Risk information generation device, risk information generation method, and program

JP2026137426APending Publication Date: 2026-08-27NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025023524
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2026-08-27

AI Technical Summary

Benefits of technology

【0008】 本開示によれば、リスクの把握を容易にするための新たな技術が提供される。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026137426000001_ABST
    Figure 2026137426000001_ABST
Patent Text Reader

Abstract

We provide new technologies to make it easier to understand risks. [Solution] The risk information generating device relating to this disclosure acquires audit information representing the results of a security audit conducted on a target entity, uses the audit information to identify the degree of security measures in the target entity, identifies the degree of impact of the target entity on related entities that are associated with the target entity, and generates risk information indicating the degree of security measures and the degree of impact.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a risk information generation device, a risk information generation method, and a program.

Background Art

[0002] Risks are being evaluated in enterprises and the like. For example, Patent Document 1 discloses a system that executes a security audit for each node connected to a network subject to security auditing and publishes the results of the audit. The audit results can be aggregated and published for each organization such as a business unit.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Indicators for evaluating risks are not limited to the results of security audits in individual organizations and the like. The present disclosure has been made in view of this problem, and one of its purposes is to provide a new technology for facilitating the grasping of risks.

Means for Solving the Problems

[0005] The risk information generation device according to the present disclosure includes an acquisition unit that acquires audit information representing the results of a security audit performed on a target entity, a first specification unit that specifies the degree of adequacy of security measures in the target entity using the audit information, a second specification unit that specifies the degree of influence of the target entity on a related entity associated with the target entity, and a generation unit that generates risk information indicating the degree of adequacy and the degree of influence.

[0006] The risk information generation method relating to this disclosure is performed by a computer. The risk information generation method includes an acquisition step of acquiring audit information representing the results of a security audit conducted on a target entity; a first identification step of using the audit information to identify the degree of security measures in the target entity; a second identification step of identifying the degree of impact of the target entity on related entities that are associated with the target entity; and a generation step of generating risk information indicating the degree of security measures and the degree of impact.

[0007] The program relating to this disclosure causes a computer to perform the following steps: an acquisition step of acquiring audit information representing the results of a security audit conducted on a target entity; a first identification step of using the audit information to identify the degree of security measures in the target entity; a second identification step of identifying the degree of impact of the target entity on related entities that are associated with the target entity; and a generation step of generating risk information indicating the degree of security measures and the degree of impact. [Effects of the Invention]

[0008] This disclosure provides new technologies that facilitate risk assessment. [Brief explanation of the drawing]

[0009] [Figure 1] This diagram illustrates the general operation of a risk information generation device. [Figure 2] This is a block diagram illustrating the functional configuration of a risk information generation device. [Figure 3] This is a block diagram illustrating the hardware configuration of a computer that implements a risk information generation device. [Figure 4] This flowchart illustrates the processing flow performed by the risk information generation device. [Figure 5] This is a diagram illustrating a risk graph. [Figure 6] The second figure illustrates a risk graph. [Figure 7] An example of a risk graph that aggregates information about multiple target entities is provided. [Figure 8] This diagram illustrates a risk graph that further illustrates information regarding the handling of personal information. [Modes for carrying out the invention]

[0010] Embodiments of the present disclosure will be described in detail below with reference to the drawings. In each drawing, the same or corresponding elements are denoted by the same reference numerals, and redundant explanations are omitted as necessary for clarity. Unless otherwise specified, predetermined values ​​such as specified values ​​and thresholds are stored in advance in a storage device accessible from the device that uses those values. Furthermore, unless otherwise specified, the storage unit is composed of one or any number of storage devices.

[0011] <Overview> Figure 1 illustrates an overview of the operation of the risk information generation device 2000. Herein, Figure 1 is intended to facilitate understanding of the risk information generation device 2000's overview, and the operation of the risk information generation device 2000 is not limited to the operation shown in Figure 1.

[0012] The risk information generator 2000 generates risk information 40 for a combination of the target entity 10 and related entities 20. The risk information 40 indicates 1) the degree of security measures in the target entity 10, and 2) the degree of impact that the target entity 10 has on the related entities 20.

[0013] The impact that the target entity 10 has on the related entity 20 is, for example, the impact that the related entity 20 experiences as a result of a security-related incident occurring in the target entity 10. Security-related incidents include, for example, data breaches, unauthorized access, malware infections, or system failures. Security measures are measures taken to prevent the occurrence of the various incidents mentioned above.

[0014] The degree to which security measures are implemented will also be expressed as "security measures adequacy." Furthermore, the degree to which the target entity 10 has an impact on related entities 20 will also be expressed as "the degree of impact of the target entity 10 on related entities 20."

[0015] An entity refers to any entity that conducts business activities. For example, an entity could be a company, a department, a team, or an employee. Alternatively, an entity could be a group consisting of multiple companies, departments, or teams.

