Cascading Security Schema for Risk Indicator Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in maintaining a robust information security infrastructure due to evolving threats and the need for continuous monitoring and updates, as defined by standards like ISO and NIST.
Innovation Solution
A computer-implemented method and system that utilize a cascading classification schema to identify Key Risk Indicators (KRIs), assign weights and thresholds, and determine aggregate scores to assess the robustness of the information security infrastructure, providing a graphical user interface for visual representation and gap analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If organizations continuously monitor and update their information security infrastructure to keep pace with evolving threats and standards updates, then information security robustness is improved, but the complexity and resource requirements of maintenance increase
Solution Approach 1:
The patent segments the information security infrastructure assessment into a hierarchical cascading classification schema with multiple levels (Level 1: Policy and Governance, Level 2: Security Controls, Level 3: Technical Implementation, Level 4: Evidence Verification). This segmentation allows organizations to systematically evaluate different aspects of security independently while maintaining overall coherence, making the complex maintenance task more manageable and structured.
Solution Approach 2:
The patent implements preliminary action by continuously monitoring standards updates (NIST, ISO, industry-specific) and maintaining a dynamic library of security controls and assessment criteria. This allows organizations to proactively prepare for upcoming compliance requirements and threat scenarios, updating their security infrastructure before gaps are exploited, rather than reacting to breaches or failures.
2Measurement precision
If organizations implement comprehensive security assessments covering all infrastructure components, then vulnerability identification accuracy is improved, but the time and resources required for assessment increase
Solution Approach 1:
The patent implements continuous feedback mechanisms where security assessments are not one-time events but ongoing processes. The system continuously collects data from security controls, monitors threat intelligence, and updates vulnerability assessments in real-time. This feedback loop allows organizations to maintain high identification accuracy without requiring periodic lengthy reassessments, as the system adapts and updates continuously based on new information.
Solution Approach 2:
The patent transforms discrete, time-consuming security assessments into a continuous monitoring and evaluation process. By implementing automated security control monitoring, continuous vulnerability scanning, and real-time threat intelligence integration, the system maintains constant vigilance over security infrastructure health, eliminating the need for periodic shutdowns or intensive manual assessment periods.
3Adaptability or versatility
If organizations adopt detailed classification schemas and multiple security metrics, then security assessment comprehensiveness is improved, but the difficulty of implementation and interpretation increases
Solution Approach 1:
The patent adds a temporal dimension to security assessment by implementing continuous monitoring and real-time evaluation across the cascading classification levels. Instead of static point-in-time assessments, the system evaluates security posture continuously across multiple dimensions (policy, controls, implementation, evidence) and time, providing dynamic insights that are both comprehensive and interpretable through standardized metrics and automated reporting.
Data Source
AI summary
A computer implemented method for maintaining information security infrastructure of an entity, includes accessing a cascading classification schema comprising a plurality of levels of classifications indicative of critical security controls, identifying a plurality of Key Risk Indicators (KRIs) and assigning a plurality of respective KRI weight values, a plurality of respective first KRI threshold values, and a plurality of respective second KRI threshold values to the plurality of respective KRIs, assigning the plurality of KRIs to the lowest level of classification, defining a plurality of data points corresponding to the plurality of KRIs, determining a plurality of KRI score values corresponding to the plurality of respective KRIs by comparing a plurality of data values associated with the plurality of respective data points, with the plurality of first KRI threshold values and the plurality of second KRI threshold values, and determining a cascading schema of aggregate scores.


