Diagnostic logic selection device, diagnostic logic selection method, and program

JP2026126994APending Publication Date: 2026-08-05CLOUDBASE INC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
CLOUDBASE INC
Filing Date
2025-03-04
Publication Date
2026-08-05

AI Technical Summary

Benefits of technology

【0007】 本開示に係る診断ロジック選別装置によれば、前記一の情報資産が遵守すべき前記一の セキュリティポリシーに適合する診断ロジックを選別することが可能となる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026126994000001_ABST
    Figure 2026126994000001_ABST
Patent Text Reader

Abstract

This invention provides a diagnostic logic selection device, method, and program for selecting diagnostic logic that conforms to the security policies that information assets must comply with. [Solution] In the diagnostic logic selection system SSS, the diagnostic logic selection device SS includes a storage unit KI that stores in advance multiple diagnostic logics for checking whether multiple information assets comply with multiple security policies, an extraction unit CY that searches for multiple diagnostic logics based on one of the multiple security policies that one of the multiple information assets must comply with, and extracts at least one diagnostic logic that conforms to the one security policy, and a determination unit HA that determines whether the one diagnostic logic conforms to the one security policy that the one information asset must comply with, based on at least one of the one information asset and one security policy, and the extracted at least one diagnostic logic.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a diagnostic logic selection device, a diagnostic logic selection method, and a program.

Background Art

[0002] The IT risk management system described in Patent Document 1 aims to enhance compliance with regulations and the like defined in regulations and the like held by a general organization, that is, to ensure that the organization complies with the regulations and the like (for example, paragraphs 0002-0005 and 0048 of Patent Document 1). To achieve the above object, the IT risk management system and the like perform (1) extracting vulnerabilities from data such as control items and control actions included in control elements decomposed from control policies, (2) associating and displaying the extracted vulnerabilities with the control elements, information assets, and threats, and (3) displaying operations related to the regulations and the like based on the control compliance level (for example, claim 1 of Patent Document 1). from the data of control items, control actions, etc. included in the control elements decomposed from the control policy, (2) associating and displaying the extracted vulnerabilities with the control elements, information assets, threats, etc., and (3) displaying operations related to the control based on the control compliance level (for example, claim 1 of Patent Document 1). することを目的の1つとする(例えば、特許文献1の段落0002-0 005、0048)。前記ITリスクマネジメントシステム等は、前記目的を達成すべく 、(1)統制ポリシーから分解された統制要素に含まれる統制項目、統制行為等のデータ から脆弱点(vulnerability)を抽出すること、(2)前記抽出された脆弱点と、前記統 制要素、情報資産、脅威とを関連付けて表示すること、及び、(3)統制コンプライアン スレベルに基づき、前記統制等についての作業を表示することを含む(例えば、特許文献 1の請求項1)。

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the above-described IT risk management system and the like, although operations related to the above-described regulations and the like, that is, operations related to the above-described control policies can be displayed, いての作業、即ち、上記した統制ポリシーについての作業を表示することができるものの For example, to diagnose whether the above-mentioned information assets comply with the aforementioned control policy Of the multiple diagnostic logics that may be used, which of the diagnostic logics will be used? I couldn't decide whether or not they should be there.

[0005] The purpose of this disclosure is to ensure that the information assets comply with the security policies that must be followed. A diagnostic logic selection device, a diagnostic logic selection method, and a program capable of selecting a diagnostic logic. The objective is to provide. [Means for solving the problem]

[0006] To address the above-mentioned issues, the diagnostic logic selection device related to this disclosure uses multiple information assets Multiple diagnostic logs to check whether multiple security policies are being complied with A memory unit that pre-stores the data, and a system that one of the multiple information assets complies with. Based on one of the aforementioned security policies, By searching for multiple diagnostic logics, it is possible to find one that conforms to the aforementioned security policy. An extraction unit that extracts at least one diagnostic logic that has the potential to do so, and the one information asset and At least one of the aforementioned security policies, and at least one of the extracted Based on one diagnostic logic, the extracted at least one diagnostic logic is, Determine whether the information asset described in item 1 conforms to the security policy described in item 1 that must be followed. Includes a judgment unit. [Effects of the Invention]

[0007] According to the diagnostic logic selection device relating to this disclosure, the information asset that the first information asset must comply with It becomes possible to select diagnostic logic that conforms to the security policy.