[0016] Target Entity 10 and Related Entity 20 are entities that have some kind of relationship with each other in their business activities. If both Target Entity 10 and Related Entity 20 are companies, for example, Target Entity 10 is an affiliated company of Related Entity 20. An affiliated company of Related Entity 20 is, for example, a company located below Related Entity 20 in the hierarchy of the corporate group to which Related Entity 20 belongs (for example, a subsidiary or sub-subsidiary of Related Entity 20). In addition, for example, an affiliated company of Related Entity 20 is a company that receives business outsourcing from Related Entity 20. In addition, for example, an affiliated company of Related Entity 20 is a company that provides goods or services (hereinafter referred to as "goods, etc.") to Related Entity 20.

[0017] Assume that the target entity 10 and the related entity 20 are departments or teams. In this case, for example, the target entity 10 is a department or team located below the related entity 20 in the hierarchy of departments or teams. Additionally, for example, the target entity 10 is a department or team that provides the results of activities (such as produced parts) to the related entity 20.

[0018] When the target entity 10 and the related entity 20 are employees, for example, the related entity 20 is the leader of the department or team to which the target entity 10 belongs.

[0019] The risk information generation device 2000 generates risk information 40, for example, in the following manner. The risk information generation device 2000 acquires audit information 30. The audit information 30 represents the results of a security audit conducted on the target entity 10. The risk information generation device 2000 uses the audit information 30 to identify the degree of adequacy of countermeasures for the target entity 10. The risk information generation device 2000 further identifies the degree of influence of the target entity 10 on the related entity 20. Then, the risk information generation device 2000 generates risk information 40 indicating the identified degree of adequacy of countermeasures for the target entity 10 and the identified degree of influence of the target entity 10 on the related entity 20.

[0020] <Examples of effects> According to the risk information generation device 2000, risk information 40 representing a pair of the degree of adequacy of security countermeasures for the target entity 10 and the degree of influence of the target entity 10 corresponding to the related entity 2 is generated. Therefore, by using the risk information generation device 2000, it is possible to comprehensively grasp the degree of adequacy of security countermeasures and the degree of influence of the target entity 10 on the related entity 20 for the target entity 10. Thus, according to the risk information generation device 2000, a new technology for facilitating the grasping of risks is provided.

[0021] [[ID=In this scenario, an incident occurring in target entity 10 could potentially affect related entity 20. Therefore, for related entity 20, strengthening security measures in target entity 10 is crucial.

[0022] However, the extent to which enhanced security measures in target entity 10 are important to related entity 20 depends on the magnitude of the impact that an incident occurring in target entity 10 would have on related entity 20. Specifically, if an incident occurring in target entity 10 has a relatively large impact on related entity 20, the importance of enhanced security measures in target entity 10 will be relatively high for related entity 20. On the other hand, if an incident occurring in target entity 10 has a relatively small impact on related entity 20, the importance of enhanced security measures in target entity 10 will be relatively low for related entity 20. For this reason, it is preferable to understand the degree of enhanced security measures in target entity 10 and the degree of impact of target entity 10 on related entity 20 in combination.

[0023] According to the risk information generation device 2000, risk information 40 is provided that shows the degree of security measures in the target entity 10 and the degree of influence of the target entity 10 on related entities 20. Therefore, the degree of security measures in the target entity 10 and the degree of influence of the target entity 10 on related entities 20, which are preferable to understand together, can be understood in combination.

[0024] The risk information generation device 2000 of this embodiment will be described in more detail below.

[0025] <Example of functional configuration> Figure 2 is a block diagram illustrating the functional configuration of the risk information generation device 2000. For example, the risk information generation device 2000 has an acquisition unit 2020, a first identification unit 2040, a second identification unit 2060, and a generation unit 2080. The acquisition unit 2020 acquires audit information 30. The first identification unit 2040 uses the audit information 30 to identify the degree of effectiveness of countermeasures for the target entity 10. The second identification unit 2060 identifies the degree of impact of the target entity 10 on related entities 20. The generation unit 2080 uses the degree of effectiveness of countermeasures identified by the first identification unit 2040 and the degree of impact identified by the second identification unit 2060 to generate risk information 40.

[0026] <Example of hardware configuration> Each functional component of the risk information generation device 2000 may be implemented by hardware (e.g., hardwired electronic circuits) or by a combination of hardware and software (e.g., a combination of electronic circuits and programs that control them). The following will further explain the case where each functional component of the risk information generation device 2000 is implemented by a combination of hardware and software.

[0027] Figure 3 is a block diagram illustrating the hardware configuration of computer 1000, which implements the risk information generation device 2000. Computer 1000 is any computer. For example, computer 1000 is a stationary computer such as a PC (Personal Computer) or a server machine. Alternatively, computer 1000 is a portable computer such as a smartphone or a tablet terminal. Alternatively, computer 1000 is an integrated circuit such as a SoC (System on Chip). Computer 1000 may be a dedicated computer designed to implement the risk information generation device 2000, or it may be a general-purpose computer.

