Database construction method and system for complying with cybersecurity regulations

The database construction method and system efficiently manage cybersecurity regulations by displaying pre-configured items, inputting datasets, and establishing relationships, enhancing compliance and reducing costs through automated management.

JP2026075074APending Publication Date: 2026-05-07FESCARO CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
FESCARO CO LTD
Filing Date
2025-10-20
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Existing systems lack an efficient method to comply with cyber security regulations throughout the life cycle of mobility devices, necessitating a system for managing cyber threats and risks.

Method used

A database construction method and system that displays pre-configured cybersecurity items, allows for dataset input, establishes relationships between these items, and maps predefined threats and security controls, thereby automating the management of cybersecurity information.

Benefits of technology

Improves regulatory compliance efficiency, reduces costs, and ensures data consistency and accuracy by automating repetitive tasks and validating logical dependencies between cybersecurity items.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026075074000001_ABST
    Figure 2026075074000001_ABST
Patent Text Reader

Abstract

This invention provides a database construction method and system that can efficiently comply with cybersecurity regulations. [Solution] A database construction method for complying with cybersecurity regulations includes: step 801, in which an operational server displays a first interface for one or more pre-configured pre-configured items related to cybersecurity; step 802, in which an operational server can input a dataset relating to the attributes of the pre-configured items included in the first interface; step 804, in which an operational server provides a third interface for establishing a relationship between two pre-configured items from among a plurality of pre-configured items; and step 806, in which a relationship is established between a specific dataset of the first pre-configured item and a specific dataset of the second pre-configured item from among a plurality of pre-configured items using values ​​obtained from a user terminal via the third interface.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The following embodiments relate to a database construction method and system for coping with cyber security regulations.

Background Art

[0002] Currently, due to the increasing electrification and connectivity in the mobility industry, the threat of cyberattacks has significantly increased. As a result, cyber security regulations are being strengthened internationally. For example, the United Nations Economic Commission for Europe (UNECE) has established the international standard UNR155 for automotive cyber security, and the Ministry of Land, Infrastructure and Transport in South Korea has also revised the Automobile Management Act to stipulate that only automotive manufacturers and import sales companies that have received CSMS (Cyber Security Management System) certification can sell automobiles in the country. Furthermore, when all products (hardware and software) including digital elements, not just automobiles, are launched or distributed in the European Union (EU) market, the Cyber Resilience Act (CRA), which obliges to strengthen and manage cyber security throughout the entire life cycle of the product, is also scheduled to be implemented, affecting the entire mobility industry.

[0003] Various cyber security regulations require an organizational process and management system for managing cyber threats and risks and protecting mobility devices from cyberattacks. To comply with the regulations, a system for ensuring cyber security throughout the entire life cycle of mobility devices, such as design, development, production, and maintenance, is necessary.

Summary of the Invention

Problems to be Solved by the Invention

[0004] The problem to be solved by the present invention is to provide a database construction method and system that can efficiently cope with cyber security regulations.

[0005] The problems that the present invention aims to solve are not limited to those described above, and other problems and advantages of the present invention not mentioned can be understood from the following description and will be more clearly understood from embodiments of the present invention. Furthermore, it will be understood that the problems and advantages that the present invention aims to solve can be achieved by the means and combinations thereof shown in the claims. [Means for solving the problem]

[0006] According to one embodiment of the present invention, a database construction method is provided that can efficiently respond to cybersecurity regulations, comprising the steps of: displaying a first interface for one or more pre-configured pre-configured items related to cybersecurity; providing a second interface for inputting a dataset for the attributes of the pre-configured items included in the first interface; providing a third interface for establishing a relationship between two pre-configured items from among a plurality of the pre-configured items; and using values ​​obtained through the third interface to establish a relationship between a specific dataset of a first pre-configured item and a specific dataset of a second pre-configured item from among the plurality of pre-configured items.

[0007] In the present invention, after the step of establishing the relationships between the datasets, the following steps may be additionally included: acquiring threat scenarios; providing a fourth interface that can establish relationships between the acquired threat scenarios and predefined threats; and using the values ​​acquired via the fourth interface, setting up one or more of the predefined specific threat datasets that are mapped to specific datasets of the threat scenarios.

[0008] In the present invention, after the step of establishing the relationships between the datasets, the following steps may be additionally included: obtaining security objectives corresponding to a specific threat scenario from among the threat scenarios; providing a fifth interface that can establish relationships between the obtained security objectives and security controls; and setting up one or more specific datasets of security controls linked to a specific dataset of security objectives using values ​​obtained through the fifth interface.

[0009] In the present invention, the fourth interface provides a list of predefined threats that can be mapped to a dataset of threat scenarios, and the dataset of predefined threats corresponding to a user selection from the list can be mapped to a specific dataset of threat scenarios.

[0010] In the present invention, the fifth interface provides a list of security control datasets that can be mapped to a specific dataset of the security objective, and from the list of security control datasets, a dataset corresponding to a user selection can be mapped to a specific dataset of the security objective.

[0011] In the present invention, the predefined threat dataset list or the security control dataset list may be based on values ​​obtained using the second interface.

[0012] In the present invention, a specific dataset of one or more pre-configured items can be linked to a specific dataset of the threat scenario or the security objective.

[0013] In the present invention, one or more preconfigured items on the first interface can be changed by operator input.

[0014] In the present invention, the first interface provides an interface for adding pre-configured items or item-specific attributes by user input, in addition to pre-configured pre-configured items or item-specific attributes, and the first interface can provide change history information regarding the attributes of the pre-configured pre-configured items.

[0015] In the present invention, the dataset input by the second interface may include the value of an identifier field among the attributes of the preconfigured item that uniquely distinguishes the individual dataset.

[0016] In the present invention, the step of providing the third interface can provide an interface that can input a specific dataset of the first preconfiguration item and a specific dataset of the second preconfiguration item in a concatenated manner.

[0017] In the present invention, the third interface may include the step of mapping an ID value corresponding to a specific dataset of the first preconfiguration item to an ID value corresponding to a specific dataset of one or more second preconfiguration items, or mapping an ID value corresponding to a specific dataset of the second preconfiguration item to an ID value corresponding to a specific dataset of one or more first preconfiguration items.

[0018] In the present invention, the third interface may be an interface that can establish a relationship between two pre-configured pre-configuration items from among a plurality of pre-configuration items.

[0019] In the present invention, among the pre-configured items, the pre-set first and second pre-configured items may be one of the following: "security control - security request", "functional verification test case - security request", "pre-defined threat - non-functional verification test case", and "pre-defined threat - pre-defined mitigation".

