Cybersecurity Risk Remediation via Zone Rating Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity solutions are inadequate in effectively assessing and remediating cybersecurity risks in large computer networks with diverse resources, as they lack the ability to accurately identify critical risks and require manual, framework-specific calculations, making it challenging to prioritize and address vulnerabilities in a timely manner.
Innovation Solution
A cybersecurity solution that includes a system, method, and computer program capable of receiving data from computing resources, selecting a risk framework (such as OWASP, CVSS, or TRIKE), calculating risk scores, and remediating risks by assigning resources based on calculated risk ratings, allowing for automated and tailored remediation within each network zone.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual framework-specific risk calculations are performed, then measurement precision of risk assessment is improved, but loss of time and productivity deteriorate
Solution Approach 1:
The system performs self-service by automatically selecting appropriate risk frameworks and executing calculations without requiring manual intervention. The risk assessment system autonomously processes computing resources, selects frameworks based on resource types, and computes risk scores automatically, eliminating the need for manual framework-specific calculations while maintaining measurement precision.
Solution Approach 2:
The system changes parameters by dynamically selecting different risk frameworks (OWASP, CVSS, TRIKE, OCTAVE) based on the type of computing resource being assessed. This parameter change allows the system to adapt the assessment methodology to match the specific characteristics of each resource type, maintaining accuracy while standardizing the process to reduce time consumption.
2Productivity
If automated risk assessment is implemented, then productivity is improved, but measurement precision of risk scoring deteriorates
Solution Approach 1:
The system incorporates feedback mechanisms where risk scores are calculated, stored in a scoreboard, and used to determine remediation priorities. The feedback loop ensures that automated calculations are continuously refined and validated, maintaining measurement precision while achieving high productivity through automation.
Solution Approach 2:
The system achieves universality by supporting multiple risk frameworks (OWASP, CVSS, TRIKE, OCTAVE) within a single automated platform. This multi-functionality allows the system to maintain measurement precision across different assessment methodologies while achieving productivity improvements through unified automated processing.
3Reliability
If zone risk ratings are applied to override individual risk ratings, then reliability of risk management is improved, but device complexity increases
Solution Approach 1:
The system segments the network into zones, each with its own risk rating, and compares individual resource risk ratings against their respective zone ratings. This segmentation approach improves reliability by ensuring consistent risk management at the zone level while managing complexity through modular, hierarchical comparison logic that processes each zone independently.
4Adaptability or versatility
If multiple risk frameworks are supported, then adaptability to different computing resources is improved, but device complexity increases
Solution Approach 1:
The system implements dynamics by automatically selecting the appropriate risk framework based on the type of computing resource being assessed. The framework selection is not static but adapts dynamically to the resource characteristics, improving versatility while managing complexity through automated, context-aware selection rather than manual configuration.
Data Source
AI summary
A system, a method, and a computer program remediate a risk of a computing resource located in a computer network that has a plurality of other computing resource assets each having an associated risk. Data associated with a first computing resource is received, and a first risk framework is selected from among a plurality of risk frameworks. A risk score is calculated based on the received data and the selected first risk framework, and a first risk rating is determined based on the risk score. The first risk rating is compared against a zone risk rating to determine whether the first risk rating is greater than the zone risk rating, and the first risk rating is replaced by the zone risk rating when the zone risk rating is greater than the first risk rating. The cybersecurity risk of the first computing resource is remediated according to the first risk rating.


