Information processing systems, information processing methods, and programs
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- BIZREACH INC
- Filing Date
- 2025-01-22
- Publication Date
- 2026-08-03
Smart Images

Figure 2026125142000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing system, an information processing method, and a program.
Background Art
[0002] Patent Document 1 describes a system audit support system including a checkpoint sheet database that stores checkpoint array information data for identifying each checkpoint when auditing an audit target in a regular order, and stores evidence array information data for identifying evidence necessary for evaluating each checkpoint in association with the checkpoint array information data.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] There is a need for a technology capable of analyzing the results of a risk survey.
[0005] In view of the above circumstances, the present invention aims to provide an information processing system or the like capable of analyzing the results of a risk survey.
Means for Solving the Problems
[0006] According to one aspect of the present invention, an information processing system is provided, comprising at least one processor, wherein the processor is configured to perform the following steps by reading a program: in the investigation result acquisition step, the results of multiple risk investigations for the person being evaluated are acquired; in the item reception step, input of a first item and a second item for analyzing and displaying multiple results is received from the evaluation user; and in the analysis information display control step, analysis information is displayed for each of multiple display areas in a coordinate system with the first item on the horizontal axis and the second item on the vertical axis, showing the number of results including the content of the first item and the content of the second item corresponding to the coordinate of the display area, wherein the display area is an area obtained by dividing the planar area of the coordinate system along at least one of the horizontal and vertical axes.
[0007] In this configuration, the evaluation user can analyze the results of the risk assessment of the person being evaluated according to any item of their choosing. [Brief explanation of the drawing]
[0008] [Figure 1] This is a diagram showing the configuration of Information Processing System 1. [Figure 2] This block diagram shows the hardware configuration of the server device 10 and the target terminal 20. [Figure 3] This block diagram shows the hardware configuration of the evaluator terminal 30 and the user terminal 40. [Figure 4] This block diagram shows the functions realized by the server device 10 (control unit 11), the subject terminal 20 (control unit 21), the evaluator terminal 30 (control unit 31), and the user terminal 40 (control unit 41). [Figure 5] This figure shows an example of the analysis information display screen AD displayed on the user terminal 40. [Figure 6] This figure shows an example of the analysis information display screen AD displayed on the user terminal 40. [Figure 7] This figure shows a continuation of the analysis information display screen AD in Figure 5. [Figure 8]Figure 5 shows the state where one of the display areas of the analysis information AI is selected in the analysis information display screen AD. [Figure 9] This figure shows an example of the results information display screen RD shown on the user terminal 40. [Figure 10] This is an activity diagram showing an example of the flow of information processing (analysis and display processing) performed by Information Processing System 1. [Modes for carrying out the invention]
[0009] Embodiments of the present invention will be described below with reference to the drawings. The various features shown in the embodiments below can be combined with each other.
[0010] Incidentally, the program for implementing the software appearing in one embodiment may be provided as a non-transitory computer-readable medium, or it may be provided as a downloadable medium from an external server, or it may be provided so that the program is launched on an external computer and its functions are realized on a client terminal (so-called cloud computing).
[0011] Furthermore, in various information processing according to one embodiment, an input and an output corresponding to the input can be realized. Here, as long as an output is obtained as a result of the input, the form of the information referenced in such information processing (hereinafter referred to as "reference information") is not limited. The reference information may be, for example, rule-based information such as a database, a lookup table, or a predetermined function (including a decision formula such as a regression equation constructed by a statistical method), or a pre-trained model that has learned the correlation between input and output in advance, or a large-scale language model that can output a desired result by inputting a prompt.
[0012] Furthermore, in one embodiment, "part" may include, for example, hardware resources implemented by a circuit in a broad sense, and the information processing of software that can be specifically realized by these hardware resources. Also, in one embodiment, various types of information are handled, and this information can be represented, for example, by the physical values of signal values representing voltage and current, the high or low values of signal values as a set of binary bits composed of 0s or 1s, or by quantum superposition (so-called qubits), and communication and calculations can be performed on a circuit in a broad sense.
[0013] Furthermore, a circuit in a broad sense is a circuit realized by combining at least a suitable combination of circuits, circuits, processors, and memory. The processor may be a general-purpose processor or a dedicated circuit. In other words, it includes application-specific integrated circuits (ASICs), programmable logic devices (for example, simple programmable logic devices (SPLDs), complex programmable logic devices (CPLDs), and field programmable gate arrays (FPGAs)), etc.
[0014] 1. Hardware Configuration This section describes the hardware configuration.
[0015] <Information Processing System 1> FIG. 1 is a configuration diagram showing an information processing system 1. The information processing system 1 includes a communication line 2, a server device 10, a plurality of subject terminals 20, at least one evaluator terminal 30, and a plurality of user terminals 40. The server device 10, the subject terminals 20, the evaluator terminal 30, and the user terminals 40 are configured to be able to communicate with each other through the communication line 2. The connections of the server device 10, the subject terminals 20, the evaluator terminal 30, and the user terminals 40 may be wired or wireless.
[0016] The information processing system 1 constitutes at least a part of a security evaluation system used by, for example, a plurality of evaluation subjects (the first evaluation subject U1 and the second evaluation subject U2), at least one evaluator U3, and a plurality of evaluation users (the first evaluation user U4 and the second evaluation user U5). The information processing system 1 mainly performs evaluations of the security of commercial materials and the like provided by the evaluation subjects, provision of security evaluations, and the like. For example, the information processing system 1 mainly provides security evaluation services by evaluators. In one embodiment, the information processing system 1 consists of one or more devices or components. Hereinafter, these components will be described.
[0017] <Server device 10> FIG. 2 is a block diagram showing the hardware configuration of the server device 10 and the subject terminal 20. As shown in FIG. 2A, the server device 10 includes a control unit 11, a storage unit 12, a communication unit 13, and a communication bus 14. The control unit 11, the storage unit 12, and the communication unit 13 are electrically connected to each other inside the server device 10 via the communication bus 14.
[0018] <Control unit 11> The control unit 11 performs processing and control of the overall operation related to the server device 10. The control unit 11 is, for example, a Central Processing Unit (CPU). The control unit 11 realizes various functions related to the server device 10 by reading predetermined programs stored in the memory unit 12. That is, information processing by software stored in the memory unit 12 is concretely realized by the control unit 11, which is an example of hardware, and can be executed as each functional unit included in the control unit 11. These will be described in more detail in the next section. Note that the control unit 11 is not limited to being a single unit, and the server device 10 may have multiple control units 11 for each function. The server device 10 may also be composed of a combination of these.
[0019] <Storage section 12> The storage unit 12 stores various types of information as defined above. This can be done, for example, as a storage device such as a solid-state drive (SSD) that stores various programs related to the server device 10 executed by the control unit 11, or as memory such as random access memory (RAM) that stores temporarily necessary information (arguments, arrays, etc.) related to program calculations. The storage unit 12 stores various programs, variables, etc. related to the server device 10 executed by the control unit 11.
[0020] <Communications Department 13> The communication unit 13 preferably uses wired communication methods such as USB, IEEE1394, Thunderbolt®, and wired LAN network communication, but may also include wireless LAN network communication, mobile communication such as LTE / 5G, and Bluetooth® communication as needed. In other words, it is more preferable to implement it as a collection of these multiple communication methods. That is, the server device 10 may communicate various information from the outside via the communication unit 13 and the network.
[0021] The server device 10 may be on-premises or in a cloud environment. A cloud-based server device 10 may provide the above-mentioned functions and processing in the form of, for example, SaaS (Software as a Service) or cloud computing.
[0022] <Target user device 20> The target terminal 20 is an information processing terminal used by the person being evaluated for security. The "person being evaluated" includes business partners or their representatives who have any form of business relationship with the evaluation user (especially the evaluation requester), such as the provision of goods or services (e.g., provision of cloud services) or the outsourcing of work. The person being evaluated is, for example, a business operator such as a service provider, supplier, or outsourced organization to the evaluation user (evaluation requester).
[0023] Here, "trading partner organization" includes primary trading partner organizations that receive transactions directly from evaluation users (evaluation requestors), secondary trading partner organizations that receive secondary transactions from primary trading partner organizations, etc. In other words, a trading partner organization refers to a primary trading partner organization or an Nth-tier trading partner organization (N>1) from the perspective of the trading source organization (evaluation user), and the primary trading partner organization and Nth-tier trading partner organizations for a single transaction object constitute the supply chain for that transaction object. The transaction object includes the goods traded, outsourced services, etc. Furthermore, a trading partner organization may also include individual business owners who receive transactions.