Brief Description of the Drawings

[0008] [Figure 1] Shows the configuration of the diagnostic logic selection system SSS of the embodiment. [Figure 2] Shows the configuration of the diagnostic logic selection device SS of the embodiment. [Figure 3] Shows the configuration of the public cloud PK of the embodiment. [Figure 4] Shows the configuration of the terminal TM of the embodiment. [Figure 5] It is a flowchart showing the operation of the diagnostic logic selection system SSS of the embodiment. [Figure 6] Shows the information asset JS of the embodiment. [Figure 7] Shows the security policy SP of the embodiment. [Figure 8] Shows the diagnostic logic SL of the embodiment. [Figure 9] Shows the association of the information asset JS, security policy SP, and diagnostic logic SL of the embodiment. [Figure 10] Shows the hardware configuration of the diagnostic logic selection device SS, public cloud PK, and terminal TM of the embodiment. [Figure 11] Shows the hardware configuration based on the software implementation of the diagnostic logic selection device SS, public cloud PK, and terminal TM of the embodiment.

Modes for Carrying Out the Invention

[0009] Embodiments of the diagnostic logic selection system according to the present disclosure will be described.

[0010] 〈Embodiment〉 The diagnostic logic selection system SSS of the embodiment will be described.

[0011] 〈Configuration of the Embodiment〉 <Configuration of the diagnostic logic selection system SSS> Figure 1 shows the configuration of the diagnostic logic selection system SSS according to the embodiment.

[0012] The diagnostic logic selection system SSS of Embodiment 1, as shown in Figure 1, is a diagnostic logic... The sorting device SS, the public cloud PK, and multiple terminals TM1, TM2, TM3, , and, including.

[0013] Diagnostic logic selection device SS, public cloud PK, and multiple terminals TM1, TM2 TM3, etc., as shown in Figure 1, refers to a network NW (for example, the Internet They are interconnected via (T).

[0014] The diagnostic logic sorting device SS, as shown in Figure 1, comprises a storage unit KI and an extraction unit CY, It includes a determination unit HA and a display control unit HS.

[0015] The memory unit KI, as shown in Figure 1, stores multiple information assets JS1, JS2, JS3, ... Check whether it complies with multiple security policies SP1, SP2, SP3, etc. It has multiple diagnostic logics, SL1, SL2, SL3, etc., pre-stored for checking. .

[0016] The extraction unit CY extracts, for example, one of several information assets JS1, JS2, JS3, ... Information asset JS (for example, information asset JS1 (also shown in Figure 6)) must comply with several security requirements. Security policy SP1, SP2, SP3, etc., one of the security policies SP( For example, based on security policy SP3 (also illustrated in Figure 7), multiple diagnostic logics By searching for SL1, SL2, SL3, etc., you can find a security policy SP. (For example, the security policy SP3 mentioned above) may be compliant, at least One diagnostic logic SL (for example, diagnostic logics SL3, SL4 (also shown in Figure 8)) Extract.

[0017] Details of the operation of the extraction unit CY will be described later.

[0018] The decision unit HA determines one information asset JS (for example, the information asset JS1 mentioned above) and one security At least one of the security policy SPs (for example, the security policy SP3 mentioned above) In addition, at least one diagnostic logic SL (for example, the diagnostic logic S mentioned above) Based on L3, SL4), at least one diagnostic logic SL (for example, the diagnostic logic described above) JIC SL3, SL4) and one information asset JS (for example, the information asset JS1 mentioned above) comply One security policy SP that must be followed (for example, the security policy SP3 mentioned above) Determine whether or not it conforms to the ) standard.

[0019] Details of the operation of the decision unit HA will be described later.

[0020] The display control unit HS can handle multiple terminals, for example, for multiple users US1, US2, US3, etc. Of TM1, TM2, TM3, etc., one user US (for example, user US1) (1) one information asset JS (for example, the information asset JS1 mentioned above) and Of one security policy SP (for example, security policy SP3 mentioned above) (1) at least one of the above, and (2) at least one diagnostic logic SL (e.g., the diagnostic as described above) Of the logic SL3 and SL4, one information asset JS (for example, the information asset JS1 mentioned above) ), to one security policy SP (for example, security policy SP3 mentioned above) The diagnostic logic SL that was determined to be suitable (for example, diagnostic logic SL3) is linked to it. Display it.

