Risk information processing device, risk information providing system, risk information processing method, risk information providing method, and recording medium

The risk information processing apparatus and system address the challenge of comprehensive cyber security investment judgment by selecting relevant parameters, calculating management risk values, and outputting display information, thereby facilitating easy confirmation of multiple information pieces for investment decisions.

WO2025134248A1PCT designated stage expired Publication Date: 2025-06-26NEC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2023/045587
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-20
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Companies face challenges in comprehensively judging cyber security investment decisions, as existing systems primarily focus on system vulnerability assessments without considering a broader range of internal and external information such as laws, regulations, and industry trends.

Method used

A risk information processing apparatus and system that selects parameters affecting business indicators from cyber security guidelines, calculates management risk values using acquired functions, and outputs display information to facilitate easy confirmation of multiple information pieces for investment judgment.

Benefits of technology

Enables companies to easily confirm and assess multiple information pieces necessary for cyber security investment judgments, providing a comprehensive view of cyber security risks and their impact on business indicators.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2023045587_26062025_PF_FP_ABST
    Figure JP2023045587_26062025_PF_FP_ABST
Patent Text Reader

Abstract

In order to easily check a plurality of pieces of information to be used in investment determination for cyber security in a company, a risk information processing device according to the present disclosure comprises: a parameter selection means for selecting parameters that affect the management index of the company from among parameters that indicate actions and factors which are required for satisfying a requirement for ensuring the cyber security, in guidelines pertaining to cyber security for management; a risk function acquisition means for acquiring a function for calculating, on the basis of the values of at least some of the selected parameters, management risk values that are values indicating a state of a risk item which indicates a management risk in business management; a management risk calculation means for calculating the management risk values on the basis of the values of the parameters and the function; and an information output means for outputting display information that is for displaying a list of at least some of the calculated management risk values side by side.
Need to check novelty before this filing date? Find Prior Art

Description

Risk information processing device, risk information providing system, risk information processing method, risk information providing method, and recording medium

[0001] The present disclosure relates to a risk information processing device, a risk information providing system, a risk information processing method, a risk information providing method, and a recording medium.

[0002] Patent Document 1 discloses a vulnerability risk assessment system that assesses risks related to vulnerabilities in a system that executes information processing related to a business.

[0003] Japanese Patent Application Laid-Open No. 2017-224063

[0004] When corporate management decides on cybersecurity investments, it is necessary to make a comprehensive judgment based not only on indicators of the cybersecurity of information processing systems, but also on multiple pieces of information both inside and outside the company, such as laws and regulations and industry trends.

[0005] An object of the present disclosure is to provide a risk information processing device and the like that enables a company to easily check multiple pieces of information used in making investment decisions for cybersecurity.

[0006] A risk information processing device in one form of the present disclosure comprises a parameter selection means for selecting parameters that affect a company's management indicators from parameters that indicate actions and factors necessary to realize the requirements for ensuring cybersecurity in guidelines for cybersecurity for management; a risk function acquisition means for acquiring a function for calculating a management risk value, which is a value that indicates the state of a risk item, which is an item that indicates management risk in corporate management, based on the values ​​of at least some of the selected parameters; a management risk calculation means for calculating the management risk value based on the parameter values ​​and the function; and an information output means for outputting display information for displaying a list of at least some of the calculated management risk values ​​side by side.

[0007] A risk information provision system in one embodiment of the present disclosure comprises the above-mentioned risk information processing device, a terminal device that outputs a definition of a management risk value to the risk information processing device, and a display device that displays a list of at least a portion of the management risk values ​​output by the risk information processing device.

[0008] A risk information processing method in one embodiment of the present disclosure selects parameters that affect a company's management indicators from parameters that indicate the actions and factors necessary to realize the requirements for ensuring cybersecurity in guidelines for cybersecurity for management, obtains a function for calculating a management risk value, which is a value that indicates the state of a risk item, which is an item that indicates management risk in corporate management, based on the values ​​of at least some of the selected parameters, calculates the management risk value based on the parameter values ​​and the function, and outputs display information for displaying a list of at least some of the calculated management risk values ​​side by side.

[0009] In one embodiment of the risk information providing method of the present disclosure, a risk information processing device executes the above-mentioned risk information processing method, a terminal device outputs a definition of a management risk value to the risk information processing device, and a display device displays a list of at least a portion of the management risk values ​​output by the risk information processing device.

[0010] In one embodiment of the present disclosure, a recording medium is a recording medium that records a program that causes a computer to execute the following processes: selecting parameters that affect a company's management indicators from parameters that indicate actions and factors necessary to realize the requirements for ensuring cybersecurity in guidelines for cybersecurity for management; obtaining a function for calculating a management risk value, which is a value that indicates the state of a risk item, which is an item that indicates management risk in corporate management, based on the values ​​of at least some of the selected parameters; calculating the management risk value based on the values ​​of the parameters and the function; and outputting display information for displaying a list of at least some of the calculated management risk values ​​side by side.

[0011] According to the present disclosure, it is possible to easily check multiple pieces of information used in investment decisions for cybersecurity in companies.

[0012] 1 is a block diagram showing an example of the configuration of a risk information processing device. FIG. 2 is a diagram showing an example of data used in spreadsheet software. FIG. 3 is an example of a dashboard of a list of management indicators. FIG. 4 is an example of a dashboard of security levels. FIG. 5 is an example of a dashboard of compliance rates with laws and regulations. FIG. 6 is an example of a dashboard of budget adequacy. FIG. 7 is an example of a dashboard of security human resources maturity. FIG. 8 is an example of a dashboard of the risk of stock price declines and reputational damage. FIG. 9 is an example of a dashboard of business continuity. FIG. 10 is an example of a dashboard of security maturity between third-party companies. FIG. 11 is an example of a dashboard of compliance rates with laws and regulations in base countries. FIG. 12 is an example of a dashboard of communication maturity. FIG. 13 is an example of a dashboard of the security awareness level of management. FIG. 14 is a diagram showing an example of a list of management risk values ​​displayed in tabular form. FIG. 15 is a flow diagram showing an example of the operation of a risk information processing device. FIG. 16 is a block diagram showing an example of the configuration of a modified example of a risk information processing device. FIG. 17 is a block diagram showing an example of the hardware configuration of a risk information processing device. FIG. 18 is a block diagram showing an example of the configuration of a risk information provision system that provides risk information using a risk information processing device.

