to the server via their device. The server will then prepare to incorporate this feedback into the next audit process.

[1166] In this way, by using this system, ISMS certification audits can be carried out effectively and efficiently.

[1167] The flow of the identification process in the first embodiment will be described with reference to FIG.

[1168] Step 1: Access the Database

[1169] The server obtains connection information to access the information management database. The connection information includes the database URL, user name, password, etc. The server uses this authentication information to connect to the database. If the connection is successful, the server extracts the necessary data from the database, such as security guidelines, procedures, and access logs related to ISMS certification. The input is the authentication information and database URL, and the output is the extracted data set. With this step, the server is ready to access the information management database and retrieve the necessary data.

[1170] Step 2: Analyze the information management policy document

[1171] The server inputs the extracted information management regulations document into the generation AI. The input data includes security guidelines and procedures. The server sets specific questions as prompts for the generation AI, such as, "Please confirm whether this information protection policy complies with the latest laws and regulations." The generation AI analyzes the document based on these prompts and evaluates whether it complies with laws and regulations and best practices. The analysis results are returned to the server, and the evaluation results and points for improvement are obtained as output. This step allows the server to use the generation AI to analyze the document.

[1172] Step 3: Analyze the log data

[1173] The server analyzes the log data using an anomaly detection algorithm (e.g., Kibana). Input data includes access logs and system logs. The server inputs the log data into the anomaly detection algorithm to detect abnormal access or unauthorized behavior. For example, it evaluates whether a specific user is accessing the system at an abnormal time. The analysis results output details of any abnormal events or unauthorized access detected by the anomaly detection algorithm. Through this step, the server identifies abnormal system behavior and reduces security risks.

[1174] Step 4: Generate an assessment report

[1175] The server generates an assessment report based on the analysis results of the information management regulations document and the log data. These analysis results are input, and the server uses a generation AI to create the assessment report. The generation AI compiles the analysis results into a report that details the maintenance status, operational status, and areas for improvement. The assessment report is saved in PDF format or other common formats, and a comprehensive assessment report is obtained as output. With this step, the server is ready to compile the audit results and provide them to the relevant parties.

[1176] Step 5: Notification of the evaluation report

[1177] The server notifies the relevant parties of the generated assessment report. The inputs are the generated assessment report and the relevant parties' email addresses. The server uses an email sending system (for example, SendGrid or Amazon SES) to send the assessment report to the auditor and company administrator. The assessment report is attached to the email, so that the relevant parties can immediately check the contents. The output is the sent notification email. This step ensures that the analysis results are communicated to the relevant parties quickly.

[1178] Step 6: Review the assessment report

[1179] The user receives an email sent from the server. The input is the email, and the user opens the assessment report attached to the email. The assessment report clearly shows the current state of the company's information security management and areas for improvement, so the user can review it and provide feedback or instructions to each department as necessary. The output is the contents of the assessment report reviewed by the user. This step allows the user to understand the audit results and take any necessary actions.

[1180] Step 7: Provide feedback

[1181] The user provides feedback based on the evaluation report. The input is the contents of the evaluation report and the user's feedback. The user accesses a dedicated input form and enters their opinions on the evaluation report, suggestions for improvement, and further confirmation items. Once the input is complete, the feedback is sent to the server by clicking the send button. The output is the feedback information provided by the user. This step allows the user to contribute to system improvements based on the evaluation report.

[1182] Step 8: Submit your feedback

[1183] The terminal collects the feedback entered by the user and sends it to the server. The input is the feedback entered by the user. The terminal communicates to consolidate the feedback and send it to the server. The server receives the feedback and prepares to reflect it in the next audit process. The output is the feedback sent to the server. This step allows the feedback provided by the user to be used in the next audit process, ensuring continuous improvement of the system.

[1184] In this way, the servers, users, and terminals work together to efficiently carry out the audit and improvement process of information security management.

[1185] (Application example 1)

[1186] Next, a description will be given of Application Example 1. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1187] Currently, auditing a company's information security management system (ISMS) requires manual checking of information management databases and analysis of documents and log data, which is time-consuming and laborious. The process for users to review assessment reports and provide feedback is also cumbersome. This reduces the efficiency of ISMS audits. Furthermore, access from mobile devices is difficult, limiting the location and time at which audit work can be performed. The purpose of this invention is to solve these issues and provide a more efficient and user-friendly ISMS audit system.

[1188] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 1 is realized by the following means.

[1189] In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document, means for analyzing log data, means for generating an evaluation report based on the analysis results, means for notifying the generated evaluation report, means for collecting feedback, means for reflecting the collected feedback in the next process, means for securely accessing the information management database from a mobile device, and means for checking the evaluation report and providing feedback on the mobile device. This enables ISMS audits to be conducted efficiently and quickly, and enables users to check the evaluation report on their mobile devices and provide feedback.

[1190] An "information management database" is a database for collecting and managing data related to the information management of a company or organization.

[1191] An "information management regulations document" is a document in which a company or organization lists rules and procedures regarding information security and information management.

[1192] "Log data" refers to data that records the operating status of a system or application, and includes access history and system operation records.

[1193] An "evaluation report" is a report that summarizes the evaluation of a system or process, created based on the results of document analysis and log data analysis.

[1194] "Generative AI" is a technology or program that uses artificial intelligence to automatically analyze documents and data and generate results.

[1195] An "anomaly detection algorithm" is an algorithm that automatically detects unusual patterns or abnormal behavior from data.