[0021] Details of the operation of the display control unit HS will be described later.

[0022] Public cloud PK, as shown in Figure 1, is for example, a company with multiple users. Multiple information assets such as US1, US2, US3, etc., JS1, JS2, JS3, etc., Multiple security policies that must be followed for multiple information assets JS1, JS2, JS3, etc. Includes SP1, SP2, SP3, etc.

[0023] Multiple terminals TM1, TM2, TM3, etc. are multiple users US1, US2, US3, It is used by , and .

[0024] In the following sections, for the sake of clarity and ease of understanding, for example, multiple names will be collectively referred to as a single name. For example, information assets JS1, JS2, JS3, etc., are collectively referred to as information asset JS. Sometimes.

[0025] <Configuration of the diagnostic logic sorting device SS> Figure 2 shows the configuration of the diagnostic logic sorting device SS according to the embodiment.

[0026] The diagnostic logic selection device SS of the embodiment is shown in Figure 2, and the input / output section NY (SS ) and a processing unit SY(SS), a memory unit KI(SS), and a communication unit TU(SS) .

[0027] The input / output unit NY(SS) is, for example, the administrator of the diagnostic logic selection device SS (not shown). However, it is used to perform input and output for monitoring and controlling the operation of the diagnostic logic selection device SS. The input / output section NY(SS) can handle, for example, a keyboard, mouse, LCD monitor, and printer. That is the case.

[0028] The processing unit SY(SS) consists of the extraction unit CY, the judgment unit HA, and the display control unit HS (Figure 1). (This indicates that) is responsible for the processing that should be performed.

[0029] The memory unit KI(SS) stores, for example, the data necessary for processing by the processing unit SY(SS). .

[0030] The Communications Unit (TU) (SS) uses the network NW to access public cloud PK and multiple endpoints. It communicates with terminals TM1, TM2, TM3, etc. (all illustrated in Figure 1).

[0031] <Public Cloud PK Configuration> Figure 3 shows the configuration of the public cloud PK in the embodiment.

[0032] The public cloud PK of Embodiment 1, as shown in Figure 3, has an input / output section NY (PK ) and a processing unit SY(PK), a memory unit KI(PK), and a communication unit TU(PK) are included. .

[0033] The input / output unit NY(PK) is used by the administrator of the public cloud PK (not shown). It is used to monitor and control the operation of the PK cloud. The input / output section NY(PK) is Examples include keyboards, mice, LCD monitors, and printers.

[0034] The processing unit SY(PK) handles, for example, multiple information assets JS1, JS2, JS3, etc. (Figure 1) As shown in the diagram, this involves monitoring multiple security policies SP1, SP2, SP3, This involves managing (as shown in Figure 1).

[0035] The memory unit KI(PK) stores, for example, the data necessary for processing by the processing unit SY(PK). .

[0036] The communication unit TU (PK) communicates via the network NW to the diagnostic logic selection device SS and multiple It communicates with terminals TM1, TM2, TM3, etc. (all illustrated in Figure 1).

[0037] <Terminal™ Configuration> Figure 4 shows the configuration of the terminal TM in the embodiment.

[0038] As shown in Figure 4, the terminal TM of Embodiment 1 consists of an input / output unit NY(TM) and a processing unit S It has Y(TM), a memory unit KI(TM), and a communication unit TU(TM).

[0039] The input / output section NY(TM) is used by user US to use terminal TM. Examples of NY(TM) products include keyboards, mice, LCD monitors, and printers.

[0040] The processing unit SY(TM) is used, for example, when the information asset JS (shown in Figure 1) is subject to security policy - A diagnostic logic SL to check whether or not the SP (illustrated in Figure 1) is being complied with. As shown in Figure 1, the diagnostic logic sorting device SS (shown in Figure 1) is required to sort the following: Perform the following process.

[0041] The memory unit KI(TM) stores, for example, the data necessary for processing by the processing unit SY(TM). .

[0042] The communications unit TU(TM) communicates via the network NW with the diagnostic logic selection device SS and public It communicates with the PK cloud (both illustrated in Figure 1).

