Information processing program and information processing device
An information processing program and device efficiently generate operation manuals by integrating an information management ledger, process control table, and sequence diagram, addressing inefficiencies in existing methods and ensuring compliance with regulatory changes.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- LOYALTY MARKETING
- Filing Date
- 2024-10-23
- Publication Date
- 2026-05-11
AI Technical Summary
Existing methods for creating operation manuals are inefficient and fail to account for changes in rules, regulations, or operations, particularly in handling sensitive information like personal data, leading to a need for frequent and laborious updates.
An information processing program and device that utilize a generative model to create business manuals by integrating an information management ledger, process control table, and sequence diagram, enabling efficient generation of operation manuals tailored to specific business operations.
Streamlines the creation of operation manuals, ensuring compliance and quality by automating the process and adapting to changes in laws, regulations, and operational updates.
Smart Images

Figure 2026076005000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing program and an information processing apparatus for efficiently creating an operation manual related to information handling.
Background Art
[0002] In operations that handle various types of information, operation procedure manuals and procedure memos are created for each department or operator in charge of the operation. However, when rules or regulations regarding the information being handled are revised or new operations occur, it is necessary to create or update the operation procedure manuals each time, which is time-consuming. Also, it is desirable to efficiently create an operation manual with a certain level of quality so that it can be referred to among different departments and operators. Furthermore, when an operation manual is created, it is necessary to update all operation manuals regularly or at an arbitrary timing in response to changes in compliance matters such as laws, regulations, ordinances, and internal company regulations, or when operations or tasks included in the operations are abolished or added.
[0003] For example, with regard to personal information and the like, legal systems for information protection have been established, and strict management by businesses and organizations is required. Therefore, businesses and organizations are required to perform proper operations based on laws and regulations regarding the acquisition and use of personal information and the like in operations, and in order to achieve this, it is necessary to ensure the quality of work based on the operation manual. Also, regarding the handling of personal information and the like, there is a high possibility that compliance matters will change with changes in the situation. In such cases, it is necessary to appropriately update all operation manuals in response to changes in compliance matters.
[0004] Patent Document 1 describes comparing an old operation flow and a new operation flow that correspond to each other, identifying the corresponding relationships of each of the plurality of tasks that make up the operation flow through the comparison, and transcribing the contents of the tasks included in the old manual to a blank manual template according to the matching status of the corresponding relationships of each task.
[0005] Patent Document 2 describes creating an electronic manual based on the principles outlined in Annex A of ISO 10013, "Guidelines for the Preparation of Quality Manuals." [Prior art documents] [Patent Documents]
[0006] [Patent Document 1] Japanese Patent Publication No. 2021-105797 [Patent Document 2] Japanese Patent Publication No. 2001-306549 [Overview of the project] [Problems that the invention aims to solve]
[0007] In the invention disclosed in Patent Document 1, manuals are created based on the correspondence between tasks included in the business flow by comparing the old and new business flows. Therefore, when creating a new business manual, it is not possible to create the manual efficiently.
[0008] In the invention disclosed in Patent Document 2, in order to create an electronic manual based on international quality assurance standards, it is not possible to effectively create an operational manual based on information other than the quality assurance standards.
[0009] This invention was made in view of the above circumstances, and its purpose is to provide an information processing program and an information processing device for streamlining the creation of business manuals related to information handling. [Means for solving the problem]
[0010] In one embodiment, an information processing program that creates a business manual for a target business selected from a plurality of business operations that handle information to be handled causes a computer to perform the following actions: acquire an information management ledger, a process control table, and a sequence diagram for the target business; input the information management ledger, the process control table, and the sequence diagram into a generation model; and acquire a business manual for the target business generated by the generation model. [Effects of the Invention]
[0011] According to this embodiment, the creation of operational manuals regarding information handling can be streamlined. [Brief explanation of the drawing]
[0012] [Figure 1] Figure 1 is an overview view showing an example of the overall configuration of the manual generation support system according to the embodiment. [Figure 2] Figure 2 is a block diagram showing an example of the functional configuration of the manual generation support device according to this embodiment. [Figure 3] Figure 3 shows an example of the data structure of an information management ledger managed by the manual generation support device according to the embodiment. [Figure 4] Figure 4 shows an example of an information rank evaluation value according to the present invention. [Figure 5] Figure 5 shows an example of the evaluation value for the number of cases according to the embodiment. [Figure 6] Figure 6 shows an example of the evaluation value of a storage location according to the embodiment. [Figure 7] Figure 7 shows an example of an evaluation value for the retention period according to the embodiment. [Figure 8] Figure 8 shows an example of evaluation values for the waste disposal method according to the present invention. [Figure 9] Figure 9 shows an example of the data structure of a process control table managed by the manual generation support device according to the embodiment. [Figure 10]FIG. 10 is a diagram showing an example of a sequence diagram managed by the manual generation support apparatus according to the embodiment. [Figure 11] FIG. 11 is a diagram showing an example of configuration management information managed by the manual generation support apparatus according to the embodiment. [Figure 12] FIG. 12 is a flowchart for explaining an example of the operation of the manual generation support apparatus according to the embodiment. [Figure 13] FIG. 13 is a diagram showing an example of an operation manual created by the manual generation support apparatus according to the embodiment. [Figure 14] [[ID=,12]]FIG. 14 is a diagram showing an example of an operation manual created by the manual generation support apparatus according to the embodiment. [Figure 15] FIG. 15 is a diagram showing an example of an operation manual created by the manual generation support apparatus according to the embodiment. [Figure 16] FIG. 16 is a diagram showing an example of an operation manual created by the manual generation support apparatus according to the embodiment.
BEST MODE FOR CARRYING OUT THE INVENTION
[0013] (Embodiment) Hereinafter, the embodiment will be described with reference to the drawings. In each drawing, the same reference numerals are given to the same components as much as possible, and redundant explanations are omitted.
[0014] (1) Overall Configuration of Manual Generation Support System 1 Figure 1 is an overview view showing an example of the overall configuration of the manual generation support system 1 according to the embodiment. The manual generation support system 1 shown in Figure 1 includes a manual generation support device 2 and user terminals 3-1 to 3-N (where N is a natural number of 2 or more). The manual generation support device 2 and user terminals 3-1 to 3-N are connected to each other freely via a network 4. For example, network 4 is the internet. The network may include a wireless network or a wired network. Note that the manual generation support system 1 may also refer to a system that includes at least two of the manual generation support device 2 and user terminals 3-1 to 3-N. The configuration of multiple user terminals may be the same as that of user terminal 3-1. The configuration of a user terminal will be described as the configuration of user terminal 3-1.
[0015] Manual Generation Support System 1 is a system for creating business manuals related to information handling operations. Handling includes using, utilizing, providing, saving, storing, managing, and updating information. Information handled in operations is referred to as "handled information." Handled information is information handled in one or more operations. Handled information includes, for example, information for which rules regarding handling are stipulated by laws or internal regulations. Handled information includes, for example, personal information that is subject to protection under the Act on the Protection of Personal Information (hereinafter referred to as the Personal Information Protection Act). However, handled information is not limited to the above and may include any information used in operations.