[0013] In order for corporate management to make decisions on measures such as investing in cybersecurity countermeasures, they need to make comprehensive decisions based not only on information about the cybersecurity of information systems, but also on multiple pieces of information both inside and outside the company. For example, among the guidelines that management must achieve are cybersecurity guidelines for management. The cybersecurity guidelines contain a large number of requirements other than ensuring the cybersecurity of information systems. Management must decide on measures to achieve these requirements. However, simply checking requirements using a checklist makes it difficult to grasp the relevance of cybersecurity requirements, such as the impact they have on a company's management indicators. To grasp the relevance, it is desirable to display multiple pieces of related information on a single screen. Therefore, the risk information processing device of each embodiment outputs display information for displaying at least a portion of the multiple pieces of information used for judgment on a single screen, so that corporate management can easily confirm the multiple pieces of information used for judgment.

[0014] The management team is the people who have management responsibility, have the authority to allocate management resources, and are held accountable by shareholders and other stakeholders for achieving management targets. For example, the management team refers to directors under the Companies Act, but is not limited to this and may include general company presidents, managing directors, senior managing directors, and executive officers who are responsible for business execution.

[0015] 1 is a block diagram showing an example of the configuration of a risk information processing device 10. The risk information processing device 10 includes a parameter selection unit 110, a risk function acquisition unit 120, a management risk calculation unit 130, and an information output unit 140.

[0016] The parameter selection unit 110 selects parameters that affect the company's management indicators from among parameters that indicate the actions and factors necessary to realize the requirements for ensuring cybersecurity in guidelines on cybersecurity for management.

[0017] Cybersecurity guidelines for management describe requirements that management must implement as necessary conditions for ensuring cybersecurity related to corporate management. Furthermore, the guidelines describe parameters indicating actions and factors required to achieve the requirements. The parameter selection unit 110 may use multiple guidelines, not just one. A guideline generally describes multiple requirements. Furthermore, requirements for management generally relate to multiple actions and factors, and therefore, there are often multiple parameters associated with each requirement. Therefore, a guideline often describes multiple parameters, although a guideline describing a single requirement may also be used. Furthermore, a guideline may include a requirement related to one parameter.

[0018] In this way, the parameters indicate the actions and factors necessary to realize the requirements for ensuring cybersecurity related to the management of a company. The parameter values ​​indicate the state of the actions and factors necessary to realize the requirements for ensuring cybersecurity related to the management of a company. For example, if the requirement is "appointing a security officer," the parameter would be the action of "appointing a security officer to the organization." In this case, the parameter value would be, for example, a value indicating "whether or not a security officer has been appointed within the organization." Alternatively, the parameter value could be "the number of organizations that have appointed a security officer." Alternatively, the parameter value could be "the ratio of organizations that have appointed a security officer to all organizations." In this way, the parameter values ​​are arbitrary and can be set by the user.

[0019] Cybersecurity guidelines for management are prepared by government agencies or industry associations, such as the guidelines listed below. The parameter selection unit 110 may acquire parameters specified in the following pre-prepared guidelines as parameters indicating actions and factors for achieving the requirements for ensuring cybersecurity. Information-technology Promotion Agency, Japan: Cybersecurity Management Guidelines Ver. 3.0, Practice Collection for Implementing the Cybersecurity Management Guidelines Ver. 2.0 Ver. 3.0, Guidelines for the Development of a Connected World Ver. 2.0, Information Security Measures Guidelines for Small and Medium-sized Enterprises, Version 3.1. Japan Business Federation: Cyber ​​Risk Handbook for Directors, Japan Edition, Call for Strengthening Cybersecurity Toward the Realization of Society 5.0. NTT Data Institute of Management Consulting, Inc.: Research on the Roles and Responsibilities Expected of Management, CISOs, and Others in Cybersecurity Measures at Financial Institutions. Cabinet Secretariat's National Center of Incident Readiness and Strategy for Cybersecurity: Cybersecurity-Related Legislation Q&A Handbook. However, guidelines are not limited to the above.

[0020] A company's management indicators are indicators determined by the management of each company to determine its business status. The degree of achievement of management indicators can be determined based on the actions and factors of the company. In other words, management indicators are defined to be calculated using parameters that indicate actions and factors. The parameters defined here for calculating the management indicators are parameters that affect the company's management indicators. Therefore, the parameter selection unit 110 selects parameters that affect the company's management indicators based on the definition of the management indicators from among parameters that indicate the actions and factors necessary to achieve the requirements for ensuring cybersecurity in the cybersecurity guidelines for management.

[0021] The behavioral parameters are parameters that indicate behavior within a company. Therefore, the values ​​of the behavioral parameters are values ​​that can be obtained from internal information of the company. When the parameter is a behavior, the parameter selection unit 110 may obtain the parameter values ​​from internal information of the company, such as instructions and reports stored by the company, such as a data lake of the company. A data lake is a flexible and scalable data storage system for storing and managing massive amounts of data held by an organization such as a company.

[0022] Internal information is, for example, internal document information related to cybersecurity response within a company and log information of the company's information system. Log information of a company's information system is, for example, an access log and a communication log in the company's information system, but is not limited to these. Document information is, for example, the information described below. In the following description, instructions are, for example, but are not limited to, document files, emails, or guidelines. Reports are, for example, but are not limited to, evaluation results of document files, emails, or guidelines. Furthermore, internal information may be information regarding the acquisition and updating of document information, such as whether document information has been acquired, the date and time the document information was acquired, and the frequency with which the document information is acquired.- Document information related to risk assessment: - Risk assessment instructions and reports for the business (in more detail, the status of response to items in the operational rules (such as expected response time)) - Risk assessment instructions and reports for companies in the supply chain (in more detail, including instructions and reports for estimating damage) - Reports on risk assessments requested by other companies - Reports on the results of judgments on the appropriateness of risk countermeasures at companies in the supply chain - The extent of impact, such as laws and regulations that would be violated if the company were to become a perpetrator, social responsibility, and the amount of damage - Assessment results of the relationship between cybersecurity risks and increases or decreases in stock prices - Assessment results of cybersecurity risks and the risk of information leaks and business suspension - Document information related to cybersecurity: - Instructions and reports for cybersecurity measures at the company - Whether or not management has made a judgment on cybersecurity risks, and the results of that judgment - Instructions and reports on the status of cybersecurity measures shared between your company and other companies, such as those in the supply chain (including business partners' track record of implementing cybersecurity measures, requests for cybersecurity measures to business partners whose cybersecurity measures are below standard levels, and cybersecurity risk assessment reports from third parties / service providers) - Records of management's attendance at cybersecurity training sessions (specifically, the number of training sessions attended, the number of participants in each, and the number of times attended, etc.) - Records of participation in cybersecurity symposiums (specifically, the number of symposiums attended, the number of participants in each, and the number of times attended, etc.) - Contracts with business partners that clearly state who is responsible for cybersecurity measures - Instructions to consider taking out insurance in accordance with cybersecurity risks, receipt of reports, and contracts - Documents that describe cybersecurity management strategies However, internal information is not limited to the above and can include other information.

