Centralized Application Controls Enablement for Consistent CI/CD Gating
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems fail to ensure consistent validation and post-production monitoring of applications due to issues such as failing to operate for tested applications, lack of a repository for tracking granular control logic, absence of a standard way to define granular control logic, and no formal gating process prior to production implementation, leading to exposure of environments to unauthorized users.
Innovation Solution
Implementing a platform, language, and cloud agnostic application controls enablement module that establishes a centralized system of record (SoR) for application controls, ensuring consistent and complete testing and monitoring, tracking granular control logic, and providing a standard framework for controls testing and formal gating processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional systems are used for application controls, then system simplicity is maintained, but consistency and reliability of control validation are compromised
Solution Approach 1:
The system segments control validation into distinct phases: pre-implementation validation using templates and post-implementation monitoring. This segmentation allows each phase to be handled by specialized components, improving reliability while managing complexity through modular architecture.
Solution Approach 2:
The patent introduces an intermediary control validation system that sits between the application and production environment. This intermediary layer enforces standardized validation procedures and gating processes, ensuring consistency without requiring changes to the underlying application complexity.
2Loss of information
If no centralized repository is implemented, then system complexity is reduced, but tracking and monitoring of granular control logic becomes impossible
Solution Approach 1:
The centralized repository serves multiple functions: storing control logic definitions, tracking validation status, maintaining audit trails, and supporting both pre- and post-implementation phases. This multi-functionality justifies the infrastructure complexity by consolidating multiple information management needs into a single system.
3Reliability
If formal gating processes are implemented, then reliability of production deployment is improved, but productivity and speed of implementation are reduced
Solution Approach 1:
The system performs preliminary validation actions during development and testing phases using standardized templates. By completing validation work before production deployment, the gating process becomes a formality rather than a bottleneck, maintaining reliability while preserving deployment speed.
Solution Approach 2:
The control validation system operates autonomously through automated testing, validation rules, and gating logic that require minimal manual intervention. This self-service capability reduces the time overhead of formal gating processes while maintaining rigorous validation standards.
4Measurement precision
If standardized control frameworks are implemented, then measurement precision and consistency are improved, but ease of operation is reduced
Solution Approach 1:
The system standardizes control validation through defined parameters, templates, and metrics that ensure precise measurement and consistent evaluation. These standardized parameters automate the validation process, reducing the operational burden on users while maintaining high measurement precision.
Data Source
AI summary
Various methods, apparatuses/systems, and media for enablement of application controls are disclosed. A processor implements a centralized database to serve as a system of record for application controls for an application, the centralized database storing control data associated with application controls; calls a first API to register the application controls associated with the application onto the centralized database; calls a second API to obtain the control data from the centralized database; develops control objectives and control procedures as rules to enable linkage of pre implementation validation checks for the application; integrates the centralized database with continuous integration and a continuous delivery (CICD) pipeline; executes the rules in the CICD pipeline to test the control data in a periodic manner; and automatically transmits the application to a production environment when it is determined that the control data passed the test executed by the CICD pipeline.