[1196] A "mobile device" is a portable electronic device such as a smartphone or tablet.

[1197] "Feedback" refers to the act and content of providing evaluations, opinions, and areas for improvement.

[1198] "Means of notification" refers to the methods or functions used by the system to notify the user of specific information.

[1199] "Means of reflection" are the methods and functions for incorporating collected information and feedback into the next operation of a process or system.

[1200] The embodiment of the present invention will be described below: The system mainly consists of three components: a server, a user, and a mobile device.

[1201] Server Processing

[1202] The server accesses the information management database and extracts necessary data. Specifically, the server accesses the database using a security protocol to collect data such as security guidelines, procedures, and access logs.

[1203] The information management policy document is then analyzed using a generative AI, such as OpenAI's GPT-3 model, to ensure that the document complies with the latest regulations and best practices.

[1204] The server then analyzes the log data using anomaly detection algorithms, such as Isolation Forest and k-means clustering.

[1205] To generate an evaluation report based on the analysis results, the server uses a report generation library such as Python's ReportLab to create a comprehensive evaluation report.

[1206] The generated evaluation report is sent to the user via email using the SMTP protocol and the Python smtplib library.

[1207] Mobile Device Handling

[1208] Users use their mobile devices to access the server and check the assessment report. The HTTPS protocol is used to securely access the information management database from mobile devices.

[1209] After reviewing the evaluation report, the user can provide feedback if necessary. The feedback is entered directly from the mobile device and sent to the server.

[1210] User Action

[1211] The user checks the evaluation report sent from the server, understands the current situation and areas for improvement, and provides feedback based on the contents of the evaluation report, which is then sent back to the server.

[1212] The feedback may include specific improvements to the evaluation report or additional points to be checked, and will be reflected in the next audit process.

[1213] Specific examples

[1214] Specific examples are shown below.

[1215] When Company B uses the Mobile Security Audit Assistant, the server accesses the information management database and extracts the latest security guidelines and access logs.

[1216] The generative AI uses the following prompt to analyze the "Information Security Policy" document and ensure it complies with regulations:

[1217] Please confirm that the contents of your "Information Security Policy" document comply with the latest laws and regulations. Also, review the following seven aspects: 1. Advanced security measures 2. Appropriate management of information assets 3. Employee education and training 4. Risk assessment 5. Access control 6. Continuous improvement 7. Detection of abnormal login attempts.

[1218] The flow of the specific processing in the application example 1 will be described with reference to FIG.

[1219] Step 1:

[1220] The server accesses the information management database. It uses security authentication information and the database URL as input to retrieve data such as security guidelines, procedures, and access logs from the database. It obtains the extracted data as output. This process is securely accessed using the HTTPS protocol.

[1221] Step 2:

[1222] The server uses a generative AI model to analyze the information management regulations document. Using the extracted regulations document as input, the generative AI model (e.g., GPT-3) is given a prompt to analyze it. As a specific example, a prompt to confirm whether the contents of the "Information Security Policy" document comply with the latest laws and regulations is input to the generative AI. The analysis results are obtained as output.

[1223] Step 3:

[1224] The server analyzes the log data using an anomaly detection algorithm. Using the acquired log data as input, it applies an anomaly detection algorithm such as Isolation Forest or k-means clustering. The output is anomaly detection results. Specific operations include detecting unauthorized access and abnormal login attempts.

[1225] Step 4:

[1226] The server generates an evaluation report based on the analysis results. It uses the analysis results of the information management regulations document and the anomaly detection results from the log data as input, and creates the evaluation report using a report generation library such as Python's ReportLab. The generated evaluation report is obtained as output. Specifically, the report includes an evaluation of the current security measures and areas for improvement.

[1227] Step 5:

[1228] The server notifies the user of the evaluation report. Using the generated evaluation report and the user's email address as input, the server sends the report by email using the SMTP protocol. The server obtains the evaluation report that is notified to the user as output. Specifically, the email is sent using Python's smtplib library.

[1229] Step 6:

[1230] The user checks the evaluation report using a mobile device. Using the received evaluation report as input, the user views the report using the viewer function of the mobile device. The user receives the evaluation report as output. The user checks the report contents to understand the current situation and areas for improvement.

[1231] Step 7:

[1232] The user provides feedback from their mobile device. The evaluation report contents and any additional comments from the user are used as input and sent to the server via the feedback function within the application. The collected feedback is obtained as output. The feedback may include specific improvements or further considerations.

[1233] Step 8:

[1234] The server reflects the collected feedback in the next process. It uses the feedback provided by the user as input and saves and manages it as data to be reflected in the next audit process. It obtains feedback to be reflected in the next audit as output. Specifically, it saves the feedback content in a database and uses it as reference for the next analysis.

[1235] Furthermore, an emotion engine that estimates the user's emotion may be further combined. That is, the identification processing unit 290 may estimate the user's emotion using the emotion identification model 59, and perform identification processing using the user's emotion.

[1236] This invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, and generates and notifies an evaluation report based on the analysis results. By combining this system with an emotion engine, it collects and evaluates feedback from users more precisely and reflects the results in the next process.

[1237] System program processing description

[1238] The program processing flow of this system is shown below. The system is mainly composed of three components: the server, the user, and the terminal.

[1239] Server Processing

[1240] Accessing the database

[1241] The server accesses the information management database and connects to it using the necessary authentication information to extract data such as security guidelines, procedures, and access logs related to the company's ISMS certification.

