Coordinated Risk Management System for OT IT ST Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current risk management approaches in enterprises are fragmented and informal, lacking holistic analysis of complex interactions between operational technology (OT), information technology (IT), and security technology (ST) domains, leading to ineffective cyber security and business risk mitigation due to subjective assessments and inadequate automated processes.

Innovation Solution

A coordinated risk management system that identifies business functions, vulnerabilities, and threats across multiple domains, using automated and adaptive methodologies for real-time analysis and control, integrating situational awareness and domain-specific knowledge to prioritize and refine security and risk control mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If sub-domain specific expertise and ad hoc decisions are used for security and risk assessment, then personal experience and guidelines can be applied, but the approach becomes non-holistic and fragmented, unable to consider complex relationships between security and risk concepts systemically

Engineering Contradiction:
Improveflexibility in applying personal experience and guidelinesVSAvoidholistic analysis capability
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent combines multiple sub-domain specific assessments (OT, IT, ST) into a unified enterprise-wide risk management system that holistically analyzes complex relationships between security and risk concepts across all domains simultaneously

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates a universal risk management framework that can assess security and risk concepts across diverse domains (operational technology, information technology, security technology) using a common systematic approach rather than domain-specific fragmented methods

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If formal and automated methods are implemented to improve integrity, repeatability, effectiveness, and timeliness of security and business risk analysis, then systematic analysis is achieved, but the complexity of coordinating OT, IT, and ST systems increases

Engineering Contradiction:
Improveintegrity and repeatability of risk analysisVSAvoidsystem coordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex enterprise-wide risk management system into coordinated sub-systems for OT, IT, and ST domains, each handling specific assessment tasks while contributing to the overall systematic analysis through standardized interfaces and data exchange protocols

Inventive Principle:
Principle #1Segmentation

3Loss of information

If enterprise-wide interconnection of OT, IT, and ST domains is implemented to meet business and regulatory demands, then comprehensive risk visibility is achieved, but adverse impacts can propagate from one system to others requiring coordinated response

Engineering Contradiction:
Improvecompleteness of risk informationVSAvoidpropagation of adverse impacts
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback mechanisms that continuously monitor and analyze risk indicators across interconnected OT, IT, and ST domains, enabling early detection of adverse impacts and coordinated response actions to prevent propagation throughout the enterprise-wide system

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11501234B2Pervasive, domain and situational-aware, adaptive, automated, and coordinated big data analysis, contextual learning and predictive control of business and operational risks and security
Publication Date: 2022.11.15 ALBEADO
  • US11501234B2 patent drawing
  • US11501234B2 patent drawing
  • US11501234B2 patent drawing

AI summary

Real time security, integrity, and reliability postures of operational (OT), information (IT), and security (ST) systems, as well as slower changing security and operational blueprint, policies, processes, and rules governing the enterprise security and business risk management process, dynamically evolve and adapt to domain, context, and situational awareness, as well as the controls implemented across the operational and information systems that are controlled. Embodiments of the invention are systematized and pervasively applied across interconnected, interdependent, and diverse operational, information, and security systems to mitigate system-wide business risk, to improve efficiency and effectiveness of business processes and to enhance security control which conventional perimeter, network, or host based control and protection schemes cannot successfully perform.