[0024] A trading partner organization is an organization located downstream from the trading source organization (evaluation user) in the supply chain. From the perspective of the trading source organization, a trading partner organization may include trading partners, contractors (including subcontractors, sub-subcontractors, etc.), vendors, suppliers, sellers, subsidiaries, etc. A trading partner organization may include entities other than end users in the supply chain.
[0025] Furthermore, "organizations" include for-profit corporations (e.g., companies), non-profit corporations (e.g., cooperatives, foundations, etc.), and public corporations (e.g., local governments, etc.).
[0026] As shown in Figure 2B, the target terminal 20 comprises a control unit 21, a storage unit 22, a communication unit 23, an input unit 24, an output unit 25, and a communication bus 26. The control unit 21, storage unit 22, communication unit 23, input unit 24, and output unit 25 are electrically connected within the target terminal 20 via the communication bus 26. The descriptions of the control unit 21, storage unit 22, and communication unit 23 are the same as the descriptions of each part in the server device 10 and are therefore omitted.
[0027] <Input section 24> The input unit 24 receives operation inputs made by the user. The operation inputs are transmitted as command signals to the control unit 21 via the communication bus 26. The control unit 21 can perform predetermined controls or calculations based on the transmitted command signals as needed. The input unit 24 may be included in the housing of the user terminal 20 or it may be an external component. For example, the input unit 24 may be implemented as a touch panel integrated with the output unit 25. When the input unit 24 is implemented as a touch panel, the user can input tap operations, swipe operations, etc. to the input unit 24. Instead of a touch panel, the input unit 24 can be a switch button, mouse, trackpad, QWERTY keyboard, etc.
[0028] <Output section 25> The output unit 25 displays a graphical user interface (GUI) screen that can be operated by the user. The output unit 25 may be included in the casing of the user terminal 20 or it may be an external component. Specifically, the output unit 25 can be implemented as a display device such as a CRT display, liquid crystal display, organic EL display, or plasma display. It is preferable that these display devices be used in accordance with the type of user terminal 20.
[0029] <Evaluator terminal 30> The evaluator terminal 30 is an information processing terminal used by the evaluator to evaluate the responses of the person being evaluated. The "evaluator" is an organization such as a company that conducts security evaluations (for example, a security evaluation company that conducts security evaluations of services such as cloud services, software, etc.) or a person in charge thereof. The evaluator, for example, conducts the security evaluation of the person being evaluated via the information processing system 1 from the evaluator terminal 30.
[0030] Figure 3 is a block diagram showing the hardware configuration of the evaluator terminal 30 and the user terminal 40. As shown in Figure 3A, the evaluator terminal 30 comprises a control unit 31, a storage unit 32, a communication unit 33, an input unit 34, an output unit 35, and a communication bus 36. The control unit 31, storage unit 32, communication unit 33, input unit 34, and output unit 35 are electrically connected within the evaluator terminal 30 via the communication bus 36. The descriptions of the control unit 31, storage unit 32, communication unit 33, input unit 34, and output unit 35 are the same as the descriptions of each part in the subject terminal 20 and are therefore omitted.
[0031] <User terminal 40> User terminal 40 is an information processing terminal used by evaluation users who utilize services provided by information processing system 1 (for example, response data evaluation service, security report provision service, etc.). "Evaluation users" include evaluation requesters, viewers, etc.
[0032] A "requester for evaluation" is an evaluation user who requests an evaluation of the security of the person being evaluated. This may be, for example, an individual, organization, or a person in charge of such organization that has a business relationship with the person being evaluated. Requesters for evaluation include, for example, evaluation users who are registered with the security evaluation service provided by Information Processing System 1.
[0033] The requester for evaluation includes trading organizations, which are organizations or individuals that request transactions from trading partners (the entities being evaluated). Trading organizations receive, use, etc., the goods and services provided by trading partners. For example, if the goods and services being traded are physical goods, the requester for evaluation (trading organization) is the purchaser of the goods (finished products or parts) manufactured by the trading partner. Also, for example, if the goods and services being traded are services, the requester for evaluation (trading organization) is a user of the services provided by the trading partner (for example, a user of cloud services provided by a cloud service provider). Furthermore, for example, if the goods and services being traded are operations (work), the requester for evaluation (trading organization) is the client or contractor for the operations.
[0034] Applicants for evaluation include not only individuals or organizations that conduct transactions subject to evaluation (such as service use or outsourcing) with the person being evaluated, but also individuals or organizations that request evaluations of specific services. For example, applicants for evaluation may include companies that want to have the security of cloud services they use or are considering using evaluated, or companies that want to verify such evaluations.
[0035] A "viewer" is an individual or organization that uses the results of a security assessment of the person being assessed, conducted at the request of the assessment requester. Viewers are, for example, providers of goods or services that are to be used, business partners with whom transactions are planned, or individuals or organizations that seek an assessment of the person being assessed as a potential candidate for such a business. Viewers may include assessment users who are registered with the security assessment service provided by the Information Processing System 1, and other assessment users who are not registered with the assessment service (for example, assessment users who are not registered with the assessment service but have obtained links to web pages displaying assessments provided by the assessment service, files containing such assessments, etc., that are accessible from outside the assessment service).
[0036] As shown in Figure 4B, the user terminal 40 comprises a control unit 41, a storage unit 42, a communication unit 43, an input unit 44, an output unit 45, and a communication bus 46. The control unit 41, storage unit 42, communication unit 43, input unit 44, and output unit 45 are electrically connected within the user terminal 40 via the communication bus 46. The descriptions of the control unit 41, storage unit 42, communication unit 43, input unit 44, and output unit 45 are the same as the descriptions of each part in the target terminal 20 and are therefore omitted.
[0037] 2. Functional Configuration This section describes the functional configuration of this embodiment. Information processing by software stored in the memory unit 12 is specifically realized by the control unit 11, which is an example of hardware, and can be executed as each functional unit included in the control unit 11 (at least one processor provided by the information processing system 1).
[0038] Figure 4 is a block diagram showing the functions realized by the server device 10 (control unit 11), the subject terminal 20 (control unit 21), the evaluator terminal 30 (control unit 31), and the user terminal 40 (control unit 41).
[0039] As shown in Figure 4A, the server device 10 (control unit 11) comprises a basic display control unit 111, a response reception unit 112, an evaluation reception unit 113, a survey result acquisition unit 114, an item reception unit 115, a question reception unit 116, an analysis information display control unit 117, a report output unit 118, and an artificial intelligence unit 120.
[0040] As shown in Figure 4B, the subject terminal 20 (control unit 21) comprises a display unit 211 and an operation acquisition unit 212. As shown in Figure 4C, the evaluator terminal 30 (control unit 31) comprises a display unit 311 and an operation acquisition unit 312. As shown in Figure 4D, the user terminal 40 (control unit 41) comprises a display unit 411 and an operation acquisition unit 412.
[0041] <Basic display control unit 111> The basic display control unit 111 is configured to display various information on the subject terminal 20, the evaluator terminal 30, and the user terminal 40. For example, the basic display control unit 111 displays the answer input form in which the subject enters their answers, the answers registered by the subject, and the evaluator's evaluation results of the answers on the display unit 211 of the subject terminal 20, the display unit 311 of the evaluator terminal 30, or the display unit 411 of the user terminal 40.
[0042] <Response Reception Department 112> The response reception unit 112 is configured to create or update response data by receiving input from the person being evaluated regarding their answers to questions in the risk assessment. The risk assessment is an investigation into the security or secondary transactions of the person being evaluated.
[0043] In a security survey (security investigation), the response reception unit 112 displays a predetermined response input form on the subject terminal 20 to receive answers from the subject to be evaluated regarding security-related questions, and registers the answers entered in the response input form as response data. A security survey may also be called a security risk survey.
[0044] The person being evaluated will, for example, answer questions at the request of an evaluation user with whom they are conducting business (with whom they have a contract related to the transaction).
[0045] The response receiving unit 112 may receive responses from the subject terminal 20 to security-related questions from the subject, along with the designation of the category to be assigned to the response, and add the response data, including the response and category, to the response database. Note that the category is assigned to the entire response data, including multiple responses.
[0046] Furthermore, the response receiving unit 112 does not necessarily have to accept category designations from the person being evaluated. For example, the response receiving unit 112 may present the person being evaluated with questions (response input forms) in which categories have been pre-specified, and register the response data in which the pre-specified categories have been assigned to the answers entered on the person's terminal 20.
