Automated Control Chain Generation for Security Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Certification and Accreditation (C&A) process for information systems is time-consuming and overwhelming for users, especially those with little security experience, as it requires manual selection and implementation of security controls, making it difficult to ensure regulatory compliance and risk mitigation.

Innovation Solution

An automated system that includes a control chain generation module to select and implement security controls based on guidelines and asset attributes, with a control assessor to monitor compliance, simplifying the process and reducing user burden.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual selection and implementation of security controls is performed, then security compliance and risk mitigation can be achieved, but the process becomes time-consuming and overwhelming for users

Engineering Contradiction:
Improvesecurity complianceVSAvoidC&A process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically generating control chains and selecting security controls before the user needs to review them. The control chain generation module pre-processes security requirements, asset inventories, and control selections, presenting finalized control chains to users for approval rather than requiring manual construction from scratch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing users to input basic asset information and security requirements, then the automated control chain generation module independently performs control selection, validation, and chain construction without requiring extensive user expertise or manual intervention in the complex security control selection process.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive security controls are implemented, then asset protection is improved, but system complexity increases for users with little security experience

Engineering Contradiction:
Improveasset protectionVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex security control implementation into distinct control chains, each targeting specific security requirements. Users interact with individual control chains rather than overwhelming comprehensive security frameworks, breaking down complexity into manageable, context-specific segments that are easier to understand and implement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The control chain generation module acts as an intermediary between security requirements and implementation details. It translates complex security control selections into structured control chains with clear relationships between controls, assessments, and evidence requirements, reducing the complexity users must directly manage.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If automated control chain generation is implemented, then user burden is reduced, but the need for continuous compliance monitoring increases

Engineering Contradiction:
Improvecontrol implementation easeVSAvoidcompliance monitoring automation
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The system implements feedback mechanisms where control assessors continuously monitor control chain compliance and provide feedback to the control chain generation module. This automated feedback loop detects compliance changes, triggers re-assessments, and updates control chains as needed, maintaining compliance without increasing user burden.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system ensures continuous compliance monitoring through automated control assessors that continuously evaluate control effectiveness and compliance status. This continuous automated action maintains security compliance without requiring ongoing manual user intervention, balancing ease of operation with sustained automation.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9817978B2Systems and methods for implementing modular computer system security solutions
Publication Date: 2017.11.14 ARK NETWORK SECURITY SOLUTIONS LLC
  • US9817978B2 patent drawing
  • US9817978B2 patent drawing
  • US9817978B2 patent drawing

AI summary

In some embodiments, an apparatus includes a control chain generation module is configured to receive, from a control database, a security guideline control to be implemented with respect to a hardware asset. The control chain generation module is configured to select, based on requirements to satisfy the security guideline and attributes of the hardware asset, a security implementation control. The control chain generation module is configured to select a control assessor to monitor the compliance of the hardware asset with the security guideline and is configured to define a control chain including the security guideline control, the security implementation control, and the control assessor. The control chain generation module is configured to send an instruction to apply the control chain to the hardware asset such that the control assessor monitors the hardware asset for compliance with the security guideline.