[0028] For example, by installing a predetermined application on computer 1000, the various functions of the risk information generation device 2000 are realized on computer 1000. The above application consists of programs for realizing each functional component of the risk information generation device 2000. The method of obtaining the above program is arbitrary. For example, the program can be obtained from a storage medium (such as a DVD (Digital Versatile Disc) or USB (Universal Serial Bus) memory) on which the program is stored. Alternatively, the program can be obtained by downloading it from a server device that manages the storage device on which the program is stored.

[0029] Computer 1000 includes a bus 1020, a processor 1040, memory 1060, a storage device 1080, an input / output interface 1100, and a network interface 1120. The bus 1020 is a data transmission path for the processor 1040, memory 1060, storage device 1080, input / output interface 1100, and network interface 1120 to send and receive data from each other. However, the method of connecting the processor 1040 and other components is not limited to bus connection.

[0030] The processor 1040 is a type of arithmetic unit such as a CPU (Central Processing Unit), MPU (Microprocessor Unit), GPU (Graphics Processing Unit), DSP (Digital Signal Processor), or FPGA (Field-Programmable Gate Array). The memory 1060 is a main memory device implemented using RAM (Random Access Memory), etc. The storage device 1080 is an auxiliary storage device implemented using a hard disk, SSD (Solid State Drive), memory card, or ROM (Read Only Memory), etc.

[0031] The input / output interface 1100 is an interface for connecting the computer 1000 with input / output devices. For example, input devices such as keyboards and output devices such as display devices are connected to the input / output interface 1100.

[0032] The network interface 1120 is an interface for connecting computer 1000 to a network. This network may be a LAN (Local Area Network) or a WAN (Wide Area Network).

[0033] The storage device 1080 stores programs that implement each functional component of the risk information generation device 2000 (programs that implement the aforementioned applications). The processor 1040 reads these programs into memory 1060 and executes them to implement each functional component of the risk information generation device 2000.

[0034] The risk information generation device 2000 may be implemented using one computer 1000 or multiple computers 1000. In the latter case, the configuration of each computer 1000 does not need to be identical and can be different.

[0035] <Processing flow> Figure 4 is a flowchart illustrating the processing flow performed by the risk information generation device 2000. The acquisition unit 2020 acquires audit information 30 (S102). The first identification unit 2040 uses the audit information 30 to identify the degree of effectiveness of countermeasures for the target entity 10 (S104). The second identification unit 2060 identifies the degree of impact of the target entity 10 on related entities 20 (S106). The generation unit 2080 generates risk information 40 (S108).

[0036] <Acquisition of audit information 30: S102> The acquisition unit 2020 acquires the audit information 30 (S102). There are various ways in which the acquisition unit 2020 acquires the audit information 30. For example, the audit information 30 is pre-stored in any storage unit in a manner accessible from the risk information generation device 2000. In this case, the acquisition unit 2020 acquires the audit information 30 by reading it from the storage unit. The audit information 30 to be read from the storage unit is specified, for example, by the user of the risk information generation device 2000.

[0037] Here, let's assume that audit information 30 is stored in the storage unit for each of the multiple entities. In this case, the acquisition unit 2020 acquires the audit information 30 for the target entity 10 from among these multiple audit information 30. To do this, for example, the acquisition unit 2020 accepts the specification of an identifier for the entity to be treated as the target entity 10. Then, the acquisition unit 2020 acquires the audit information 30 stored in the storage unit in association with the specified identifier as the audit information 30 for the target entity 10. Any information that can identify the entity (for example, a name or identification number) can be used as the entity identifier.

[0038] There are various ways in which the acquisition unit 2020 can accept the designation of the target entity 10. For example, suppose the risk information generation device 2000 is available via a web system. In this case, for example, a user of the risk information generation device 2000 accesses the web system from a user terminal (such as a PC or smartphone) and provides the identification information of the target entity 10 to the risk information generation device 2000 via the web system.

[0039] The audit information 30 may be transmitted to the risk information generation device 2000 from another device. In this case, the acquisition unit 2020 acquires the audit information 30 by receiving the audit information 30 transmitted from the other device. For example, the audit information 30 is provided to the risk information generation device 2000 from a user terminal via the aforementioned web system.

[0040] <Regarding the contents of audit information 30> The audit information 30 for target entity 10 is information that shows the results of a security audit conducted on target entity 10. For example, the audit information 30 indicates the degree of security measures in target entity 10. The degree of security measures is expressed as a score within a predetermined range, such as between 0 and 10. The score may be expressed as an integer or as a decimal.

[0041] The audit information 30 may indicate the degree to which each of the multiple security measures is implemented in the target entity 10. In this case, for example, the audit information 30 may show a score for each of the multiple security measures.

[0042] Furthermore, the audit information 30 does not need to show all the results of the audit conducted on the target entity 10; it is sufficient to show information that allows for an understanding of the degree of security measures in the target entity 10 (for example, the score mentioned above).

[0043] <Identification of the level of adequacy of countermeasures: S104> The first identification unit 2040 uses the audit information 30 to identify the level of security measures for the target entity 10 (S104). For example, suppose the audit information 30 shows a score representing the level of security measures for the target entity 10. In this case, the first identification unit 2040 uses the score shown in the audit information 30 as the level of security measures.