[0043] <Correspondence> The memory unit KI corresponds to the "memory unit," the extraction unit CY corresponds to the "extraction unit," and the judgment unit HA The "Decision Unit" corresponds to the "Display Control Unit," and the Display Control Unit HS corresponds to the "Display Control Unit."

[0044] <Operation of the Embodiment> Figure 5 is a flowchart showing the operation of the diagnostic logic selection system SSS of the embodiment. ru.

[0045] Figure 6 shows the information asset JS of the embodiment.

[0046] Figure 7 shows the security policy SP of the embodiment.

[0047] Figure 8 shows the diagnostic logic SL of the embodiment.

[0048] Figure 9 shows the correspondence between the information asset JS, security policy SP, and diagnostic logic SL of the embodiment. To indicate attachment.

[0049] The operation of the diagnostic logic selection system SSS of this embodiment will be explained with reference to Figures 5 to 9. I will reveal it.

[0050] To facilitate explanation and understanding, user US1 will use terminal TM1 to provide the following information: It is assumed that the diagnostic logic selection device SS will be contacted. (1) Information asset JS1 (shown in Figure 6) owned by user US1 is compromised by multiple security Which of the following policies should be followed? (Shown in Figure 7) ? (2) Information asset JS1 has its security policy SP (for example, security policy To diagnose whether or not SP3 is being complied with, multiple diagnostic logics SL1, SL2 Which of the following should be used? (Shown in Figure 8.)

[0051] Step ST10: In the diagnostic logic selection device SS, from user US1's terminal TM1, Upon receiving an inquiry regarding the information asset JS1 as described above, the extraction unit CY (shown in Figure 1) will be called. ) is a public cloud PK (illustrated in Figure 1) with multiple security policy SPs. 1. SP2, SP3, etc., among the information assets JS1 "Data DTa (Storage Service)" (Possible use) (Illustrated in Figure 6) Security points that are deemed to be required to comply LICE SP, i.e., Security Policy SP3, states that "Data DT shall, in principle, be stored." At that time, choose to encrypt the data (as shown in Figure 7).

[0052] The extraction unit CY selects the above-mentioned information asset JS1 "Data DTa (Storage)" for example. Using the phrase "Data DTa" within "Service available" as the search key, multiple Seki Security Policy SP1: "User US account ACs will, in principle, be issued with multi-factor authentication." "To carry out," SP2 "SSH port PO (SSH) is, in principle, accessible only from within the company." SP3 "Data DT should, in principle, be encrypted when stored." This is done by searching for "thing".

[0053] After the above selection, the extraction unit CY will follow security policy SP3 "Data DT is, in principle Based on the principle of "encrypting when saving," the storage unit of the diagnostic logic sorting device SS Search for multiple diagnostic logics SL1, SL2, SL3, etc. (illustrated in Figure 8) within KI. Therefore, the extraction unit CY will adhere to security policy SP3 "Data DT is, in principle, And, when saving, it may conform to the requirement of encryption, in other words, information assets J S1 "Data DTa (Storage service available)" is a security policy - We comply with SP3, which states that "Data DT should, in principle, be encrypted when stored." Diagnostic logic SL3 "Data D" may be used to diagnose whether or not it is true. When T uses a storage service, it encrypts the data when saving it. SL4 "When data DT uses the virtual machine service, it is encrypted when saving data." Extract the characters "る" (all illustrated in Figure 8).

[0054] Here, the extraction unit CY performs the above search, for example, security policy SP3, multiple The diagnostic logics SL1, SL2, SL3, etc., are each converted into multidimensional vectors (features). Replace the security policy SP3 vector with the diagnostic logic SL1, SL2, SL3 Compare each of the vectors and find the diagnostic logic SL that is closest to both vectors (for example, You may also extract the diagnostic logics SL3 and SL4.

[0055] The extraction unit CY also performs the above search based, for example, on security policy SP3. , queries (for example, the words "data", "save" that make up security policy SP3) Create a query consisting of "encryption," and use that query to perform multiple diagnostic logics. Among SL1, SL2, SL3, etc., the diagnostic logic SL that corresponds to the aforementioned query (for example) Alternatively, you may extract the diagnostic logics SL3 and SL4.

