Agile Governance System for Cloud Security Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managed computer systems, including virtualized and cloud-based systems, face challenges in ensuring security compliance with dynamic resource provisioning and multi-tenancy, requiring a technology that can consistently enforce security controls across distributed environments while maintaining agility and flexibility.

Innovation Solution

An agile governance system that uses a data-centric workflow to assess risk and enforce regulatory controls through a risk-scoring algorithm, dynamically generating interrogatories to determine security requirements and recommend pre-approved or custom solutions for infrastructure changes, ensuring compliance with security policies and reducing approval timeframes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated risk assessment and dynamic interrogatories are implemented to enforce security controls, then security compliance is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary risk assessment and generates interrogatories before infrastructure changes are implemented. By assessing risk upfront and requiring pre-approval through dynamic interrogatories, the system ensures security compliance is established before deployment, preventing compliance issues rather than detecting them later.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The interrogatory system is dynamically generated based on the specific risk profile of each infrastructure change request. The system adapts the number, type, and complexity of questions according to the assessed risk level, making the compliance process flexible rather than rigid. This dynamic approach maintains security while reducing unnecessary complexity for low-risk changes.

Inventive Principle:
Principle #15Dynamics

2Reliability

If manual security approval processes are used to ensure compliance, then security control is improved, but approval timeframes increase

Engineering Contradiction:
Improvesecurity controlVSAvoidapproval timeframe
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary risk assessment and generates appropriate interrogatories before the formal approval process. By preparing the risk assessment and required questions in advance, the system streamlines the subsequent approval process, reducing the time reviewers need to spend on each request while maintaining thorough security control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the parameter of approval complexity based on risk assessment results. For low-risk infrastructure changes, the system reduces the number and complexity of interrogatories required, allowing faster approval. For high-risk changes, more comprehensive interrogatories are generated. This parameter-based adaptation maintains security control while optimizing approval timeframes according to actual risk levels.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If dynamic interrogatories are generated based on risk profiles, then security assessment accuracy is improved, but processing complexity increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidprocessing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies different levels of assessment depth to different parts of the infrastructure change request based on local risk characteristics. Instead of applying a uniform comprehensive assessment to all requests, the system generates interrogatories targeted specifically at the risk factors present in each request. This local quality approach improves assessment accuracy for relevant issues while avoiding unnecessary processing complexity for unrelated areas.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9781165B1Methods for assuring security governance in managed computer systems
Publication Date: 2017.10.03 ENTRUST CORP
  • US9781165B1 patent drawing
  • US9781165B1 patent drawing
  • US9781165B1 patent drawing

AI summary

An agile governance system provides recommendations for infrastructure change requests concerning a cloud-based computer environment in accordance with security policies regarding data to be used in connection with applications impacted by the requests. The nature and character of the data is determined using an interactive dialog with a requesting entity. Possible responses provided by the requesting entity are mapped to security policy requirements, which, in turn, are used to determine infrastructure stack requirements. Where pre-approved solutions that satisfy the security needs for the requested infrastructure change exist, they are recommended; otherwise, the requesting entity is presented with the recommendation for the requested infrastructure change along with a list of required approvals and approvers.