[0044] In addition, for example, the audit information 30 may show a score for each of the multiple security measures, representing the degree of adequacy of that security measure in the target entity 10. In this case, the first identification unit 2040 calculates a statistical value of the multiple scores shown in the audit information 30 and uses this statistical value as the degree of adequacy of the security measures in the target entity 10. The statistical value may be a simple sum, a weighted sum, a simple average, or a weighted average. When a weighted sum or a weighted average is used as the statistical value, the weight of each security measure is predetermined. Information representing the weight of each security measure is stored in advance in a storage unit accessible from the risk information generation device 2000, for example.

[0045] <Identifying the degree of impact: S106> The second identification unit 2060 identifies the degree of influence of the target entity 10 on the related entity 20 (S106). The following is an example of how to identify the degree of influence.

[0046] For example, the second identification unit 2060 acquires information representing the relationship between the target entity 10 and related entities 20 (hereinafter referred to as "related information"), and uses this related information to determine the degree of impact. The method for acquiring related information is the same as the method for acquiring audit information 30.

[0047] Related information, for example, shows the type of relationship and the content of the relationship for target entity 10 and related entity 20. The type of relationship can be expressed as, for example, "same group," "outsourcing," or "provision of goods, etc." The type of relationship "same group" indicates, for example, that target entity 10 and related entity 20 are companies belonging to the same corporate group, or departments or teams belonging to the same company. The type of relationship "outsourcing" indicates that work has been outsourced from related entity 20 to target entity 10. The type of relationship "provision of goods, etc." indicates that goods, etc., have been provided from target entity 10 to related entity 20.

[0048] The content of the relationship shown in the related information differs depending on the type of relationship between the target entity 10 and the related entity 20. Let's assume the type of relationship is "same group". In this case, for example, the content of the relationship indicates the positional relationship between the target entity 10 and the related entity 20 within the group. The positional relationship between the target entity 10 and the related entity 20 is expressed, for example, as the position of the target entity 10 relative to the related entity 20 (e.g., subsidiary or sister company), or as the position of the related entity 20 relative to the target entity 10 (e.g., parent company or sister company).

[0049] Let's assume the type of relationship is "outsourcing." In this case, the details of the relationship would include, for example, the type of work being outsourced and the scale of that work. The type of work could include various categories such as defense, space, infrastructure, automotive, or consumer electronics. The type of work could also indicate whether it falls under a specific type of work (for example, a specific critical task). The scale of the work could be expressed, for example, by the total number of people involved in the work.

[0050] Let's assume the type of relationship is "provision of goods, etc." In this case, the details of the relationship would include, for example, the type of goods, etc. provided and the scale of the provision. The scale of the provision of goods, etc. could be expressed, for example, the total number of goods provided, the number of people engaged in the service provided, or the sales and profits generated from the provision. Sales and profits could be expressed, for example, as figures for the most recent year.

[0051] The second identification unit 2060 identifies the degree of influence using the related information. Assume that the types of related entities belong to the same group. In this case, the second identification unit 2060 determines that the closer the distance between the target entity 10 and the related entity 20 within the group, the greater the influence of the target entity 10 on the related entity 20.

[0052] For example, suppose a group of companies is represented by a graph in which entities represented by nodes are connected by edges. In this case, for example, the second identification unit 2060 uses the number of edges between the target entity 10 and related entities 20 as the degree of influence.

[0053] However, the distance represented by each edge may be different. In this case, the second identification unit 2060 uses the sum of the distances represented by each edge existing between the target entity 10 and the related entity 20 as the degree of influence.

[0054] For example, the distance given to edges representing vertical positional relationships (such as parent-child relationships) can be made greater than the distance given to edges representing horizontal positional relationships (such as sibling relationships). By doing this, the influence of horizontal positional relationships (such as sibling relationships) can be made greater than the influence of vertical positional relationships (such as parent-child relationships).

[0055] Let's assume the type of relationship is outsourcing. In this case, for example, the Second Specific Department 2060 identifies the degree of impact based on the type and scale of the work. For example, a score representing the degree of impact is predetermined for each type of work. Also, a score representing the degree of impact is predetermined for each of several numerical ranges of the scale of the work. Here, the larger the scale of the work outsourced to the target entity 10, the higher the score assigned.

[0056] The second identification unit 2060 uses relevant information to identify scores based on the type of work and scores based on the scale of work, respectively, and calculates statistical values ​​for the identified scores. The second identification unit 2060 then uses the calculated statistical values ​​as the impact. Statistical values ​​can include simple sums, weighted sums, simple averages, or weighted averages. When weighted sums or weighted averages are used as statistical values, the weights for the type of work and the scale of work are predetermined. Information representing these weights is pre-stored in a memory unit accessible from, for example, the risk information generation device 2000.