[0047] The response data may include not only the response data and information indicating the category, but also the question data. Furthermore, if response data has already been registered for the same question and category, the response receiving unit 112 will replace the response included in the response data with the newly entered response.
[0048] The "category" is information that indicates the evaluator's prerequisites for answering the questions (for example, the product being answered, the business being answered, the department being answered, the contract with the trading organization being answered, etc.). In other words, the category is information such as the product being answered, the business being answered, the department being answered, and the contract being answered. The evaluator enters their answers to the questions for the product being answered, etc., that is designated as the category.
[0049] The categories may include the type of goods handled by the person being evaluated, the customers to whom the goods are provided, the types of plans included in the goods, the business that provides the goods, or a combination of these. The categories may also be contract names representing these combinations. This allows for different answers to questions to be entered and registered depending on the goods being evaluated, even for the same person being evaluated.
[0050] The service provider being evaluated will input responses according to service attributes, such as the type of service (e.g., AI (Artificial Intelligence) service, Recruitment Process Outsourcing (RPO) service, etc.), the recipient of the service (e.g., the name of the organization requesting the evaluation, etc., and other attributes of the evaluation requester), the type of plan (option) included in the service, and the name of the business or department providing the service. In other words, the service provider offering multiple services or plans may input responses for each of these service attributes or for each contract, and the response receiving unit 112 may register the response data for each service attribute. The input responses are stored as response data, associated with their respective service attributes (categories).
[0051] The "services" provided by the evaluated party include services delivered via the internet, such as SaaS, IaaS (Infrastructure as a Service), PaaS (Platform as a Service), and cloud services. In this case, the "evaluated party" includes cloud service providers, etc. Furthermore, the "services" provided by the evaluated party may also be services provided to business partners, customers, etc.
[0052] The response receiving unit 112 does not need to accept category input (specification) for response data that is not category-dependent (i.e., does not fall into a specific category and applies to any service, plan, provider, etc.). The response receiving unit 112 may also accept the specification (input) of an "uncategorized category" for response data that is not category-dependent. For example, the response receiving unit 112 may accept the specification (input) of the category "common" as an uncategorized category.
[0053] The response data includes the evaluated party's answers to multiple questions regarding the evaluated party's security. The "questions" are items that the evaluated party is required to answer, and may include, for example, matters concerning the evaluated party's own security, the security of the goods or services provided by the evaluated party, etc. The "questions" may also include matters concerning the security of other organizations included in the evaluated party's supply chain. "Other organizations" include, for example, organizations to which the evaluated party outsources its operations (including subcontractors, sub-subcontractors, sub-subcontractors, etc.), and other organizations that are the evaluated party's business partners. In other words, "other organizations" may include matters concerning the security of N-tier business partners (N>1) from the perspective of the trading organization, including not only secondary business partners that directly receive secondary transactions from primary business partners whose responses are received in the secondary transaction survey described later, but also tertiary business partners that receive tertiary transactions from secondary business partners, etc. The "questions" may also include so-called security checklists.
[0054] The questions may include, for example, those that confirm the status or evaluation of security certifications, service levels, scope of responsibility, security measures within the evaluated entity, handling of data related to the evaluation requester, handling of data managed by the evaluated entity, and service development, maintenance, or operational policies (such as account management) (questions that require answers from the evaluated entity).
[0055] "Response data" consists of the evaluator's answers to multiple questions regarding the security of the service, and is the information that evaluators check and evaluate. Response data may be evaluated only once or multiple times. In other words, evaluation of response data may include an initial evaluation (so-called review), an intermediate evaluation, a final evaluation, etc. Initial and intermediate evaluations are evaluations that are further evaluated after the initial evaluation. Response data may be modified by the evaluator based on the initial or intermediate evaluation. Multiple evaluations may be performed by the same evaluator or by different evaluators (so-called reviewers, etc.). The final evaluation creates an evaluation to be used in a report or document provided to the evaluation user. Furthermore, response data may be evaluated again by the evaluator when it is modified or updated by the evaluator. The evaluator's evaluation results of the response data are used as part of or as reference information in the report or document.
[0056] The responses to each question included in the response data are those entered by the evaluators into the response input form for each question presented in the response input form, and registered in the response database. Responses to a single question may be hierarchical.
[0057] Furthermore, the response receiving unit 112 may accept responses through an interface other than the response input form (for example, uploading a data file containing responses by the person being evaluated) and register these responses as response data in the response database.
[0058] The risk investigations for which the response reception unit 112 accepts responses may include investigations related to secondary transactions (secondary transaction investigations). A secondary transaction investigation is an investigation into the transactions of the trading partner organization with other organizations that are the subject of the trading. For example, a secondary transaction investigation is an investigation into the existence of N-th tier trading partners (N>1) from the perspective of the trading partner organization, including secondary trading partners that receive secondary transactions directly from the primary trading partner organization, as well as tertiary trading partners that receive tertiary transactions from the secondary trading partner organization, and may be rephrased as an "N-th tier transaction investigation." A secondary transaction investigation may also be called a "subcontractor investigation." A secondary transaction investigation may also be an investigation into the constituent organizations of the subsupply chain formed by the trading partner organization with respect to the trading target.
[0059] A secondary transaction investigation may be requested by the primary trading organization from the primary trading organization, or it may be requested directly by the primary trading organization from secondary trading organizations that the primary trading organization is aware of. Note that "a secondary transaction investigation of an Nth-tier trading organization" refers to an investigation of trading partners further downstream than the Nth-tier trading organization (i.e., N+1th-tier trading organizations and beyond).
[0060] The response receiving unit 112 displays a predetermined response input form on the subject terminal 20 for receiving responses from the subject to evaluation to questions regarding secondary transactions, and registers the responses entered in the response input form as response data.
[0061] The response form for the secondary transaction investigation may be sent to the person being evaluated upon request from the evaluation user. Similarly, the response form for the security investigation may be sent to the person being evaluated upon request from the evaluation user. Furthermore, these response forms may be sent to the secondary transaction organization upon request from the evaluation user. In addition, these response forms may be created and sent for each transaction target.
[0062] The evaluators may be sent a response form corresponding to the type of security survey they selected. For example, an evaluator who selected "Standard Survey" as the type of security survey may be sent a response form with a large number of questions (e.g., around 120 items), while an evaluator who selected "Simplified Survey" as the type of security survey may be sent a response form with fewer questions than the "Standard Survey" (e.g., around 30 items). Note that a security survey may not be conducted for evaluators who are prohibited from engaging in secondary transactions.
[0063] <Evaluation Reception Department 113> The evaluation reception unit 113 is configured to receive evaluations from evaluators for the response data registered (created or updated) by the response reception unit 112. The evaluation reception unit 113, for example, registers the evaluated response data along with the evaluation results in a response database or the like. The evaluation results include at least an evaluation value (security score) indicating the level of security measures (how many or few problems there are in security measures).
[0064] "Evaluation" refers to the act of checking for deficiencies or inconsistencies in the responses included in the response data, creating comments on the content of the responses, assessing the content of the responses, and scoring the responses based on predetermined criteria. As mentioned above, evaluation may be carried out by multiple evaluators, and the first evaluator may request the second evaluator to evaluate the registered response data. In that case, the evaluation reception unit 113 may accept the evaluation from the second evaluator after the evaluation by the first evaluator.
[0065] For example, if the evaluation is conducted in two stages, the initial evaluation (review) involves checking for deficiencies or inconsistencies, and creating points of concern. Subsequently, the response data after the initial evaluation is evaluated as a final evaluation based on predetermined criteria, including assessment and scoring of the content (responses) and creation of comments on the entire response data. A report or document (e.g., a security report) containing the results is then created. The report or document is created by the final evaluator or by the evaluation unit of the control unit 11. The evaluation unit is configured to generate part or all of the report or document based on the input response data. The evaluation results of the response data may be included in the report or document as part of the report or as supplementary information.
[0066] The evaluation reception unit 113 receives input such as characters and sentences to be used for evaluation from the evaluator terminal 30. Typically, evaluation is performed on answer data in which all questions have been answered. Answer data that contains unanswered questions (questions for which answers have not been registered) is not subject to evaluation, and the evaluation reception unit 113 does not need to accept the evaluation. Furthermore, even if answer data contains unanswered questions (questions for which answers have not been registered), only the questions that have been answered may be partially subject to evaluation.