[1242] Analysis of information management regulations documents

[1243] The server uses a generative AI to analyze information management policy documents extracted from the database. The generative AI checks whether the documents comply with the latest laws and regulations and best practices. Specifically, it analyzes "information protection policies" and "risk assessment reports" and evaluates whether their contents are appropriate.

[1244] Analyzing log data

[1245] The server analyzes the log data using anomaly detection algorithms, which examine access logs and system logs to check for abnormal access or unauthorized behavior, specifically detecting abnormal access patterns from specific IP addresses.

[1246] Generate an assessment report

[1247] An evaluation report is generated based on the analysis results. The server uses the generation AI to create an evaluation report that details the maintenance and operational status. The report includes any issues discovered and suggestions for improvement.

[1248] Evaluation report notification

[1249] The server notifies the auditor and company administrator of the generated assessment report by sending an email with the assessment report attached for immediate review.

[1250] User Action

[1251] Review the assessment report

[1252] The user receives an email sent from the server, checks the assessment report, and understands the current state of security management and areas for improvement.

[1253] Providing feedback

[1254] The user provides feedback based on the evaluation report. The user may add supplementary information or provide additional confirmations. The emotion engine also analyzes the user's emotional state.

[1255] Terminal handling

[1256] Send Feedback

[1257] The device sends the feedback entered by the user to the server, including the user's emotions.

[1258] Emotion Engine Operation

[1259] The emotion engine analyzes the emotion of the user based on the feedback, for example, identifying whether the user is dissatisfied or satisfied based on the content of the feedback.

[1260] Rating and categorizing feedback

[1261] Evaluate and categorize feedback content based on emotional data collected using an emotion engine, for example generating an alert for negative feedback requiring immediate attention.

[1262] Generate and send follow-ups

[1263] The server automatically generates and sends follow-up communications based on the user's emotions recognized by the emotion engine, for example, if the user is dissatisfied, it sends a follow-up email to offer additional support.

[1264] Specific examples

[1265] Company B's information management database stores the latest security guidelines, procedures, and access logs. The server accesses the database, extracts the necessary information, and begins analysis. The generation AI analyzes the regulation documents and checks whether their contents comply with the latest laws and regulations. In parallel, the anomaly detection algorithm analyzes the access logs and checks for any abnormal behavior. The server generates an evaluation report based on the analysis results and notifies the auditor and company administrator. The user checks the evaluation report and sends any necessary feedback to the server via their device. The feedback also includes the user's emotions, which are analyzed by the emotion engine. The server evaluates the feedback based on the emotion data and automatically generates and sends follow-up emails as necessary.

[1266] As described above, by using this system, ISMS certification audits can be carried out efficiently and accurately, and feedback that takes user feelings into consideration can be reflected immediately.

[1267] The processing flow will be explained below.

[1268] Step 1:

[1269] The server accesses the information management database, connecting using the necessary authentication information to extract data such as security guidelines, procedures, and access logs related to the company's ISMS certification.

[1270] Step 2:

[1271] The server launches a generation AI to analyze information management regulations documents. The generation AI analyzes documents such as "information protection policies" and "risk assessment reports" to verify that their contents comply with the latest laws, regulations, and best practices.

[1272] Step 3:

[1273] The server analyzes the log data using an anomaly detection algorithm. It analyzes access logs and system logs to check for abnormal access or unauthorized behavior. Specifically, it detects abnormal access patterns from specific IP addresses.

[1274] Step 4:

[1275] The server generates an evaluation report based on the analysis results. Using the generation AI, the report details the maintenance and operational status. The report includes any issues discovered and suggestions for improvement.

[1276] Step 5:

[1277] The server notifies the auditor and company administrator of the generated assessment report by sending an email with the assessment report attached for immediate review.

[1278] Step 6:

[1279] The user receives an email sent from the server and checks the evaluation report to understand the current state of security management and areas for improvement.

[1280] Step 7:

[1281] The user provides feedback based on the evaluation report. For example, the user may add supplementary information to the contents of the evaluation report or provide additional confirmation items. Here, the user may input feedback including their feelings.

[1282] Step 8:

[1283] The terminal transmits the feedback input by the user to the server, and the terminal transmits the feedback to the server in near real time.

[1284] Step 9:

[1285] The server receives the feedback sent from the device. The feedback includes the user's emotional data, which is then analyzed by the emotion engine. For example, the content and expressions of the sentences are used to measure the user's dissatisfaction or satisfaction.

[1286] Step 10:

[1287] The server evaluates and classifies the feedback content based on the user's emotions recognized by the emotion engine, for example, generating an alert indicating that negative feedback requires immediate attention.

[1288] Step 11:

[1289] The server generates follow-up communications based on the emotion engine's analysis, and if the user is dissatisfied, generates and sends a follow-up email to provide additional support or clarification.

[1290] Step 12:

[1291] The server then incorporates the feedback and sentiment analysis results into the next audit process. For example, if any issues are identified, specific steps and measures to resolve them can be added to the next audit plan.

[1292] Through these steps, this system can efficiently and accurately conduct ISMS certification audits and instantly reflect feedback that takes into account the user's feelings.

[1293] Example 2

[1294] Next, a description will be given of Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1295] Modern companies must manage large amounts of information and operate in compliance with laws and industry best practices. Appropriate document management and log analysis are essential, particularly for Information Security Management System (ISMS) certification. However, these tasks require time and effort when performed manually, and there is a high risk of human error. Furthermore, collecting and incorporating feedback after creating an evaluation report is cumbersome, making it difficult to properly reflect user sentiment and opinions. To address these challenges, a system that achieves advanced automation and sophisticated sentiment analysis is needed.