[0057] Let's assume the type of relationship is the provision of goods or services. In this case, for example, the second specific unit 2060 identifies the degree of impact based on the type of goods or services and the scale of the provision of those goods or services. For example, a score representing the degree of impact is predetermined for each type of goods or services. Also, a score representing the degree of impact is predetermined for each of several numerical ranges of the scale of the provision. Here, the larger the scale of the provision of goods or services by the target entity 10, the higher the score assigned.

[0058] The second identification unit 2060 uses relevant information to identify scores based on the type of goods, etc., and scores based on the scale of provision, respectively, and calculates statistical values ​​for the identified scores. The second identification unit 2060 then uses the calculated statistical values ​​as the degree of impact. As statistical values, simple sums, weighted sums, simple averages, or weighted averages can be used. When weighted sums or weighted averages are used as statistical values, the weights for the type of goods, etc., and the scale of provision, respectively, are predetermined. Information representing these weights is stored in advance in a memory unit accessible from, for example, the risk information generation device 2000.

[0059] The second identification unit 2060 may determine the degree of impact using information other than related information. For example, the second identification unit 2060 may determine the degree of impact of the target entity 10 on the related entity 20 based on the size of the target entity 10. In this case, a score is predetermined for each of several numerical ranges representing the size of the target entity 10. The second identification unit 2060 determines the score corresponding to the numerical range to which the size of the target entity 10 belongs as the degree of impact based on the size of the target entity 10. Note that the larger the size of the target entity 10, the higher the score assigned to it.

[0060] If the size of the target entity 10 is used to determine the degree of impact, the second identification unit 2060 obtains information representing the size of the target entity 10. The method for obtaining this information is the same as the method for obtaining audit information 30.

[0061] The size of Entity 10 can be expressed, for example, by the number of members, the number of group companies, the number of members in group companies, the number of contracted companies, the number of contracted workers, sales, or profits. The number of members of an entity represents the number of people belonging to that entity (e.g., the number of employees belonging to a company, the number of members belonging to a department, or the number of members belonging to a project team). The number of group companies of an entity represents the number of companies belonging to a corporate group that includes the entity (hereinafter referred to as "group companies"). The number of members belonging to group companies represents the total number of members for each group company. The number of contracted companies of an entity represents the number of external companies to which the entity outsources its work. The number of contracted workers represents the total number of people working on the outsourced work at the external companies to which the work has been outsourced. The sales and profits of an entity represent the sales and profits of that entity, respectively. For example, sales and profits are expressed as figures for the most recent year.

[0062] The second identification unit 2060 may determine the degree of influence of the target entity 10 on the related entity 20 based on the degree of similarity between the name of the target entity 10 and the name of the related entity 20. Here, the degree of influence is determined such that the higher the similarity between the name of the target entity 10 and the name of the related entity 20, the higher the degree of influence. For example, the second identification unit 2060 calculates the similarity between the name of the target entity 10 and the name of the related entity 20, and uses the calculated similarity as the degree of influence.

[0063] The similarity between two names can be calculated, for example, using the edit distance. Specifically, the second identification unit 2060 calculates the edit distance between a first text representing the name of the target entity 10 and a second text representing the name of the related entity 20. The second identification unit 2060 then calculates the similarity such that the smaller the calculated edit distance, the larger the similarity. For example, the reciprocal of the edit distance calculated between the first text and the second text is used to determine the similarity between the name of the target entity 10 and the name of the related entity 20.

[0064] The second identification unit 2060 may determine the degree of influence of the target entity 10 on the related entity 20 by comprehensively considering the various factors described above. For example, the second identification unit 2060 may determine a first degree of influence based on related information, a second degree of influence based on the size of the target entity 10, and a third degree of influence based on the similarity between the name of the target entity 10 and the name of the related entity 20. The second identification unit 2060 then uses the statistical values ​​of the first degree of influence, the second degree of influence, and the third degree of influence as the degree of influence of the target entity 10 on the related entity 20.

[0065] Statistical values ​​such as simple sum, weighted sum, simple average, or weighted average can be used. The weights of each element are predetermined. Information representing these weights is stored in advance in a memory unit accessible from, for example, the risk information generation device 2000.

[0066] <Generation of Risk Information 40: S108> The generation unit 2080 generates risk information 40 (S108). For example, the generation unit 2080 generates risk information 40 that includes text representing the degree of effectiveness of countermeasures for the target entity 10 and text representing the degree of impact of the target entity 10 on related entities 20.

[0067] In addition, the generation unit 2080 may generate risk information 40 that includes a graph showing pairs of the degree of effectiveness of countermeasures for the target entity 10 and the degree of impact of the target entity 10 on related entities 20. Hereinafter, the graph showing the pairs of effectiveness and impact will be called a risk graph.

[0068] Figure 5 illustrates a risk graph. In the risk graph 100 of Figure 5, the X-axis represents the degree of effectiveness of countermeasures, and the Y-axis represents the degree of impact. The risk graph 100 of Figure 5 shows points 102 that represent pairs of the degree of effectiveness of countermeasures for the target entity 10 and the degree of impact of the target entity 10 on related entities 20.

