Dynamic Compliance Management for Integrated Computing Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional compliance management systems for integrated computing systems are static and fail to scale with dynamic changes in resources, such as additions, deletions, or modifications, leading to difficulties in maintaining compliance with security and performance policies, especially in highly configurable environments where resources frequently change.

Innovation Solution

An integrated computing system compliance management system that uses a security hardening-based object instance to dynamically assess compliance against established security hardening standards by creating a unified entity representing the system, with hierarchically arranged sub-object instances, and continually monitors for changes to ensure ongoing compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional static compliance management systems are used, then initial compliance can be established, but the system cannot adapt to dynamic changes in resources leading to compliance degradation

Engineering Contradiction:
Improveadaptability to resource changesVSAvoidcompliance maintenance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The compliance management system transitions from a static to a dynamic model by implementing continuous monitoring of resource configurations and automated re-evaluation of compliance policies. The system dynamically updates compliance status when resource additions, deletions, or modifications occur, ensuring ongoing compliance without requiring manual intervention for each change.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where compliance violations are detected, reported, and triggered for automated remediation. The continuous monitoring loop provides feedback on compliance status, and when changes occur in the computing environment, the system automatically re-evaluates policies and notifies administrators of any violations, creating a closed-loop compliance management process.

Inventive Principle:
Principle #23Feedback

2Productivity

If manual compliance verification is performed, then detailed security checks can be conducted, but the process becomes time-consuming and cannot keep pace with frequent resource modifications

Engineering Contradiction:
Improvecompliance verification speedVSAvoidcompliance assessment accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system replaces manual compliance verification processes with automated computational methods. Software agents continuously monitor resource configurations and automatically evaluate compliance against security policies, eliminating the need for manual checking while maintaining or improving assessment accuracy through consistent, rule-based evaluation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The compliance management system operates continuously rather than periodically, maintaining constant surveillance of resource configurations. This continuous operation ensures that compliance is verified in real-time as resources are created, modified, or deleted, significantly increasing verification speed compared to manual batch processing while maintaining comprehensive coverage.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If comprehensive security policies are applied to all resources, then security coverage is maximized, but system complexity and administration burden increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidcompliance management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The compliance management system segments the computing environment into manageable units such as resource pools, clusters, and individual components. Security policies are applied hierarchically at different levels, allowing comprehensive coverage while simplifying administration through modular policy management and localized enforcement points.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements universal compliance management capabilities that can handle multiple resource types and security policies through a single unified platform. The automated monitoring and evaluation framework provides multi-functional support for various security standards and compliance requirements, reducing administrative burden through consolidation rather than requiring separate management systems for each policy type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10587655B1Compliance management system and method for an integrated computing system
Publication Date: 2020.03.10 EMC IP HLDG CO LLC
  • US10587655B1 patent drawing
  • US10587655B1 patent drawing
  • US10587655B1 patent drawing

AI summary

A integrated computing system compliance management system includes a computer-based system to obtain an integrated computing system object instance of an integrated computing system that is generated from an object model comprising a unified entity representing the integrated computing system. The integrated computing system object instance has multiple hierarchally arranged sub-object instances representing hierarchally arranged resources of the integrated computing system. The system receive security hardening policies associated with an established security hardening standard, modify those sub-object instances to include the security hardening policies that are associated with those sub-object instances to form a security hardening-based object instance. Using the security hardening-based object instance, the system determines, for each security hardening policy, whether the configuration of the resources meets the security hardening policy using the security hardening-based object instance. Once determined, the system may then output the result of the determination.