[1296] The identification process by the identification processing unit 290 of the data processing device 12 in the second embodiment is realized by the following means. In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document using a generative AI model, means for analyzing log data using an anomaly detection algorithm, means for generating an evaluation report based on the analysis results, means for notifying the generated evaluation report by email, means for collecting feedback from the user, means for analyzing the user's emotional state using an emotion engine, and means for reflecting the collected feedback and the analyzed emotional state in the next process. This makes it possible to improve the efficiency of the information management and evaluation processes related to ISMS certification and accurately reflect the user's emotions and opinions.

[1297] An "information management database" is a system that centrally stores and manages data used by companies and organizations for information security management.

[1298] A "generative AI model" is an artificial intelligence algorithm that uses natural language processing and machine learning techniques to analyze and generate text data.

[1299] An "information management regulations document" is a document that clearly states the procedures and policies regarding the operation and management of information security.

[1300] An "anomaly detection algorithm" is an algorithm that analyzes log data and the like to detect abnormal access or behavior that deviates from normal patterns.

[1301] An "evaluation report" is a report summarizing the results of the analysis, detailing the current state of security management and areas for improvement.

[1302] "Email" is a means of communication for sending documents and files to other parties via the Internet.

[1303] "Users" are people involved in information security management, such as employees and managers of companies that use the system.

[1304] "Feedback" refers to user opinions and comments provided in response to an evaluation report.

[1305] The "emotion engine" is an artificial intelligence algorithm that analyzes feedback content and identifies the user's emotional state.

[1306] This invention relates to a system that enables companies and organizations to manage information security efficiently and precisely. This system accesses an information management database, analyzes information management regulations documents and log data using generative AI models and anomaly detection algorithms, and generates and notifies evaluation reports based on the analysis results. It also collects feedback from users and uses an emotion engine to reflect the feedback in the next process.

[1307] Hardware and Software Configuration

[1308] This system is mainly composed of three components: the server, the terminal, and the user. The hardware and software for each component are as follows:

[1309] server

[1310] Hardware: The server is a server machine equipped with a powerful processor, ample memory space, and large storage capacity.

[1311] software:

[1312] Database Management System (DBMS): Used to manage information management databases.

[1313] Generative AI model: Used to analyze information management policy documents.

[1314] Anomaly detection algorithms: Used to analyze log data.

[1315] SMTP Server: Used for email notification of assessment reports.

[1316] Terminal

[1317] Hardware: Terminal devices such as PCs and tablets that accept user input.

[1318] software:

[1319] Web browser: Used by users to view evaluation reports and provide feedback.

[1320] HTTP client: Used to send feedback data to the server.

[1321] Emotion engine: Used to analyze feedback content and determine the user's emotional state.

[1322] User

[1323] Role: The user is responsible for using the system to review the evaluation reports and provide feedback.

[1324] System Operation

[1325] 1. Access to the database

[1326] The server connects to the information management database using authentication information and extracts the necessary data (security guidelines, procedures, access logs, etc.).

[1327] 2. Analysis of information management regulations documents

[1328] The server uses the generative AI model to analyze the extracted information management regulations document. For example, analysis can be performed by inputting the following prompt sentence into the generative AI model:

[1329] "Analyze this document for compliance with the latest regulations."

[1330] 3. Log data analysis

[1331] The server analyzes the log data using anomaly detection algorithms, for example, to detect abnormal access patterns from specific IP addresses.

[1332] 4. Generate an evaluation report

[1333] The generative AI model generates an evaluation report based on the analysis results. The evaluation report includes any issues found and suggestions for improvement. An example of a prompt is as follows:

[1334] "Please prepare an evaluation report based on the analysis results. Please include any issues and suggestions for improvement."

[1335] 5. Notification of Evaluation Report

[1336] The server will notify the auditor or company administrator of the generated assessment report via email.

[1337] 6. Feedback Collection and Analysis

[1338] Users use their devices to check the evaluation reports and provide feedback, which is then sent to the server and analyzed by the emotion engine.

[1339] For example, the server analyzes security guidelines, procedures, and access logs obtained from a company's information management database, generates an evaluation report, and notifies the administrator. The user (administrator) checks the evaluation report and enters feedback into the system. The emotion engine analyzes the user's emotional state from the feedback and reflects it in the next process.

[1340] By using this system, companies can efficiently and accurately manage information related to ISMS certification, and can instantly reflect feedback that takes user emotions into consideration.

[1341] The flow of the identification process in the second embodiment will be described with reference to FIG.

[1342] Step 1:

[1343] The server accesses the information management database. Specifically, it connects to the database management system (DBMS) using authentication information (user ID and password) set by the administrator. At this time, the server executes the necessary queries and extracts data such as "security guidelines," "procedures," and "access logs." The input is the authentication information, and the output is the extracted data set.

[1344] Step 2:

[1345] The server uses a generative AI model to analyze the information management regulations document. The input data is the "information management regulations document" extracted from the database. Specifically, the analysis is performed by inputting the following prompt into the generative AI model: "Please analyze whether this document complies with the latest laws and regulations." The generative AI model analyzes the document content and outputs whether it complies with the regulations and any necessary improvements.