[0023] The factor parameters are external factors that are beyond the control of the company and affect cybersecurity related to corporate management. When the parameters are external factors, the parameter selection unit 110 may select parameters that affect the company's management indicators from parameters that are external factors provided by external corporate information service companies, etc. External factors include, for example, comparisons of cybersecurity measures with those of other companies, the status of other companies related to cybersecurity, and other companies' evaluations of cybersecurity. External factors are, in detail, for example, as described below. - A comparison of the level of investment made by your company with other companies in cybersecurity measures - A comparison of the size of your cybersecurity department with other companies - A comparison of your company's cybersecurity level with other companies - A report on the cybersecurity status of third-party software used - A report on changes in the cybersecurity level of the supply chain - Assessment results of cybersecurity-related laws and regulations in the country of base - The number of new attack methods discovered, and the number or percentage of attacks that have been dealt with among those discovered methods - Assessment results of the number of new domestic laws and regulations enacted, and the status of response to these new laws and regulations - Evaluation results of the maturity of business continuity management - Assessment results of compliance matters required for the business However, external factors are not limited to the above, and could include other information such as industry trends, economic conditions, social conditions such as the status of cyberattacks, international conditions such as the outbreak of war, and environmental conditions such as the occurrence of disasters.

[0024] The risk function acquisition unit 120 acquires a function for calculating a management risk value, which is a value indicating the state of a risk item that indicates management risk in corporate management, based on the values ​​of at least some of the selected parameters. Management risk is a risk in corporate activities that may affect the achievement of management goals, business plans, etc. Management risk is influenced by internal actions of the company and external factors. Therefore, the function for calculating the management risk value includes, in its definition, at least some of the parameters that affect the company's management indicators selected by the parameter selection unit 110. Therefore, the management risk value calculated using the function acquired by the risk function acquisition unit 120 is not simply the value of a parameter related to cybersecurity, but is a value calculated using the values ​​of parameters that affect the management indicators. In the following description, the higher the risk, the higher the management risk value. However, the management risk value may also be a value that decreases as the risk increases.

[0025] Management risk in corporate management is determined by the management of each company. Therefore, the function for calculating the management risk value based on parameters is determined by the management of the company and differs from company to company. Therefore, the risk function acquisition unit 120 acquires a function defined by the management of the target company as a function for calculating the management risk value indicating the state of risk items, which are items that indicate management risk in corporate management, based on the values ​​of parameters. For example, the risk function acquisition unit 120 may acquire the function from a terminal device operated by the company's management or a person instructed by the management. Alternatively, the risk function acquisition unit 120 may acquire a function created by an expert based on the results of an interview with the company's management. The risk function acquisition unit 120 may acquire a function created in advance by the management or an expert and stored in a storage device.

[0026] The function of the management risk value may be, for example, a weighted sum of a plurality of parameters calculated as the management risk value. For example, the function of the management risk value may be expressed as "Management risk value = Σ k ((parameter k ) × (parameter weight k))) The parameter weights are values ​​set for each company. However, the parameter weights may be set with reference to multiple companies in the same industry. For example, the parameter weights may be set using a model machine-learned using the parameter weights of multiple companies in the same industry. In this case, the model is a model machine-learned using the relationship between the parameters, the parameter weights set for multiple companies, and the correct data of the management risk value calculated using the parameters and the weights.

[0027] Management may want to know the difference between a target risk value set as a target for the value of a risk item in corporate management and the current management risk value. Therefore, the management risk value function may calculate the difference between the target management risk value and a management risk value calculated using parameters. Hereinafter, the target management risk value will be referred to as the "target risk value." For example, the difference calculated by the management risk value function may be a value calculated using a formula such as "difference = target risk value - weighted sum of parameters." In this case, the information output unit 140 may output display information for displaying the difference. Alternatively, the management risk value function may calculate the ratio between the target risk value and the management risk value, such as "management risk value = weighted sum of parameters / target risk value."

[0028] The risk item indicating the business risk, the business risk value indicating the state of that risk item, and the function for calculating the business risk value are, for example, as follows: The description in the example below is "Risk item: Business risk value = Function [unit]".・Budget: Budget sufficiency = Actual results / Budget [percent] ・Personnel: Personnel sufficiency = Current number of personnel / Number of personnel required [percent] ・Business continuity: Business continuity plan achievement rate = Achievement rate of business continuity plan formulated based on business impact analysis [percent] ・Compliance with domestic laws and regulations: Compliance status of domestic relevant laws and regulations = Complied laws and regulations / Total number of laws and regulations [percent] ・Compliance with overseas laws and regulations: Compliance status of overseas laws and regulations = Number of complied countries / Number of trading countries [percent] ・Social impact: Social impact amount = Amount of damage to the company if a situation assumed as a risk occurs, or Amount of damage to all business partners [amount] ・Business partner risk: Amount of damage caused by business partners = Amount of damage to the company if a situation assumed as a risk occurs to business partners [amount] ・Cybersecurity: Internal cybersecurity level = Level value determined as a result of cybersecurity assessment of internal systems [level units] ・Risk communication: Sufficiency of risk communication system = Scope of probable risk communication / Scope of communication for the entire company [percent] Management responsibility: degree of management responsibility of management team = corporate governance evaluation result [unit of evaluation result by corporate evaluation agency] However, the management risk items and management risk value functions are not limited to the above.

