AI Model for Security Control Identification Across Standards

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack an efficient method to identify and map security and privacy controls across different standards, leading to compliance challenges due to varying language and interpretations across standards like NIST, HIPAA, and GDPR, resulting in duplicate control checks and incomplete compliance.

Innovation Solution

A computer system utilizing an AI model manager, mapping manager, and training manager to leverage an AI model for identifying candidate controls, traversing relationship maps to find mapped controls, and selectively training the AI model to improve its compliance mapping and scoring capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual control identification and mapping across standards is performed, then accuracy in identifying controls can be maintained through expert review, but productivity is reduced due to time-consuming duplicate checks and incomplete compliance coverage

Engineering Contradiction:
Improvecontrol identification accuracyVSAvoidcompliance checking efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

An AI model is introduced as an intermediary between compliance requirements and control identification. The model learns from training data containing control mappings across multiple standards (NIST, HIPAA, GDPR, PCI-DSS) and automatically identifies applicable controls, replacing manual expert analysis while maintaining accuracy through supervised learning

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a digital representation of control mappings by training the AI model on structured training data that copies existing control relationships across standards. This learned model can then rapidly replicate the control identification process without requiring manual review of each compliance scenario

Inventive Principle:
Principle #26Copying

2Productivity

If AI model is used for control identification without training, then productivity is improved through automated identification, but measurement precision deteriorates due to inaccurate control matching across different standards

Engineering Contradiction:
Improvecontrol identification speedVSAvoidcontrol mapping accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The AI model undergoes preliminary training before deployment, learning from structured training data that contains control mappings across multiple standards. This pre-training phase establishes the model's understanding of control relationships, ensuring accurate identification when the model is later used for automated control mapping across NIST, HIPAA, GDPR, and PCI-DSS standards

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses structured training data as feedback to train and refine the AI model. The training data contains labeled examples of control mappings that provide feedback signals for adjusting model parameters, improving the model's ability to accurately match controls across different standards through iterative learning

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If comprehensive control mapping across multiple standards is implemented, then adaptability is improved for handling different compliance requirements, but device complexity increases due to multiple standards and mappings

Engineering Contradiction:
Improvemulti-standard compliance capabilityVSAvoidsystem structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A single AI model is designed to handle multiple compliance standards (NIST, HIPAA, GDPR, PCI-DSS) simultaneously. The model learns universal control mapping patterns from training data that spans different standards, enabling one system to perform multiple compliance assessment functions without requiring separate systems for each standard

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages complexity by changing the input parameters to the AI model rather than changing the system structure. Different standards are handled by providing different target standard identifiers and control descriptions as input parameters to the trained model, allowing the same model architecture to adapt to various compliance requirements through parameter variation

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20220383093A1Leveraging and Training an Artificial Intelligence Model for Control Identification
Publication Date: 2022.12.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20220383093A1 patent drawing
  • US20220383093A1 patent drawing
  • US20220383093A1 patent drawing

AI summary

A computer system, program code, and a method are provided to leverage an AI model with respect to a target specification for a target standard. The AI model is configured to identify at least one candidate control associated with a corresponding standard. A map is subject to traversal to identify the candidate control in the map. Source and destination controls of the map are leveraged to identify at least one mapped control associated with the target standard. The AI model is selectively subject to training with the mapped control and the target standard.