[0067] <Research Results Acquisition Section 114> The investigation results acquisition unit 114 is configured to acquire the results of multiple risk investigations concerning the evaluation user. "Results of risk investigations concerning the evaluation user" include, for example, the results of risk investigations of trading partners (evaluated entities) that the evaluation user has requested from trading partners with which the evaluation user conducts business as a trading source organization; the results of risk investigations of trading partners (evaluated entities) that have been requested by someone other than the evaluation user from trading partners with which the evaluation user conducts business as a trading source organization; and the results of risk investigations of entities with which the evaluation user does not conduct business but whose risk investigation results it wishes to analyze. The investigation results acquisition unit 114 may also acquire the results of risk investigations of multiple entities.
[0068] The "results of the risk assessment" include, for example, at least one of the response data (answers to questions) and the evaluation results of the security assessment (security score). Furthermore, the results of the risk assessment may also be the results of a risk assessment conducted for each contract or transaction between the assessment user (trading organization) and the assessed party (trading partner organization). This allows the assessment user to analyze the results of the assessed party's risk assessment on a contract-by-contract or transaction-by-transaction basis, thereby facilitating the management of security risks on a contract-by-contract or transaction-by-transaction basis.
[0069] "Contracts or transactions" may be conducted at the supply chain level. In other words, "results of risk assessments conducted for each contract or transaction" can be rephrased as "results of risk assessments conducted for each supply chain." By obtaining the results of risk assessments conducted for each supply chain as the subject of analysis, it becomes easier to manage risks at the supply chain level, etc.
[0070] The results of the risk assessment may include information about the assessed party that was the subject of the risk assessment. Information about the assessed party included in the results of the risk assessment may include, for example, the organization name, business name, contracted business name, transactions used (services used, outsourced work, etc.), information handled (for example, the type of information entrusted to the assessed party), the importance of the transaction, and the status of the assessed party's secondary transactions (for example, whether secondary transactions are permitted, information about secondary business partners, whether there is an obligation to notify when secondary business partners change, etc.).
[0071] The information of the person being evaluated may, for example, be information entered by the evaluation user (evaluation requestor) from the user terminal 40, or information entered by the person being evaluated from the subject terminal 20 in response to a request from the evaluation user. Furthermore, the information of the person being evaluated may be entered using a predetermined format (for example, the response format for the secondary transaction survey sent to the person being evaluated). The information of the person being evaluated, along with, for example, response data and evaluation results, is registered in the response database.
[0072] Furthermore, the information of those being evaluated may include information recorded in the service ledger managed by the evaluation user (for example, whether the contract is being continued, the company's own priority, the department using the service, the number of registered accounts for the service, etc.).
[0073] <Item reception section 115> The item reception unit 115 is configured to receive input from the evaluation user (user terminal 40) for the first and second items, which are used to analyze and display the results of multiple risk surveys acquired by the survey results acquisition unit 114. The first and second items are indicators that will be used as the horizontal axis and vertical axis, respectively, in the analysis information generated by the analysis information display control unit 117, which will be described later.
[0074] The first and second items are each arbitrarily selected from the items included in the risk assessment results, where the content is either numerical or information selected from pre-prepared options. The item reception unit 115 may, for example, present multiple items that can be selected as the first or second item, and accept the item selected from the user terminal 40 as the first or second item.
[0075] Items 1 and 2 may be a security score calculated based on a risk assessment, or attributes of the person being assessed, respectively. This allows for analysis of the results of the risk assessment based on the security score or attributes of the person being assessed.
[0076] The attributes of the person being evaluated may include at least one of the following: the type of information entrusted to the person being evaluated, the importance of the transactions the person being evaluated conducts, and the status of the person being evaluated's secondary transactions. This allows the evaluation user to analyze security risks according to the attributes of the person being evaluated. Furthermore, the attributes of the person being evaluated may include the attributes of the person being evaluated, the attributes of the transactions and contracts the person being evaluated conducts, and the attributes of the information the person being evaluated handles (information other than the information entrusted to them).
[0077] The "types of information to be deposited" include, for example, highly sensitive information such as personal information, confidential information, and information whose use should be limited. Furthermore, "secondary transactions" include, for example, tertiary transactions from a secondary trading partner organization to a tertiary trading partner organization, which are Nth-order transactions (N≧2) from the perspective of the trading organization.
[0078] The first and second items may each consist of a security score and an attribute of an arbitrary person being evaluated. This allows for analysis that combines the security score with the attributes of the evaluation user. Furthermore, the first and second items may each consist of different attributes. This allows for analysis that combines different attributes.
[0079] The item reception unit 115 may further accept input of division conditions for dividing the coordinate system along the horizontal or vertical axis from the evaluation user (user terminal 40). This allows for the creation of analysis information at the evaluation user's desired level of detail, thereby improving the accuracy of the risk survey results.
[0080] If the content of the first or second item is a numerical value, the division condition is any numerical value that divides the horizontal or vertical axis. In this case, the vertical or horizontal axis is divided into two regions with the numerical value entered as the division condition as the threshold. For example, if the numerical value "X" is entered as the division condition for the first item, the horizontal axis of the division information will be divided into a region less than X and a region greater than or equal to X. The item reception unit 115 may also accept input of multiple numerical values as division conditions. If the number of numerical values entered is N, the horizontal or vertical axis will be divided into N+1 regions.
[0081] Furthermore, if the content of the first or second item is information selected from the options, the division condition is two or more arbitrary options that divide the horizontal or vertical axis. In this case, the vertical or horizontal axis is divided into multiple areas, each representing one of the multiple options entered as the division condition. For example, if "Option A" and "Option B" are entered as the division condition for the second item, the vertical axis of the division information will be divided into an area representing "Option A" and an area representing "Option B". In addition, the remaining options (e.g., "Option B") may be automatically set based on the selection of some options (e.g., "Option A").
[0082] The item receiving unit 115 may accept only the division conditions for the first item (horizontal axis), or only the division conditions for the second item (vertical axis). Furthermore, the item receiving unit 115 may accept division conditions only for items among the first and second items whose content is expressed numerically (for example, security score).
[0083] The item reception unit 115 may, for example, present input fields or options for division conditions corresponding to the first and second items to the user terminal 40, and accept the input of a numerical value as the division condition or the selection of an option.
[0084] The item reception unit 115 may set pre-configured splitting conditions for each item among the first and second items, for items that do not accept splitting conditions or for which splitting conditions have not been entered. For example, if "Type of information deposited by the person being evaluated" is selected as the second item, the item reception unit 115 may automatically set the splitting conditions to "Personal information deposited" and "Personal information not deposited." In addition, for items whose content is information selected from options, the item reception unit 115 may set all available options as splitting conditions.
[0085] <Question Reception Section 116> The question reception unit 116 receives questions included in the risk survey and their corresponding answers from the evaluation user (user terminal 40) as filtering criteria. This allows for risk analysis of the results of the risk survey based on specific answers.
[0086] The question reception unit 116 may, for example, present the user terminal 40 with options for questions included in the risk survey and accept input of questions to be used as filtering criteria. Alternatively, the question reception unit 116 may, for example, present the user terminal 40 with options for selected questions (options presented to the person being evaluated in the risk survey) and accept input of answers to be used as filtering criteria. Furthermore, the question reception unit 116 may, as the answer to the filtering criteria, present the user terminal 40 with an indicator representing the answer (such as a ○ or × answer rank), as described later, rather than the options for the questions themselves, and accept input of the answer (indicator) to be used as filtering criteria.
[0087] Furthermore, the question reception unit 116 may accept input of multiple question-and-answer combinations, as well as the logical relationships (AND conditions or OR conditions) between these combinations, from the user terminal 40.
[0088] <Analysis Information Display Control Unit 117> The analysis information display control unit 117 is configured to display analysis information for each of several display areas in a coordinate system where the horizontal axis represents the first item received by the item receiving unit 115 and the vertical axis represents the second item received by the item receiving unit 115. This information includes the content of the first item and the content of the second item corresponding to the coordinate of the display area, and the number of results obtained by the survey result acquisition unit 114.
[0089] This allows evaluation users, especially those with multiple supply chains, trading partners, and contracts, to understand the distribution of security risks across all of them. As a result, they can analyze which security risks should be prioritized for action.
[0090] The analysis information is displayed, for example, as a planar graph. The multiple display areas included in the analysis information are regions obtained by dividing the planar region of the coordinate system that constitutes the graph along at least one of the horizontal axis and the vertical axis. The planar region may be divided only along the horizontal axis (display areas may be arranged only along the horizontal axis), divided only along the vertical axis (display areas may be arranged only along the vertical axis), or it may be a matrix divided along both the horizontal and vertical axes.
