Automated Cybersecurity Policy Compliance Platform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for auditing, assessing, and monitoring cybersecurity policy documents in large organizations are inefficient, often requiring multiple weeks to complete and involving significant manual effort, due to challenges in information sharing across divisions and the need for compliance with regulations like the Federal Information System Security Act and NIST standards.

Innovation Solution

A method and system that consolidates policy document assessment, authorization, and monitoring in a single platform using intellectual property, enabling automated processes, digital signatures, and a cloud-based infrastructure to ensure compliance with regulations, reduce manual work, and facilitate regular updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual auditing and assessment processes are used to review policy documents across organizational divisions, then compliance with regulations can be achieved, but the process takes multiple weeks and requires significant manual effort

Engineering Contradiction:
Improvecompliance assuranceVSAvoidauditing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical auditing processes with an automated computer-based system that electronically retrieves, analyzes, and assesses policy documents against regulatory requirements, dramatically reducing the time from multiple weeks to significantly shorter periods while maintaining compliance assurance

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables policy documents to be automatically assessed and evaluated against regulatory requirements without requiring manual intervention at each division, with the automated process independently retrieving documents, analyzing compliance, and generating assessment results

Inventive Principle:
Principle #25Self-service

2Reliability

If auditors physically visit each operational division to locate policy documents, then comprehensive review can be conducted, but the process becomes challenging in large organizations due to information sharing problems across divisions

Engineering Contradiction:
Improvedocument completenessVSAvoiddocument retrieval difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a centralized automated system as an intermediary that connects to multiple organizational divisions through electronic interfaces, eliminating the need for auditors to physically navigate across divisions and automatically retrieving policy documents from various locations while ensuring comprehensive collection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates and manages electronic copies of policy documents in a centralized repository, allowing auditors to access document copies electronically without needing to locate physical documents at each division, thereby simplifying retrieval while maintaining document completeness

Inventive Principle:
Principle #26Copying

3Reliability

If multiple policy documents located throughout the organization are reviewed manually, then comprehensive compliance assessment is achieved, but the complexity and resource requirements increase significantly

Engineering Contradiction:
Improvecompliance assessment thoroughnessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal automated system that performs multiple functions including document retrieval, analysis, compliance assessment, and reporting within a single integrated platform, reducing the need for separate manual processes for each document and thereby managing complexity while maintaining thoroughness

Inventive Principle:
Principle #6Universality (Multi-functionality)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution significantly reduces the time and resources required for cybersecurity policy management, ensures compliance with regulations, and provides a centralized platform for monitoring and reporting, enhancing the Risk Management Framework (RMF) by automating the validation and monitoring of organizational policy documents.

Implementation Method 1

The present invention uses a MD5 (Message Digest algorithm 5) hashing function to ensure that a document has not been tampered with

Methodology Applied
Scientific EffectMD5 hashing:

Data Source

PatentUS11558182B2Method and system to facilitate assessment, authorization, and monitoring of policy documents related to an organization
Publication Date: 2023.01.17 FUDALA JAMES MARK
  • US11558182B2 patent drawing
  • US11558182B2 patent drawing
  • US11558182B2 patent drawing

AI summary

A method for facilitating assessment, authorization, and monitoring of policy documents in organizations for cyber security. The method includes a process of receiving indications of policy documents related to an organization from a user, thus, allowing the user to manager cyber security controls of written policy documents in accordance with regulations and standards. The method also includes retrieving regulations from external databases. Further, the method includes analysis of policy documents against regulations and generating insights. Subsequently, the method transmits the generated insights and/or reports to the user. Further, the method includes receiving monitoring data related to the organization from one or more user's PC devices. Further, the method uses a MD5 (Message Digest algorithm 5) hashing function to ensure that a document has not been tampered with and may include a time-based trigger utilizing a standard green/yellow/red light chart for ongoing authorizations and monitoring.