[0029] For example, the management risk value may be defined as a vector function calculated by multiplying a "vector of parameters" and a "matrix of weights." In this case, the function acquired by the risk function acquisition unit 120 may be a function that calculates the element values ​​of the vector of management risk values ​​from the element values ​​of the vector of parameters and the element values ​​of the matrix as weights. For example, the risk function acquisition unit 120 may acquire a spreadsheet that calculates the management risk value using parameters and weights as the function for calculating the management risk value. Figure 2 is a diagram showing an example of data used in the spreadsheet software. In Figure 2, the two leftmost columns show the element names and values ​​of the vector of management risk values. The top two rows show the element names and values ​​of the vector of parameters. The rest show the element values ​​of the weight matrix. Each management risk value is the sum of the values ​​obtained by multiplying the value of each parameter by the weight of the column of that parameter. For example, the value of management risk value A is "1 x 5 + 3 x 7 = 26." When taking into consideration the impact of corporate activities on the outside of the company, it is desirable that at least some of the functions of the management risk value include at least one external factor as a parameter.

[0030] The management risk calculation unit 130 calculates the management risk value based on the parameter value and the function. For example, if the management risk value is defined as a vector function calculated by multiplying the parameter vector by the weight matrix, the management risk calculation unit 130 calculates the product of the parameter vector by the weight matrix as the value of the management risk value vector.

[0031] The information output unit 140 outputs display information for displaying a list of at least some of the calculated management risk values. The management risk values ​​are not simply values ​​related to cybersecurity, but values ​​that indicate the impact of cybersecurity on management indicators. Therefore, the information output unit 140 outputs display information that displays a list of values ​​indicating the impact of cybersecurity on management indicators, rather than simply cybersecurity values. For example, the information output unit 140 may output display information of a dashboard that visualizes multiple management risk values ​​to a display device of a terminal device used by management. A dashboard is a business intelligence (BI) tool that collects and analyzes data. A dashboard collects and analyzes large amounts of digital data accumulated in a company and visualizes the analyzed data in an easy-to-understand format, such as aggregate values, tables, and graphs. In other words, a dashboard displays a list of various analysis results or indicators for a company. If the risk information processing device 10 is equipped with a display device, the information output unit 140 may display a list of management risk values ​​on the display device. The information output unit 140 may output display information for displaying a list of management risk values ​​side by side on one screen, or may output display information for displaying a list of management risk values ​​side by side on multiple screens.

[0032] 3 to 13 are diagrams showing examples of a cybersecurity dashboard, which is an example of a case where display information output by the information output unit 140 is graphically displayed. Management can easily check multiple pieces of information used for investment decisions by referring to the lists displayed on each dashboard in FIGS. 3 to 13. FIG. 3 is an example of a dashboard listing management indicators. For example, the information output unit 140 outputs display information to a display device of a terminal device used by management to display the dashboard listing management indicators shown in FIG. 3. The display device of the terminal device then displays the dashboard listing management indicators shown in FIG. 3. The list of management risk values ​​affecting management indicators is not limited to that shown in FIG. 3. Therefore, the information output unit 140 may output display information for displaying other lists other than those shown in FIG. 3. FIGS. 4 to 13 are display examples of other lists. FIG. 4 is an example of a security level dashboard. FIG. 5 is an example of a compliance rate dashboard. FIG. 6 is an example of a budget adequacy dashboard. FIG. 7 is an example of a security personnel maturity dashboard. FIG. 8 is an example of a dashboard listing stock price declines and reputational damage risks. FIG. 9 is an example of a dashboard for business continuity. FIG. 10 is an example of a dashboard for security maturity between third-party companies. FIG. 11 is an example of a dashboard for legal compliance rates in base countries. FIG. 12 is an example of a dashboard for communication maturity. FIG. 13 is an example of a dashboard for security awareness levels of management. The information output unit 140 may output display information to change these displays in response to instructions acquired via a user interface. If the display device has multiple displays, the information output unit 140 may output display information for displaying different dashboards on each of the multiple displays. The information output unit 140 may output display information for displaying a list of management risk values ​​in a format such as a table, rather than display information for graphically displaying the list of management risk values ​​as shown in FIGS. 3 to 13. FIG. 14 is a diagram showing an example of a list of management risk values ​​displayed in a table format. In FIG. 14, the scores represent management risk values ​​calculated based on a function.The target value is the target risk value for the business risk value. The percentage is the ratio of the business risk value to the target risk value. As previously explained, the function may calculate a ratio to the target risk value, such as the percentage in FIG. 14.

[0033] The information output unit 140 may output display information for displaying a warning about a management risk value that has become higher than a risk threshold, which is a threshold for risk. The risk threshold is a value that is preset for each management risk value. The information output unit 140 may output, as a warning, display information that indicates the name of the item of the management risk value that has become higher than the risk threshold.

[0034] The information output unit 140 may output, as a warning, display information for displaying a warning at or near the location where a management risk value that has become higher than the risk threshold is displayed in a list displayed on one screen. Alternatively, the information output unit 140 may output, as a warning, display information in which the display color or type of text of a management risk value that has become higher than the risk threshold is changed.

[0035] Management may want to know the parameters included in the function for calculating a management risk value as a factor in a management risk value that has exceeded the risk threshold. Therefore, in addition to issuing a warning, the information output unit 140 may output display information for displaying the parameters included in the function for calculating a management risk value that has exceeded the risk threshold. Furthermore, management may want to know the degree of influence of the parameters on other management risk values. Therefore, the management risk calculation unit 130 may count the number of parameters included in the function for calculating the management risk value that has exceeded the risk threshold that are included in the functions for calculating the other management risk values. The information output unit 140 may then output display information for displaying the parameters based on the number of parameters included in the function for calculating the management risk value that has exceeded the risk threshold that are included in the functions for calculating the other management risk values. For example, the information output unit 140 may output display information for displaying the parameters that are most frequently included in the functions for calculating the other management risk values. Alternatively, the information output unit 140 may output display information for displaying parameters sorted by the number of parameters included in the functions in descending order. The information output unit 140 may output display information for displaying the number of other management risk values ​​that include the parameters in the functions for calculation.