[0091] In other words, the analysis information display control unit 117 may display analysis information for each of the multiple display areas obtained by dividing the plane region of the coordinate system along both the horizontal and vertical axes, showing the number of risk survey results including the content of the first item and the content of the second item corresponding to the coordinate of the display area. This makes it possible to perform a risk analysis of the person being evaluated by cross-referencing any two items.
[0092] "The content of the first (second) item corresponding to the coordinates of the display area" refers to the content set for each divided area on the horizontal (vertical) axis. For example, if the content of the first (second) item is a numerical value, it means the content (numerical value) of the first (second) item that satisfies the range of numerical values set for the divided area (e.g., "70 or more"). Also, for example, if the content of the first (second) item is information selected from options, it means the content of the first (second) item that matches the option set for the divided area (e.g., "Personal information is entrusted").
[0093] Therefore, each display area displays the number of results from multiple risk surveys acquired by the survey results acquisition unit 114 that include a first item corresponding to the content of the first item set for each display area, and a second item corresponding to the content of the second item set for each display area. In other words, the analysis information display control unit 117 classifies the results of multiple risk surveys into display areas in which both the first and second items of these results satisfy the conditions (correspond to the set content).
[0094] If the item reception unit 115 has received input for division conditions, the analysis information display control unit 117 may display analysis information for each of the multiple display areas that divide the horizontal or vertical axis using the division conditions, showing the number of risk survey results including the content of the first item and the content of the second item corresponding to the coordinates of the display area. In this case, each division area on the horizontal or vertical axis is assigned a range or selection of numerical values entered as division conditions.
[0095] The analysis information display control unit 117 may change the display format for each display area according to the level of security risk (hereinafter referred to as "risk score") based on the combination of the content of the first item and the content of the second item (hereinafter referred to as "combination information"). This allows evaluation users to easily and visually grasp areas with high security risks.
[0096] The analysis information display control unit 117 calculates a risk score for each display area based, for example, on combination information for each display area and reference information. The reference information includes at least the correlation between the combination information and the risk score. The reference information is stored, for example, in the storage unit 12.
[0097] Reference information may include, for example, tables, functions, simple algorithms, etc., that show the correlation between combination information and risk scores. The correlations included in the reference information can be constructed, for example, by statistically analyzing data that records combination information and corresponding risk scores.
[0098] The reference information may include a risk score calculation model, which is a learning model or generative AI trained to take combined information as input and output a risk score. In this case, the analysis information display control unit 117 inputs the combined information into the risk score calculation model and causes the risk score calculation model to output a risk score. In the risk score calculation model, parameters calculated and tuned through learning constitute the correlation of the reference information.
[0099] The risk score calculation model is included in the artificial intelligence unit 120. The risk score calculation model, which is trained to output a risk score, is trained using, for example, combination information and corresponding risk score data as training data.
[0100] If the risk score calculation model is a generative AI including a large-scale language model, the analysis information display control unit 117 takes combination information as input, inputs a prompt to the risk score calculation model that includes an instruction to calculate a risk score corresponding to the combination information, and causes the risk score calculation model to output the risk score. The analysis information display control unit 117 may also generate a prompt that gives an instruction to the risk score calculation model to calculate a risk score and input the prompt to the risk score calculation model. In addition to the risk score calculation / output instruction and combination information, the analysis information display control unit 117 may also input a prompt to the risk score calculation model that includes, for example, one or more samples of combination information and one or more samples of corresponding risk scores as examples, samples, or training data of input and output pairs.
[0101] The analysis information display control unit 117 may calculate a first sub-risk score based on the content of the first item (horizontal axis) and a second sub-risk score based on the content of the second item (vertical axis) based on the reference information. In this case, the analysis information display control unit 117 may calculate the risk score for each display area by summing, multiplying, etc., the first sub-risk score and the second sub-risk score, or it may determine the display format of the display area based on a table that defines the risk score for each combination of the first sub-risk score and the second sub-risk score. When calculating the first sub-risk score and the second sub-risk score, the analysis information display control unit 117 may, for example, input the content of the first item or the content of the second item into the risk score calculation model and have the risk score calculation model output the first sub-risk score or the second sub-risk score.
[0102] Furthermore, the analysis information display control unit 117 may determine a segmented area where both the first sub-risk score and the second sub-risk score exceed their respective thresholds as a high-risk score area. The thresholds are pre-set for each of the first and second items. For example, the analysis information display control unit 117 may display a segmented area in a warning color where both the first item (horizontal axis) and the second item (vertical axis) contain content or values that pose a high security risk (exceeding the threshold). Moreover, for example, a segmented area where both contain content or values that pose a high security risk may be displayed in a way that distinguishes it from a segmented area where only one of the first item (horizontal axis) or the second item (vertical axis) contains content or values that pose a high security risk.
[0103] The "display format of the display area" includes, for example, the color of the display area, the thickness of the border (frame) of the display area, the decoration of the display area (whether or not it is shaded, etc.), the size of the characters representing the number of results, and the addition of icons (marks, characters, etc.) to the display area. For example, the analysis information display control unit 117 may change the color of the display area so that the higher the risk score, the closer it gets to a warning color such as red. Also, for example, the analysis information display control unit 117 may add a warning mark to display areas where the risk score exceeds a predetermined threshold.
[0104] If the question reception unit 116 has received a combination of questions and answers as filtering conditions, the analysis information display control unit 117 may display analysis information for each of the multiple display areas, showing the number of results from the risk survey that satisfy the filtering conditions, which include the content of the first item and the content of the second item corresponding to the coordinates of the display area. For example, if the filtering condition "Answer to question Q2 is ○" is entered from the user terminal 40, the question reception unit 116 extracts the risk survey results for which "Answer to question Q2 is ○" from the results acquired by the survey results acquisition unit 114, and classifies only the extracted results into each display area of the analysis information.
[0105] The analysis information display control unit 117 may display on the user terminal 40 a list of result information showing the contents of each of the multiple risk survey results that constitute the analysis information, along with the analysis information itself. The result information includes at least the contents of the first item and the contents of the second item. This allows the evaluation user to immediately confirm the source of the analysis information. In addition, the evaluation user can refer to the details of the risk survey results included in the analysis information.
[0106] The result information is information extracted from the information contained in the results of the risk survey acquired by the survey results acquisition unit 114. The result information may include only the first and second items (set by the user) received by the item reception unit 115, or it may include information other than the first and second items.
[0107] If the result information includes information other than the first and second items, the analysis information display control unit 117 may highlight the first and second items included in the result information. "Highlighting the first and second items" includes, for example, coloring the first and second items, shading the first and second items, enlarging the characters representing the content of the first and second items, or adding icons (marks, characters, etc.) to indicate that they are the first or second item.
[0108] The results information may include multiple response records representing the answers to each of the multiple questions included in the risk assessment. This allows the assessment user to refer to the responses of the assessed individuals when analyzing the results of the risk assessment.
[0109] The response information may be the actual responses included in the response data (responses entered or selected by the person being evaluated). Alternatively, the response information may be an indicator showing the level of security measures taken in response to the questions. In other words, the analysis information display control unit 117 may display response information, in which the actual response content has been replaced with an indicator, as result information. This allows the evaluation user to grasp the elements with high security risks in the results of the risk survey from an overview perspective. Therefore, it becomes easier for the evaluation user to consider countermeasures against security risks.
[0110] The "indicator of the level of security measures" (hereinafter referred to as the "response indicator") is a response rank determined according to the level of security measures, and is expressed by symbols or codes such as "○·×·△" or "A·B·C". The number of rank levels in the response rank is not particularly limited as long as it is two or more. The response indicator may also be a numerical value indicating the level of security measures. The response indicator is set in advance for each option of the question, for example. The response indicator may be the same for all questions (for example, the response indicator may be displayed as a two-choice option of "○·×" for the entire risk survey result), or it may be different for each question.
[0111] Specifically, for example, in a given question, if option A or option B is selected as the answer, the answer indicator may be set to ○, and if option C is selected as the answer, the answer indicator may be set to ×. Alternatively, for example, if option A is selected as the answer, the answer indicator may be set to ○, if option B, option C, or option D is selected as the answer, the answer indicator may be set to △, and if option E is selected as the answer, the answer indicator may be set to ×.
[0112] Typically, the analysis information display control unit 117 may display result information on the user terminal 40 that includes the category of the risk investigation (e.g., contract name), the name of the person who conducted the risk investigation, multiple items that can be selected as the first or second item, and the response information.