[0020] According to another embodiment, as a database construction system that can efficiently respond to cyber security regulations, a first interface for one or more preset pre-configuration items is displayed, and a second interface that can input a data set for the attributes of the pre-configuration items included in the first interface is provided. A third interface capable of establishing a relationship between two preset pre-configuration items among the plurality of pre-configuration items is provided, and the value obtained by the third interface is used to establish a relationship between a specific data set of a first pre-configuration item and a specific data set of a second pre-configuration item among the plurality of pre-configuration items. A database construction method that can efficiently respond to cyber security regulations is provided.

Advantages of the Invention

[0021] According to the means for solving the problems of the present disclosure described above, by constructing a database that manages information related to cyber security items and automatically establishes relationships between cyber security items, the efficiency and convenience of regulatory compliance can be improved.

[0022] Furthermore, by providing an interface, it is possible to control the registration order and structure of data even in complex data, and ensure the consistency and accuracy of data management.

[0023] Furthermore, by managing the connection relationships between items stored in the database, repetitive and overlapping operations can be automated, various validity verifications can be performed, and productivity can be improved, costs can be reduced, and consistency in regulatory compliance can be ensured.

Brief Description of the Drawings

[0024] [Figure 1] It is a system diagram of a database construction method for responding to cyber security regulations according to an embodiment. [Figure 2] It is a diagram showing a first screen of a first interface according to an embodiment of the present invention. [Figure 3]It is a diagram showing the second screen of the first interface according to an embodiment of the present invention. [Figure 4] It is a diagram showing the second interface for dataset input for attributes by preconfigured item according to an embodiment of the present invention. [Figure 5] It is a diagram showing the third interface for establishing the relationship between datasets of preconfigured items according to an embodiment of the present invention. [Figure 6] It is a diagram showing the fourth interface for establishing the relationship between a threat scenario and a predefined threat according to an embodiment of the present invention. [Figure 7] It is a diagram showing the fifth interface for establishing the relationship between security goals and security controls according to an embodiment of the present invention. [Figure 8] It is a diagram showing, in a flowchart, the operations of the operation server and the user terminal in the preconfiguration step according to an embodiment. [Figure 9] It is a diagram showing, in a flowchart, the operations of the operation server and the user terminal in an individual engineering step according to an embodiment. [Figure 10] It is a block diagram of a server according to an embodiment.

Modes for Carrying Out the Invention

[0025] The advantages, features, and the method for achieving them of the present invention will become clear by referring to the embodiments described in detail together with the accompanying drawings. However, the present invention is not limited to the embodiments presented below, but can be realized in various different forms, and it should be understood that it includes all conversions, equivalents, and substitutes within the spirit and technical scope of the present invention.

[0026] The terminology used in this application is used solely to describe specific embodiments and is not intended to limit the invention. Singular expressions include plural expressions unless the context clearly indicates otherwise. In this application, terms such as “includes” or “having” are intended to specify the existence of features, figures, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood not to preemptively exclude the existence or possibility of one or more other features or figures, steps, actions, components, parts, or combinations thereof.

[0027] Some embodiments of this disclosure can be represented by functional block configurations and various processing steps. Some or all of such functional blocks may be implemented by various numbers of hardware and / or software configurations that perform a particular function. For example, a functional block of this disclosure may be implemented by one or more microprocessors, or by a circuit configuration for a given function. Furthermore, for example, a functional block of this disclosure may be implemented in various programming or scripting languages. A functional block may be implemented by an algorithm that runs on one or more processors. Furthermore, this disclosure may employ prior art for electronic environment setup, signal processing and / or data processing, etc. Terms such as “mechanism,” “element,” “means,” and “configuration” can be used broadly and are not limited to mechanical and physical configurations.

[0028] Furthermore, the connecting lines or members between components shown in the drawings are merely illustrative examples of functional and / or physical or circuit connections. In actual devices, connections between components may be indicated by a variety of alternative or added functional, physical, or circuit connections.

[0029] The actions performed by the user below can refer to actions performed by the user via the user terminal. For example, a command corresponding to an operation performed by the user can be entered into the user terminal via an input device embedded in or additionally connected to the user terminal (e.g., a keyboard, mouse, etc.). Alternatively, a command corresponding to an operation performed by the user can be entered into the user terminal via the user terminal's touchscreen. In this case, the user's operation can include a predetermined gesture. For example, gestures can include tapping, touching and holding, double-tapping, dragging, panning, flicking, and drag-and-dropping.

[0030] The present disclosure will be described in detail below with reference to the attached drawings.

[0031] Figure 1 is a system diagram of a database construction method for complying with cybersecurity regulations according to one embodiment of the present invention.

[0032] A system according to one embodiment may include an operation server 110, an operator terminal 111, and a user terminal 120.

[0033] According to one embodiment, the operational server 110 is a server that provides a method for constructing a database to comply with cybersecurity regulations. The operational server 110 is controlled by the operator terminal 111 and can provide an interface to the user terminal 120 and process data.

[0034] Furthermore, the operator terminal 111 is the terminal of the operator who manages the operation server 110, and it is a terminal that allows the operator to access the operation server 110 and perform overall system configuration and management. The user terminal 120 is a terminal that allows the user to input and manage cybersecurity data via the user interface provided by the operation server 110. In this case, the user may be a cybersecurity officer of an automobile manufacturer (OEM) or a controller / parts manufacturer (Tier), and there may be one or more officers. The operator terminal 111 and the user terminal 120 may include input / output devices for data input and output.

[0035] An operational server 110 according to one embodiment, although not shown in Figure 1, may include a processor and a database (hereinafter referred to as DB). Below, through a description of the operational server 110, a database construction method that can efficiently respond to cybersecurity regulations for compliance with the present invention will be explained.

[0036] According to one embodiment, the processor of the operational server 110 can provide a pre-configuration step and an individual engineering step for compliance with cybersecurity regulations. The pre-configuration step of the present invention is a process in which information related to pre-configured items among cybersecurity items is configured as a database at the automobile manufacturer (OEM) level, prior to individual engineering steps related to individual vehicles or projects. More specifically, the pre-configuration step can store data on pre-set pre-configured items, user-entered pre-configuration items, and item-specific attributes of pre-configured items in the DB. Furthermore, the pre-configuration step can automatically design and generate relationships between pre-configured items based on user input.

[0037] The pre-configuration step is not merely for data organization; its primary purpose is to centrally manage and establish a reusable library of OEM's standard cybersecurity assets. This allows all subsequent engineering work across different vehicle projects to begin from a common foundation with consistency and conformance, standardizing the cybersecurity approach across the organization.

[0038] Furthermore, in the pre-configuration step, the processor of the operation server 110 can provide a first interface to the user terminal 120. The first interface can provide or display pre-configured pre-configuration items and item-specific attributes, allow the user to add pre-configuration items or item-specific attributes based on user input, and provide an environment for establishing relationships between pre-configuration items based on user input. In this case, even if the user uses the first interface, they cannot change the pre-configured pre-configuration items and item-specific attributes, and only the operator can change the pre-configured pre-configuration items and item-specific attributes.