[0016] Business operations are also referred to as operations that handle information subject to handling. Business operations include, for example, operations to provide services to customers. Services include the sale of tangible or intangible goods, and the provision of services. The type of business operator providing services can be any type. For example, a business operator operates at least one store, website, etc. that provides a service. A business operator includes not only the business operator itself but also a group of business operators. A group of business operators is a group that operates stores recognized as a chain. For example, a group of business operators is a group that operates stores using the same name. A group of business operators may also include franchisees in which a business operator is involved as a franchisor. A business operator includes, for example, a personal information handling business operator that handles personal information.
[0017] The term "business operations" includes operations that handle the information subject to handling within an organization. An organization is, for example, a company, corporation, or office. However, the organization is not limited to those mentioned above; it may also be a community that handles the information subject to handling. Business operations may include operations performed by each department within an organization, as well as operations performed between multiple departments. Business operations are also called "handling operations." Business operations include multiple processes. The information subject to handling is information handled by multiple processes.
[0018] An operational manual is a manual that includes the processes, steps, procedures, implementing bodies, compliance requirements, and points to note for carrying out a business. An operational manual is created for each business that handles the information being handled, among multiple business operations for which an operational manual is required. An operational manual may also include the background and objectives for carrying out the business. An operational manual may also include educational elements for the organization and employees. An operational manual may be of a quality that can withstand compliance and audits. For example, an operational manual for operations that handle personal information may include information on laws, regulations, ordinances that must be complied with when handling personal information, and / or risk management in each operation.
[0019] The manual generation support device 2 is a device that collects and processes data. The device includes a computer. The manual generation support device 2 is connected to user terminals 3-1 to 3-N via network 4. The manual generation support device 2 receives various data from user terminals 3-1 to 3-N and outputs various data to user terminals 3-1 to 3-N. The manual generation support device 2 is an example of an information processing device. An example of the configuration of the manual generation support device 2 will be described later.
[0020] User terminal 3-1 is a device capable of communicating with other devices. User terminal 3-1 is a PC (Personal Computer), smartphone, or tablet device, etc. User terminal 3-1 is an example of an information processing terminal. User terminal 3-1 is used by employees, etc., who perform tasks that involve handling information.
[0021] (2) Hardware configuration (2-1) Manual generation support device 2 The manual generation support device 2 comprises a processor 21, memory 22, storage 23, a communication interface (I / F) 24, an input / output interface (I / F) 25, and a bus 26 connecting these. The processor 21 controls the operation of the entire manual generation support device 2. The processor 21 may be a general-purpose processor such as a CPU (Central Processing Unit), MPU (microprocessor unit), or GPU (Graphics Processing Unit), but is not limited to a general-purpose processor and may be a dedicated processor such as an ASIC (Application Specific Integrated Circuit) or FPGA (field-Programmable Gate Array). The memory 22 is the main memory and includes RAM (Random Access Memory), etc. The storage 23 is the auxiliary memory and includes a non-volatile memory such as EEPROM (Registered Trademark) (Electric Erasable Programmable Read-Only Memory), HDD (Hard Disk Drive), or SSD (Solid State Drive). The communication interface 24 is a wired or wireless communication interface and is a module for communicating with devices such as user terminals 3-1 to 3-N via the network 4. The network 4 may include, for example, the internet, and may also include access networks such as LAN (local area network), WAN (wide area network), mobile communication network, wired telephone network, FTTH (fiber to the home), and CATV (community antenna television system) network. The input / output interface 25 takes in input data from an external device and outputs output data to an external device.
[0022] (3) Functional configuration (3-1) Manual generation support device 2 Figure 2 is a block diagram showing an example of the functional configuration of the manual generation support device 2 according to this embodiment. The manual generation support device 2 of this embodiment includes a processing unit 200, a storage unit 210, and a communication control unit 220 as its functional configuration. The communication control unit 220 controls communication with user terminals 3-1 to 3-N via the network 4 according to instructions from the processing unit 200.
[0023] (3-1-1) Storage section 210 The storage unit 210 includes an information management ledger storage unit 211, a process control table storage unit 212, and a sequence diagram storage unit 213. The storage unit 210 may be implemented by storage 23. Here, an example is described in which the manual generation support device 2 includes an information management ledger storage unit 211, a process control table storage unit 212, and a sequence diagram storage unit 213, but each storage unit may be included in a device other than the manual generation support device 2.
[0024] The information management ledger storage unit 211 is a storage unit for centrally storing and maintaining the information management ledger. The information management ledger is a ledger for managing the information to be handled. The information management ledger may be a ledger for managing the information to be handled for each of multiple business operations. The information management ledger may be a ledger for managing the information to be handled for each of multiple processes included in the target business operations. The information management ledger may be similar to the personal information management ledger required for obtaining / operating the Privacy Mark.
[0025] The information handled includes, for example, evaluation values. Evaluation values are values that indicate an evaluation of the information handled. The evaluation of the information handled is, for example, an evaluation of information security. The evaluation of the information handled includes, for example, an evaluation based on at least one of the following: the impact of external leakage, the risk of information leakage, the response method in the event of information leakage, the information management method, and the vulnerability of the information. The evaluation of the information handled includes an evaluation based on multiple evaluation items related to the information handled. The multiple evaluation items include, for example, evaluation items related to information rank, number of items, storage location, retention period, and disposal.
[0026] Information rank indicates multiple levels of information handled. Information rank is assigned to the type of information handled. Information rank is an index that classifies information handled according to considerations or evaluation factors such as importance, impact in the event of external leakage, or need for protection. Information rank is an index that classifies information handled according to handling rules. Information rank may also be an index that classifies information handled based on evaluation values. Information rank may also be an index that ranks multiple types of information contained in the information handled. Information rank is also simply called rank. For example, if the information handled is personal information, the types of information handled include personal ID, name, address, email address, etc. Personal ID is, for example, information that can uniquely identify a member of a service provided by a business operator. The number indicates the number of acquired or held items. The number is the unit for counting information. Evaluation items are not limited to those described above, and may be at least one item that allows the information handled to be evaluated based on predetermined evaluation criteria. Predetermined evaluation criteria may be set as appropriate by the administrator or other person managing the information handled. The information to be handled may be classified according to its information rank in relation to its handling in business operations.
[0027] The information management ledger includes risk values related to the handling of the information being handled. Risk values are values that indicate an assessment of the risks associated with handling the information being handled. For example, risks related to information management. Risks include risks related to information leakage. Risk values are calculated, for example, based on the evaluation value of at least one evaluation item. The information management ledger is information that aggregates information related to the handling of the information being handled.
[0028] The information management ledger will be explained with reference to Figure 3. Figure 3 shows an example of the data structure of the information management ledger managed by the manual generation support device 2 according to this embodiment.
[0029] The following explanation uses an example of a business that handles personal information as the information to be handled. The "target business" refers to a business that is included in multiple business operations that handle personal information and is the subject of the creation of a business manual. Multiple business operations that handle personal information include multiple processes that handle personal information. The business manual is assumed to be a business manual for multiple business operations that handle personal information.
[0030] The information management ledger includes at least the following information: management number, business name, details of the information to be handled, information rank, target processing name, purpose of use, person in charge of management, number of items, storage location, retention period, number of workers handling the information, and disposal method. The information management ledger includes evaluation values based on evaluation items. The information management ledger shown in Figure 3 is an information management ledger for managing personal information. The management number is information that can uniquely identify the business to be handled. The management number may also be information that can uniquely identify the processing to be handled. The business name is information that can uniquely identify the business. Details of the information to be handled include, for example, the type of information to be handled and the information rank. In the example in Figure 3, there are three types of information ranks: X, Y, and Z. The number of types or stages of information ranks is not limited to "3" and may be any number. The case where the information to be handled is personal information will be explained. The information rank may be three types, for example, "raw personal information," "identification information or attribute information," and "hashed information or encrypted information." For example, if the type of information handled is "personal ID," the information rank is "identification information or attribute information." If the type of information handled is "name," the information rank is "raw personal information." If the type of information handled is "hashed information (email address)," the information rank is "hashed information or encrypted information."