[0113] The analysis information display control unit 117 may display multiple result information in a list format on the user terminal 40. For example, if the results of the risk assessment are on a contract basis, the result information for each contract may be displayed as a list on the user terminal 40.
[0114] The analysis information display control unit 117 may receive input from the evaluation user regarding the selection of display areas in the analysis information, highlight the selected display area, and display result information narrowed down to the results of the risk investigation belonging to the selected display area. This allows the evaluation user to select the display area they want to check in detail, and display only the results of the risk investigation included in that display area. For example, it is possible to extract contracts included in display areas with high security risks and consider countermeasures such as reviewing those contracts.
[0115] "Selecting a display area" is done, for example, by tapping the display area or clicking while the pointer is over the display area.
[0116] "Highlighting the display area" includes processes such as making the selected display area a more prominent color, thickening the border of the display area, shading the display area, enlarging the text representing the number of results, and adding an icon (mark, text, etc.) to indicate that it is selected. The analysis information display control unit 117 may also highlight the display area when the pointer hovers over it, and then refine the result information when a click is performed.
[0117] The analysis information display control unit 117 may accept input of filtering conditions for result information from the evaluation user and display result information filtered to include only the risk survey results that meet the filtering conditions. This makes it possible to display only the result information filtered while maintaining the display of the analysis information (without filtering the risk survey results in the analysis information).
[0118] Furthermore, if filtering conditions (for example, combinations of questions and answers) are set for the analysis information, the results of the risk survey filtered by those filtering conditions will be further refined and displayed.
[0119] The filtering criteria for the result information can be any information included in the result information. Therefore, if the result information includes answer information, the analysis information display control unit 117 may accept the combination of question and answer as the filtering criteria.
[0120] The analysis information display control unit 117 may display the response information, which indicates the response status of each security risk as a result of the risk investigation, as part of the results information on the user terminal 40, based on the input of the evaluation user. The "response information" is, for example, expressed using keywords that represent the degree of acceptance of the evaluation user's response to the results of the risk investigation, such as "acceptable," "requires action," or "taken action." The response information may be input by the evaluation user by selecting from pre-prepared options, or by the evaluation user by text input. In addition to keywords indicating the degree of acceptance, the response information may also include notes entered by the person being evaluated.
[0121] Figures 5 and 6 show an example of the analysis information display screen AD displayed on the user terminal 40. The analysis information display screen AD includes the analysis information display area AA and the results display area RA.
[0122] The analysis information display area AA displays the first item input field IF1, the condition input field CF, the second item input field IF2, the analysis information AI, and the question reception object QO.
[0123] The first item input field IF1 accepts input for the first item, which forms the horizontal axis of the analysis information AI. As shown in Figure 6, the evaluation user selects the first item from the options presented in a pull-down list, for example. The condition input field CF shown in Figure 5 accepts input for the division conditions of the horizontal axis. The evaluation user selects the division conditions from the options presented in a pull-down list, for example. The second item input field IF2 accepts input for the second item, which forms the vertical axis of the analysis information AI. The evaluation user selects the second item from the options presented in a pull-down list, for example. Note that in the example in Figure 5, the condition input field CF for the first item is displayed, but the condition input field CF for the second item may also be displayed, or the condition input field CF for the first item may not be displayed at all.
[0124] The analysis information AI is a graph created based on the input content in the first item input field IF1, the condition input field CF, and the second item input field IF2. (For each of the multiple display areas in a coordinate system with the first item on the horizontal axis and the second item on the vertical axis, the number of results including the content of the first item and the content of the second item corresponding to the coordinate of the display area is shown.) If the input content of any of the first item input field IF1, the condition input field CF, or the second item input field IF2 is changed, the analysis information AI is regenerated and the new analysis information AI is displayed.
[0125] In the example in Figure 5, an analytical information AI is displayed with four display areas (first display area DA1, second display area DA2, third display area DA3, and fourth display area DA4), with the horizontal and vertical axes each divided into two. In this example, the horizontal axis (first item) is the security score ("Score" in Figure 5), and the vertical axis (second item) is the status of secondary transactions ("Deposit Information" in Figure 5).
[0126] The first display area DA1 shows the number of risk assessment results for individuals with a security score of 70 or higher and who have not had their personal information entrusted to them. The second display area DA2 shows the number of risk assessment results for individuals with a security score of less than 70 and who have not had their personal information entrusted to them. The third display area DA3 shows the number of risk assessment results for individuals with a security score of 70 or higher and who have had their personal information entrusted to them. The fourth display area DA4 shows the number of risk assessment results for individuals with a security score of less than 70 and who have had their personal information entrusted to them.
[0127] Furthermore, the third display area DA3 is displayed in a way that indicates a higher security risk than the first display area DA1 and the second display area DA2 (for example, colored yellow). In addition, the fourth display area DA4 is displayed in a way that indicates a higher security risk than the third display area DA3 (for example, colored red), and is displayed in a way that is different from the first display area DA1 and the second display area DA2, making it distinguishable from those areas.
[0128] The question receiving object QO accepts input of a combination of a question and its answer as a filtering condition for the analysis information AI. When an input operation is performed on the question receiving object QO in Figure 5, the question input field QF, the answer selection field AF, and the cancel object CO are displayed, as shown in Figure 6. The question input field QF accepts input of the question, for example, via a pull-down list. The answer selection field AF accepts answers to the question entered in the question input field QF, for example, via a pull-down list. When an input operation is performed on the cancel object CO, the question input field QF and the answer selection field AF are deleted (the entered filtering condition is cleared). Also, when the question input field QF and the answer selection field AF are displayed, an input operation is performed on the question receiving object QO, and the question input field QF and the answer selection field AF are added.
[0129] As shown in Figure 5, the results display area RA is displayed below the analysis information display area AA. The results display area RA displays the filtering condition input field NF and the results information list RL.
[0130] The filtering criteria input field NF accepts input for filtering criteria for the result information displayed in the result information list RL.
[0131] The results information list RL contains result information about the risk survey results that constitute the analysis information AI (counted in one of the display areas of the analysis information AI). Figure 7 is a continuation of the analysis information display screen AD of Figure 5. In the example in Figure 7, multiple result information for each contract unit is displayed side by side in the results information list RL. The results information list RL includes the first basic information RI1, the second basic information RI2, and the response information RI3 as result information. Note that the results display area RA displays some of the multiple result information included in the results information list RL, and the result information displayed in the results display area RA can be switched by operations such as scrolling left or right or switching pages.
[0132] The first basic information, RI1, includes the person being evaluated (the "Contractor Name" in Figure 7) and the risk response object, RO. The risk response object RO is an object that displays response information and accepts input of response information. When an input operation is performed on the risk response object RO, an input field for entering (selecting) response information is displayed. The response information entered in the input field is displayed on the risk response object RO.
[0133] The second basic information section, RI2, displays items that can be selected as either the first or second item (i.e., items that are displayed as options in the first item input field IF1 or the second item input field IF2 in the analysis information display area AA of Figure 5). In addition, items included in the second basic information section, RI2, that are selected as either the first or second item are highlighted (shaded in Figure 7).
[0134] Some items included in the second basic information RI2 are assigned a sort object SO or a filtering object NO. When an input operation is performed on the sort object SO, the left-right sorting order of the result information for each contract is changed based on the size of the item assigned the sort object SO (in Figure 7, "Score"). When an input operation is performed on the filtering object NO, filtering options are displayed. When an option is selected by the evaluation user, only the result information in the result information list RL whose content matches the selected option in the item assigned the filtering object NO (in Figure 7, "Deposit Information" or "Business Impact").
[0135] The response information RI3 contains multiple questions included in the risk assessment, along with the answers to each question. In the example in Figure 7, the questions are represented by symbols (codes), and the answers are represented by indicators (○ or ×). Each question is also associated with a question display object DO. When the pointer is hovered over a question display object DO, the content (text) of the question associated with that object is displayed, for example, in a pop-up window.
[0136] Figure 8 shows the state in the analysis information display screen AD of Figure 5 where one display area of the analysis information AI is selected. In Figure 8, the fourth display area DA4 is selected and highlighted. In addition, the results display area RA displays result information showing the results of the risk investigation included in the fourth display area DA4.
[0137] In the results information list RL, when an input operation is performed for the results information of any contract (for example, an input operation for the contract name such as "Contract A"), detailed information of the risk assessment results for that contract (including information not included in the results information list RL) is displayed on the user terminal 40. Figure 9 shows an example of the results information display screen RD displayed on the user terminal 40. In the results information display screen RD, the displayed information is switched by switching tabs TB.