[0036] Parameters included in the function of a management risk value that has become higher than the risk threshold may also affect other management risk values. Therefore, management may want to know risk items corresponding to other management risk values ​​calculated by other functions that include parameters included in the function that calculates a management risk value that has become higher than the risk threshold. Therefore, the information output unit 140 may output display information for displaying risk items corresponding to other management risk values ​​calculated by other functions that include parameters included in the function that calculates a management risk value that has become higher than the risk threshold. The parameters selected by the parameter selection unit 110 are parameters that affect management indicators. Therefore, the information output unit 140 may output display information for displaying management indicators of a company that are affected by parameters included in the function used to calculate a management risk value that has become higher than the risk threshold.

[0037] FIG. 15 is a flow diagram showing an example of the operation of the risk information processing device 10. The parameter selection unit 110 selects parameters that affect the company's management indicators from among parameters indicating actions and factors necessary to achieve the requirements for ensuring server security in the cybersecurity guidelines for management (step S401). The risk function acquisition unit 120 acquires a function for calculating a management risk value, which is a value indicating the state of a risk item that indicates management risk in corporate management, based on the values ​​of at least some of the selected parameters (step S402). The management risk calculation unit 130 calculates the management risk value based on the parameter values ​​and the function (step S403). The information output unit 140 outputs display information for displaying a list of at least some of the calculated management risk values ​​side by side (step S404).

[0038] As such, the risk information processing device 10 includes a parameter selection unit 110, a risk function acquisition unit 120, a management risk calculation unit 130, and an information output unit 140. The parameter selection unit 110 selects parameters that affect a company's management indicators from parameters that indicate actions and factors necessary to realize the requirements for ensuring cybersecurity in cybersecurity guidelines for management. The risk function acquisition unit 120 acquires a function for calculating a management risk value, which is a value indicating the state of a risk item that is an item indicating management risk in corporate management, based on the selected parameters. The management risk calculation unit 130 calculates the management risk value based on the parameter value and the function. The information output unit 140 outputs display information for displaying a list of at least a portion of the calculated management risk values ​​side by side.

[0039] In this way, the management risk calculation unit 130 calculates a management risk value based on the function acquired by the risk function acquisition unit 120 and the values ​​of the parameters selected by the parameter selection unit 110 that affect the company's management indicators. Then, the information output unit 140 outputs display information for displaying a list of at least some of the calculated management risk values ​​side by side. The management risk value is not simply a numerical value of cybersecurity, but a numerical value that indicates the impact of cybersecurity on the management indicators. Therefore, the information output unit 140 outputs display information that shows a list of management risk values ​​that indicate the impact of cybersecurity on the management indicators, rather than simply a numerical value of cybersecurity. Therefore, management can easily check multiple pieces of information used for making investment decisions regarding cybersecurity at the company.

[0040] The function for calculating the management risk value based on the parameters differs for each company. The risk function acquisition unit 120 then acquires a function for calculating the management risk value, which is the value of a risk item in corporate management, based on the parameters. The management risk calculation unit 130 then calculates the management risk value based on the function acquired by the risk function acquisition unit 120. Therefore, the management risk calculation unit 130 calculates a management risk value corresponding to a function that differs for each company. The information output unit 140 then outputs display information for displaying a list of the management risk values ​​calculated in this manner. In this way, the risk information processing device 10 can output display information corresponding to a function that calculates a management risk value that differs for each company. Therefore, management can check a list of management risk values ​​calculated using a function defined for their own company.

[0041] Various cybersecurity guidelines for management have been proposed for various industries and systems, and these guidelines are constantly being updated. The parameter selection unit 110 selects parameters that affect the company's management indicators from the cybersecurity guidelines for management and parameters indicating the actions and factors necessary to achieve the requirements for ensuring cybersecurity. The management risk calculation unit 130 then calculates a management risk value based on the parameters selected by the parameter selection unit 110. Therefore, the management risk calculation unit 130 calculates a management risk value corresponding to the parameters indicating the actions and factors necessary to achieve the requirements of the cybersecurity guidelines for management. The information output unit 140 then outputs display information for displaying a list of the calculated management risk values. In this way, the risk information processing device 10 can output display information for management risk values ​​corresponding to the cybersecurity guidelines. Therefore, management can check the list of management risk values ​​corresponding to the cybersecurity guidelines.

[0042] <Modification> Figure 16 is a block diagram showing an example of the configuration of a risk information processing device 11 which is a modification. The risk information processing device 11 uses the degree of fulfillment of guideline requirements calculated using the degree of achievement of parameters in addition to parameters of internal information and external factors. Therefore, the risk information processing device 11 includes a fulfillment degree calculation unit 150 in addition to the configuration of the risk information processing device 10. The parameter selection unit 110 operates in the same way as the risk information processing device 10, so a detailed description will be omitted.

[0043] The fulfillment calculation unit 150 calculates a fulfillment level indicating the degree of fulfillment of all parameters required to realize the requirements using the fulfillment level calculated based on the current and target values ​​of the parameters. The fulfillment level of a parameter is a value indicating the state of the current value, which is the degree of current effort on the parameter, relative to the target value of the parameter in the guideline. For example, the fulfillment level of a parameter is the ratio between the current value of the parameter and the target value of the parameter. The fulfillment level of a guideline requirement indicates the degree of fulfillment of all parameters required to realize the requirement and is a value calculated using the fulfillment levels of the parameters. The fulfillment level of a requirement ranges from "0.0," which indicates that none of the parameters are achieved, to "1.0," which indicates that the current values ​​of all parameters are the target values. For example, the fulfillment level of a requirement is a weighted average of the fulfillment levels of the parameters. However, the fulfillment level is not limited to this. The fulfillment level can be set in the fulfillment level calculation unit 150 in advance by management or the like according to the size and industry of the company. The fulfillment level calculation unit 150 may obtain a fulfillment level definition for each action.

[0044] The risk function acquisition unit 120 acquires a function for calculating a management risk value based on the degree of fulfillment as a function for calculating at least a part of the management risk value. For example, the risk function acquisition unit 120 acquires a function for calculating a management risk value based on the degree of fulfillment as a function for calculating the management risk value. j ((Sufficiency j ) × (sufficiency weight j ))) may be obtained. As with the parameter weights, the sufficiency weights are values ​​set for each company. The sufficiency weights may be set using a model that is machine-learned using the sufficiency weights of multiple companies. The function for calculating the management risk value may be a function that includes both the parameters and the sufficiency.