[0069] Here, to represent the level of preparedness in the X-axis direction, in the risk graph 100 of Figure 5, the further you are from the origin, the lower the level of preparedness. The same applies to the other risk graphs 100 shown later.

[0070] Figure 6 is a second diagram illustrating a risk graph. Risk graph 100 in Figure 6 is a so-called bubble chart, and marks 104 are shown instead of points 102. The size of marks 104 represents some characteristic of the target entity 10 other than the degree of countermeasures and impact. For example, the size of marks 104 represents the size of the target entity 10.

[0071] <Identifying the 10 entities requiring attention> For users of the risk information generator 2000 (for example, stakeholders of related entity 20), target entity 10 with a low level of preparedness and a high impact is an entity that requires particular attention. Therefore, it is preferable for related entity 20 to be able to easily identify target entity 10 with a low level of preparedness and a high impact. Hereinafter, target entity 10 with a low level of preparedness and a high impact on related entity 20 will be referred to as an entity requiring attention.

[0072] The generation unit 2080 may determine whether the target entity 10 is an entity requiring attention. To this end, the generation unit 2080 determines whether the level of countermeasures taken by the target entity 10 is below the first threshold. The first threshold is a value that represents the boundary between a sufficiently high level of countermeasures and a level of countermeasures that is not sufficiently high. The generation unit 2080 also determines whether the influence of the target entity 10 on the related entity 20 is above the second threshold. The second threshold is a value that represents the boundary between a sufficiently high level of influence and a level of influence that is not sufficiently high.

[0073] The generation unit 2080 identifies the target entity 10 as an entity requiring attention if it determines that the level of countermeasures is below the first threshold and that the level of impact is above the second threshold.

[0074] The first and second thresholds may be predetermined or specified by the user of the risk information generation device 2000.

[0075] The generation unit 2080 may further include information in the risk information 40 indicating whether or not the target entity 10 is an entity requiring attention. In this way, users of the risk information generation device 2000 can easily determine whether or not the target entity 10 is an entity that requires attention.

[0076] For example, the generation unit 2080 generates risk information 40 which includes text indicating the degree of effectiveness of countermeasures for the target entity 10, text indicating the degree of impact of the target entity 10 on related entities 20, and text indicating whether or not the target entity 10 is an entity requiring attention.

[0077] In addition, the generation unit 2080 may generate a risk graph that shows whether or not the target entity 10 is a high-risk entity. For example, the generation unit 2080 may make the display of points 102 different when the target entity 10 is a high-risk entity and when the target entity 10 is not a high-risk entity. More specifically, the generation unit 2080 may make the color, shape, or both of the points 102 when the target entity 10 is a high-risk entity and when the target entity 10 is not a high-risk entity different from each other. The same applies when using marks 104.

[0078] In addition, the generation unit 2080 may make the range of the risk graph 100 where the entities of concern are plotted distinguishable from other ranges. For example, the generation unit 2080 may assign a different color or pattern to the range where the entities of concern are plotted compared to other ranges.

[0079] <Output of Risk Information 40> The risk information generator 2000 outputs risk information 40 in various ways. For example, the risk information generator 2000 stores the risk information 40 in an arbitrary memory unit. Alternatively, for example, the risk information generator 2000 displays the risk information 40 on a display device by outputting it to a display device or the like. Alternatively, for example, the risk information generator 2000 transmits the risk information 40 to other devices. For example, as mentioned above, suppose a user of the risk information generator 2000 uses the risk information generator 2000 from a user terminal via a web system. In this case, the risk information generator 2000 transmits the risk information 40 to the user terminal.

[0080] <Graph showing multiple entities> The risk information generation device 2000 may identify pairs of countermeasure adequacy and impact for each of the multiple target entities 10. In this case, the related entities 20 are common among the multiple target entities 10. When the countermeasure adequacy and impact have been identified for each of the multiple target entities 10, it is preferable for the first identification unit 2040 to generate risk information 40 that aggregates the information for the multiple target entities 10.

[0081] For example, the risk information 40 includes a table that shows, for each target entity 10, a pair of the degree to which the countermeasures for that target entity 10 are adequate and the degree to which that target entity 10 has an impact on related entities 20. Each row in the table corresponds to the identifier of the target entity 10 and shows the degree to which the countermeasures for that target entity 10 are adequate and the degree to which that target entity 10 has an impact on related entities 20.

[0082] In addition, for example, risk information 40 includes a risk graph 100 which aggregates information about multiple target entities 10. Figure 7 illustrates a risk graph which aggregates information about multiple target entities 10.

[0083] In Figure 7, each mark 104 represents the impact level in the X coordinate, the level of countermeasures adequacy in the Y coordinate, and the scale in the size for each target entity 10. Each mark 104 is also labeled with the name of the target entity 10. Furthermore, in Figure 7, marks 104 where the level of countermeasures adequacy is below the first threshold and the impact level is above the second threshold are colored with diagonal lines.

