Access Management Service for Multi-Vendor Security Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of managing multi-vendor licensed software deployments by managed service providers (MSPs) often leads to inefficient over-purchasing and tedious manual management, resulting in de-prioritization of information and data security policy compliance.
Innovation Solution
A centralized access management system architecture that provides security policy compliance verification and certification as a service, facilitating access to third-party software provider APIs for compliance testing and simplifying billing and license management for MSPs and organizations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If MSPs manually manage multi-vendor software licenses and deployments, then they can provide comprehensive support to organizations, but the process becomes cumbersome and time-consuming, leading to de-prioritization of security policy compliance
Solution Approach 1:
The patent introduces an intermediary access management service that acts as a mediator between MSPs, organizations, and multiple third-party software vendors. This service consolidates license management and compliance verification functions, allowing MSPs to manage multi-vendor software deployments without directly handling the complexity of each vendor's licensing system. The intermediary automatically performs security policy compliance checks, eliminating the time-consuming manual verification process while maintaining comprehensive support capabilities.
Solution Approach 2:
The access management service provides universal functionality that handles multiple software vendors' licensing and compliance requirements through a single unified interface. Instead of requiring separate manual processes for each vendor, the system universally manages diverse software portfolios, performing both license administration and security compliance verification in one integrated platform, thereby improving ease of operation and recovering lost time.
2Adaptability or versatility
If organizations license access to multiple third-party software tools, then they can access diverse software capabilities, but managing licenses across multiple vendors becomes complex and results in inefficient over-purchasing
Solution Approach 1:
The patent merges the management of multiple third-party software licenses into a single consolidated access management service. Instead of separately tracking licenses for email services, document storage, office suites, and design platforms from different vendors, the system combines all license management functions into one unified interface. This merging maintains full access to diverse software tools while eliminating the complexity of managing multiple separate licensing systems, preventing over-purchasing through centralized visibility.
3Device complexity
If MSPs and organizations disclaim responsibility for security policy compliance, then they avoid the burden of compliance management, but this exposes all parties to unknowable security risks and increases insurance rates
Solution Approach 1:
The access management service implements self-service automation where the system automatically performs security policy compliance verification without requiring manual intervention from MSPs or organizations. The service autonomously checks software deployments against security policies, generates compliance reports, and maintains audit trails. This self-service approach eliminates the burden of manual compliance management while simultaneously providing reliable security compliance assurance, as the automated system consistently verifies and documents compliance status, reducing insurance risks.
Data Source
AI summary
A system and method for providing access to third-party application programming interfaces (APIs) as a service. In particular, an API access manager can be configured to execute one or more serverless functions selected form a database of serverless functions in order to obtain data from one or more third-party APIs. Retrieved data can be used to evaluate compliance with one or more information security policies.


