Compliance Evidence Analysis for Automated Cybersecurity Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity compliance assessments in organizations are time-consuming, expensive, and prone to subjectivity due to manual processes and varying levels of human competency, necessitating a more efficient and objective evaluation method.

Innovation Solution

An automated system utilizing machine learning algorithms, regular expression analysis, and image text extraction to assess cybersecurity compliance, incorporating hardware and software probes to monitor network activity, generate compliance scores, and transmit remediation commands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual processes are used for cybersecurity compliance assessments, then human judgment and flexibility can be applied, but the assessments become time-consuming, expensive, and prone to subjectivity

Engineering Contradiction:
Improveassessment objectivityVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual human assessment processes with an automated computer-based system that uses machine learning models, regular expression analysis, and image text extraction. This substitution eliminates human subjectivity and variability while maintaining consistent, objective evaluation criteria across all assessments. The automated system processes compliance data without human intervention, thereby resolving the contradiction between achieving objective measurements and reducing assessment time.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service automation where the compliance assessment process serves itself through automated data collection, analysis, and scoring. The computer-based system automatically extracts data from network devices, applies assessment criteria, generates compliance scores, and identifies remediation actions without requiring human operators to manually perform each step. This self-service capability simultaneously improves objectivity and reduces the time required for assessments.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual cybersecurity compliance assessments are performed, then detailed human analysis can be conducted, but the process becomes expensive and inconsistent due to varying human competency

Engineering Contradiction:
Improveassessment consistencyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces variable human analysis with a standardized automated computer-based assessment system. The system uses consistent machine learning models and regular expression patterns that apply the same evaluation criteria to all assessments, eliminating variability caused by different human competencies. This substitution ensures reliable and consistent results while managing system complexity through automated processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system transforms the assessment process from human-dependent to parameter-driven evaluation. By using machine learning models with defined parameters, regular expression patterns, and standardized scoring criteria, the system ensures that the same parameters are applied consistently across all assessments. This parameter-based approach guarantees reliability and consistency while the automated nature of the system manages the complexity of implementing these standardized parameters.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If traditional compliance assessment methods are used, then comprehensive analysis can be performed, but frequent monitoring becomes impractical due to time and resource constraints

Engineering Contradiction:
Improvemonitoring frequencyVSAvoidautomation system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent replaces traditional manual compliance assessment methods with an automated computer-based system that can execute assessments frequently and efficiently. The automated system collects data from network devices, processes compliance information, and generates reports without the time and resource constraints that limit manual assessment frequency. This substitution enables continuous or near-continuous monitoring while managing the complexity of the automation infrastructure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary automated data collection and preparation from network devices before conducting compliance assessments. By pre-collecting and organizing compliance data through automated probes and data extraction mechanisms, the system reduces the time required for each assessment execution, thereby enabling more frequent monitoring. This preliminary action approach manages the complexity of frequent assessments by preparing data in advance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250378172A1Cybersecurity standards controls compliance evidence analysis engine
Publication Date: 2025.12.11 SAUDI ARABIAN OIL CO
  • US20250378172A1 patent drawing
  • US20250378172A1 patent drawing
  • US20250378172A1 patent drawing

AI summary

A method and a system for assessing the compliance of continuous cybersecurity data security of infrastructure, endpoints, and other organization aspects. The method may include obtaining image data from a data repository and performing, by a computer processor, a similarity comparison of the obtained image data using a plurality of comparison techniques. Further, the method includes extracting cybersecurity data from the obtained image data and preprocessing the cybersecurity data using at least one preprocessing technique. A first assessment of the preprocessed cybersecurity data is generated using regular expression analysis and a second assessment of the preprocessed cybersecurity data is generated using a plurality of machine learning models. A cybersecurity compliance score is computed based on the first assessment and the second assessment and a remediation command configured to adjust at least one configuration setting of a network is transmitted.