[0031] Information ranks are assigned different evaluation values depending on the rank. For example, the evaluation value for information with information rank X is "5". The evaluation value for information with information rank Y is "3". The evaluation value for information with information rank Z is "1". The assignment of information ranks and evaluation values may be set as appropriate by the administrator of the information management ledger, etc. If the information to be handled is personal information, the information to be handled may be classified into, for example, raw personal information, personal-related information, anonymized information, pseudonymized information, etc. Evaluation values will be described later with reference to Figures 4 to 8.
[0032] The target process name is information that uniquely identifies each of the multiple processes included in a business. The target process refers to one of the multiple processes included in the target business. The target process includes multiple work steps. A work step includes multiple tasks. Each of the tasks may be managed as a work component. A work component indicates the content of a task that has been subdivided from a work step. A work component indicates each of the multiple tasks included in a work step. A work component is the smallest unit of work included in a work step. A work component indicates a task that is performed in common across different business processes. A work component may indicate a task that appears in common or repeatedly in multiple sequence diagrams. For example, a work component may indicate tasks such as receiving incoming calls, verifying member information, or recording information. For example, by componentizing tasks, when the same task is performed in multiple different business processes, work steps and work content can be efficiently reflected in process management tables and sequence diagrams. Furthermore, by componentizing tasks, it is possible to strengthen IT control as an IT system or IT tool by softwareizing them into programs, etc.
[0033] The purpose of use indicates the purpose or use of handling the information in the target process. The person responsible for managing the information in the target process indicates the person responsible for managing the information in the target process. The person responsible may be the department or organization that performs the target process. The number of items indicates the number of items of information to be acquired. The number may be the total number of items of information to be acquired, or the number of items acquired during a specified period. The specified period is, for example, one day. The storage location indicates the place where the information to be handled is stored. Storage locations include, for example, servers, clouds, external data centers (DCs), internal servers, cabinets, etc. The retention period indicates the period for which the information to be handled is retained. Retention periods include, for example, permanent, specified number of years or more, less than a specified number of years, less than a specified number of months, immediate deletion, etc. The specified number of years and specified number of months may be set as appropriate by the administrator of the information management ledger, etc. The number of workers handling the information indicates the number of people who work with the information to be handled. The disposal method indicates the method or means of deleting or disposing of the information to be handled. Disposal methods include manual erasure, dissolution, and automatic erasure, etc.
[0034] The information management ledger includes evaluation values for multiple evaluation items such as information rank, number of items, storage location, retention period, number of handling personnel, and disposal method. The information management ledger also includes risk values calculated based on the evaluation values for multiple evaluation items.
[0035] This section explains the evaluation values for multiple evaluation items. Figure 4 shows an example of an information rank evaluation value according to the present invention. Figure 4 shows an example of information rank and evaluation value for personal information. Personal information includes, for example, raw personal information, identification information, attribute information, hashed information, and encrypted information. Raw personal information includes, for example, name, address, telephone number, email address, etc. Identification information is, for example, personal ID, etc. Attribute information includes, for example, gender, age, etc. Information rank may be set according to, for example, the degree to which a specific individual can be identified (identifiable, identifiable by cross-referencing with other information, identifiable, etc.). For example, personal information may have three ranks as information rank: X, Y, and Z. Personal information is assigned different evaluation values according to its information rank. The evaluation value may be set according to, for example, the degree of impact if the information being handled is leaked to the outside. For example, "name" is information with information rank "X" and an evaluation value of "5". The evaluation value for information rank is set according to multiple levels. An information rank is assigned to each type of information being handled. The evaluation value according to the information rank is recorded in the information management ledger. The information management ledger may, for example, count the number of items for each information rank and store the number of information ranks as an evaluation value. For example, the evaluation value for the evaluation item "Information Rank" may be information indicating that there are 3 items of information rank "X", 1 item of information rank "Y", and 2 items of information rank "Z". Alternatively, the information management ledger may count the number of items for each information rank and store the result of multiplying the number of information ranks by the evaluation value for each information rank as the evaluation value for the information rank. For example, the evaluation value is (Number of X ranks × X rank evaluation value) × (Number of Y ranks × Y rank evaluation value) × (Number of Z ranks × Z rank evaluation value). If the X rank evaluation value is "5", the Y rank evaluation value is "3", and the Z rank evaluation value is "1", and the number of X ranks is "3", the number of Y ranks is "1", and the number of Z ranks is "2", the evaluation value is calculated as (3 × 5) × (1 × 3) × (2 × 1). The setting of information ranks and their corresponding evaluation values may be set as appropriate by the administrator, etc. For example, the importance of handling personal information in business operations varies depending on the type of personal information. The manual generation support device 2 can efficiently create business manuals for handling information appropriately according to its rank by using information rank and evaluation value.
[0036] Figure 5 shows an example of an evaluation value for the number of items of information to be handled according to the embodiment. Figure 5 shows an example of the number of personal data records acquired and their evaluation values. The number of acquired records represents the cumulative number or the number of records held. The evaluation value for the number of acquired records is set according to multiple levels. For example, the number of acquired records can be classified into multiple levels, and the basis for determining leakage risk can be set for each level. The evaluation value is set according to the basis for determining leakage risk. In the example in Figure 5, the basis for determining leakage risk is the risk if the information is leaked. For example, if the number of personal data records is 10 million or more, the leakage risk determination is "business crisis," and the evaluation value is set to "5." The evaluation value corresponding to the number of acquired records is recorded in the information management ledger. For example, if the number of acquired records is 900,000, the information management ledger will store "3" as the evaluation value for the evaluation item "number of records." The setting of the number of acquired records and the corresponding evaluation value can be set as appropriate by the administrator, etc.
[0037] Figure 6 shows an example of an evaluation value for the storage location of the information to be handled according to the embodiment. Figure 6 shows an example of personal information storage locations and their evaluation values. The evaluation values for storage locations are set according to multiple levels. For example, a basis for determining leakage risk is set for each storage location. The evaluation value is set according to the basis for determining leakage risk. For example, if the storage location is a third-party server, the leakage risk determination is "cannot be managed or controlled by the company," and the evaluation value is set to "5." The evaluation value corresponding to the storage location is recorded in the information management ledger. For example, if the storage location is a third-party server, the information management ledger will store "5" as the evaluation value for the evaluation item "storage location." The settings for storage locations and their corresponding evaluation values can be set as appropriate by the administrator or other relevant personnel.
[0038] Figure 7 shows an example of an evaluation value for the retention period of the information to be handled according to the embodiment. Figure 7 shows an example of retention periods and evaluation values for personal information. Evaluation values for retention periods are set according to multiple levels. For example, the basis for determining leakage risk is set for each retention period. The evaluation value is set according to the basis for determining leakage risk. For example, if the retention period is indefinite, the leakage risk determination will be "highest information leakage risk," and the evaluation value will be set to "5." The evaluation value corresponding to the retention period is recorded in the information management ledger. For example, if the retention period is 7 years, the information management ledger will store "4" as the evaluation value for the evaluation item "retention period." The retention period and the corresponding evaluation value may be set as appropriate by the administrator, etc.
