Adaptive Data Risk Management System for Personal Information

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a significant risk of personal data exposure and data loss incidents when computing systems are in communication with external systems, particularly due to data breaches and other loss events, which existing technologies have not adequately addressed.

Innovation Solution

A method and system that identify potential risk triggers, analyze inventory attributes, and respond by modifying encryption levels, access permissions, or inventory attributes based on similar past risks experienced by the entity or similarly situated entities, to mitigate data exposure and loss.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If computing systems communicate with external systems to enable data processing and storage, then productivity and functionality are improved, but the risk of data exposure and data loss incidents increases

Engineering Contradiction:
Improvedata processing capabilityVSAvoiddata exposure risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary risk assessments and identifies potential risk triggers before data breaches occur. By proactively analyzing inventory attributes and determining risk levels in advance, the system can implement protective measures before harmful events happen, thus maintaining productivity while reducing data exposure risk.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors data assets and their inventory attributes, providing feedback loops that enable dynamic risk management. When changes in inventory attributes indicate increased risk, the system responds by adjusting security measures, thus maintaining an optimal balance between productivity and security.

Inventive Principle:
Principle #23Feedback

2Reliability

If the system implements comprehensive risk assessment and responsive actions to mitigate data exposure, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system manages complexity by focusing on changing key parameters (inventory attributes) rather than implementing comprehensive complex controls across all system aspects. By monitoring and responding to changes in specific inventory attributes that indicate risk, the system achieves improved data security through targeted parameter management rather than blanket complexity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies different levels of security and monitoring to different data assets based on their specific inventory attributes and risk profiles. Rather than uniformly complex controls across all assets, the system tailors security measures to local characteristics of each data asset, improving overall security while managing system complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If the system modifies encryption levels and access permissions in response to risk triggers, then data security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically modifies encryption levels and access permissions in response to detected risk triggers without requiring manual intervention. By enabling the system to self-manage security adjustments based on inventory attribute changes, data security is improved while operational simplicity is maintained through automation rather than manual security management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts encryption and access controls based on real-time risk assessments rather than using static configurations. This dynamic approach allows security measures to adapt automatically to changing conditions, improving data security while maintaining ease of operation through automated adaptation rather than manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20220164475A1Data processing systems for identifying, assessing, and remediating data processing risks using data modeling techniques
Publication Date: 2022.05.26 ONETRUST LLC
  • US20220164475A1 patent drawing
  • US20220164475A1 patent drawing
  • US20220164475A1 patent drawing

AI summary

In various embodiments, a Data Model Adaptive Execution System may be configured to take one or more suitable actions to remediate an identified risk in view of one or more regulations (e.g., one or more legal regulations, one or more binding corporate rules, etc.). For example, in order to ensure compliance with one or more standards related to the collection and/or storage of personal data, an entity may be required to modify one or more aspects of a way in which the entity collects, stores, and/or otherwise processes personal data (e.g., in response to a change in a legal or other requirement). In order to identify whether a particular change or other risk trigger requires remediation, the system may be configured to assess a relevance of the risk posed by the risk and identify one or more processing activities or data assets that may be affected by the risk.