[1346] Step 3:

[1347] The server analyzes the log data using an anomaly detection algorithm. The input data is the "access log" and "system log." The server uses pattern matching technology to detect abnormal access patterns or unauthorized behavior from a specific IP address. For example, it detects "multiple invalid login attempts from a specific IP address." The output is the anomaly detection results and their details.

[1348] Step 4:

[1349] The server generates an evaluation report based on the analysis results. The input data are the "analysis results of the regulations document" and the "analysis results of the log data." Using the generative AI model, the server creates an evaluation report that includes issues and improvement suggestions. As a specific example, the following prompt is input to the generative AI model: "Please create an evaluation report based on the analysis results. Please include issues and improvement suggestions." The output is the created evaluation report.

[1350] Step 5:

[1351] The server will notify the generated assessment report by email. The input data is the "assessment report". The server will attach the assessment report to an email and send it to the designated auditor and company administrator using the SMTP protocol. The output is the sent email and a confirmation of its delivery.

[1352] Step 6:

[1353] The user checks the evaluation report using a terminal. The input data is the "email sent from the server." The user opens the evaluation report in an email client to understand the current state of security management and areas for improvement. The output is a review of the evaluation report and an understanding of its contents.

[1354] Step 7:

[1355] The user provides feedback based on the content of the evaluation report. The input data is the "evaluation report." The user uses the feedback form to enter supplementary information or additional confirmations. The feedback also includes an emotional state that can be analyzed by the emotion engine. The output is the written feedback.

[1356] Step 8:

[1357] The terminal sends the feedback entered by the user to the server. The input data is "user feedback". The terminal sends an HTTP POST request to send the feedback to the server. The output is the sent feedback data.

[1358] Step 9:

[1359] The emotion engine analyzes the user's feedback content. The input data is the "feedback content." The emotion engine uses text analysis technology to determine the user's emotion from the feedback content. For example, it identifies "dissatisfied" or "satisfied." The output is the analyzed emotion data.

[1360] Step 10:

[1361] The server evaluates and classifies the feedback content using the emotional data analyzed by the emotion engine. The input data is the analyzed emotional data and the feedback content. For example, an alert is generated indicating that negative feedback requires immediate action. The output is the evaluated and classified feedback data.

[1362] Step 11:

[1363] The server generates and sends follow-up communications based on the user's emotions recognized by the emotion engine. The input data is the "evaluated and classified feedback data and analyzed emotion data." For example, if the user is dissatisfied, a follow-up email offering additional support is automatically generated and sent using the SMTP protocol. The output is the sent follow-up email and its confirmation of delivery.

[1364] (Application example 2)

[1365] Next, a description will be given of Application Example 2. In the following description, the data processing device 12 will be referred to as a "server" and the robot 414 will be referred to as a "terminal."

[1366] Traditional information management systems mainly focus on functions such as document analysis and log data monitoring, but lack the ability to analyze feedback sentiment and generate follow-up communications and notifications based on it. This makes it difficult to improve user satisfaction and take prompt and effective action. As a result, the quality of information security management may decline and users may lose trust.

[1367] The specific processing by the specific processing unit 290 of the data processing device 12 in the application example 2 is realized by the following means.

[1368] In this invention, the server includes means for accessing the information management database, means for analyzing the information management regulations document, means for analyzing log data, means for generating an evaluation report based on the analysis results, means for notifying the generated evaluation report, means for collecting feedback, means for reflecting the collected feedback in the next process, means for analyzing the emotions of the feedback using an emotion engine, and means for generating and notifying follow-up communication based on the analyzed emotions. This enables emotion analysis based on user feedback and rapid follow-up accordingly, thereby improving the quality of information security management and increasing user satisfaction and trust.

[1369] An "information management database" is a database that centrally manages data related to information security management for companies and organizations.

[1370] An "information management regulations document" is a document that contains guidelines and best practices regarding information security.

[1371] "Log data" refers to data that records system behavior and access history.

[1372] An "evaluation report" is a report generated based on the results of analysis of information management regulations documents and log data.

[1373] "Means of notification" refers to the means of transmitting the evaluation report and follow-up communications.

[1374] "Feedback" refers to the user's opinions and thoughts on the evaluation report.

[1375] An "emotion engine" is a system for analyzing emotions based on user feedback.

[1376] "Follow-up communications" are additional messages or support generated based on sentiment analysis.

[1377] "Generative AI" refers to artificial intelligence that analyzes natural language and automatically generates documents and reports.

[1378] An "anomaly detection algorithm" is an algorithm that analyzes log data to detect abnormal behavior or unauthorized access.

[1379] The present invention relates to a system that accesses an information management database, analyzes information management regulations documents and log data, generates and notifies evaluation reports, collects feedback and analyzes emotions, and generates and notifies follow-up communications. A specific embodiment of this system is described below.

[1380] Key Components of the System

[1381] It consists of three components: server, user, and terminal.

[1382] Server Processing

[1383] 1. Access to the database:

[1384] The server uses appropriate authentication information (e.g., tokens) to access the information management database and extracts data such as security guidelines and access logs. The hardware used is a high-performance server, and the software may utilize a REST API.

[1385] 2. Analysis of information management regulations documents:

[1386] The server uses a generative AI model (e.g., GPT-3) to analyze information management policy documents extracted from the database, using libraries such as AutoTokenizer and AutoModelForSeq2SeqLM to ensure that the document content complies with the latest regulations.

[1387] 3. Log data analysis:

[1388] The server analyzes the log data using an anomaly detection algorithm (e.g., IsolationForest), processes the log data in a tabular format, and detects anomalous access patterns from specific IP addresses.