[0056] Step ST20: In the diagnostic logic selection device SS, the judgment unit HA (shown in Figure 1) is, Information asset JS1 "Data DTa (possibility of using storage service)", and Seki Security Policy SP3: "Data DT should, in principle, be encrypted when stored." At least one of the following, as well as diagnostic logic SL3 "Data DT, Storage Service When using or saving, encrypt the data. Also, the diagnostic logic SL4 "Data DT However, when using the virtual machine service, the diagnostic process is based on the principle that "encryption is required when saving." Whether ZIC SL3 and SL4 comply with Security Policy SP3, in other words, Diagnostic logics SL3 and SL4 are used when information asset JS1 complies with security policy SP3. To determine whether or not it is appropriate to use this method to determine whether or not it is true.

[0057] Here, the decision unit HA makes the above decision, for example, (1) Information asset JS1 "Data DTa (Storage service available) The phrase "Data DTa", "Storage service (2) Security Policy SP3 "Data DT will, in principle, be stored The phrases "data DT", "encryption", and (3)(3A) diagnostic logic SL3 "When using the storage service, data is encrypted when it is saved." The phrases within "to do" are "Data DT", "Storage Service", and (3B) Diagnostic Logic SL4. "When data DT uses the virtual machine service, it encrypts the data when saving it." You may also want to focus on the terms "Data DT" and "Virtual Machine Service."

[0058] As is clear from the above, the phrase "storage service" in the information asset JS1 is, It is included in the disconnection logic SL3, but not in the diagnostic logic SL4. As a result, a judgment is made. Department HA's diagnostic logic SL3 determines the security policy S that information asset JS1 must comply with. It was determined that it conforms to P3, while on the other hand, the diagnostic logic SL4 states that information asset JS1 must comply with It is determined that this does not comply with Security Policy SP3.

[0059] Step ST30: In the diagnostic logic selection device SS, the display control unit HS (shown in Figure 1) As shown in Figure 9, the information asset JS1 "Data DTa (Use of Storage Service)" is used. (Possible) and Security Policy SP3 "Data DT should, in principle, be stored When encryption is performed, the diagnostic logic SL3 "Data DT will use the storage service When using, when saving, encrypt, and link it to user US1's terminal TM1. The output is displayed on the input / output section NY(TM) (for example, an LCD monitor).

[0060] The display control unit HS displays the above-mentioned information assets (JS1, security policy SP3, diagnostic). In addition to displaying the linked disconnection logic SL3, the information is also provided by the extraction unit CY and the judgment unit HA. The same applies to information assets other than JS1, such as JS2, JS3, etc. (as shown in Figure 6). Based on the results of the extraction and judgment (steps ST10 and ST20 in Figure 5), the results shown in Figure 9 are obtained. For example, (1) Information Asset JS2 "Data DTb (Availability of Virtual Machine Service) (Yes) and Security Policy SP3 "Data DT should, in principle, be saved when, Encryption, and diagnostic logic SL4 "Data DT uses virtual machine service In the case of saving, encrypt the data, and display the information associated with it, and (2) Information Asset JS3 "User US Account AC" and security policy SP1 "User U S's account AC should, in principle, be issued using multi-factor authentication, and the diagnostic logic SL 1. Issue all user US account ACs with multi-factor authentication and diagnostic logic SL 2. Link the statement "Issue only the account AC of a specific user US with single-factor authentication" to the table. You may also have them demonstrate it.

[0061] The display control unit HS uses the information asset JS (for example, information asset JS1) and security as described above. Security Policy SP (for example, Security Policy SP3) and Diagnostic Logic SL (for example) Instead of linking and displaying the three elements (1) information Information Asset JS (e.g., Information Asset JS1), and Diagnostic Logic SL (e.g., Diagnostic Logic) It is also acceptable to link and display only the two parties of (2) Security Policy S P (e.g., Security Policy SP3), and Diagnostic Logic SL (e.g., Diagnostic Logic It is also acceptable to display only the two items (Jick SL3) linked together.

[0062] <Effects of the Embodiment> As described above, the diagnostic logic selection system SSS of the embodiment uses multiple diagnostic logics Of the SL1, SL2, SL3, etc., information asset JS1 must comply with security policies. This makes it possible to select a diagnostic logic SL3 that is compatible with C-SP3.