[0084] The risk graph 100 in Figure 7 shows the distribution of risk for multiple target entities 10 associated with the related entity 20, represented by a combination of the degree of adequacy of countermeasures taken by the target entities 10, the degree of influence of the target entities 10 on the related entity 20, and the size of the target entities 10. This distribution allows for easy understanding of the risk for multiple target entities 10 associated with the related entity 20.

[0085] The risk graph 100 may further indicate information regarding the handling of personal information for each target entity 10. For example, the risk information generator 2000 identifies whether or not each target entity 10 handles sensitive personal information. The risk information generator 2000 then generates a risk graph 100 in which the marks for each target entity 10 are such that they can be identified as handling sensitive personal information or not. For example, the marks for target entities 10 that handle sensitive personal information and the marks for target entities 10 that do not handle sensitive personal information may have different colors or shapes.

[0086] Figure 8 illustrates a risk graph 100 that further illustrates information regarding the handling of personal information. In Figure 8, the marks 104 of target entities 10 that handle sensitive personal information are represented by a dot pattern. On the other hand, the marks 104 of target entities 10 that do not handle sensitive personal information are represented in white.

[0087] Note that in Figure 8, the size of each mark 104 is the same. However, as explained with reference to Figure 7, the risk information generator 2000 may also change the size of each mark 104 in Figure 8 according to the scale of the target entity 10.

[0088] There are various methods for determining whether or not sensitive personal information is handled by each target entity 10. For example, the risk information generator 2000 acquires information for each target entity 10 indicating whether or not sensitive personal information is handled by that target entity 10. By using this acquired information, it is possible to determine whether or not sensitive personal information is handled by each target entity 10.

[0089] In addition, for example, the risk information generator 2000 acquires information indicating the types of personal information handled by each target entity 10. The risk information generator 2000 determines whether a predetermined type is included among the types of personal information handled by the target entity 10. If a predetermined type is included among the types of personal information handled by the target entity 10, the risk information generator 2000 determines that important personal information is being handled by that target entity 10.

[0090] Whether or not the target entity 10 handles sensitive personal information, and the types of personal information handled by the target entity 10, may be indicated in the audit information 30 or in other information.

[0091] Although the present disclosure has been described above with reference to embodiments, the present disclosure is not limited to the embodiments described above. Various modifications to the structure and details of the present disclosure can be made as can be understood by those skilled in the art within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.

[0092] Each drawing is merely illustrative to illustrate one or more embodiments. Each drawing may be associated with one or more other embodiments rather than with only one specific embodiment. As those skilled in the art will understand, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings, for example, to create embodiments not explicitly shown or described. Not all features or steps shown in any one drawing to illustrate an exemplary embodiment are necessarily required, and some features or steps may be omitted. The order of steps shown in any of the drawings may be changed as appropriate.

[0093] The program, when loaded into a computer, includes a set of instructions (or software code) for causing the computer to perform one or more of the functions described in the embodiments. The program may be stored on a non-temporary computer-readable medium or a physical storage medium. Examples, but not limited to, include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, CD-ROM, digital versatile disc (DVD), Blu-ray® disc or other optical disc storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices. The program may be transmitted over a temporary computer-readable medium or a communication medium. Examples, but not limited to, include temporary computer-readable medium or a communication medium that includes electrically, optically, acoustically or otherwise propagating signals.

[0094] Some or all of the above embodiments may also be described as follows, but are not limited to the following: (Note 1) A means of obtaining audit information that represents the results of a security audit conducted on the target entity, A first identification means for identifying the degree of security measures in the target entity using the aforementioned audit information, A second identification means for identifying the degree of influence of the target entity on related entities that are associated with the target entity, A risk information generating device having generating means for generating risk information indicating the degree of completeness and the degree of impact. (Note 2) The acquisition means acquires the audit information for each of the multiple target entities, The first identification means identifies the degree of completeness for each of the plurality of target entities, The second identification means identifies the degree of influence for each of the plurality of target entities, The risk information generation device according to Appendix 1, wherein the generation means generates risk information indicating a combination of the degree of completeness and the degree of impact for each of the multiple target entities. (Note 3) The generation means generates a graph in which marks are plotted at coordinates determined by a combination of the degree of completeness and the degree of influence for each of the multiple target entities, and includes the graph in the risk information. The size of the mark on the target entity is determined based on the size of the target entity, according to the risk information generating device described in Appendix 2. (Note 4) The generation means generates a graph in which marks are plotted at coordinates determined by a combination of the degree of completeness and the degree of influence for each of the multiple target entities, and includes the graph in the risk information. The risk information generating device according to claim 2, wherein the form of the mark of the target entity differs depending on whether the target entity handles sensitive personal information or not. (Note 5) The generating means is A determination is made as to whether the degree of fulfillment is below the first threshold, and whether the degree of influence is above the second threshold. A risk information generating device according to any one of the appendices 1 to 4, which includes information representing the result of the said determination in the risk information. (Note 6) The risk information generating device according to any one of the appendices 1 to 4, wherein the second identification means identifies the degree of influence based on the positional relationship between the target entity and the related entity in the hierarchy of the group to which both the target entity and the related entity belong. (Note 7) The second identification means is a risk information generating device according to any one of the appendices 1 to 4, which identifies the degree of impact based on the type of work entrusted from the related entity to the target entity, the scale of the work, or both. (Note 8) The risk information generating device according to any one of the appendices 1 to 4, wherein the second identifying means identifies the degree of impact based on the type of goods or services provided from the related entity to the target entity, the scale of the provision, or both. (Note 9) The risk information generating device according to any one of the appendices 1 to 4, wherein the second identification means identifies the degree of impact based on the similarity between the name of the target entity and the name of the related entity. (Note 10) A retrieval step to obtain audit information representing the results of a security audit conducted on the target entity, A first identification step involves using the aforementioned audit information to identify the degree of security measures in the target entity, A second identification step of identifying the degree of influence of the target entity on related entities that are associated with the target entity, A risk information generation method performed by a computer, comprising a generation step of generating risk information indicating the degree of completeness and the degree of impact. (Note 11) A retrieval step to obtain audit information representing the results of a security audit conducted on the target entity, A first identification step involves using the aforementioned audit information to identify the degree of security measures in the target entity, A second identification step of identifying the degree of influence of the target entity on related entities that are associated with the target entity, A program that causes a computer to perform a generation step of generating risk information indicating the degree of completeness and the degree of impact.