[0039] Figure 8 shows an example of an evaluation value for the disposal method of the information to be handled according to the embodiment. Figure 8 shows an example of personal information disposal methods and evaluation values. Evaluation values for disposal methods are set according to multiple levels. For example, a basis for determining leakage risk is set for each disposal method. The evaluation value is set according to the basis for determining leakage risk. For example, if the disposal method is manual deletion, the leakage risk determination is "high risk of leakage due to human error or fraud," and the evaluation value is set to "5." The evaluation value according to the disposal method is recorded in the information management ledger. For example, if the disposal method is manual deletion, the information management ledger will store "5" as the evaluation value for the evaluation item "Disposal Method." The disposal methods and the corresponding evaluation values can be set as appropriate by the administrator, etc.
[0040] Furthermore, the evaluation items are not limited to those mentioned above, and may be any items arbitrarily set to evaluate the information being handled.
[0041] Let's return to the explanation of Figure 2. The process control sheet storage unit 212 is a storage unit for centrally storing and maintaining process control sheets. A process control sheet is a list of tasks for each task that handles the information to be handled. The process control sheet includes a management number and a task name. The process control sheet is linked to the information management ledger by its management number. The process control sheet includes information showing the work procedure for each process included in the task that handles the information to be handled. The work procedure is arranged in the order in which the work components are executed. The process control sheet includes text information that expresses the work procedure in text. The process control sheet includes the person in charge of the task, the work location, the work content, the information to be handled, the system used, the frequency of implementation, etc. for each work process. The work content includes the work process. The process control sheet includes information based on the practical knowledge of the person in charge of the task.
[0042] The process control chart will be explained with reference to Figure 9. Figure 9 shows an example of the data structure of a process control table managed by the manual generation support device 2 according to this embodiment.
[0043] The process control sheet includes at least the management number, task name, background, purpose, details for each work process, frequency of implementation, and information to be handled. The background includes an explanation of the background and necessity of the task. The purpose includes an explanation of the purpose and significance of the task. The details for each work process include the person in charge of each work process included in the task, the work location, the work content, the information to be handled, the number of workers involved, the system used, and the frequency of implementation. The person in charge of the task indicates the employee or organization in charge of the task. The organization is, for example, a department or division within an organization. The work location indicates the place where the work is performed. The work location may also be the organization to which the person in charge of the task belongs. The work content indicates the content of the work components, which are subdivisions of the multiple work processes included in the target process. The work content may include an overview of the work components. The work content may indicate the order or procedure of implementation of the work components.
[0044] The information to be handled refers to the information handled in the work process. The information to be handled may also refer to the information handled for each subdivided task. The information to be handled may include multiple types of information. The system used refers, for example, to the information system used in the target business. The system used includes information systems, electronic devices, folders, and directories. The frequency of implementation refers to the timing of implementation, the duration of implementation, or the deadline for implementation. The system used is also simply referred to as the system.
[0045] Figure 9 shows a process management chart for "incident response" operations. The process management chart in Figure 9 includes information indicating the background and objectives of the "incident response" operations. Figure 9 shows a list of tasks related to the "point fraud detection" process included in the "incident response" operations. The process management chart in Figure 9 shows management number "XX01". The process management chart in Figure 9 is linked, for example, to the information management ledger with management number "XX01". The process management chart for management number "XX01" is a process management chart for operations that handle the information to be handled stored in the information management ledger with management number "XX01".
[0046] For example, Process 1 is a task performed by the person in charge, "Company Call Center," at the work location, "Call Center." The work content describes the work performed in response to "an incoming call from a person reporting fraudulent use of points." The work content describes a detailed procedure that breaks down the work performed in response to "an incoming call from a person reporting fraudulent use of points." The information handled indicates the type of information handled for each procedure. The systems used indicate the systems used in Process 1. For example, the systems used may include the dedicated terminal used at the call center and the points system. The systems used may also describe information regarding the exchange of information between the systems used. The exchange between systems includes the acquisition, reception, transfer, transmission, or output of the information. The exchange between systems indicates the flow of the information. The frequency of implementation indicates "each time an incoming call is made." The frequency of implementation may include, for example, the timing of the start of implementation, the time priority, the conditions for completion, etc.
[0047] Let's return to the explanation of Figure 2. The sequence diagram storage unit 213 is a storage unit for centrally storing and maintaining sequence diagrams. The sequence diagram includes the exchange of information between user systems handling the information, work procedures (flows), and handling methods. The sequence diagram is information that shows the coordination between user systems. The sequence diagram may visualize the processing procedures of multiple processes included in a business. The sequence diagram may include elements of IT (information technology) control or IT risk management related to the handling of the information. The sequence diagram may be created based on a process control table. The sequence diagram may also include information security or information management information added to the process control table. The sequence diagram may reflect elements of IT control or IT risk management for each of the multiple processes included in a business that handles the information. The sequence diagram includes a management number and a business name. The sequence diagram is linked to the information management ledger by the management number. The sequence diagram is linked to the process control table by the management number. The sequence diagram may include work processes and information ranks. The work processes indicate the work processes defined in the process control table. The information rank indicates the information rank of the information being handled. The sequence diagram may include the work part number. The work part number is identification information that uniquely identifies the work part. The sequence diagram includes information based on information security knowledge requirements regarding the handling of the information being handled.
[0048] The sequence diagram will be explained with reference to Figure 10. Figure 10 shows an example of the data structure of a sequence diagram managed by the manual generation support device 2 according to this embodiment.
[0049] A sequence diagram includes the work process, information rank, work part number, and processing procedure for the target process included in the target business. The processing procedure is information that shows the interactions between work entities along a timeline. A work entity indicates the entity that handles the target information in the work process. A work entity is also called a worker, object, or entity. The processing procedure includes the processing flow by the work entities. The sequence diagram includes information regarding the handling of target information among work entities.
[0050] In the example in Figure 10, the sequence diagram shows the processing steps related to the point fraud detection process. The sequence diagram in Figure 10 shows management number "XX01". The sequence diagram in Figure 10 is linked, for example, to the information management ledger for management number "XX01". The sequence diagram in Figure 10 is linked, for example, to the process management sheet for management number "XX01". The sequence diagram for management number "XX01" is a sequence diagram related to the operations that handle the information to be handled stored in the information management ledger for management number "XX01".
[0051] For example, Process 1 includes multiple tasks. The first task in Process 1 indicates receiving incoming calls from members at the "Call Center". The first task in Process 1 handles information of information rank "X". The first task in Process 1 is managed as task part number "1". The second task in Process 1 indicates accessing the "Point System" based on member information obtained from members at the "Call Center". The second task in Process 1 handles information of information rank "X". The second task in Process 1 is managed as task part number "2". The sequence diagram may show different task entities depending on the business.
[0052] Let's return to the explanation of Figure 2. The memory unit 210 may store regulatory information. Regulatory information is information that indicates regulations concerning at least one of the target business and the information to be handled. For example, regulatory information indicates regulations based on laws and regulations and at least one of internal regulations concerning the information to be handled in multiple business operations. Regulatory information includes information such as terminology and definitions, operation, auditing, management, and complaint handling methods related to the information to be handled. Regulatory information may also include information such as terminology and definitions, operation, auditing, management, and complaint handling methods related to the target business. For example, regulatory information is personal information protection regulations based on the Personal Information Protection Act. Regulatory information may also include information on relevant laws and regulations. Regulatory information includes, for example, obligations, best efforts, prohibited items, taboo items, mandatory items, and implementation items regarding the handling of the information to be handled. Regulatory information includes information based on knowledge from a compliance and audit perspective.