[0063] <Hardware configuration of the embodiment> Figure 10 shows the diagnostic logic selection device SS, public cloud PK, and terminal TM of the embodiment. This shows the hardware configuration.

[0064] The diagnostic logic selection device SS, public cloud PK, and terminal TM of the embodiment are as described above. To perform the function, as shown in Figure 10, it includes a processing circuit SYO, and if necessary, It further includes an input circuit NYU and an output circuit SYU.

[0065] The processing circuit SYO is dedicated hardware. The processing circuit SYO is for diagnostic logic selection. Device SS, public cloud PK, terminal TM's processing unit SY(SS), processing unit SY(PK) ), and realize the functions of the processing unit SY(TM) (illustrated in Figures 2 to 4).

[0066] Processing circuits SYO can be, for example, single circuits, complex circuits, programmed processors, or parallel circuits. Programmed processor, ASIC (Application Specific Integrated Circuit) FPGA (Field Programmable Gate Array), or a combination of these. ru.

[0067] The input circuit NYU and output circuit SYU are, for example, diagnostic logic selection device SS, public The inputs and outputs related to the operation of the processing circuit SYO are transmitted between the cloud PK and the outside of the terminal TM. They exchange power.

[0068] <Hardware configuration based on software implementation of the embodiment> Figure 11 shows the diagnostic logic selection device SS, public cloud PK, and terminal TM of the embodiment. This shows the hardware configuration based on the software implementation.

[0069] The diagnostic logic selection device SS, public cloud PK, and terminal TM of the embodiment are shown in Figure 11. As shown, it includes a processor PRO and a memory circuit KIO, and, if necessary, input It further includes a power circuit NYU and an output circuit SYU.

[0070] The PRO processor is the CPU (Central Processing Unit) that executes programs. Processing unit, processing unit, arithmetic unit, microprocessor, microcomputer, DSP ( Also known as Digital Signal Processing. The PRO processor is a diagnostic logic. Sorting device SS, public cloud PK, terminal TM processing unit SY(SS), processing unit SY( The functions of PK and the processing unit SY(TM) (shown in Figures 2 to 4) are realized.

[0071] Processor PRO implements the above functions using software, firmware, or This is done through a combination of software and firmware. The data is written as a program (PRG) and stored in the memory circuit (KIO).

[0072] Processor PRO reads the program PRG mentioned above from the memory circuit KIO and executes it. This enables the above-mentioned functions. The above-mentioned program PRG is the diagnostic logic. Sorting device SS, public cloud PK, terminal TM processing unit SY(SS), processing unit SY( PK) and the procedures and methods of the processing unit SY(TM) are to be executed by the computer. Yes, I can.

[0073] Here, the memory circuit KIO is, for example, RAM (Random Access Memory), ROM (Read Flash memory, EPROM (Erasable Programmable Read Only Memory), Flash memory, EPROM (Erasable Programmable Read Only Memory) mory), EEPROM (Electrically Erasable Programmable Read-Only Memory), etc. , non-volatile or volatile semiconductor memory, as well as magnetic disks, flexible disks Optical discs, compact discs, minidiscs, DVDs (Digital Versatile Discs) And so on.

[0074] Diagnostic logic sorting device SS, public cloud PK, terminal TM processing unit SY(SS) Of the functions of the processing unit SY(PK) and processing unit SY(TM), some functions are processed by the processing circuit SY O (illustrated in Figure 10) is used to implement this, while other functions are implemented by processor PRO (Figure 1 This may be achieved by (as shown in Figure 1).

[0075] As described above, the diagnostic logic selection device SS, public cloud PK, and terminal TM The functions of the SY(SS), SY(PK), and SY(TM) processing units are determined by the hardware. This can be achieved through software, firmware, or a combination thereof.

[0076] The input circuit NYU and output circuit SYU are, for example, diagnostic logic selection device SS, public Inputs and outputs related to the operation of the processor PRO between the cloud PK and the external terminal TM. They exchange power.

[0077] <Example of structure> The diagnostic logic selection device, diagnostic logic selection method, and program relating to this disclosure are, for example, The following configuration is present.