[0045] The management risk calculation unit 130 calculates the management risk value for at least some of the management risk values ​​based on the parameter values, the degree of sufficiency, and the function.

[0046] The information output unit 140 may operate in the same manner as the information output unit 140 of the risk information processing device 10, or may output display information for displaying, in addition to a list of management risk values, the degree of fulfillment of the management risk values, and at least one of the parameters and the degree of achievement of the parameters. The information output unit 140 may output display information for displaying parameters included in a function for calculating a management risk value based on the degree of achievement of the parameters. For example, the information output unit 140 may output display information for displaying the parameter with the lowest degree of achievement, or parameters sorted from lowest to highest degree of achievement.

[0047] <Hardware Configuration> Next, the hardware configuration of the risk information processing devices 10 and 11 will be described. Each component of the risk information processing devices 10 and 11 may be configured with a hardware circuit. Alternatively, each component of the risk information processing devices 10 and 11 may be configured using multiple devices connected via a network. For example, the risk information processing devices 10 and 11 may be configured using cloud computing. Multiple components of the risk information processing devices 10 and 11 may be configured with a single piece of hardware. Alternatively, the risk information processing devices 10 and 11 may be realized as a computer including a processor, a memory, and an interface. The processor may be, for example, a central processing unit (CPU), but is not limited to this. The memory may be, for example, a read-only memory (ROM) and a random access memory (RAM), but is not limited to these. The interface may be, for example, a network interface for connecting the computer to an external network, but is not limited to these.

[0048] 17 is a block diagram showing the configuration of a computer 600, which is an example of the hardware configuration of the risk information processing devices 10 and 11. The computer 600 includes a processor 610, a ROM 620, a RAM 630, a storage device 640, and a network interface 650.

[0049] Processor 610 loads a program from at least one of ROM 620 and storage device 640. Then, processor 610 controls RAM 630, storage device 640, and network interface 650 based on the loaded program. Computer 600 including processor 610 controls these components to realize the functions of parameter selection unit 110, risk function acquisition unit 120, management risk calculation unit 130, information output unit 140, and satisfaction level calculation unit 150. In this way, computer 600 may realize its functions as a combination of hardware and software.

[0050] The processor 610 may read the program contained in the recording medium 690, which stores the program in a computer-readable manner, using a recording medium reading device (not shown). Alternatively, the processor 610 may receive the program from another device via the network interface 650.

[0051] The ROM 620 stores programs and fixed data executed by the processor 610. The ROM 620 is, for example, a programmable ROM (P-ROM) or a flash ROM. The RAM 630 temporarily stores programs and data executed by the processor 610. The RAM 630 is, for example, a dynamic RAM (D-RAM). The storage device 640 stores data and programs that the computer 600 stores long-term. The storage device 640 may also operate as a temporary storage device for the processor 610. The storage device 640 is, for example, a hard disk device, a solid state drive (SSD), or a disk array device.

[0052] The ROM 620 and the storage device 640 are non-volatile (non-transitory) recording media. On the other hand, the RAM 630 is a volatile (transitory) recording media. The processor 610 can operate based on programs stored in the ROM 620, the storage device 640, and the RAM 630. In other words, the processor 610 can operate using either a non-volatile recording medium or a volatile recording medium. When realizing each function, the processor 610 may use at least one of the RAM 630 and the storage device 640 as a temporary storage medium for programs and data.

[0053] The network interface 650 relays data exchange between the processor 610 and other devices. The network interface 650 is, for example, a LAN (Local Area Network) card or a wireless LAN card.

[0054] The computer 600 configured in this manner executes the operations of each component in the risk information processing devices 10 and 11 to realize the functions of the risk information processing devices 10 and 11.

[0055] <System> Figure 18 is a block diagram showing an example of the configuration of a risk information provision system 40 that provides risk information using a risk information processing device 10. The risk information provision system 40 includes a risk information processing device 10, a terminal device 20, and a display device 30. The risk information processing device 10, the terminal device 20, and the display device 30 are connected via a network such as an intranet or the Internet. The risk information provision system 40 may use a risk information processing device 10 that is provided as software on the cloud, for example. The risk information provision system 40 may include a risk information processing device 11.

[0056] The terminal device 20 outputs a function for calculating a management risk value, which is the value of a risk item in corporate management, based on the parameter values ​​to the risk function acquisition unit 120. The display device 30 displays a list of at least a portion of the calculated management risk values ​​output by the information output unit 140 on one screen.

[0057] The parameter selection unit 110 selects parameters that affect the company's management indicators from among parameters that indicate actions and factors necessary to achieve requirements for ensuring cybersecurity in guidelines on cybersecurity for management. The risk function acquisition unit 120 acquires from the terminal device 20 a function for calculating a management risk value, which is a value indicating the state of a risk item that is an item indicating management risk in corporate management, based on the value of the selected parameter. The management risk calculation unit 130 calculates the management risk value based on the parameter value and the function. The information output unit 140 outputs display information to the display device 30 for displaying a list of at least a portion of the calculated management risk values ​​side by side. In this way, the management risk calculation unit 130 calculates the management risk value based on the function acquired by the risk function acquisition unit 120 from the terminal device 20 and the value of the parameter that affects the company's management indicators selected by the parameter selection unit 110. Then, the information output unit 140 outputs display information for displaying a list of at least a portion of the calculated management risk values ​​side by side on the display device 30.

[0058] For example, a company's management uses the terminal device 20 to output a function for calculating a management risk value, which is the value of a risk item in company management, based on the parameter values ​​to the risk function acquisition unit 120 of the risk information processing device 10. The management then refers to a list of at least some of the management risk values ​​displayed side by side on the display device 30 to decide on investments in cybersecurity measures.

[0059] A part or all of the above-described embodiments can be described as, but not limited to, the following supplementary notes.