[1389] 4. Evaluation report generation and notification:

[1390] Based on the analysis results, an assessment report is generated using a generative AI model, which includes a detailed assessment and improvement suggestions based on the analyzed data, and the generated assessment report is notified to the auditor and company management via email.

[1391] User Action

[1392] 1. Review the assessment report:

[1393] The user receives the email sent from the server and checks the evaluation report. The user understands the contents of the report and confirms the current state of security management and any necessary improvements.

[1394] 2. Providing Feedback:

[1395] Users provide feedback on the evaluation report, including their opinions and thoughts entered through a feedback form.

[1396] Terminal handling

[1397] 1. Feedback submission and sentiment analysis:

[1398] The device sends the user-entered feedback to the server, which then uses an emotion engine to analyze the user's emotions from the feedback content. It uses libraries such as TextBlob to classify the emotions of the feedback text as positive, neutral, or negative.

[1399] 2. Follow-up generation and notification:

[1400] The server automatically generates follow-up communications based on the analyzed sentiment data: if the user provides negative feedback, a follow-up email is sent to offer additional support.

[1401] Specific examples

[1402] A company with multiple departments is using this system. One day, the company's security team receives a weekly security assessment report. The report was generated using a generative AI model (e.g., GPT-3) and includes the latest security guidelines and access log analysis results. Security team members review the report and provide feedback within the app. The device analyzes this feedback with an emotion engine and detects positive emotions, such as "Please enter your feedback: The contents of this report were very helpful." Based on the analysis results, the server automatically generates a follow-up message, such as "Thank you for using our service," and notifies the user, thereby improving satisfaction.

[1403] Prompt Sentence Examples

[1404] "Analyze the document and assess its compliance with modern security standards: 'All employees must comply with company security policies...'"

[1405] As described above, the embodiment of the present invention provides an integrated system for efficiently and effectively managing corporate information security.

[1406] The flow of the specific processing in the application example 2 will be described with reference to FIG.

[1407] Step 1:

[1408] The server accesses the information management database. The inputs are the database URL and authentication token. Based on this, data such as security guidelines and access logs are extracted using a REST API. The output is the extracted data. Specifically, a GET request is sent using the requests library. The required data is returned as a response to this request.

[1409] Step 2:

[1410] The server analyzes the information management regulations document. The input is the text of the information management regulations document extracted in step 1. This text is passed to a generative AI model (e.g., GPT-3), which analyzes the document content. The output is an evaluation as the analysis result. Specifically, the text is tokenized using AutoTokenizer, and then the generation process is performed by the model using AutoModelForSeq2SeqLM.

[1411] Step 3:

[1412] The server analyzes the log data. The input is the log data, such as the access log obtained in step 1. This data is passed to an anomaly detection algorithm (e.g., Isolation Forest) to detect abnormal access patterns. The output is the anomaly detection results. Specifically, the log data is converted into a table format using the pandas library, and anomalies are detected using Isolation Forest.

[1413] Step 4:

[1414] The server generates an evaluation report based on the analysis results. The inputs are the analysis results from steps 2 and 3. These results are combined and passed to a generative AI model to generate an evaluation report. The output is the generated evaluation report. Specifically, the generative AI uses an evaluation report template to generate a report containing detailed descriptions.

[1415] Step 5:

[1416] The server notifies the user of the generated evaluation report. The input is the evaluation report and the user's contact information. An email is generated based on this information and the notification is sent. The output is the sent notification email. Specifically, the server uses an SMTP server to send an email with the evaluation report attached.

[1417] Step 6:

[1418] The user receives the evaluation report and checks its contents. The input is the email containing the evaluation report sent from the server. The output is a confirmation of the evaluation report. The user opens the report and understands the current state of security management.

[1419] Step 7:

[1420] The user provides feedback on the evaluation report. The input is the user's opinion or impression on the evaluation report. This is entered through a feedback form and sent. The output is the entered feedback. Specifically, the user enters text into the feedback form and presses the "Submit" button.

[1421] Step 8:

[1422] The terminal sends the feedback entered by the user to the server. The input is the feedback text entered by the user. The terminal sends this data to the server. The output is the sent feedback data. The specific operation is to send the feedback data to the server using an HTTP POST request.

[1423] Step 9:

[1424] The server uses an emotion engine to analyze the sentiment of the feedback. The input is the feedback text, which is passed to an emotion analysis library (e.g., TextBlob) to classify the sentiment as positive, neutral, or negative. The output is the analyzed emotion data. Specifically, it uses TextBlob to calculate the sentiment score of the text and classifies it based on that.

[1425] Step 10:

[1426] The server generates and notifies follow-up communications based on the analyzed emotional data. The input is the emotional analysis results and the user's contact information. A follow-up message is generated based on this information and a notification email is sent. The output is the generated follow-up message and the sent notification email. The specific operation is that the generation AI generates a follow-up message and sends the email using the SMTP server.

[1427] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the control target 443 to output the result of the specific processing. The microphone 238 acquires voice indicating a user input regarding the result of the specific processing. The control unit 46A transmits voice data indicating the user input acquired by the microphone 238 to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the voice data.