[0039] Furthermore, in the pre-configuration step, the processor of the operational server 110 can provide a second interface to the user terminal 120. The second interface can provide an environment for inputting datasets for the item-specific attributes of the pre-configuration items included in the first interface.

[0040] Furthermore, in the pre-configuration step, the processor of the operational server 110 can provide a third interface to the user terminal 120. The third interface can provide an environment in which the user can establish a relationship between two pre-configured pairs of pre-configured items through user input. More specifically, in the relationship between pre-configured items established through user input, the pairs of relationships between the inputtable pre-configured items are fixed, and the pre-configured attributes (e.g., item-specific IDs) mapped for the relationship for each item may also be fixed in advance. That is, the user can establish a relationship between pre-configured items in the third interface, but the pairs of pre-configured items for which a relationship can be established can only exist in the standardized form required by the third interface. Details of the first to third interfaces will be explained later with the help of the diagrams.

[0041] Furthermore, the processor of the operational server 110 can provide individual engineering steps. Individual engineering steps are processes that correspond to all individual cybersecurity engineering, such as at the vehicle level, component level, and system level. In connection with this, threat scenarios are generated during the TARA activities at each level to comply with cybersecurity regulations, and the processor of the operational server 110 can acquire the generated threat scenarios. The processor of the operational server 110 can also provide the user terminal 120 with a fourth interface that provides an environment for inputting mapping information between acquired threat scenarios and predefined threats in the individual engineering steps, and a fifth interface that provides an environment for inputting mapping information between security objectives and security controls corresponding to a specific threat scenario among the threat scenarios. Furthermore, in the individual engineering steps, the relationships between pre-configured items and predefined threats or security objectives can be automatically established using user input acquired via the fourth or fifth interface, and the relationships between all cybersecurity items, including pre-configured items, can be automatically established.

[0042] On the other hand, the operational server 110 may include one or more databases (DBs) for storing and providing the above-mentioned interfaces. The processor can provide one or more interfaces to the user terminal 120 based on the data stored in the DB of the operational server 110. More specifically, the DB may include information on pre-configured items and attributes for each item. According to one embodiment, the DB may include information on security controls (Cyber ​​Security Control, hereafter SC), security requirements (Cyber ​​Security Control Requirement, hereafter CSR), functional verification test cases (Verification Test Case, hereafter V-TC), non-functional verification test cases (Penetration Test Case, hereafter P-TC), predefined threats (Threats defined by regulations, hereafter THR, hereafter THR), and predefined mitigation measures (Mitigation, hereafter MIT, hereafter MIT) as pre-configured pre-configured items. In one embodiment, THR may be UNR 155 Annex 5 Threat and MIT may be UNR 155 Annex 5 Mitigation, but this is just an example, and all threats and mitigation measures defined by regulations, etc., can be the THR and MIT of the present invention. However, the pre-configured items exemplified above are merely illustrative and may be added or modified according to embodiments of the present invention. Furthermore, in addition to the pre-configured items, additional pre-configured items and item-specific attributes may be stored in the DB by user input. Furthermore, the first interface shown in Figures 2 and 3, described later, may be provided to provide pre-configured items and item-specific attributes, or to receive input of data related to pre-configured items. For the sake of brevity in the following specification, pre-configured items may be referred to as configuration items.

[0043] In one embodiment, SC as a component is a safeguard or countermeasure implemented to protect information systems, organizations, assets, and data. Furthermore, CSR is a specific condition or specification that must be met in order to effectively implement security controls. Furthermore, V-TC is a set of conditions and steps designed to verify that a particular function or system is operating as intended. Furthermore, P-TC is a scenario designed to identify security vulnerabilities in a system and evaluate the system from an attacker's perspective. Also, THR is a risk factor as defined by regulations, and may be, for example, a potential risk factor related to automotive cybersecurity as described in Annex 5 of UN Regulation No. 155. Furthermore, MIT is a mitigation measure as defined by regulations, and may be a countermeasure or safeguard against identified cybersecurity threats as shown in Annex 5 of UN Regulation No. 155. However, it goes without saying that the pre-configuration item names and definitions described herein may be changed depending on operator or user input.

[0044] Furthermore, the database of the operational server 110 contains dataset information related to the attributes of each configuration item. The database stores specific dataset information related to the aforementioned attributes of each configuration item, and may include dataset information for one of the following attributes: SC, CSR, V-TC, P-TC, THR, or MIT. In addition, a second interface, as shown in Figure 4, described later, may be provided to receive input datasets for the aforementioned attributes of each configuration item.

[0045] Furthermore, the DB of the operational server 110 contains information about the relationships between preconfigured items. Specifically, "relationships between preconfigured items" can mean the relationships between specific datasets for the attributes of each preconfigured item. In this case, the relationships between preconfigured items stored in the DB can be defined as relationships between specific datasets of a pair of two preconfigured items (a first preconfigured item and a second preconfigured item). In this case, the relationship "specific dataset of the first preconfigured item: specific dataset of the second preconfigured item" may be mapped to 1:1, 1:N, or N:1. For the sake of clarity, in the following specification, "relationships between specific datasets of a pair of preconfigured items" can be simply referred to as "relationships between preconfigured items." Specifically in one embodiment, the pair of preconfigured items may be any pair of SC and CSR, CSR and V-TC, or THR and P-TC items. Furthermore, a third interface, as shown in Figure 5, described later, may be provided to receive input for the relationships between preconfigured items described above.

[0046] Here, "establishing a relationship" means creating a persistent and traceable link between the unique identifiers (IDs) of two different data objects within the system's database. For example, as shown in Figure 5, the ID of a security control (SC) object is explicitly mapped to the IDs of one or more cybersecurity request (CSR) objects. This mapping ensures that logical dependencies between items are maintained and automatically validated by the system.

[0047] More specifically, the user can establish a relationship between a specific dataset of a first preconfiguration item and a specific dataset of a second preconfiguration item via a third interface. Each preconfiguration item is assigned a unique identifier (ID). The specific value of the identifier, for example "SC-01", is used when mapping the relationship. In this case, the DB can map the ID value corresponding to a specific dataset of the first preconfiguration item to the ID value corresponding to a specific dataset of one or more second preconfiguration items.

[0048] Furthermore, the database (DB) of the operational server 110 can store and manage data related to cybersecurity items of individual engineering steps (individual vehicle level, component level, system level). In this case, the cybersecurity items of individual engineering steps may be threat scenarios (Threat Scenario) or Cyber ​​Security Goals (CSG), and the DB can store the relationships between threat scenarios or CSGs and pre-configured items. More specifically, the DB can store relationship information between threat scenarios acquired in individual cybersecurity engineering steps and THR datasets. Alternatively, the DB may store relationship information between CSGs corresponding to threat scenarios and SC datasets. That is, by storing the relationships between cybersecurity items and pre-configured items in individual engineering steps, the relationship information between all cybersecurity items can be managed. To receive input for the aforementioned relationships between cybersecurity items and pre-configured items in individual engineering steps, the fourth interface in Figure 6 or the fifth interface in Figure 7 may be provided, as described later.