[0060] (Supplementary Note 1) A risk information processing device comprising: a parameter selection means for selecting parameters that affect a company's management indicators from parameters that indicate actions and factors necessary to realize the requirements for ensuring cybersecurity in guidelines on cybersecurity for management; a risk function acquisition means for acquiring a function for calculating a management risk value, which is a value that indicates the state of a risk item, which is an item that indicates management risk in corporate management, based on the values ​​of at least some of the selected parameters; a management risk calculation means for calculating the management risk value based on the parameter values ​​and the function; and an information output means for outputting display information for displaying a list of at least some of the calculated management risk values ​​side by side.

[0061] (Supplementary Note 2) A risk information processing device as described in Supplementary Note 1, wherein the function calculates the difference between a target risk value set as a target for a management risk item in corporate management and the management risk value, and the information output means outputs display information for displaying the difference.

[0062] (Supplementary Note 3) The risk information processing device according to Supplementary Note 1 or 2, wherein the function calculates a weighted sum of parameters using weights set for the parameters as the management risk value.

[0063] (Supplementary Note 4) The risk information processing device according to Supplementary Note 3, wherein the weights are calculated using a model machine-learned using parameters, parameter weights set in multiple companies, and correct answer data of management risk values.

[0064] (Appendix 5) A risk information processing device described in any one of Appendices 1 to 4, further comprising a fulfillment calculation means for calculating a fulfillment level indicating the degree of fulfillment of all parameters necessary to realize requirements using a degree of achievement calculated based on the current value and target value of the parameter; a risk function acquisition means for acquiring a function for calculating a management risk value based on the fulfillment level as a function for calculating at least a portion of the management risk value; and a management risk calculation means for calculating at least a portion of the management risk value based on the parameter value, the fulfillment level, and the function.

[0065] (Supplementary Note 6) The risk information processing device according to Supplementary Note 5, wherein the degree of fulfillment of the requirement is a weighted average of the degree of achievement of the parameter.

[0066] (Supplementary Note 7) The risk information processing device according to Supplementary Note 5 or 6, wherein the degree of achievement of a parameter is a value indicating the state of a current value that is the degree of current efforts regarding the parameter relative to a target value of the parameter in a guideline.

[0067] (Supplementary Note 8) The risk information processing device according to Supplementary Note 7, wherein the degree of achievement of a parameter is a ratio of a current value, which indicates the degree of current efforts for the parameter, to a target value of the parameter in the guideline.

[0068] (Supplementary Note 9) The risk information processing device according to any one of Supplementary Notes 5 to 8, wherein the information output means outputs display information for displaying at least one of the degree of fulfillment of the management risk value and the degree of achievement of the parameter.

[0069] (Supplementary Note 10) The risk information processing device according to any one of Supplementary Notes 5 to 9, wherein the information output means outputs display information for displaying parameters included in a function for calculating a management risk value based on the degree of achievement of the parameters.

[0070] (Supplementary Note 11) The risk information processing device according to any one of Supplementary Notes 1 to 10, wherein the information output means outputs display information for displaying a warning about a business risk value that has become higher than a risk threshold.

[0071] (Appendix 12) A risk information processing device as described in Appendix 11, wherein the information output means outputs, as a warning, display information for displaying risk items whose management risk values ​​are higher than the risk threshold in a list displayed on one screen.

[0072] (Supplementary Note 13) The risk information processing device according to Supplementary Note 11 or 12, wherein the information output means outputs, as a warning, display information for displaying a parameter included in a function of the management risk value that has become higher than the risk threshold.

[0073] (Appendix 14) A risk information processing device described in any one of Appendices 11 to 13, wherein the management risk calculation means counts the number of parameters included in a function that calculates a management risk value that is higher than a risk threshold that are included in a function for calculating other management risk values, and the information output means outputs display information for displaying parameters based on the number of parameters included in the function that calculates a management risk value that is higher than the risk threshold that are included in a function for calculating other management risk values.

[0074] (Supplementary Note 15) A risk information processing device according to any one of Supplementary Notes 11 to 14, wherein the information output means outputs display information for displaying management indicators of a company that are affected by parameters included in a function of a management risk value that has become higher than a risk threshold.

[0075] (Supplementary Note 16) The risk information processing device according to any one of Supplementary Notes 1 to 15, wherein the parameters include at least one of internal information of the company and external factors.

[0076] (Appendix 17) A risk information provision system comprising: a risk information processing device described in any one of Appendices 1 to 16; a terminal device that outputs a function for calculating a management risk value to the risk information processing device; and a display device that displays a list of at least a portion of the management risk values ​​output by the risk information processing device.

[0077] (Appendix 18) A risk information processing method comprising the steps of: selecting parameters that affect a company's management indicators from among parameters that indicate actions and factors necessary to realize requirements for ensuring cybersecurity in guidelines for management regarding cybersecurity; obtaining a function for calculating a management risk value, which is a value indicating the state of a risk item that is an item that indicates management risk in corporate management, based on the values ​​of at least some of the selected parameters; calculating the management risk value based on the parameter values ​​and the function; and outputting display information for displaying a list of at least some of the calculated management risk values ​​side by side.

[0078] (Appendix 19) A risk information providing method, in which a risk information processing device executes the risk information processing method described in Appendix 18, a terminal device outputs a definition of a management risk value to the risk information processing device, and a display device displays a list of at least a portion of the management risk values ​​output by the risk information processing device.

[0079] (Appendix 20) A recording medium for recording a program that causes a computer to execute the following processes: a process of selecting parameters that affect a company's management indicators from among parameters that indicate actions and factors necessary to realize the requirements for ensuring cybersecurity in guidelines for management-level cybersecurity; a process of obtaining a function for calculating a management risk value, which is a value that indicates the state of a risk item that is an item that indicates management risk in corporate management, based on the values ​​of at least some of the selected parameters; a process of calculating the management risk value based on the values ​​of the parameters and the function; and a process of outputting display information for displaying a list of at least some of the calculated management risk values ​​side by side.

[0080] Furthermore, some or all of the configurations described in Supplementary Notes 2 to 17 that are subordinate to the above-mentioned Supplementary Note 1 (risk information processing device) may also be subordinate to Supplementary Note 18 (risk information processing method) and Supplementary Note 20 (recording medium) in the same subordinate relationship as Supplementary Note 2 to 17. Furthermore, not limited to Supplementary Note 1, Supplementary Note 18, and Supplementary Note 20, some or all of the configurations described as Supplements may also be subordinate to various hardware, software, various recording means for recording software, or systems, within the scope of each of the above-mentioned embodiments.

