Cybersecurity Risk Tracking Framework Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity risk tracking solutions are often application-specific, tied to a single organization, and require ongoing system updates and maintenance, limiting their ability to adapt to emerging frameworks and providing inaccurate status reporting.

Innovation Solution

The Compliance and Risk Tracker (CRT) system uses a framework-agnostic, adaptive risk model with a Cyber Maturity Index score to identify and prioritize risks, providing a unified platform for managing multiple clients and compliance frameworks, and offering continuous remediation through Cyber Maturation as a Service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing cybersecurity risk tracking solutions are used, then they can track risks within a single organization, but they require ongoing system updates and maintenance and cannot adapt to emerging frameworks

Engineering Contradiction:
Improveadaptability to emerging frameworksVSAvoidsystem updates and maintenance
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The risk tracking system is designed to support multiple compliance frameworks (NIST, ISO 27001, CMMC, etc.) within a single platform, allowing one system to serve multiple functions and adapt to different frameworks without requiring separate systems for each framework

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system employs dynamic configuration capabilities that allow it to adapt to emerging frameworks through updated configuration files and parameters, enabling the system to evolve with changing compliance requirements without fundamental redesign

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If application-specific risk tracking systems are used, then they can be tailored to a single organization's needs, but they provide inaccurate status reporting when managing multiple clients

Engineering Contradiction:
Improveaccuracy of status reportingVSAvoidability to manage multiple clients
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system segments client data and risk assessments into isolated instances, with each client's data properly delimited and tracked separately, enabling accurate status reporting for each client while managing multiple clients within a unified platform

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces configuration files and instance management layers that act as intermediaries between the core risk tracking engine and multiple clients, ensuring that status reporting accurately reflects each client's specific state while maintaining system-wide coordination

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If framework-specific risk tracking systems are used, then they can provide detailed tracking for that framework, but they cannot provide a unified platform for managing multiple frameworks simultaneously

Engineering Contradiction:
Improveability to manage multiple frameworksVSAvoidplatform unification
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal risk tracking platform that can manage multiple compliance frameworks (NIST, ISO 27001, CMMC, etc.) simultaneously through a common architecture, reducing the need for multiple separate systems while maintaining framework-specific tracking capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses configurable parameters and framework-specific configuration files that allow the same core platform to adapt to different frameworks by changing parameters rather than changing the underlying system architecture, simplifying platform unification

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20230385424A1Cybersecurity risk tracking, maturation, and/or certification
Publication Date: 2023.11.30 HILL II ROBERT
  • US20230385424A1 patent drawing
  • US20230385424A1 patent drawing
  • US20230385424A1 patent drawing

AI summary

A system that utilizes a risk model. The system preferably includes devices that identify cybersecurity risks, measure the risks, prioritize the risks, and provide options for remediating the risks. The devices may include computing infrastructure. Preferably, measuring the risks is adaptive to various inputs, for example using a score based process. The score based process may involve at least group analysis such as at least scores for risk management, asset configuration and change management, and identity and access management. Various aspects such as the score based process and other aspects may be adaptive and/or involve machine learning. Also, associated methods.