[0049] The operational server 110 of the present invention systematically manages data necessary for compliance with cybersecurity regulations through the interface described above, and can automatically link the data required in individual cybersecurity engineering steps based on the items and relationships defined in the pre-configuration step. The database construction method and system of the present invention will be described in detail below with reference to the drawings.

[0050] Figure 2 shows the first screen of the first interface according to one embodiment of the present invention.

[0051] Referring to Figure 2, the first screen of the first interface may consist of a search area 210 and a table area 220.

[0052] The search area 210 provides functionality to help users find information on desired configuration items. This area includes various search fields such as configuration item name, description, group usage status, and group attributes, allowing users to enter values ​​in these fields to search for items that meet specific criteria. Search operations can also be initialized or executed via the search initialization button and search button on the right. The search initialization button and search button enable list queries for configuration items and support queries against configuration items (in one example shown in Figure 2, SC, CSR, V-TC, P-TC, THR, MIT). According to one embodiment of the present invention, pre-configured configuration items may be configured so that they can only be modified by the operator and cannot be modified or deleted by the user. In other embodiments, in addition to pre-configured configuration items, users can also directly add, modify, and delete configuration items.

[0053] Tablespace 220 provides a list of components or overall components queried through search space 210 and corresponding component-specific attribute information in tabular format. Tablespace 220 may include columns for number 221, component name 222, description 223, group usage status 224, and group attributes 225. Each column can provide specific information about the component. For example, component name 222 indicates the name of a cybersecurity component such as SC, CSR, V-TC, P-TC, THR, or MIT. Description 223 provides a detailed description of the component, and group usage status 224 indicates whether the component is used as part of a group. Group attributes 225 displays the attributes of the group.

[0054] Furthermore, each row in the tablespace 220 includes a button that displays individual component information or allows additional operations to be performed on individual component. A component attribute button 226 may display a page for managing the detailed attributes of the component, and a group button 227 may display a page for grouping the component. Specifically, in one embodiment, clicking the component attribute button 226 may display a component-specific attribute management page (or popup). Clicking the group button 227 may display a component-specific group settings popup, supporting the user in performing detailed management and configuration of each component. In other words, through the first screen of the first interface according to one embodiment, the user can efficiently manage and query pre-configured component-specific attributes.

[0055] Figure 3 shows an example of the second screen of the first interface according to one embodiment of the present invention.

[0056] According to one embodiment, the second screen of the first interface is the screen displayed when the configuration item attribute button 226 is selected on the first screen in Figure 2, and is an interface that allows the user to query and input each pre-configuration item attribute. Through the second screen of the first interface, the user can query, add, modify, delete, and manage the history of pre-configuration item attributes.

[0057] Referring to Figure 3, the second screen of the first interface may consist of a basic information area 310, a search area 320, and a management area 330.

[0058] The basic information area 310 displays the basic information of the configuration item currently to be managed. This area includes the configuration item name and description fields. Referring to the embodiment in Figure 3, the basic information area 310 shows SC, which is a pre-configured item shown on the second screen of the current first interface, and CS Control, which is a description of SC. This allows the user to see that the current interface is handling attribute information related to the SC (Security Control) configuration item.

[0059] The search area 320, which allows you to query attribute lists for each DB configuration item, has the same or similar functionality as the search area 210 in Figure 2, so its explanation is omitted.

[0060] The management area 330 is an area that provides a tabular list of attributes of pre-configured items queried through the search area 320 and provides management functions for each attribute. This area includes a data export button 331, a registration button 332, a bulk registration button 333, and a delete button 334. Clicking the data export button 331 downloads the configuration item-attribute list file, clicking the registration button 332 displays a popup for registering attributes by configuration item, allowing the user to add new attributes, clicking the bulk registration button 333 displays a popup for bulk registration of attributes by configuration item, allowing the user to register multiple attributes at once, and after selecting one or more attributes to delete using the checkbox 336, clicking the delete button 334 displays a confirmation popup for deleting attributes by configuration item, allowing the user to delete the selected attributes.

[0061] Furthermore, each column in Table 335 of Management Area 330 includes fields such as the attribute number, attribute name, data input type, description, registrant name, and registration date and time, with each row providing specific information about the fields of that attribute. Specifically, the attribute name field is the name of the attribute, the data input type field is the data type entered into the attribute, such as input (INPUT) or selection (SELECT), the description field is a description of the attribute, the registrant name field is the name of the operator or user who registered the attribute, and the registration date and time represents the time the attribute was registered. For example, an attribute with the attribute name SC_ID337 indicates a unique identifier, which is a required attribute among the attributes of the pre-configured item SC, and its data input type may be input (INPUT), the registrant may be Admin, and the registration date and time may be 2025-03-20 13:00:30. The aforementioned attributes may be used as field values ​​in the tables of the second to fourth interfaces described later.

[0062] On the other hand, each row in Table 335 includes a Modify button 338 and a Change History button 339. In one embodiment, clicking the Modify button 338 displays a popup (or page) for modifying the attribute by component, allowing the user to change the information of that attribute. Clicking the Change History button 339 displays a popup (or page) for the change history of the attribute by component, allowing the user to check the change history of that attribute. In other words, the first interface provides an environment in which an operator or user can query and modify the attributes of pre-configured components, and can also query the change history of modifications made at that time. In this case, only operators can modify the attributes of pre-configured components, while users can only query them.

[0063] More specifically, some of the attributes of the pre-configured items are pre-set attributes, while some may be attributes registered by the user. In the embodiment shown in Figure 3, the pre-set attributes of the SC item may be one or more of the following: SC_ID (Security Control ID), CS_Control (Security Control Name), and SC Description (Security Control Description). In addition, user-registered attributes that are not pre-set may be SC_COL1, SC_COL2, and SC_COL3. As mentioned above, pre-set attributes cannot be deleted or modified by the user, and may only be viewable.

[0064] In yet another embodiment, if the configuration item to be queried in the first interface is a CSR (Cyber ​​Security Requirement) (i.e., the pre-configured item shown in the basic information area 310 is "CSR"), the pre-configured attributes of the CSR item may be one or more of the following: CSR ID (Cyber ​​Security Requirement ID) and CSR Description (Cyber ​​Security Requirement Description).