[0078] [Item 1] To check whether multiple information assets comply with multiple security policies A memory unit that pre-stores multiple diagnostic logics, One of the aforementioned information assets must comply with the aforementioned security policies Based on one of the security policies of the C, the aforementioned multiple diagnostic logics are searched. This may result in at least one diagnosis that is compliant with the aforementioned security policy. An extraction unit that extracts the disconnection logic, At least one of the aforementioned information asset and the aforementioned security policy, Based on the extracted at least one diagnostic logic, the extracted at least one One diagnostic logic is suitable for the security policy that the information asset must comply with. A judgment unit that determines whether or not they match, A diagnostic logic sorting device that includes this.

[0079] [Item 2] At least one of the above information assets and the above security policy is placed on the user's terminal. Both include one and the at least one diagnostic logic of the security policy. The system further includes a display control unit that links and displays the diagnostic logic that has been determined to be suitable, The diagnostic logic device described in item 1.

[0080] [Item 3] One of the aforementioned information assets must comply with the aforementioned security policies Based on one of the security policies of the C, multiple information assets are protected by multiple security Searching for multiple diagnostic logics to check whether or not the policy is being complied with. This allows for at least one diagnosis that may comply with the aforementioned security policy. The extraction process for extracting logic, At least one of the aforementioned information asset and the aforementioned security policy, Based on the extracted at least one diagnostic logic, the extracted at least one One diagnostic logic is suitable for the security policy that the information asset must comply with. A judgment process to determine whether or not they match, A diagnostic logic selection method that includes this.

[0081] [Item 4] On the computer, One of the aforementioned information assets must comply with the aforementioned security policies Based on one of the security policies of the C, multiple information assets are protected by multiple security Searching for multiple diagnostic logics to check whether or not the policy is being complied with. This allows for at least one diagnosis that may comply with the aforementioned security policy. The extraction process for extracting logic, At least one of the aforementioned information asset and the aforementioned security policy, Based on the extracted at least one diagnostic logic, the extracted at least one One diagnostic logic is suitable for the security policy that the information asset must comply with. A judgment process to determine whether or not they match, A program to execute. [Explanation of Symbols]

[0082] SSS Diagnostic Logic Selection System, SS Diagnostic Logic Selection Device, PK Public Loud, TM terminal, NW network, KI memory unit, CY extraction unit, HA judgment unit , HS display control section.

Claims

1. To check whether multiple information assets comply with multiple security policies A memory unit that pre-stores multiple diagnostic logics, One of the aforementioned information assets must comply with the aforementioned security policies Based on one of the security policies of the C, the aforementioned multiple diagnostic logics are searched. This may result in at least one diagnosis that is compliant with the aforementioned security policy. An extraction unit that extracts the disconnection logic, At least one of the aforementioned information asset and the aforementioned security policy, Based on the extracted at least one diagnostic logic, the extracted at least one One diagnostic logic is suitable for the security policy that the information asset must comply with. A judgment unit that determines whether or not they match, A diagnostic logic sorting device that includes this.

2. At least one of the above information assets and the above security policy is placed on the user's terminal. Both include one and the at least one diagnostic logic of the security policy. The system further includes a display control unit that links and displays the diagnostic logic that has been determined to be suitable, The diagnostic logic device according to claim 1.

3. One of the aforementioned information assets must comply with the aforementioned security policies Based on one of the security policies of the C, multiple information assets are protected by multiple security Searching for multiple diagnostic logics to check whether or not the policy is being complied with. This allows for at least one diagnosis that may comply with the aforementioned security policy. The extraction process for extracting logic, At least one of the aforementioned information asset and the aforementioned security policy, Based on the extracted at least one diagnostic logic, the extracted at least one One diagnostic logic is suitable for the security policy that the information asset must comply with. A judgment process to determine whether or not they match, A diagnostic logic selection method that includes this.

4. On the computer, One of the aforementioned information assets must comply with the aforementioned security policies Based on one of the security policies of the C, multiple information assets are protected by multiple security Searching for multiple diagnostic logics to check whether or not the policy is being complied with. This allows for at least one diagnosis that may comply with the aforementioned security policy. The extraction process for extracting logic, At least one of the aforementioned information asset and the aforementioned security policy, Based on the extracted at least one diagnostic logic, the extracted at least one One diagnostic logic is suitable for the security policy that the information asset must comply with. A judgment process to determine whether or not they match, A program to execute.