[0081] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention.

[0082] 10 Risk information processing device 11 Risk information processing device 20 Terminal device 30 Display device 40 Risk information provision system 110 Parameter selection unit 120 Risk function acquisition unit 130 Management risk calculation unit 140 Information output unit 150 Satisfaction level calculation unit 600 Computer 610 Processor 620 ROM 630 RAM 640 Storage device 650 Network interface 690 Recording medium

Claims

1. In a guideline for cyber security for management, parameter selection means for selecting, from among parameters indicating actions and factors necessary to achieve requirements for ensuring cyber security, the parameters that affect the business management indicators of an enterprise; risk function acquisition means for acquiring a function for calculating a business risk value, which is a value indicating the state of a risk item that is an item indicating business risks in enterprise management, based on at least some of the values of the selected parameters; business risk calculation means for calculating the business risk value based on the values of the parameters and the function; and information output means for outputting display information for arranging and displaying at least a part of the calculated business risk values. A risk information processing apparatus comprising the above.

2. The function calculates the difference between a target risk value set as a target for a business risk item in enterprise management and the business risk value, and the information output means outputs display information for displaying the difference. The risk information processing apparatus according to claim 1.

3. The function calculates, as the business risk value, the weighted sum of the parameters using the weights set for the parameters. The risk information processing apparatus according to claim 1 or 2.

4. The weight is a weight calculated using a model learned by machine learning using the parameters, the weights of the parameters set in a plurality of enterprises, and the correct data of the business risk values. The risk information processing apparatus according to claim 3.

5. Further comprising sufficiency calculation means for calculating a sufficiency indicating the degree of fulfillment of all of the parameters necessary to achieve the requirements, using the degree of achievement calculated based on the current value and the target value of the parameters; the risk function acquisition means acquires, as the function for calculating at least some of the business risk values, the function for calculating the business risk value based on the sufficiency; and the business risk calculation means calculates at least some of the business risk values based on the values of the parameters, the sufficiency, and the function. The risk information processing apparatus according to any one of claims 1 to 4.

6. The sufficiency of the requirements is the weighted average of the degrees of achievement of the parameters. The risk information processing apparatus according to claim 5.

7. The achievement degree of the parameter is a value indicating the state of the current value, which is the degree of the current effort for the parameter with respect to the target value of the parameter in the guideline. The risk information processing apparatus according to claim 5 or 6.

8. The achievement degree of the parameter is a ratio of the current value, which is the degree of the current effort for the parameter with respect to the target value of the parameter in the guideline. The risk information processing apparatus according to claim 7.

9. The information output means outputs display information for displaying at least one of the sufficiency degree of the management risk value and the achievement degree of the parameter. The risk information processing apparatus according to any one of claims 5 to 8.

10. The information output means outputs display information for displaying the parameter included in the function for calculating the management risk value based on the achievement degree of the parameter. The risk information processing apparatus according to any one of claims 5 to 9.

11. The information output means outputs display information for displaying a warning about the management risk value that has become higher than the risk threshold. The risk information processing apparatus according to any one of claims 1 to 10.

12. As the warning, the information output means outputs display information for displaying the risk item of the management risk value that has become higher than the risk threshold in a list displayed on one screen. The risk information processing apparatus according to claim 11.

13. As the warning, the information output means outputs display information for displaying the parameter included in the function of the management risk value that has become higher than the risk threshold. The risk information processing apparatus according to claim 11 or 12.

14. The management risk calculation means counts the number of parameters included in the function for calculating the management risk value that has become higher than the risk threshold, which are included in the function for calculating other management risk values. The information output means outputs display information for displaying the parameter based on the number of parameters included in the function for calculating the management risk value that has become higher than the risk threshold, which are included in the function for calculating other management risk values. The risk information processing apparatus according to any one of claims 11 to 13.

15. The risk information processing apparatus according to any one of claims 11 to 14, wherein the information output means outputs display information for displaying management indicators of an enterprise affected by the parameter included in the function of the management risk value that has become higher than the risk threshold value.

16. The risk information processing apparatus according to any one of claims 1 to 15, wherein the parameter includes at least one of internal information of an enterprise and external factors.

17. A risk information providing system comprising: the risk information processing apparatus according to any one of claims 1 to 16; a terminal device that outputs the function for calculating the management risk value to the risk information processing apparatus; and a display device that displays a list of at least a part of the management risk values output by the risk information processing apparatus.

18. In a guideline for cyber security for management, select the parameter that affects the management indicators of an enterprise from among the parameters indicating actions and factors necessary to realize the requirements for ensuring cyber security, and obtain a function for calculating a management risk value, which is a value indicating the state of a risk item, which is an item indicating the management risk in enterprise management, based on at least a part of the values of the selected parameters, calculate the management risk value based on the values of the parameters and the function, and output display information for arranging and displaying a list of at least a part of the calculated management risk values. A risk information processing method.

19. A risk information providing method, wherein the risk information processing apparatus executes the risk information processing method according to claim 18, the terminal device outputs the function for calculating the management risk value to the risk information processing apparatus, and the display device displays a list of at least a part of the management risk values output by the risk information processing apparatus.

20. In the guidelines for cyber security for management, from among the parameters indicating the actions and factors necessary to achieve the requirements for ensuring cyber security, a process of selecting the parameters that affect the business management indicators of the company, a process of obtaining a function for calculating a business risk value, which is a value indicating the state of a risk item, which is an item indicating a business risk in business management, based on at least some of the values of the selected parameters, a process of calculating the business risk value based on the values of the parameters and the function, and a process of outputting display information for arranging and displaying at least a part of the list of the calculated business risk values. A recording medium for recording a program for causing a computer to execute the above processes.

Citation Information

Patent Citations

  • Risk diagnostic system, method of generating risk map data, and program

    JP2004054954A

  • Business plan planning support system

    JP2005352709A

  • Risk evaluation analysis system

    JP2019125247A

  • Methods and Systems for Managing Corporate Risk

    US20130159050A1

  • Cyber security risk model and index

    US20200137101A1