[0065] In yet another embodiment, if the configuration item to be queried in the first interface is a V-TC (Verification TestCase), the pre-configured attributes of the V-TC item may be one or more of the following: V-TC ID (Verification TestCase ID), V-TC Description (Verification TestCase Description), V-TC Precondition (Verification TestCase Precondition), V-TC Test Input (Verification TestCase Test Input), V-TC Test Step (Verification TestCase Test Step), V-TC Expected Result (Verification TestCase Expected Result), V-TC Test Result (Verification TestCase Test Result), and V-TC Test Evidence (Verification TestCase Test Evidence).

[0066] In yet another embodiment, if the configuration item to be queried in the first interface is a P-TC (Penetration TestCase, non-functional test case), the pre-configured attributes of the P-TC item are: P-TC ID (Penetration TestCase ID, non-functional test case ID), P-TC Test Method (Penetration TestCase Test Method, non-functional test case test method), P-TC Description (Penetration TestCase Description, non-functional test case description), P-TC Precondition (Penetration TestCase Precondition, non-functional test case precondition), P-TC Test Input (Penetration TestCase Test Input, non-functional test case test input), P-TC Test Step (Penetration TestCase Test Step, non-functional test case test procedure), P-TC Expected Result (Penetration TestCase Expected Result, non-functional test case expected result), P-TC Test Result (Penetration TestCase Test Result, non-functional test case test result), and P-TC Test Evidence (Penetration TestCase Test Evidence, or an accumulation of non-functional test case tests) may be one or more of the following:

[0067] In yet another embodiment, if the configuration item to be queried by the first interface is a THR (Threat, a predefined threat), the pre-configured attributes of the THR item may be one or more of the following: THR ID (Threat ID, a predefined threat ID) and THR Description (Threat Description, a predefined threat description).

[0068] In yet another embodiment, if the configuration item to be queried in the first interface is an MIT (Mitigation, a predefined mitigation measure), the pre-configured attributes of the MIT item may be one or more of the following: MIT ID (Mitigation ID, a predefined mitigation measure ID) and MIT Description (Mitigation Description, a predefined mitigation measure description).

[0069] Furthermore, the attributes of the preconfigured items described above can be used as field values ​​in the second to fourth interfaces described later. In addition, the attributes of the preconfigured items may always include an identifier (ID) for each preconfigured item. For example, in the embodiment of Figure 3, the preconfigured item SC may always include SC_ID as an attribute. This identifier is an attribute used to distinguish a particular dataset from other datasets and can be a unique value that serves as a reference when establishing relationships between datasets.

[0070] Next, the processor can provide a second interface into which a dataset of attributes of pre-configured items included in the first interface can be input. Here, the dataset is a collection of data corresponding to the attributes of the pre-configured items, and may be the data corresponding to each row in Table 420 of Figure 4, which will be described later.

[0071] Figure 4 shows a second interface for dataset input to pre-configured item attributes according to one embodiment of the present invention.

[0072] Referring to Figure 4, the second interface can consist of a configuration item tab 411, data management buttons 412, 413, 414, 415, 416, and 417, and a work status display area 419 at the top, and a table 420 at the bottom where a dataset can be entered and edited.

[0073] The configuration tab 411 at the top provides a tab that allows the user to select the cybersecurity configuration item they are working on, and also allows for a visual display of the cybersecurity configuration item currently being worked on. Referring to Figure 4, the configuration tab 411 allows switching between the pre-configured items displayed among the SC, CSR, V-TC, P-TC, THR, and MIT pre-configured items. In other words, the configuration tab 411 is an interface that enables exploration for configuration item-specific dataset settings.

[0074] Furthermore, in one embodiment shown in Figure 4, the data management button is a button that performs a function to support the management of the dataset when selected. More specifically, the file export button 412 performs a function to export the dataset data of the configuration item when selected, and clicking this button allows the user to download the dataset of the configuration item stored in the DB as a file. The file import button 413 performs a function to upload and import the dataset file of the configuration item from the user terminal for the configuration item, and clicking this button displays a file explorer where the user terminal 120 can select the file to import. Specifically in this embodiment, the downloaded or uploaded file may be an Excel file.

[0075] The template download button 414 allows downloading a template file that provides a pre-configured form for importing a dataset file of configuration items. The row add button 415 provides the function of adding a new row (new dataset) to the dataset table 420, and can add a row below the current cursor position. The row copy button 416 can provide the function of copying the row at the current cursor position as is and generating it below when selected. The row delete button 417 can provide the function of deleting the row at the current cursor position. In another embodiment, the current cursor position may be changed to a position specified by the user or to another pre-configured position.

[0076] The work status display area 419 shows the work status for the current dataset. For example, if you add, copy, or delete rows and change the data in each cell, it will display as "Work in Progress," and it provides a function to temporarily save the changes to the current dataset when moving between datasets during operations.

[0077] Table 420 at the bottom is the main area for inputting and editing the actual datasets for each component attribute. In the embodiment shown in Figure 4, each row in Table 420 contains the SC dataset, and each column in Table 420 contains the fields SC ID, CS Control, SC COL 1, SC COL 2, and SC COL 3, with each field potentially corresponding to the attribute of the component. In the embodiment shown in Figure 4, the pre-configured dataset fields (component attributes) may be SC ID and CS Control, and the user-registered dataset fields may be SC COL 1, SC COL 2, and SC COL 3, but are not limited to these, and each field name can be transformed into various forms. The user can modify the value by selecting the data cell they want to change (for example, by double-clicking). In this way, the user can input and manage datasets for the attributes of pre-configured components via the second interface.

[0078] According to one embodiment, the processor can provide a third interface for establishing relationships between specific datasets for the attributes of configuration items. The third interface is an interface that can input a specific dataset of a first preconfiguration item and a specific dataset of a second preconfiguration item in a concatenated manner. Furthermore, the processor can use the values ​​obtained through the third interface to establish relationships between the specific dataset of the first preconfiguration item and the specific dataset of the second preconfiguration item. That is, the third interface is an interface that can establish relationships between two pre-configured preconfiguration items from among multiple preconfiguration items in the preconfiguration step. The processor can use the values ​​obtained through the third interface to store preconfiguration relationships between datasets of preconfiguration items stored in the DB.

[0079] Figure 5 shows a third interface for establishing relationships between datasets of pre-configured items according to one embodiment of the present invention.

[0080] Referring to Figure 5, the third interface may consist of a component relationship tab 511 and data management buttons 512, 513, and 514 at the top, and a table 520 at the bottom for establishing relationships with datasets. The component relationship tab 511 at the top allows the user to select a pair of component items for which they wish to establish a relationship. According to one embodiment, pre-configured component item pairs for which a relationship can be established using the third interface may be SC and CSR, V-TC and CSR, THR and P-TC, and THR and MIT, and such pre-configured component item pairs may be displayed in the relationship tab 511 as shown in Figure 5. That is, the third interface provides the relationship tab 511 so that the user can select and establish a relationship between two specific pre-configured items. In this case, the component item pairs for relationship establishment may be pre-established pairs that cannot be modified by the user, and can only be added, deleted, or modified by the operator. The embodiment in Figure 5 illustrates the case where the pair SC and CSR is selected in the relationship tab 511 as an example.

