Automated Data Protection Risk Assessment System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data protection systems lack comprehensive tools for identifying and assessing data protection gaps and risk scores across multiple resources, which can lead to inconsistencies, breaches, and reduced reliability and availability of data protection resources.

Innovation Solution

A method and system for automated data protection resource management that identifies data protection gaps and calculates risk scores by processing collected data, using rule-based analysis to assess the health and compliance of data protection schemes, and generating reports on differences in risk scores over time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated data protection management systems are implemented, then productivity and reliability of data protection resources are improved, but device complexity increases

Engineering Contradiction:
Improvereliability of data protection resourcesVSAvoidcomplexity of management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automated self-assessment of data protection status by having data protection resources evaluate themselves against defined policies and standards. This self-service mechanism reduces the need for complex external management while improving reliability through consistent automated evaluation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where assessment results are automatically fed back to stakeholders and used to trigger remediation actions. This feedback mechanism improves reliability by ensuring issues are detected and addressed promptly, while the automation reduces management complexity.

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive monitoring and assessment of all data protection resources is performed, then reliability and compliance are improved, but loss of time and processing overhead increase

Engineering Contradiction:
Improvecompliance status of data protection resourcesVSAvoidtime for assessment and monitoring
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs assessment on a selective basis, focusing monitoring efforts on critical data protection resources and high-risk areas rather than uniformly assessing all resources. This partial action approach maintains compliance reliability for critical systems while reducing overall assessment time and processing overhead.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system implements periodic assessment cycles with different frequencies based on resource criticality and change rates. High-criticality resources are assessed more frequently, while stable, low-criticality resources are assessed less frequently, optimizing the balance between compliance assurance and time consumption.

Inventive Principle:
Principle #19Periodic action

3Measurement precision

If detailed gap analysis and risk scoring are performed on data protection schemes, then measurement precision is improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improveprecision of data protection gap identificationVSAvoidcomplexity of analysis system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments gap analysis into distinct, modular components: policy definition, status assessment, gap identification, and risk scoring. Each component handles a specific aspect of the analysis independently, improving measurement precision through focused evaluation while reducing overall system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses configurable parameters and thresholds that can be adjusted based on organizational needs and risk tolerance. This allows precise measurement of protection gaps while keeping the analysis system adaptable and manageable through parameter tuning rather than complex structural changes.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9411969B2System and method of assessing data protection status of data protection resources
Publication Date: 2016.08.09 CONTINUITY SOFTWARE
  • US9411969B2 patent drawing
  • US9411969B2 patent drawing
  • US9411969B2 patent drawing

AI summary

There are provided a method, system and service for computerized managing a plurality of data protection (DP) resources. The method comprises: accommodating data related to at least part of the DP resources among said plurality of DP resources in a memory thus giving rise to accommodated data, wherein at least part of the accommodated data is obtained by automated collecting; processing by a processor operatively coupled to the memory the accommodated data, said processing resulting in identifying at least one data protection (DP) scheme characterized, at least, by a data protection technique implemented with regard to at least one DP resource related to said DP scheme; identifying by the processor one or more data protection (DP) gaps affected the at least one DP resource; and using the identified one or more DP gaps for assessing, by the processor, DP risk score to the at least one DP resource.