[1428] The data generation model 58 is a so-called generative AI (Artificial Intelligence). An example of the data generation model 58 is ChatGPT (Internet Search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search <url: https: gemini.google.com ?hl="ja">) and other generation AIs. The data generation model 58 is obtained by performing deep learning on a neural network. A prompt including an instruction is input to the data generation model 58, and inference data such as voice data indicating voice, text data indicating text, and image data indicating an image is also input. The data generation model 58 performs inference on the input inference data in accordance with the instruction indicated by the prompt, and outputs the inference result in a data format such as voice data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1429] In the above embodiment, an example was given in which the specific processing is performed by the data processing device 12, but the technology of the present disclosure is not limited to this, and the specific processing may be performed by the robot 414.

[1430] The emotion identification model 59 as an emotion engine may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to an emotion map (see FIG. 9), which is a specific mapping. Similarly, the emotion identification model 59 may determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[1431] FIG. 9 illustrates an emotion map 400 on which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. Emotions closer to the center of the concentric circles are more primitive. Emotions representing states and behaviors arising from a state of mind are arranged on the outer edges of the concentric circles. The concept of emotion includes both affect and mental states. Emotions generally generated from reactions occurring in the brain are arranged on the left side of the concentric circles. Emotions generally induced by situational judgment are arranged on the right side of the concentric circles. Emotions generally generated from reactions occurring in the brain and induced by situational judgment are arranged on the upper and lower sides of the concentric circles. Furthermore, the emotion of "pleasure" is arranged on the upper side of the concentric circles, and the emotion of "discomfort" is arranged on the lower side. In this way, in the emotion map 400, multiple emotions are mapped based on the structure by which emotions are generated, and emotions that tend to occur simultaneously are mapped close to each other.

[1432] These emotions are distributed in the 3 o'clock direction on emotion map 400, and typically fluctuate between relief and anxiety. In the right half of emotion map 400, situational awareness dominates over internal sensations, resulting in a sense of calm.

[1433] The inside of emotion map 400 represents what is going on in the mind, and the outside of emotion map 400 represents behavior, so the further you go outside emotion map 400, the more visible the emotions become (the more they are expressed in behavior).

[1434] Human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. Emotions can also be created for robots, automobiles, and motorcycles, based on various balances, such as posture and remaining battery life. When these balances deviate from the ideal, a state of discomfort is indicated, and when they approach the ideal, a state of pleasure is indicated. An emotion map can be generated, for example, based on Dr. Mitsuyoshi's emotion map (Research on Voice Emotion Recognition and Emotional Brain Physiological Signal Analysis Systems, Tokushima University, Doctoral Dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map lists emotions belonging to the "reaction" domain, where sensation is dominant. The right half of the emotion map lists emotions belonging to the "situation" domain, where situational awareness is dominant.

[1435] The emotion map defines two emotions that promote learning. One is a negative emotion on the situation side, around the middle of "repentance" or "reflection." In other words, this occurs when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is a positive emotion on the response side, around "desire." In other words, this occurs when the robot experiences positive feelings such as "I want more" or "I want to know more."

[1436] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​indicating each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple pieces of training data that are combinations of user input and emotion values ​​indicating each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions that are located close to each other have similar values, as in the emotion map 900 shown in FIG. 10. FIG. 10 shows an example in which multiple emotions, "relieved," "calm," and "reassuring," have similar emotion values.

[1437] The system according to the present disclosure has been described above mainly with respect to the functions of the data processing device 12, but the system according to the present disclosure is not necessarily implemented on a server. The system according to the present disclosure may be implemented as a general information processing system. The present disclosure may be implemented, for example, as a software program running on a personal computer or an application running on a smartphone, etc. The method according to the present disclosure may be provided to users in the form of SaaS (Software as a Service).

[1438] In the above embodiment, an example was given in which the specific processing is performed by one computer 22, but the technology of the present disclosure is not limited to this, and the specific processing may be distributed and performed by a plurality of computers including the computer 22. For example, the data generation model 58 may be provided in an external device of the data processing device 12, and data may be generated in the external device in accordance with input data.

[1439] In the above embodiment, an example in which the specific processing program 56 is stored in the storage 32 has been described, but the technology of the present disclosure is not limited to this. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-transitory storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-transitory storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes the specific processing in accordance with the specific processing program 56.

[1440] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[1441] It is not necessary to store all of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store all of the specific processing program 56 in the storage 32; only a portion of the specific processing program 56 may be stored.

[1442] The hardware resource for executing a specific process can be any of the following processors: An example of a processor is a CPU, which is a general-purpose processor that functions as a hardware resource for executing a specific process by executing software, i.e., a program. Another example of a processor is a dedicated electrical circuit, such as an FPGA (Field-Programmable Gate Array), a PLD (Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit), which is a processor with a circuit configuration designed specifically for executing a specific process. Each processor has built-in or connected memory, and each processor uses the memory to execute the specific process.

[1443] The hardware resource that executes the specific processing may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Also, the hardware resource that executes the specific processing may be a single processor.

[1444] As an example of a system configured with a single processor, first, one processor is configured by combining one or more CPUs and software, and this processor functions as a hardware resource that executes a specific process. Second, there is a system that uses a processor that realizes the functions of an entire system including multiple hardware resources that execute a specific process on a single IC chip, as typified by SoC (System-on-a-chip). In this way, a specific process is realized using one or more of the above-mentioned various processors as hardware resources.

[1445] Furthermore, the hardware structure of these various processors can be, more specifically, an electric circuit that combines circuit elements such as semiconductor devices. The specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps may be deleted, new steps may be added, or the processing order may be rearranged, without departing from the spirit of the invention.