[0081] The data management buttons 512, 513, and 514 are buttons for supporting the management of relational datasets. When a user clicks the Add Row button 512, a new row is added below the current cursor position, allowing the user to add relational datasets between configuration items. If the cursor is not currently located, a row is added below the last row. Clicking the Copy Row button 513 allows the user to duplicate an existing dataset by copying the row at the current cursor position and adding it below. The Delete Row button 514 places the current cursor position on the dataset row to be deleted, and clicking it deletes that dataset row. In another embodiment, the current cursor position may be changed to a position specified by the user or to another pre-configured position.

[0082] Table 520 at the bottom is configured to allow linked input of a specific dataset of a first preconfiguration item and a specific dataset of a second preconfiguration item. In the embodiment of Figure 5, Table 520 illustrates the establishment of a relationship between SC and CSR, with each column containing the fields SC_CSR_ID, SC ID, CS Control Name, Description, CSR ID, and Description, and each row containing a specific dataset. Specifically in the embodiment, the third interface can map an ID value corresponding to a specific dataset of a first preconfiguration item, e.g., SC_01(515), to an ID value corresponding to a specific dataset of one or more second preconfiguration items, e.g., CSR-01(516). Alternatively, the third interface can map an ID value corresponding to a specific dataset of a second preconfiguration item to an ID value corresponding to a specific dataset of one or more first preconfiguration items.

[0083] Furthermore, the user can configure the system to automatically populate the remaining attribute values ​​by selecting the ID value of the first or second preconfiguration item from the provided list. As shown in Figure 5, the third interface can provide a dropdown menu for selecting the ID field of the first or second preconfiguration item (e.g., CSR ID, SC ID), providing an interface that allows selection from already entered configuration item IDs. In this case, the dropdown menu displayed in the ID field of the first or second preconfiguration item may be based on the dataset obtained using the second interface described above. In other words, the third interface can prevent incorrect input of configuration item IDs by providing an interface that allows selection only from the ID values ​​of preconfiguration items stored in the DB.

[0084] As described above, the processor of the operational server 110 can provide first to third interfaces as a pre-configuration step. In the pre-configuration step, pre-configuration items for compliance with cybersecurity regulations are configured, and relationships between pre-configuration items (in one embodiment, SC<=>CSR, V-TC<=>CSR, THR<=>P-TC, THR<=>MIT) may be set. At this time, the relationship pairs of inputtable pre-configuration items are fixed in advance, and the user can input the dataset relationships of the pre-configured pairs of configuration items.

[0085] On the other hand, the processor of the operational server 110 can provide the fourth and fifth interfaces, described later, as individual engineering steps. In the individual engineering steps, relationships between threat scenarios or security objectives not set in the pre-configuration steps described above and pre-configured items are automatically established based on user input, thereby automatically establishing relationships between all cybersecurity items.

[0086] More specifically, individual engineering steps can generate one or more Threat Scenarios (TS) after performing TARA at the vehicle level, component level, and system level. The processor of the operational server 110 can either retrieve the generated threat scenarios and provide a fourth interface that can establish relationships between the threat scenarios and predefined threats, or provide a fifth interface that can establish relationships between security objectives (Cyber ​​Security Goals, CSGs) corresponding to specific threat scenarios and security controls.

[0087] Specifically, the third interface is an interface that establishes relationships between pre-configured items in the pre-configuration step, and the fourth or fifth interface is an interface that establishes relationships between the TS or CSG and the pre-configured items in the individual engineering step. In this case, the fourth or fifth interface is controlled to allow only data input in a pre-configured format, thereby preventing the mixing and erroneous input of data according to arbitrary user input.

[0088] As described above, the relationships between SC and CSR, V-TC and CSR, THR and P-TC, and THR and MIT have been established through the pre-configuration step. Therefore, the processor of the operational server 110 can establish the relationships between all cybersecurity items through the process of establishing the relationship between TS and THR, and the relationship between CSG and SC corresponding to a specific TS, through the individual engineering step. The fourth and fifth interfaces of the individual engineering step will be described in more detail below.

[0089] Figure 6 shows a fourth interface for establishing a relationship between a threat scenario and a predefined threat according to one embodiment of the present invention.

[0090] Referring to Figure 6, a fourth interface is shown that can establish a relationship between a threat scenario (TS) and a predefined threat (THR). In one embodiment, the fourth interface provides an environment for establishing a relationship between TS and THR datasets and provides a region in which one or more of the THR dataset lists can be selected so that they can be mapped to selected datasets of TS. Specifically, referring to Figure 6, an interface may be provided in which one or more of the THR dataset lists can be selected so that they are mapped to selected datasets of TS items.

[0091] More specifically, the fourth interface shown in Figure 6 may consist of a component relationship tab 610 at the top, a row modification area 620, and TS and THR list tables 630. The component relationship tab 610 at the top can display the currently configured component pairs, TS and THR.

[0092] The row editing area 620 also includes row add, row copy, and row delete buttons. The row add button provides the function of adding a new row (new dataset) to table 630, and can add a row below the current cursor position. The row copy button can provide the function of copying the row at the current cursor position and generating it below when selected. The row delete button can provide the function of deleting the row at the current cursor position.

[0093] In one embodiment, the user can configure one or more predefined threat datasets that are mapped to a specific dataset of a threat scenario via a fourth interface. Specifically, the fourth interface provides a TS and THR list table 630, which includes a THR mapping field 633 that provides a predefined list of threats (for example, a list displayed by threat number) that can be mapped to a dataset of a threat scenario. The user can configure the THR mapped to the TS by clicking a dropdown button 634.

[0094] More specifically, the TS and THR list table 630 contains data for establishing the relationships between TS and THR pairs. Table 630 displays information about one or more threat scenarios, each threat scenario may include a unique identifier, the Threat Scenario (TS) ID field 631, and a detailed Threat Scenario (TS description) field 632. For example, Table 630 may display a threat scenario ID "CVTELE_THREAT_2" in which the "Integrity" of "Gathering startup information" is compromised, with Asset ID "Asset_2". Table 630 can also further provide the number, asset and asset ID (the asset to be protected and its unique identifier), security property (security attributes that the asset must satisfy, e.g., confidentiality, integrity, authenticity), damage scenario ID and damage scenario (the specific damage that may occur when the security attribute is compromised and its identifier), STRIDE (a security model for classifying threat types), and threat (THR) mapping field 633.