[0053] The memory unit 210 may store configuration management information. Configuration management information is information that associates multiple components included in the target business. Components include, for example, processes, work steps, and work parts. Components may be numbered for each business. Components may be managed by a header number or outline number, etc.
[0054] Configuration management information will be explained with reference to Figure 11. Figure 11 shows an example of configuration management information managed by the manual generation support device 2 according to this embodiment. Configuration management information is information that associates multiple components based on header numbers, etc. Configuration management information shows the relationships between multiple components included in a business process. For example, let's consider the "incident response" process. The "incident response" process includes multiple processes with header numbers "1-1" to "1-4". The "point fraud detection" process with header number "1-1" includes multiple work steps with header numbers "1-1-1" to "1-1-5". The "point fraud detection" process with header number "1-1" is expanded into the upper left box in Figure 11, for example. Configuration management information is information that visualizes the relationships between multiple components.
[0055] (3-1-2) Processing Unit 200 The processing unit 200 functions as an acquisition unit 201, a generation processing unit 202, a risk assessment unit 203, and an output unit 204, with the processor 21 executing a program stored in the memory 22. The processing unit 200 executes a program for creating a business manual for a target business selected from multiple business operations that handle the information to be handled.
[0056] The acquisition unit 201 acquires information from the storage unit 210. The acquisition unit 201 acquires an information management ledger, a process control table, and a sequence diagram related to the target business. For example, the acquisition unit 201 acquires an information management ledger, a process control table, and a sequence diagram related to the target business based on a user's selection instruction for the target business.
[0057] The generation processing unit 202 performs processing to generate a business manual for the target business. Based on the information management ledger, process control table, and sequence diagram related to the target business, the generation processing unit 202 inputs command statements for generating a business manual for the target business into the generation model. A command statement is, for example, a question statement or prompt that instructs the generation of a business manual for the target business. A command statement includes, for example, information that identifies the target business. A command statement includes, for example, information that identifies information to be referenced or cited. A command statement may also include information that defines the structure or composition of the manual. Information that defines the structure or composition of the manual is also called a manual structure or manual formula. Information that defines the structure or composition of the manual is, for example, information that indicates the format of the business manual. Information that defines the structure or composition of the manual may include multiple manual structures or manual formulas.
[0058] A generative model is a model that generates and outputs information in response to input information. An example of a generative model is a generative AI (Artificial Intelligence) that incorporates a language model. A language model is a model that outputs natural language in response to natural language input, such as ChatGPT (Generative Pretrained Transformer). Language models include transformers such as BERT (Bidirectional Encoder Representations from Transformers) and BART (Bidirectional and Auto-regressive Transformer), as well as language models such as recurrent neural networks (RNNs).
[0059] Generative models include, for example, natural language generation models or natural language processing models. Generative models include general-purpose natural language processing learning models such as Large Language Models (LLMs) that have been trained on vast amounts of data. Generative models may also be language models that have been fine-tuned for generating business manuals. Generative models may also be language models that can handle various tasks without fine-tuning. Generative models are not limited to those described above. Generative models may also be a combination of text generation AI and image processing AI.
[0060] The generative model generates business manuals based on the given instructions. The generative model may perform additional learning based on feedback on the generated business manuals.
[0061] The generation processing unit 202 obtains the business manual generated by the generation model according to the command statement. The generation processing unit 202 inputs the information management ledger, process control table, and sequence diagram related to the target business into the generation model and causes the generation model to generate a business manual related to the target business. The generation processing unit 202 may further input the prescribed information related to the target business into the generation model and cause the generation model to generate a business manual related to the target business. The generation processing unit 202 may obtain the business manual generated by the generation model based on the prescribed information. The generation processing unit 202 may further input the configuration management information related to the target business into the generation model and cause the generation model to generate a business manual related to the target business. The generation processing unit 202 may obtain the business manual generated by the generation model based on the configuration management information. The generation processing unit 202 may collect the information necessary for generating the business manual from the storage unit 210 or an external device, etc., in response to a request from the generation model and input it into the generation model.
[0062] The generation processing unit 202 may input the priority order for generating the business manual, determined based on the risk value of the target business, into the generation model. The generation model may generate the business manual based on the priority order. The generation processing unit 202 may retrieve the business manual generated by the generation model based on the priority order.
[0063] The generation processing unit 202 may input updated information management ledgers, process management tables, and sequence diagrams related to the target business into the generation model and have the generation model generate a business manual related to the target business. The generation processing unit 202 may also retrieve the business manual generated by the generation model based on the updated information management ledgers, process management tables, and sequence diagrams. The generation processing unit 202 may input updated standard information related to the target business into the generation model and have the generation model generate a business manual related to the target business. The generation processing unit 202 may also retrieve the business manual generated by the generation model based on the updated standard information.
[0064] The generation processing unit 202 may also cause an external information processing device to generate the business manual using its generation model. The generation processing unit 202 may, for example, send a command to an external information processing device via the communication control unit 220 and obtain the business manual generated by the external information processing device.
[0065] The generation processing unit 202 may also automatically generate instruction statements based on information entered by the user.
[0066] The risk assessment unit 203 calculates risk values related to the handling of information in multiple business operations. The risk assessment unit 203 calculates risk values based on multiple evaluation items, including the information rank, number of items, storage location, retention period, and disposal method of the information to be handled. The risk assessment unit 203 sets evaluation values for multiple evaluation items and calculates the risk value by multiplying all the set evaluation values together. For example, if the evaluation value for the information rank is "90", the evaluation value for the number of items is "3", the evaluation value for the storage location is "5", the evaluation value for the retention period is "4", and the evaluation value for the disposal method is "5", the risk assessment unit 203 calculates the risk value as (90 × 3 × 5 × 4 × 5). The risk assessment unit 203 may also calculate risk values for each target process. The risk assessment unit 203 may also calculate risk values for each target business operation. The risk assessment unit 203 may also calculate the risk value for a target business operation based on the risk values of multiple target processes included in the target business operation. The risk assessment unit 203 may, for example, calculate the risk value of the target operation by multiplying or adding the risk values of multiple target processes.
[0067] The risk assessment unit 203 may determine the priority for generating business manuals based on the risk values. For example, the risk assessment unit 203 may set a higher priority for generating business manuals for tasks with high risk values. The risk assessment unit 203 may also decide to generate business manuals for tasks in order from those with high risk values.
[0068] In this example, the manual generation support device 2 can quantify and evaluate the information to be handled based on its importance, impact, etc., derived from evaluation elements. Furthermore, the manual generation support device 2 can prioritize the generation of business manuals for tasks with high risk values from among multiple tasks that handle the information to be handled. For example, the manual generation support device 2 can calculate risk values based on multiple evaluation items for the information to be handled. Therefore, the manual generation support device 2 can prioritize the generation of business manuals for the information to be handled, taking into account the importance of handling, based on the rules and regulations of each organization. In this way, the manual generation support device 2 can streamline the creation of business manuals related to the handling of information.