[0095] Some or all of the elements (e.g., configuration and function) described in Appendices 2 through 9 that are dependent on Appendice 1 may also be dependent on Appendices 10 and 11 in the same way as those described in Appendices 2 through 9. Some or all of the elements described in any appendice may be applicable to various hardware, software, recording means, systems, and methods for recording software. [Explanation of Symbols]

[0096] 10 Target Entities 20 Related Entities 30 Audit Information 40. Risk Information 100 Risk Graph 102 points 104 Mark 1000 computers 1020 Bus 1040 processor 1060 memory 1080 Storage Devices 1100 Input / Output Interface 1120 Network Interface 2000 Risk Information Generator 2020 Acquisition Department 2040 1st Specific Department 2060 2nd Specific Section 2080 Generation part

Claims

1. A means of obtaining audit information that represents the results of a security audit conducted on the target entity, A first identification means for identifying the degree of security measures in the target entity using the aforementioned audit information, A second identification means for identifying the degree of influence of the target entity on related entities that are associated with the target entity, A risk information generating device having generating means for generating risk information indicating the degree of completeness and the degree of impact.

2. The acquisition means acquires the audit information for each of the multiple target entities, The first identification means identifies the degree of completeness for each of the plurality of target entities, The second identification means identifies the degree of influence for each of the multiple target entities, The risk information generation device according to claim 1, wherein the generation means generates risk information indicating a combination of the degree of completeness and the degree of influence for each of the plurality of target entities.

3. The generation means generates a graph in which marks are plotted at coordinates determined by a combination of the degree of completeness and the degree of influence for each of the multiple target entities, and includes the graph in the risk information. The risk information generating device according to claim 2, wherein the form of the mark on the target entity is determined based on the size of the target entity.

4. The generation means generates a graph in which marks are plotted at coordinates determined by a combination of the degree of completeness and the degree of influence for each of the multiple target entities, and includes the graph in the risk information. The risk information generating device according to claim 2, wherein the form of the mark of the target entity differs depending on whether the target entity handles sensitive personal information or not.

5. The generating means is A determination is made as to whether the degree of fulfillment is below the first threshold, and whether the degree of influence is above the second threshold. A risk information generating device according to any one of claims 1 to 4, wherein the risk information includes information representing the result of the determination.

6. The risk information generating device according to any one of claims 1 to 4, wherein the second identifying means identifies the degree of influence based on the positional relationship between the target entity and the related entity in the hierarchy of the group to which both the target entity and the related entity belong.

7. The risk information generating device according to any one of claims 1 to 4, wherein the second identifying means identifies the degree of impact based on the type of work entrusted from the related entity to the target entity, the scale of the work, or both.

8. The risk information generating apparatus according to any one of claims 1 to 4, wherein the second identifying means identifies the degree of impact based on the type of goods or services provided from the related entity to the target entity, the scale of the provision, or both.

9. A retrieval step to obtain audit information representing the results of a security audit conducted on the target entity, A first identification step involves using the aforementioned audit information to identify the degree of security measures in the target entity, A second identification step of identifying the degree of influence of the target entity on related entities that are associated with the target entity, A risk information generation method performed by a computer, comprising a generation step of generating risk information indicating the degree of completeness and the degree of impact.

10. A retrieval step to obtain audit information representing the results of a security audit conducted on the target entity, A first identification step involves using the aforementioned audit information to identify the degree of security measures in the target entity, A second identification step of identifying the degree of influence of the target entity on related entities that are associated with the target entity, A program that causes a computer to perform a generation step of generating risk information indicating the degree of completeness and the degree of impact.

Citation Information

Patent Citations

  • System, method and program for supporting security audit

    JP2003140987A