Automated Compliance Auditing System for Vulnerability Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual compliance auditing in enterprises is time-consuming and error-prone, making it inefficient for verifying asset compliance with regulations.

Innovation Solution

An automated enterprise compliance auditing system that uses a computer product with stored program instructions to scan assets for vulnerabilities and calculate compliance scores based on associated compliance controls and publicly known vulnerabilities, providing a hierarchical database structure for asset management and vulnerability assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual compliance auditing is performed, then compliance verification can be conducted, but the process is time-consuming and error-prone

Engineering Contradiction:
Improvecompliance verification accuracyVSAvoidauditing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual compliance auditing with an automated computer-based system that scans assets for vulnerabilities and calculates compliance scores. The system uses software programs to automatically check assets against compliance regulations, eliminating the need for manual verification while improving both speed and accuracy of compliance checking.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service compliance auditing by automatically scanning assets and generating compliance scores without requiring manual intervention. The automated system performs the entire auditing process independently, from vulnerability scanning to compliance score calculation, allowing organizations to conduct their own compliance audits efficiently.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual compliance auditing is performed, then compliance verification can be conducted, but the process is error-prone

Engineering Contradiction:
Improvecompliance verification accuracyVSAvoidauditing process reliability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces manual compliance auditing with an automated computer-based system that scans assets for vulnerabilities and calculates compliance scores. The system uses software programs to automatically check assets against compliance regulations, eliminating the need for manual verification while improving both speed and accuracy of compliance checking.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system provides automated feedback by generating compliance scores that indicate the compliance status of assets. This feedback mechanism allows organizations to immediately see the results of compliance checking without manual verification, reducing errors and improving reliability of the auditing process.

Inventive Principle:
Principle #23Feedback

3Productivity

If automated compliance auditing is implemented, then auditing speed increases, but system complexity increases

Engineering Contradiction:
Improveauditing speedVSAvoidauditing system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent divides the compliance auditing system into separate functional modules: asset scanning components, vulnerability database, compliance regulation database, and compliance score calculation components. This segmentation allows each module to perform specific functions independently, making the overall system more manageable despite the automation and increased productivity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8893283B2Performing an automated compliance audit by vulnerabilities
Publication Date: 2014.11.18 MICRO FOCUS LLC
  • US8893283B2 patent drawing
  • US8893283B2 patent drawing
  • US8893283B2 patent drawing

AI summary

An automated enterprise compliance auditing by vulnerabilities system including an enterprise asset database, a compliance regulation including compliance controls, a known asset vulnerabilities database including details of publicly known asset vulnerabilities, compliance control associating functionality to associate each of a set of audited assets with at least a subset of compliance controls of the compliance regulation, the audited assets being a subset of the enterprise assets, vulnerability mapping functionality to map each compliance control to a subset of the known asset vulnerabilities which may impact compliance of at least one of the audited assets therewith, asset scanning functionality to scan each audited asset to ascertain to which publicly known asset vulnerabilities the audited asset is vulnerable to, and numeric compliance score calculating functionality to, responsive to the associating, mapping and scanning, calculate for each audited asset, a numeric compliance score for each compliance control associated therewith.