[0095] The THR mapping field 633 in the THR list table 630 is a field that provides a list of datasets for THR items, and the user can select the THR list to be mapped to the TS by selecting a checkbox displayed in the dropdown menu 635 of the THR dataset list. For example, if the user selects the dropdown button 634 located in the THR mapping field 633 of the "CVTELE_THREAT_2" row, a list of predefined threat numbers that can be mapped (e.g., "6.2", "6.3", "7.1", "7.2", "8.1", "8.2", etc.) will be displayed in the form of a dropdown menu 635. The user can select one or more numbers (e.g., "7.1", "7.2", and "8.1") related to a threat scenario from this list using checkboxes or other means. The predefined threat datasets corresponding to the numbers selected by the user in this way may be mapped and set in the dataset of the threat scenario ("CVTELE_THREAT_2").

[0096] On the other hand, the predefined list of threat numbers provided via the THR mapping field 633 may be determined based on values ​​obtained using the second interface in the pre-configuration step. That is, the THR list set in the pre-configuration step may be provided as a drop-down menu 635. This allows the fourth interface to retrieve the saved THR list and provide a THR list table 630 in a selectable form, and obtain formatted input using a controlled input scheme that maps the selected items to TS. This fourth interface allows the user to link the threat scenario dataset and the THR item dataset to establish their relationship.

[0097] Figure 7 shows a fifth interface for establishing a relationship between security objectives and security controls according to one embodiment of the present invention.

[0098] Referring to Figure 7, a fifth interface is shown that can establish a relationship between security objectives (CSGs) and security controls (SCs). In one embodiment, the fifth interface provides an environment for establishing a relationship between datasets between CSGs and SCs, and provides a region in which one or more dataset lists of SCs can be selected to map to selected datasets of CSGs. Specifically, referring to Figure 7, a table 730 may be provided, along with a table 720 providing a list of CSGs, in which one or more dataset lists of SC items can be selected to map to specific datasets of CSG items.

[0099] The component relationship tab 710 at the top can display the currently configured component pair, SC and CSG.

[0100] Table 720 of the CSG contains data for establishing the relationship between CSGs and SCs. This table includes CSG_ID, Asset ID, Asset, Impact rating result, Attack feasibility rating, Risk Value, Security Goal 721, and Security Control Mapping 722 fields as attribute fields for the CSG in each column, and each row of the table contains detailed information about the field as a CSG dataset. In particular, the Security Control Mapping 722 field is located next to the SG 721 field, and the SC to be mapped to the CSG can be set by clicking the Security Goal setting button 723. When the setting button 723 is clicked, a screen appears in a certain area where the user can select one or more of the SC list table 730 for SC mapping, i.e., the SC dataset list, and directly select the SC.

[0101] The SC list table 730 provides a list of datasets for SC items entered in the second interface, allowing the user to select the SC list to be mapped to the CSG by selecting the checkbox 731 for the SC dataset list. According to the embodiment in Figure 7, the SC list table 730 provides information regarding the SC_ID, CS control name, and SC description fields as the SC dataset list, allowing the user to view this information and select the SC to map to the CSG via the checkbox 731.

[0102] For example, in the embodiment shown in Figure 7, when the user selects the setting button 723 for a security objective with CSG ID "CSG_02", the SC list table 730 in Figure 7 is displayed, and the user can select the checkboxes 731 to select SCs with IDs SC_01, SC_05, and SC_07 and map those SCs to CSG_02. The SC list mapped to the selected CSG may be displayed at the top of the table 730 as mapped security control IDs. That is, the fifth interface provides the SC list table 730 in a form that allows the user to call up and select a stored SC list and obtain standardized input using a controlled input method that maps the selected items to CSGs. This fifth interface allows the user to link a dataset of CSG items with a dataset of SC items and establish their relationship.

[0103] As described above, the processor of the operational server 110 can establish the relationships between TS and THR, and between CSG and SC, using user input obtained via the fourth or fifth interface in the individual engineering step. This allows the processor of the operational server 110 to establish relationships between the overall cybersecurity items (SC, CSR, V-TC, P-TC, THR, MIT, TS, CSG) using the relationship information between SC<=>CSR, V-TC<=>CSR, THR<=>P-TC, and THR<=>MIT described in the pre-configuration step, and the relationships between TS<=>THR and CSG<=>SC set in the individual engineering step.

[0104] Figure 8 is a flowchart illustrating the operation of the operational server and user terminal during the pre-configuration step in one embodiment.

[0105] Referring to Figure 8, initially, at 801, the operational server 110 provides a first interface to one or more pre-configured items.

[0106] Next, in 802, the operation server 110 provides a second interface into which a dataset of attributes of pre-configured items included in the first interface can be input. Then, in 803, the operation server 110 retrieves the dataset input from the user terminal 120 using the second interface.

[0107] Next, in step 804, the operation server 110 provides a third interface that can establish a relationship between two pre-configured pre-configuration items from among several pre-configuration items. Also, in step 805, the operation server 110 obtains the relationship between pre-configuration items entered from the user terminal 120 using the third interface.

[0108] Next, at 806, the operational server 110 establishes the relationship between the first and second preconfiguration items using the values ​​obtained via the third interface.

[0109] Figure 9 is a flowchart illustrating the operation of the operational server and user terminal in individual engineering steps according to one embodiment.

[0110] First, on port 901, the operational server 110 acquires the threat scenario.

[0111] Next, in step 902, the operational server 110 provides a fourth interface that can establish a relationship between the acquired threat scenario and a predefined threat. Furthermore, in step 903, the operational server 110 obtains the relationship between the threat scenario and the predefined threat from the user terminal 120 using the fourth interface.

[0112] Next, in 904, the operational server 110 uses the values ​​obtained via the fourth interface to configure one or more predefined threat datasets that are linked to a specific dataset of threat scenarios.

[0113] Next, in step 905, the operational server 110 retrieves security objectives corresponding to a specific threat scenario among the threat scenarios.

[0114] Next, in step 906, the operational server 110 provides a fifth interface that can establish the relationship between the acquired security objectives and security controls. Also, in step 907, the operational server 110 obtains the relationship between the security objectives and security controls from the user terminal 120 using the fifth interface.

[0115] Next, in 908, the operational server 110 uses the values ​​obtained via the fifth interface to configure one or more specific datasets of security controls connected to a specific dataset of security objectives.

[0116] According to one embodiment, the complex relationships between multiple cybersecurity items can be efficiently and systematically defined and managed through the interface provided by the present invention. Specifically, because the present invention includes a pre-configuration step, the generation of relationships for each pre-configured item, which was previously done manually, is automated, improving user efficiency and convenience, and the relationships between all cybersecurity items can be linked in individual engineering steps. Furthermore, with respect to complex and numerous data, the present invention identifies the data registration order, the items to be entered for each step, the structure, etc., and enables registration and management according to the data management standard intended by the present invention. In addition, the user input structure and order can be controlled, and various validity checks (e.g., duplicate checks, similarity-based checks, NULL checks, etc.) can be automatically performed in the backend after user input and before moving to the next step.

