Automated Configuration Management for Secure Software Builds
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Manual review and selection of updates and patches for software components is time-consuming, especially for enterprises with numerous changes, making it impractical for efficient management of multiple versions, modifications, and patches.
Innovation Solution
A system and method that utilize a back-end configuration management computer server to retrieve secure configuration benchmarks, provision an initial operating system build, apply enterprise-specific modifications, validate through secure configuration and vulnerability checks, and apply updates to create a service instance, enabling automated and efficient management of software configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual review and selection of updates and patches is performed, then security and accuracy of configuration management is improved, but time consumption and operational efficiency deteriorate
Solution Approach 1:
The system performs preliminary actions by automatically retrieving, validating, and preparing configuration updates and patches before they are needed for deployment. The configuration management server proactively fetches updates from repositories, validates them against benchmarks, and prepares them for application, eliminating the need for manual review at the time of deployment.
Solution Approach 2:
The configuration management system performs self-service by automatically managing the entire update lifecycle including retrieval, validation, and application of patches and configuration changes. The system validates updates against secure configuration benchmarks and automatically applies approved changes without requiring manual human intervention for each update.
2Productivity
If automated configuration management is implemented, then productivity and operational efficiency are improved, but system complexity and validation requirements increase
Solution Approach 1:
The configuration management server acts as an intermediary between the update repositories and the target computing devices. It mediates the update process by retrieving updates from repositories, validating them against benchmarks, and automatically applying approved updates to devices, thereby simplifying the overall system architecture while maintaining security and control.
Solution Approach 2:
The system implements feedback mechanisms by validating configuration updates against secure configuration benchmarks before deployment. The validation process provides feedback on whether updates meet security requirements, and the system only applies updates that pass validation, ensuring continuous compliance while automating the process.
3Reliability
If comprehensive validation of configuration updates is performed, then security and compliance are improved, but processing time and operational overhead increase
Solution Approach 1:
The system performs validation as a preliminary action before updates are deployed to production environments. Configuration updates are validated against secure configuration benchmarks in advance, and only pre-validated updates are stored and deployed, eliminating the need for time-consuming validation during deployment while maintaining security and compliance.
Data Source
AI summary
According to some embodiments, a configuration benchmark data store may include a plurality of secure configuration benchmarks. A back-end configuration management computer server may retrieve one of the secure configuration benchmarks and provision, by an orchestration engine, an initial operating system build in accordance with the retrieved secure configuration benchmark and an automation template. The back-end configuration management computer server may then apply, by a provisioning tool, enterprise-specific modifications to the initial operating system build to create an environment compliant with an enterprise standard benchmark. The back-end configuration management computer server may validate the enterprise standard benchmark via secure configuration and vulnerability checks, apply at least one configuration update to the enterprise standard benchmark to create a service instance, and then apply application code to the service instance.