[0138] <Report Output Section 118> The report output unit 118 is configured to output a report or document created based on the evaluation received by the evaluation reception unit 113 to the user terminal 40. The report or document includes at least all or part of the response data entered by the person being evaluated and the evaluation results by the evaluator (e.g., evaluation value, comments, etc.).
[0139] <Artificial Intelligence Department 120> The artificial intelligence unit 120 is configured to receive input from each functional unit and return the instructed output. The artificial intelligence used by each functional unit of the server device 10 may be common to all units, or it may be prepared individually for each functional unit.
[0140] The artificial intelligence unit 120 is an AI (Artificial Intelligence) equipped with learning models such as transformers including GPT (Generative Pretrained Transformer, including GPT-1, GPT-2, GPT-3, and GPT-4), BERT (Bidirectional Encoder Representations from Transformers), BART (Bidirectional and Auto-regressive Transformer), and language models such as recurrent neural networks (RNNs), and may include generative AI including large-scale language models. Large-scale language models are a type of generative AI and include models provided by services such as OpenAI's GPT, Google's Gemini, and Microsoft's Azure AI Studio. In addition, the artificial intelligence unit 120 can include any machine learning model, deep learning model, artificial intelligence model, etc.
[0141] The language model is an example of a learning model using a machine learning algorithm. Specific machine learning algorithms include nearest neighbors, naive Bayes, decision trees, support vector machines, and deep learning using neural networks. The artificial intelligence unit 120 can apply the above algorithms as appropriate.
[0142] The artificial intelligence unit 120 may have a trained model constructed by a learning method such as supervised learning, unsupervised learning, or self-supervised learning. In supervised learning, machine learning is performed using training data. Training data consists of pairs of input data and output data (correct answer data) for training. Furthermore, the language model may not only be one trained for a specific task, but also a general-purpose model that can be used universally for a wide range of tasks.
[0143] The artificial intelligence unit 120 may be a general-purpose natural language processing learning model, such as a Large Language Model (LLM), which has learned from a vast amount of data. An LLM is a learning model that has been pre-trained on a large amount of data consisting of text data, etc. (for example, (i) web content on the internet, or (ii) data stored in a predetermined database), and can perform various language processing tasks by being given a task. It can perform a wide range of natural language processing tasks, such as understanding sentence patterns and context, responding to questions, and generating sentences, according to the given prompts. Such a general-purpose learning model includes language models that can handle various tasks without fine-tuning using One-shot Learning or Few-shot Learning. Furthermore, the general-purpose learning model may also be configured to handle various tasks using Zero-shot Learning. The artificial intelligence used in each functional unit of the control unit 11 may be a separate learning model, or it may be a common general-purpose learning model.
[0144] The learning models included in the artificial intelligence unit 120 (such as the risk score calculation model, which are used in each functional unit) can undergo additional learning through transfer learning or fine-tuning. For example, the artificial intelligence unit 120 may perform additional learning and fine-tuning each time new data is registered, using this data as new training data. This improves the accuracy of the information output from the learning model.
[0145] The learning model included in the artificial intelligence unit 120 may be a learning model (distilled model) obtained by knowledge distillation using the original learning model. In knowledge distillation, a pre-trained model, such as a large-scale language model, is used as the teacher model, and the parameters of the student model are adjusted so that the output loss of the student model (distilled model) relative to the output (Soft Target Loss) of the teacher model is small. The student model is then trained, and this student model becomes the distilled model. Alternatively, the student model may be trained so that the output loss of the student model relative to the correct labels (Hard Target) of the teacher data (combinations of input and output data of the learning model) is small. Compared to the original learning model (teacher model), the distilled model has similar performance to the original learning model, but with fewer parameters and a lower processing load. Therefore, using a distilled model can reduce the cost of the information processing system 1.
[0146] For example, the learning model used in each functional unit may be a distilled model that has been trained using combinations of input and output data from a large-scale language model as training data. Alternatively, when the information processing system 1 is introduced, a large-scale language model may be used as the learning model in each functional unit, and once training data from the large-scale language model has been accumulated, the distilled model obtained by knowledge distillation using that training data may be used as the learning model in each functional unit.
[0147] <Display section> The display unit 211 of the subject terminal 20, the display unit 311 of the evaluator terminal 30, and the display unit 411 of the user terminal 40 each display the screen indicated by the screen data transmitted from the server device 10.
[0148] <Operation acquisition part> The operation acquisition unit 212 of the target terminal 20 receives operations from the person being evaluated using the target terminal 20. The operation acquisition unit 312 of the evaluator terminal 30 receives operations from the evaluator using the evaluator terminal 30. The operation acquisition unit 412 of the user terminal 40 receives operations from the user being evaluated using the user terminal 40.
[0149] 3. Information Processing Methods This section describes the information processing method of the server device 10. In this information processing method, each part of the server device 10 is executed by a computer as a step.
[0150] This information processing comprises a survey results acquisition step, an item acceptance step, and an analysis information display control step. In the survey results acquisition step, the results of multiple risk surveys are acquired. In the item acceptance step, input of a first item and a second item for analyzing and displaying multiple results is accepted from the evaluation user. In the analysis information display control step, analysis information is displayed for each of the multiple display areas in a coordinate system where the first item is on the horizontal axis and the second item is on the vertical axis, showing the number of results that include the content of the first item and the content of the second item corresponding to the coordinate of the display area.
[0151] Figure 10 is an activity diagram showing an example of the flow of information processing (analysis and display processing) performed by the information processing system 1. The information processing will be explained below in accordance with each activity in this activity diagram.
[0152] The analysis information display process begins with a request from the evaluation user to display the analysis information. The evaluation user instructs the display of the analysis information on the user terminal 40 (Activity A101). The server device 10 obtains the results of the risk survey that constitute the analysis information from the response database (Activity A102).
[0153] After the server device 10 acquires the results, the evaluation user inputs the first and second items on the user terminal 40 (Activity A103). The server device 10 receives the first and second items from the user terminal 40 (Activity A104). Subsequently, the server device 10 outputs analysis information using the received first and second items to the user terminal 40 (Activity A105). As a result, the analysis information is displayed on the user terminal 40 (Activity A106).
[0154] 4. Effect The operation of this embodiment can be summarized as follows: the evaluation user can analyze the results of the risk assessment of the person being evaluated according to any item of their choosing.
[0155] Although embodiments of the present invention have been described above, the present invention is not limited thereto and can be modified as appropriate without departing from the technical spirit of the invention.
[0156] 5. Others In the above embodiment, the server device 10 performed various storage and control functions, but instead of the server device 10, multiple external devices may be used. That is, various information and programs may be stored in a distributed manner across multiple external devices using blockchain technology or the like. In particular, the artificial intelligence unit 120 may be an external configuration of the server device 10. In that case, the external artificial intelligence unit 120 may be provided by, for example, an artificial intelligence service server, and is configured to receive input from each functional unit of the server device 10, receive requests to execute artificial intelligence services, and return the instructed output as a processing result to the server device 10. The artificial intelligence service server may be a server that provides services using a language model as a learning model, or a server that executes language processing tasks using a language model. The artificial intelligence service server may be constructed using an LLM. The artificial intelligence service server receives prompt input in the form of text, images, audio, etc., and generates and responds with answers to the prompts.
[0157] The control unit 11 does not necessarily have to include a question receiving unit 116. In other words, the information processing system 1 does not necessarily have to accept combinations of questions and answers as criteria for narrowing down the analysis information.
[0158] The embodiments of this model are not limited to the information processing system 1, but may also be an information processing method or a program. The information processing method comprises each step executed by the information processing system 1. The program causes a computer to execute each step of the information processing system 1.
[0159] The product may be provided in any of the following embodiments.
[0160] (1) An information processing system comprising at least one processor, wherein the processor is configured to perform the following steps by reading a program, wherein in the step of acquiring the results of a survey, the results of a plurality of risk surveys for the person being evaluated are acquired; in the step of receiving the item, input of a first item and a second item for analyzing and displaying the plurality of said results is received from the evaluation user; and in the step of displaying the analysis information, analysis information is displayed for each of a plurality of display areas in a coordinate system with the first item on the horizontal axis and the second item on the vertical axis, showing the number of said results including the content of the first item and the content of the second item corresponding to the coordinate of the display area, wherein the display area is an area obtained by dividing the planar area of the coordinate system along at least one of the horizontal axis and the vertical axis.
