Automated Change Audit System for IT Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IT management systems face challenges in ensuring the reliability, availability, and security of IT infrastructure due to unauthorized changes, which can lead to financial loss, disruptions, and compliance issues, with 80% of unplanned downtime caused by human errors and poor change management practices.

Innovation Solution

An automated change audit system providing a triad of preventive, detective, and corrective controls that include independent change monitoring, reconciliation, and reporting across heterogeneous data processing nodes, ensuring that changes are authorized, intended, and conform to policies, thereby mitigating risks and maintaining compliance with regulatory requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated change monitoring and reconciliation controls are implemented, then system reliability and security are improved, but device complexity increases

Engineering Contradiction:
Improvesystem reliabilityVSAvoidcontrol system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary change monitoring system that acts as a mediator between IT operations and management. This system automatically monitors changes, reconciles them with authorized change requests, and provides reports without requiring manual intervention, thereby improving reliability while managing complexity through automation rather than manual processes

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring actual changes against authorized change requests and providing real-time reconciliation reports. This feedback loop enables automatic detection of unauthorized changes and provides continuous improvement data, enhancing reliability through ongoing verification and control

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If comprehensive change controls are implemented across heterogeneous data processing nodes, then security and compliance are improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity breachesVSAvoidchange management operation
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The change monitoring system is designed to universally monitor multiple types of data processing nodes (databases, servers, network devices) through a single integrated platform. This multi-functional approach provides comprehensive security coverage across heterogeneous systems while consolidating operations into one manageable interface, improving security without proportionally increasing operational complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs self-service by automatically monitoring changes, comparing them against authorized requests, and generating compliance reports without requiring manual audit processes. This automation reduces the operational burden on staff while maintaining comprehensive security controls, making the system easier to operate despite its comprehensive monitoring capabilities

Inventive Principle:
Principle #25Self-service

3Loss of information

If independent change monitoring and reconciliation are performed, then loss of information is reduced, but productivity decreases

Engineering Contradiction:
Improveinformation accuracyVSAvoidchange implementation speed
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The change monitoring operates continuously in the background, providing ongoing information accuracy without interrupting change implementation processes. The system performs reconciliation and verification actions continuously but non-intrusively, ensuring information accuracy is maintained while productivity is preserved through non-blocking monitoring operations

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10264022B2Information technology governance and controls methods and apparatuses
Publication Date: 2019.04.16 TRIPWIRE INC
  • US10264022B2 patent drawing
  • US10264022B2 patent drawing
  • US10264022B2 patent drawing

AI summary

Embodiments of the present invention provide methods and systems for automated change audit of an enterprise's IT infrastructure, including independent detection of changes, reconciliation of detected changes and independent reporting, to effectuate a triad of controls on managing changes within the IT infrastructure, preventive controls, detective controls and corrective controls.