[1446] The above-described description and illustrations are a detailed explanation of the parts related to the technology of the present disclosure and are merely an example of the technology of the present disclosure. For example, the above description of the configuration, functions, actions, and effects is an explanation of an example of the configuration, functions, actions, and effects of the parts related to the technology of the present disclosure. Therefore, it goes without saying that unnecessary parts may be deleted, new elements may be added, or replacements may be made to the above-described description and illustrations within the scope of the gist of the technology of the present disclosure. Furthermore, to avoid confusion and facilitate understanding of the parts related to the technology of the present disclosure, the above-described description and illustrations omit explanations of common technical knowledge that do not require particular explanation to enable the implementation of the technology of the present disclosure.

[1447] All publications, patent applications, and technical standards mentioned in this specification are herein incorporated by reference to the same extent as if each individual publication, patent application, or technical standard was specifically and individually indicated to be incorporated by reference.

[1448] The following is further disclosed regarding the above embodiment.

[1449] (Claim 1)

[1450] a means for accessing an information management database;

[1451] A means for analyzing the information management policy document;

[1452] a means for analyzing the log data;

[1453] a means for generating an evaluation report based on the analysis results;

[1454] means for notifying the generated evaluation report;

[1455] a means of collecting feedback;

[1456] A means to incorporate the collected feedback into the next process, and

[1457] A system including:

[1458] (Claim 2)

[1459] The system of claim 1, further comprising means for generating the evaluation report using a generation AI.

[1460] (Claim 3)

[1461] The system according to claim 1, further comprising means for analyzing the log data using an anomaly detection algorithm.

[1462] "Example 1"

[1463] (Claim 1)

[1464] a means for accessing an information management database;

[1465] A means for analyzing the information management policy document;

[1466] a means for analyzing the log data;

[1467] a means for generating an evaluation report based on the analysis results;

[1468] a means of communicating the evaluation report;

[1469] a means for collecting feedback from users;

[1470] A means to incorporate the collected feedback into the next process, and

[1471] A system including:

[1472] (Claim 2)

[1473] The system of claim 1, further comprising means for generating the evaluation report using a generation AI.

[1474] (Claim 3)

[1475] 10. The system of claim 1, further comprising means for analyzing the log data using an anomaly detection algorithm.

[1476] (Claim 4)

[1477] 10. The system of claim 1, further comprising means for inputting prompt statements to the generative AI model for analyzing the extracted information management data.

[1478] (Claim 5)

[1479] 2. The system according to claim 1, further comprising means for detecting abnormal access or unauthorized behavior based on the analysis results.

[1480] "Application Example 1"

[1481] (Claim 1)

[1482] a means for accessing an information management database;

[1483] A means for analyzing the information management policy document;

[1484] a means for analyzing the log data;

[1485] a means for generating an evaluation report based on the analysis results;

[1486] means for notifying the generated evaluation report;

[1487] a means of collecting feedback;

[1488] A means to incorporate the collected feedback into the next process, and

[1489] a means for securely accessing the information management database from a mobile device;

[1490] a means for reviewing and providing feedback on the assessment report on a mobile device;

[1491] A system including:

[1492] (Claim 2)

[1493] The system of claim 1, further comprising means for generating the evaluation report using a generation AI.

[1494] (Claim 3)

[1495] The system according to claim 1, further comprising means for analyzing the log data using an anomaly detection algorithm.

[1496] "Example 2: Combining Emotion Engines"

[1497] (Claim 1)

[1498] a means for accessing an information management database;

[1499] A means for analyzing information management policy documents using a generative AI model;

[1500] means for analyzing the log data using an anomaly detection algorithm;

[1501] a means for generating an evaluation report based on the analysis results;

[1502] a means for notifying the user of the generated evaluation report by email;

[1503] a means for collecting feedback from users;

[1504] means for analyzing the emotional state of a user using an emotion engine;

[1505] A means of incorporating the collected feedback and analyzed emotional state into the next process;

[1506] A system including:

[1507] (Claim 2)

[1508] The system of claim 1, further comprising means for generating the evaluation report using a generative AI model.

[1509] (Claim 3)

[1510] The system according to claim 1, further comprising means for analyzing the log data using an anomaly detection algorithm.

[1511] "Application example 2 when combining emotion engines"

[1512] (Claim 1)

[1513] a means for accessing an information management database;

[1514] A means for analyzing the information management policy document;

[1515] a means for analyzing the log data;

[1516] a means for generating an evaluation report based on the analysis results;

[1517] means for notifying the generated evaluation report;

[1518] a means of collecting feedback;

[1519] A means to incorporate the collected feedback into the next process, and

[1520] a means for analyzing the sentiment of the feedback using an emotion engine;

[1521] means for generating and informing follow-up communications based on the analyzed sentiment;

[1522] A system including:

[1523] (Claim 2)

[1524] The system of claim 1, further comprising means for generating the evaluation report using a generation AI.

[1525] (Claim 3)

[1526] The system according to claim 1, further comprising means for analyzing the log data using an anomaly detection algorithm. [Explanation of symbols]

[1527] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Device 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robot< / url:> < / url:> < / url:> < / url:>

Claims

1. a means for accessing an information management database; A means for analyzing the information management policy document; a means for analyzing the log data; a means for generating an evaluation report based on the analysis results; means for notifying the generated evaluation report; a means of collecting feedback; A means to incorporate the collected feedback into the next process, and A system including:

2. The system according to claim 1 , further comprising means for generating the evaluation report using a generation AI.

3. The system of claim 1 further comprising means for analyzing the log data using an anomaly detection algorithm.

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A