[0069] The output unit 204 outputs the business manual to the user terminal 3-1 via the communication control unit 220. The output unit 204 may also output the business manual to another device via the communication control unit 220. Other devices include, for example, a printer. The output unit 204 may also output information that visualizes the business manual as an electronic file such as PDF (Portable Document Format).
[0070] (4) Operation of Manual Generation Support System 1 (4-1) Overall operation of Manual Generation Support System 1 The procedure for processing using the manual generation support system 1 will be explained below. Figure 12 is a flowchart illustrating an example of the operation of the manual generation support device 2 according to the embodiment.
[0071] The processing procedure described below is merely an example, and each process may be modified as much as possible. Furthermore, depending on the embodiment, steps in the processing procedure described below may be omitted, replaced, or added as appropriate.
[0072] In the following process, it is assumed that the user of user terminal 3-1 has selected the business task for which a business manual will be generated from among several business tasks that handle the information to be handled. The user of user terminal 3-1 inputs an instruction to select the target business task, for example, according to a menu image for business manual creation displayed on the display device of user terminal 3-1. The menu image may be displayed, for example, by launching an application program for creating business manuals on user terminal 3-1. The application program is the application program for the business manual creation service provided by the manual generation support device 2. The menu image may include, for example, selection buttons for selecting the business task for which a business manual will be generated. The menu image may also include input boxes for inputting the business task for which a business manual will be generated. Based on the user's operation to select the target business task, user terminal 3-1 outputs a business manual creation instruction to request the creation of a business manual for the target business task.
[0073] In the following process, the information handled is assumed to be personal information. The user of user terminal 3-1 is assumed to have selected "Incident Response" as the target task. The "Incident Response" task includes, for example, the "Point Fraud Detection" process. The target process is assumed to be the "Point Fraud Detection" process.
[0074] User terminal 3-1 outputs instructions to manual generation support device 2 to select the target task.
[0075] The processing unit 200 obtains a business manual creation instruction from the user terminal 3-1 via the communication control unit 220 (step S1). The business manual creation instruction includes, for example, information that identifies the target business. The information that identifies the target business is, for example, the name of the target business or the management number.
[0076] The processing unit 200 acquires an information management ledger, a process control table, and a sequence diagram related to the target business from the storage unit 210 based on the instruction to create a business manual (step S2). The processing in step S2 may also be performed by the acquisition unit 201 implemented by the processing unit 200. In step S2, for example, the processing unit 200 acquires an information management ledger, a process control table, and a sequence diagram related to the target business based on information that identifies the target business.
[0077] The processing unit 200 inputs an instruction statement into the generation model to generate a business manual (step S3). The processing in step S3 may also be performed by the generation processing unit 202 implemented by the processing unit 200. In step S3, for example, the processing unit 200 generates an instruction statement into the generation model to generate a business manual related to the target business based on the business manual creation instruction, and inputs it into the generation model. The processing unit 200 inputs the information management ledger, process management table, and sequence diagram related to the target business, obtained from the storage unit 210, into the generation model. The processing unit 200 may also input an instruction statement into the generation model to generate a business manual based on the information management ledger, process management table, and sequence diagram. The processing unit 200 may further input standard information related to the target business into the generation model. The processing unit 200 may further input an instruction statement into the generation model to generate a business manual based on the standard information. The processing unit 200 may further input configuration management information related to the target business into the generation model. The processing unit 200 may also input instructions to the generation model to generate a business manual based on the configuration management information.
[0078] The processing unit 200 obtains the business manual generated by the generation model (step S4). The processing in step S4 may also be performed by the generation processing unit 202 implemented by the processing unit 200. In step S4, for example, the processing unit 200 obtains the business manual generated by the generation model according to the instruction statement.
[0079] The processing unit 200 outputs the business manual (step S5). The processing in step S5 may also be performed by the output unit 204 implemented by the processing unit 200. In step S5, for example, the processing unit 200 outputs the business manual to the user terminal 3-1 via the communication control unit 220. The processing unit 200 may also output information that allows the business manual to be displayed to the user terminal 3-1. The processing unit 200 may output the business manual to the user terminal 3-1 in a downloadable format such as a PDF. The processing unit 200 may output the business manual to a printer or the like. The user terminal 3-1 obtains the business manual. The user terminal 3-1 may display the business manual on a display device. The user terminal 3-1 may download the business manual based on user operations.
[0080] Furthermore, if the information stored in the memory unit 210 is updated, the processing unit 200 may input the updated information into the generation model. The processing unit 200 may input the updated information management ledger, process management table, and sequence diagram into the generation model and have the generation model generate a business manual for the target business. The processing unit 200 may input the updated standard information into the generation model and have the generation model generate a business manual for the target business. The processing unit 200 may input the updated configuration management information into the generation model and have the generation model generate a business manual for the target business. For example, if the standard information is updated, the processing unit 200 may have the generation model generate business manuals so that all business manuals are updated periodically or at any arbitrary time.
[0081] According to this example, the manual generation support system 1 can create a business manual for a target business selected by the user, based on an information management ledger, a process management chart, and a sequence diagram. Therefore, the manual generation support system 1 can efficiently create a business manual that includes information on handling the target information, information based on the practical knowledge of the person in charge of the business, and information based on information security. The manual generation support system 1 can create a business manual that guarantees a certain level of quality by having the generation model generate the business manual based on the information management ledger, a process management chart, and a sequence diagram. In addition, the manual generation support system 1 can create a business manual based on prescribed information. Therefore, the manual generation support system 1 can create a business manual based on compliance and audit perspectives. When information is updated, the manual generation support system 1 can create a business manual based on the updated information. Therefore, the manual generation support system 1 can always create or update a business manual based on the latest information. As a result, the manual generation support system 1 can update all operational manuals at at least one of the following times: when compliance requirements such as laws, regulations, ordinances, and internal company rules change, or when operations or work components included in operations are revised, abolished, or added. The manual generation support system 1 can perform periodic maintenance based on the latest information on operations and management controls at any time, either regularly or at any time of the user's choosing.
[0082] Furthermore, the manual generation support system 1 can create business manuals based on information that defines the structure or composition of the manual. Therefore, the manual generation support system 1 can create business manuals in a unified format for multiple business processes.
[0083] (modified version) In the example described above, the processing unit 200 created a business manual for the target business based on the user's selection, but it is not limited to this. The processing unit 200 may determine which business to create a business manual for based on priority. The processing unit 200 may then perform the processing in steps S2 to S5 for the target business determined based on priority.
[0084] For example, the processing unit 200 calculates the risk value of the information to be handled in multiple business operations. The process of calculating the risk value may also be carried out by the risk assessment unit 203 implemented by the processing unit 200. Based on the risk values for multiple business operations, the processing unit 200 determines the priority for generating business manuals. Based on the priority, the processing unit 200 determines the target business operations and inputs instructions into the generation model to generate business manuals related to the target business operations. The processing unit 200 retrieves the business manuals related to the target business operations generated by the generation model.
[0085] The processing unit 200 may also input a command statement to the generation model requesting that it generate business manuals based on priority. The processing unit 200 may also cause the generation model to generate business manuals based on priority.
[0086] In this example, the manual generation support system 1 can create operational manuals for multiple tasks that handle the target information, in order of priority. Therefore, the manual generation support system 1 can create operational manuals for a large number of tasks, starting with those with the highest priority based on risk values. The manual generation support system 1 can create operational manuals prioritizing tasks of high importance from a risk value perspective. In this way, the manual generation support system 1 can streamline the creation of operational manuals related to information handling.