[0161] (2) An information processing system as described in (1) above, wherein in the analysis information display control step, the analysis information is displayed for each of the multiple display areas obtained by dividing the planar area of the coordinate system along both the horizontal and vertical axes, and the number of results including the content of the first item and the content of the second item corresponding to the coordinates of the display area.
[0162] (3) An information processing system as described in (1) or (2) above, wherein the first item and the second item are, respectively, a security score calculated based on the risk survey or an attribute of the person being evaluated.
[0163] (4) An information processing system as described in (3) above, wherein the attribute includes at least one of the following: the type of information deposited with the person being evaluated, the importance of the transactions conducted by the person being evaluated, and the status of the secondary transactions of the person being evaluated.
[0164] (5) An information processing system according to any one of (1) to (4) above, wherein in the item reception step, the system further receives input of division conditions for dividing the coordinate system along the horizontal axis or vertical axis from the evaluation user, and in the analysis information display control step, the system displays the analysis information for each of the multiple display areas obtained by dividing the horizontal axis or vertical axis with the division conditions, showing the number of results including the content of the first item and the content of the second item corresponding to the coordinates of the display area.
[0165] (6) An information processing system described in any one of (1) to (5) above, wherein the result is the result of the risk investigation conducted for each contract or transaction between the evaluation user and the evaluation subject.
[0166] (7) An information processing system according to any one of (1) to (6) above, wherein the processor is configured to further perform the following steps: in the question reception step, it receives from the evaluation user a combination of questions included in the risk survey and answers to those questions as filtering conditions; and in the analysis information display control step, it displays the analysis information for each of the multiple display areas, showing the number of results that satisfy the filtering conditions, including the content of the first item and the content of the second item corresponding to the coordinates of the display area.
[0167] (8) An information processing system according to any one of (1) to (7) above, wherein the analysis information display control step displays a list of result information showing the contents of each of the multiple results constituting the analysis information, and the result information includes at least the contents of the first item and the contents of the second item.
[0168] (9) An information processing system as described in (8) above, wherein the result information includes multiple pieces of answer information representing the answers to each of the multiple questions included in the risk survey.
[0169] (10) An information processing system as described in (9) above, wherein the response information is an indicator of the level of security measures for the responses to the questions.
[0170] (11) An information processing system according to any one of (8) to (10) above, wherein in the analysis information display control step, the system receives input from the evaluation user for the selection of the display area in the analysis information, highlights the selected display area, and displays the result information narrowed down to the results belonging to the selected display area.
[0171] (12) An information processing system according to any one of (8) to (11) above, wherein in the analysis information display control step, the system receives input of filtering conditions for the result information from the evaluation user and displays the result information that has been filtered to satisfy the filtering conditions.
[0172] (13) An information processing system according to any one of (1) to (12) above, wherein in the analysis information display control step, the display format for each display area is changed according to the level of security risk based on the combination of the content of the first item and the content of the second item.
[0173] (14) An information processing method comprising each step performed by the information processing system described in any one of (1) to (13) above.
[0174] (15) A program that causes a computer to perform each step of the information processing system described in any one of (1) to (13) above. Of course, this is not always the case.
[0175] Finally, while various embodiments relating to this disclosure have been described, these are presented as examples only and are not intended to limit the scope of the invention. These novel embodiments can be implemented in a variety of other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their variations are included in the scope and spirit of the invention, as well as in the claims and their equivalents. [Explanation of Symbols]
[0176] 1: Information Processing System 2: Communication lines 10: Server device 11: Control Unit 12: Storage section 13: Communications Department 14: Communications bus 20: Target user's device 21: Control Unit 22: Storage section 23: Communications Department 24: Input section 25: Output section 26: Communications bus 30: Evaluator terminal 31: Control Unit 32: Storage section 33: Communications Department 34: Input section 35: Output section 36: Communications bus 40: User terminal 41: Control Unit 42: Storage section 43: Communications Department 44: Input section 45: Output section 46: Communications bus 111: Basic Display Control Unit 112: Response Reception Department 113: Evaluation Reception Department 114: Department for obtaining survey results 115: Item Reception Department 116: Question Reception Department 117: Analysis Information Display Control Unit 118: Report Output Section 120: Artificial Intelligence Department 211:Display section 212: Operation acquisition section 311: Display section 312: Operation acquisition section 411: Display section 412: Operation acquisition section AA: Analysis information display area AD:Analysis information display screen AF: Answer selection field AI: Analysis information CF: Condition input field CO: Cancel Object DA1: 1st display area DA2: 2nd display area DA3: 3rd display area DA4: 4th display area DO: Question display object IF1: Input field for item 1 IF2: Input field for item 2 NF: Filtering criteria input field NO: Filtered object QF: Question input field QO: Question Reception Object RA:Result display area RD: Result information display screen RI1: 1st basic information RI2: 2nd basic information RI3: Answer Information RL: Result Information List RO: Risk-Responding Object SO: Sort object TB: Tab
Claims
1. An information processing system, Equipped with at least one processor, The aforementioned processor is configured to perform the following steps by reading a program: In the step of obtaining the survey results, the results of multiple risk assessments for the person being evaluated are obtained. In the item reception step, the user provides input for the first and second items for analyzing and displaying multiple results. In the analysis information display control step, the information processing system displays analysis information for each of a plurality of display areas in a coordinate system where the first item is the horizontal axis and the second item is the vertical axis, showing the number of results including the content of the first item and the content of the second item corresponding to the coordinate of the display area, wherein the display area is an area obtained by dividing the planar area of the coordinate system along at least one of the horizontal and vertical axes.
2. In the information processing system described in claim 1, An information processing system that, in the analysis information display control step, displays the analysis information for each of the multiple display areas obtained by dividing the planar area of the coordinate system along both the horizontal and vertical axes, showing the number of results including the content of the first item and the content of the second item corresponding to the coordinates of the display area.
3. In the information processing system described in claim 1, The first and second items are, respectively, a security score calculated based on the risk survey, or an information processing system that represents the attributes of the person being evaluated.
4. In the information processing system described in claim 3, An information processing system in which the attributes include at least one of the following: the type of information deposited with the person being evaluated, the importance of the transactions conducted by the person being evaluated, and the status of the secondary transactions of the person being evaluated.
5. In the information processing system described in claim 1, In the aforementioned item acceptance step, the user of the evaluation further accepts input of division conditions for dividing the coordinate system along the horizontal or vertical axis. An information processing system that, in the analysis information display control step, displays the analysis information for each of the multiple display areas obtained by dividing the horizontal or vertical axis according to the division condition, showing the number of results including the content of the first item and the content of the second item corresponding to the coordinates of the display area.
6. In the information processing system described in claim 1, The above results are the results of the risk investigation conducted for each contract or transaction between the evaluation user and the evaluation subject, according to the information processing system.
7. In the information processing system described in claim 1, The aforementioned processor is configured to perform the following steps: In the question submission step, the evaluation users submit questions and answers to those questions, using the combination of questions included in the risk survey as the filtering criteria. An information processing system that, in the analysis information display control step, displays the analysis information for each of the multiple display areas, showing the number of results that satisfy the filtering conditions, including the content of the first item and the content of the second item corresponding to the coordinates of the display area.
8. In the information processing system described in claim 1, In the aforementioned analysis information display control step, a list of result information showing the content of each of the multiple results constituting the analysis information is displayed along with the analysis information. An information processing system in which the result information includes at least the contents of the first item and the contents of the second item.
9. In the information processing system described in claim 8, An information processing system in which the aforementioned result information includes multiple response pieces of information representing the answers to each of the multiple questions included in the risk survey.
10. In the information processing system described in claim 9, The aforementioned response information is an information processing system that serves as an indicator of the level of security measures taken in responding to the aforementioned questions.
11. In the information processing system described in claim 8, The information processing system, in the analysis information display control step, receives input from the evaluation user for the selection of the display area in the analysis information, highlights the selected display area, and displays the result information narrowed down to the results belonging to the selected display area.
12. In the information processing system described in claim 8, The information processing system, in the analysis information display control step, receives input of filtering conditions for the result information from the evaluation user and displays the result information that has been filtered to satisfy the filtering conditions.
13. In the information processing system described in claim 1, An information processing system that, in the analysis information display control step, changes the display format for each display area according to the level of security risk based on the combination of the content of the first item and the content of the second item.
14. Information processing method, An information processing method comprising each step performed by the information processing system according to any one of claims 1 to 13.
15. It is a program, A program for causing a computer to perform each step of the information processing system described in any one of claims 1 to 13.