[0117] Figure 10 is a block diagram of a server according to one embodiment.

[0118] In one embodiment, the server 1100 in Figure 10 may be the operational server 110 in Figure 1.

[0119] Referring to Figure 10, the server 1100 may include a communication unit 1110, a processor 1120, and a DB 1130. Only components relevant to the embodiment are shown in the server 1100 in Figure 10. Therefore, a person of the art will understand that other general components may be included in addition to the components shown in Figure 10.

[0120] The communication unit 1110 may include one or more components that enable wired / wireless communication with other nodes. For example, the communication unit 1110 may include one or more of the following: a short-range communication unit (not shown), a mobile communication unit (not shown), and a broadcast receiving unit (not shown).

[0121] DB1130 is hardware that stores various types of data processed within server 1100, and can store programs for processing and controlling processor 1120. DB1130 can store payment information, user information, and the like.

[0122] The DB1130 can include RAM (random access memory) such as DRAM (dynamic random access memory) and SRAM (static random access memory), ROM (read-only memory), EEPROM (electrically erasable programmable read-only memory), CD-ROM, Blu-ray or other optical disc storage, HDD (hard disk drive), SSD (solid state drive), or flash memory.

[0123] The processor 1120 controls the overall operation of the server 1100. For example, the processor 1120 can control the input unit (not shown), display (not shown), communication unit 1110, DB 1130, etc., by executing a program stored in DB 1130. The processor 1120 can control the operation of the server 1100 by executing a program stored in DB 1130. The processor 1120 can control at least some of the operation of the components described above in Figures 1 to 9.

[0124] The processor 1120 can be implemented using one or more of the following: ASIC (application-specific integrated circuits), DSP (digital signal processors), DSPD (digital signal processing devices), PLD (programmable logic devices), FPGA (field programmable gate arrays), controllers, microcontrollers, microprocessors, or other electrical units for performing functions.

[0125] Embodiments of the present invention can be implemented in the form of a computer program that can be executed on a computer via various components, and such a computer program can be recorded on a computer-readable medium. In this case, the medium may include magnetic media such as hard disks, floppy disks, and magnetic tapes; optical recording media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; and hardware devices such as ROMs, RAMs, and flash memory that are specially configured to store and execute program instructions.

[0126] On the other hand, the computer program may be specifically designed and configured for the present invention, or it may be publicly known and available to those skilled in the art of computer software. Examples of computer programs may include not only machine code, such as that produced by a compiler, but also high-level language code that can be executed by a computer using an interpreter or the like.

[0127] According to one embodiment, the methods according to various embodiments of the present disclosure may be provided in a computer program product. The computer program product may be traded as a commodity between a seller and a buyer. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or online (e.g., download or upload) via an application store (e.g., Play Store™) or directly between two user devices. In the case of online distribution, at least a portion of the computer program product may be at least temporarily stored or temporarily generated on a device-readable storage medium such as the memory of the manufacturer's server, the application store's server, or an intermediary server.

Claims

1. As a method for building a database to comply with cybersecurity regulations, A step of displaying a first interface for one or more pre-configured items related to cybersecurity, The steps include providing a second interface that can input a dataset for the attributes of pre-configured items included in the first interface, The step of providing a third interface that can establish a relationship between two pre-configured pre-configuration items from among a plurality of pre-configuration items, The steps include: establishing a relationship between a specific dataset of a first preconfiguration item and a specific dataset of a second preconfiguration item among the plurality of preconfiguration items using the values ​​obtained through the third interface; A method for building a database to comply with cybersecurity regulations, including those mentioned above.

2. After the step of establishing the relationships between the aforementioned datasets, Steps to obtain threat scenarios, A step of providing a fourth interface that can establish a relationship between acquired threat scenarios and predefined threats, The method according to claim 1, further comprising the step of using values ​​obtained via the fourth interface to configure one or more specific datasets of predefined threats that are mapped to specific datasets of the threat scenario.

3. After the step of establishing the relationships between the aforementioned datasets, Among the aforementioned threat scenarios, the step of obtaining security objectives corresponding to a specific threat scenario, The steps include providing a fifth interface that can establish a relationship between the acquired security objective and the security control, The method according to claim 2, further comprising the step of using values ​​obtained via the fifth interface to configure one or more specific datasets of security controls connected to specific datasets of security objectives.

4. The method according to claim 2, wherein the fourth interface provides a list of predefined threats that can be mapped to a dataset of threat scenarios, and maps a dataset of predefined threats corresponding to a user selection from the list to a specific dataset of threat scenarios.

5. The method according to claim 3, wherein the fifth interface provides a list of security control datasets that can be mapped to a specific dataset of the security objective, and maps a dataset corresponding to a user selection from the security control dataset list to a specific dataset of the security objective.

6. The method according to claim 5, wherein the predefined threat dataset list or the security control dataset list is based on values ​​obtained using the second interface.

7. The method according to claim 5, wherein a specific dataset of one or more pre-configured pre-set items is linked to a specific dataset of the threat scenario or the security objective.

8. The method according to claim 1, wherein one or more preconfigured items on the first interface can be changed by operator input.

9. The method according to claim 1, wherein the first interface provides an interface for adding pre-configured items or item-specific attributes by user input, in addition to pre-configured pre-configured items or item-specific attributes, and the first interface provides change history information regarding the attributes of the pre-configured pre-configured items.

10. The method according to claim 1, wherein the dataset input by the second interface includes the value of an identifier field among the attributes of the preconfigured item that uniquely distinguishes individual datasets.

11. The method according to claim 1, wherein the step of providing the third interface is to provide an interface that can input a specific dataset of the first preconfiguration item and a specific dataset of the second preconfiguration item in a concatenated manner.

12. The method according to claim 1, wherein the third interface includes the step of mapping an ID value corresponding to a specific dataset of the first preconfiguration item to an ID value corresponding to a specific dataset of one or more second preconfiguration items, or mapping an ID value corresponding to a specific dataset of a second preconfiguration item to an ID value corresponding to a specific dataset of one or more first preconfiguration items.

13. The method according to claim 1, wherein the third interface is an interface that can establish a relationship between two pre-configured pre-configuration items from among a plurality of pre-configuration items.

14. The method according to claim 1, wherein the first and second pre-configured

15. As a database construction system for complying with cybersecurity regulations, It displays a first interface for one or more pre-configured items, A second interface is provided that can input a dataset relating to the attributes of the pre-configured items included in the first interface. A third interface is provided that can establish a relationship between two pre-configured pre-configuration items from among a plurality of pre-configuration items. The system is configured to establish a relationship between a specific dataset of a first preconfiguration item and a specific dataset of a second preconfiguration item, using the values ​​obtained through the third interface. A database construction system for complying with cybersecurity regulations.