[0087] (Example of a business manual) Examples of operational manuals will be explained with reference to Figures 13 to 16. Figures 13 to 16 show examples of business manuals created by the manual generation support device 2 according to this embodiment. Figures 13 to 16 show an example of a business manual for "incident response," a target business that handles personal information.
[0088] Figure 13 shows the cover page of the operations manual. Figure 13 includes area Ar1, which shows the name of the operations, and area Ar2, which shows the date of creation. Area Ar1 shows the name of the operations in question, "Incident Response." The name of the operations is, for example, the name of the operations selected by the user. The name of the operations in question is based on information from the information management ledger and the process management sheet. Area Ar2 shows the date the operations manual was created.
[0089] Figure 14 shows the table of contents of the operations manual. Figure 14 includes area Ar3, which shows the items of the table of contents. Area Ar3 shows the items of the operations manual. The items are, for example, information that relies on the manual structure or manual formula.
[0090] Figure 15 shows items 1 and 2 of the work manual. Figure 15 includes area Ar4 showing item 1 and area Ar5 showing item 2. Area Ar4 includes background, purpose, and overview. Item 1 is, for example, information based on the process control sheet. The background and purpose are, for example, information based on the background and purpose of the process control sheet. The overview is, for example, information based on the details of each work process in the process control sheet. Area Ar5 includes the scope of work. The scope of work is, for example, information based on the process control sheet. The work structure is, for example, information based on the process control sheet and structure management information.
[0091] Figure 16 shows items 3 to 6 of the work manual. Figure 16 includes area Ar6 showing item 3, area Ar7 showing item 4, area Ar8 showing item 5, and area Ar9 showing item 6. Area Ar6 includes role assignments and organizational structure. Organizational structure is information based on, for example, a sequence diagram. Role assignments are information based on, for example, a process control sheet. Workflow diagrams are information based on a sequence diagram. Area Ar7 includes the implementation cycle. Implementation timing and deadlines are information based on, for example, a process control sheet.
[0092] Area Ar8 includes prohibitions and mandatory requirements. Prohibitions and mandatory requirements are, for example, information that relies on prescribed information. Area Ar9 includes references. References include, for example, a list of handling information and a list of work part numbers. The list of handling information and the list of work part numbers are information that relies on other information related to the target business. Other information related to the target business includes, for example, information indicating data definitions and a common processing master. The information indicating data definitions and the common processing master may be information stored in the storage unit 210 or information stored in an external device. Other information related to the target business may be, for example, information acquired by the processing unit 200 at the request of the generation model. Other information related to the target business may also include configuration management information. Other information related to the target business may also include information used or generated in the process of generating the business model by the generation model.
[0093] According to this example, the manual generation support system 1 can create a business manual for a target business among multiple business processes that handle the target information, based on the information management ledger, process control sheet, and sequence diagram. The manual generation support system 1 can create business manuals for multiple business processes in a unified format by using information that defines the structure or composition of the manual. In addition, the manual generation support system 1 can create business manuals based on prescribed information, in addition to the information from the information management ledger, process control sheet, and sequence diagram. Therefore, the manual generation support system 1 can create business manuals that include information based on the practical knowledge of the business person in charge and information based on knowledge from compliance and audit perspectives. By creating business manuals using a generation model, the manual generation support system 1 can efficiently create business manuals by extracting the necessary information for each item of the business manual from multiple types of information.
[0094] (5) Effects The manual generation support device 2 of this embodiment can obtain an information management ledger, process management table, and sequence diagram for a target business selected from multiple business operations that handle target information, using an information processing program to create a business manual for that target business. The information management ledger, process management table, and sequence diagram are input into a generation model, and a business manual for the target business generated by the generation model is obtained. For example, the manual generation support device 2 can create a business manual for a target business selected from multiple business operations that handle personal information, based on the information management ledger, process management table, and sequence diagram, using the generation model. Therefore, the manual generation support device 2 can efficiently create a business manual for the target business.
[0095] The information management ledger includes risk values related to the handling of information in multiple business operations. For example, the manual generation support device 2 can evaluate the risk values related to handling according to the type of personal information and efficiently create business manuals while taking these risk values into consideration.
[0096] A process management chart includes information showing the work process and work content for each process in multiple tasks. For example, the manual generation support device 2 can create a work manual that includes information showing the work process and work content for each process included in the target task. Therefore, the manual generation support device 2 can efficiently create a work manual that includes practical knowledge of the tasks that handle the information being handled.
[0097] The sequence diagram includes information showing the entities that handle specific information in target processes across multiple business operations, and the processing flow performed by those entities. Therefore, the manual generation support device 2 can efficiently create business manuals that include the entities that perform the processing of business operations that handle the target information, and the processing flow.
[0098] The manual generation support device 2 of this embodiment can determine the priority for generating business manuals based on risk values and obtain business manuals generated by the generation model based on those priorities. For example, the manual generation support device 2 can determine the priority of tasks that handle personal information based on risk values related to the handling of personal information and create business manuals based on those priorities. Therefore, the manual generation support device 2 can prioritize the creation of business manuals for tasks with high risk values among multiple tasks. As a result, the manual generation support device 2 can efficiently create business manuals for tasks that handle the information to be handled.
[0099] The manual generation support device 2 of the embodiment can further acquire provision information indicating regulations concerning at least one of the target business and the information to be handled, and can acquire a business manual generated by the generation model based on the provision information. Therefore, the manual generation support device 2 can efficiently create business manuals that include information based on knowledge of compliance and audit perspectives.
[0100] The prescribed information includes laws and regulations, as well as internal regulations, concerning the information handled in multiple business operations. Therefore, the manual generation support device 2 can efficiently create business manuals that comply with laws and regulations and internal regulations.
[0101] The manual generation support device 2 of this embodiment can acquire business manuals generated based on updated information management ledgers, process management tables, and sequence diagrams. For example, the manual generation support device 2 can update business manuals whenever the information contained in the business manuals is updated. Therefore, the manual generation support device 2 can update all business manuals periodically or at any time in response to changes in compliance requirements such as laws, regulations, ordinances, and internal company rules, and consequently to revisions, abolitions, or additions to business operations or work components included in those operations. This allows the manual generation support device 2 to perform maintenance on business manuals in a batch at the appropriate time.
[0102] The manual generation support device 2 of the embodiment can acquire business manuals generated based on updated regulatory information. For example, when laws and regulations or internal regulations are revised or updated, it is necessary to create business manuals that match these changes. Therefore, the manual generation support device 2 can update business manuals each time regulatory information is updated. For example, the manual generation support device 2 can update all business manuals periodically or at any time in response to changes in compliance requirements such as laws, regulations, ordinances, and internal regulations. This allows the manual generation support device 2 to apply the latest information on laws and regulations and internal regulations and perform maintenance on business manuals in a comprehensive manner at the appropriate time.
[0103] The manual generation support device 2 of this embodiment can further acquire configuration management information that associates multiple business elements related to the target business, and can acquire a business manual generated by a generation model based on the configuration management information. For example, the manual generation support device 2 can efficiently assemble the structure and chapter organization of a business manual by associating multiple business elements. Therefore, the manual generation support device 2 can efficiently create a business manual.
[0104] The manual generation support device 2 of this embodiment can calculate risk values based on multiple evaluation items, including information rank, number of items, storage location, retention period, and disposal method. Therefore, the manual generation support device 2 can calculate risk values that comprehensively evaluate the risks for multiple items with respect to the information to be handled. The manual generation support device 2 can create business manuals based on the comprehensively evaluated risk values.
[0105] (6) Other embodiments The above embodiment describes the case of creating a business manual for operations that handle personal information, but it is not limited to this. The manual generation support device 2 can also be applied to creating business manuals for operations that handle any information.
[0106] In the embodiments described above, the information managed in the information management ledger was described as including evaluation values, but this is not limited to that. The manual generation support device 2 can also be applied to the creation of business manuals for operations that handle information that does not include evaluation values. In this case, the information management ledger does not need to include risk values. The information management ledger may calculate risk values using any method other than evaluation values.
[0107] In the embodiments described above, the manual generation support device 2 caused the generation model to generate a business manual, but it is not limited to this. The manual generation support device 2 may also cause the generation model to generate a business flow that manualizes the procedures and contents of the processes included in the business. In this case, the generation model may be a combination of text generation AI and image processing AI. The manual generation support device 2 may also create a business flow that shows the procedures and contents of the processes in diagrams and tables.
[0108] The manual generation support device may be implemented as a single device, such as manual generation support device 2, or as multiple devices with distributed functions.
[0109] The embodiments described above may apply not only to the apparatus but also to the methods performed by the apparatus. The embodiments described above may apply to a program that can cause the computer of the apparatus to perform each function. The embodiments described above may apply to a recording medium that stores the program. The embodiments described above may apply not only to the system but also to the methods performed by multiple elements included in the system.
[0110] The program may be transferred while stored in the device, or it may be transferred without being stored in the device. In the latter case, the program may be transferred via a network, or it may be transferred while recorded on a recording medium. The recording medium is a non-temporary tangible medium. The recording medium is a computer-readable medium. The recording medium can be any medium that is capable of storing a program and is readable by a computer, such as a CD-ROM or memory card, and its form is not limited.
[0111] Although embodiments of the present invention have been described in detail above, the above description is merely illustrative in all respects of the present invention. Needless to say, various improvements and modifications can be made without departing from the scope of the present invention. In other words, when implementing the present invention, specific configurations may be adopted as appropriate depending on the embodiment.
[0112] In short, this invention is not limited to the embodiments described above, and in the implementation stage, the components can be modified and materialized without departing from the gist of the invention. Furthermore, various inventions can be formed by appropriately combining the multiple components disclosed in the embodiments. For example, some components may be deleted from all the components shown in the embodiments. Moreover, components from different embodiments may be appropriately combined.
[0113] (7) Note The above-described embodiments may be represented as follows: (1) A program that creates a business manual for a target business selected from among multiple business operations that handle the information to be handled, To obtain information management ledgers, process control tables, and sequence diagrams related to the aforementioned target operations, The information management ledger, the process management table, and the sequence diagram are input into the generation model, and the business manual for the target business is obtained from the generation model. An information processing program that causes a computer to execute something. (2) The information management ledger includes risk values related to the handling of information in the aforementioned multiple operations, (1) The information processing program described above. (3) The process control sheet includes information showing the work process and work content for each process in the multiple tasks, (1) The information processing program described above. (4) The sequence diagram includes information showing the entity that handles the target information in the target processing in the multiple business operations, and the processing flow by the entity. (1) The information processing program described above. (5) Based on the risk values, determine the priority for generating the business manuals, To obtain the business manual generated by the generation model based on the aforementioned priority order, An information processing program described in (2) that causes a computer to execute. (6) Further obtaining regulatory information that shows the provisions relating to at least one of the aforementioned subject business and the aforementioned information to be handled, Based on the aforementioned specified information, obtain the business manual generated by the generation model, An information processing program described in (1) that causes a computer to execute. (7) The aforementioned information includes laws and regulations and internal regulations concerning the information handled in multiple business operations. (6) The information processing program described above. (8) Obtaining the aforementioned operational manual includes obtaining the operational manual generated based on the updated information management ledger, the process management table, and the sequence diagram. (1) The information processing program described above. (9) Obtaining the aforementioned operational manuals includes obtaining operational manuals that have been further generated based on the updated aforementioned provision information, (6) The information processing program described above. (10) Further acquisition of configuration management information relating multiple business elements related to the aforementioned target business, Based on the aforementioned configuration management information, the business manual generated by the generation model is obtained, An information processing program described in (1) that causes a computer to execute. (11) The risk value is calculated based on multiple evaluation items including information rank, number of items, storage location, retention period, and disposal method. (2) The information processing program described above. (12) Memory and, An information processing device comprising a processor connected to the memory, The memory stores the program described in any one of items (1) to (11). Information processing device. [Explanation of Symbols]
[0114] 1...Manual generation support system, 2...Manual generation support device, 3-1~3-N...User terminal, 4...Network, 21...Processor, 22...Memory, 23...Storage, 24...Communication interface, 25...Input / output interface, 26...Bus, 200...Processing unit, 201...Acquisition unit, 202...Generation processing unit, 203...Risk assessment unit, 204...Output unit, 210...Storage unit, 211...Information management ledger storage unit, 212...Process control table storage unit, 213...Sequence diagram storage unit, 220...Communication control unit, Ar1~Ar9...Area.
Claims
1. A program that creates a business manual for a selected business task from among multiple tasks that handle the information to be handled, To obtain information management ledgers, process control tables, and sequence diagrams related to the aforementioned target operations, The information management ledger, the process management table, and the sequence diagram are input into the generation model, and the business manual for the target business is obtained from the generation model. An information processing program that causes a computer to execute something.
2. The aforementioned information management ledger includes risk values related to the handling of information in the aforementioned multiple operations, The information processing program according to claim 1.
3. The aforementioned process control sheet includes information indicating the work process and work content for each process in the aforementioned multiple tasks. The information processing program according to claim 1.
4. The sequence diagram includes information showing the entity that handles the target information in the target processing of the multiple business operations, and the processing flow by the entity. The information processing program according to claim 1.
5. Based on the aforementioned risk values, the priority for generating the aforementioned business manuals will be determined, To obtain the business manual generated by the generation model based on the aforementioned priority order, The information processing program according to claim 2, which causes a computer to execute.
6. Further obtaining regulatory information that indicates the provisions concerning at least one of the aforementioned target operations and the aforementioned information to be handled, Based on the aforementioned specified information, obtain the business manual generated by the generation model, An information processing program according to claim 1 that causes a computer to execute.
7. The aforementioned regulations include laws and regulations, as well as internal regulations, concerning the information handled in multiple business operations. The information processing program according to claim 6.
8. Obtaining the aforementioned operational manual includes obtaining the operational manual generated based on the updated information management ledger, the process control sheet, and the sequence diagram. The information processing program according to claim 1.
9. Obtaining the aforementioned operational manual includes obtaining an operational manual generated based on updated aforementioned provision information, The information processing program according to claim 6.
10. Further acquisition of configuration management information that associates multiple business elements related to the aforementioned target business, Based on the aforementioned configuration management information, the business manual generated by the generation model is obtained, An information processing program according to claim 1 that causes a computer to execute.
11. The aforementioned risk value is calculated based on multiple evaluation items, including information rank, number of items, storage location, retention period, and disposal method. The information processing program according to claim 2.
12. Memory and An information processing device comprising a processor connected to the memory, The memory stores the information processing program described in any one of claims 1 to 11. Information processing device.