Event Correlation Architecture for Unified GRC Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing governance, risk, and compliance (GRC) solutions are limited in providing a comprehensive and future-proof correlation solution for real-time monitoring and remediation across various organizational areas, as they often focus on specific types of correlation, failing to address dynamic and changing regulatory and risk management needs.
Innovation Solution
A system and method using an event correlation architecture that includes a solution designer for defining and deploying solution packs containing correlation rules, workflows, and actions to enforce governance, risk, and compliance controls, enabling integrated incident management and remediation across multiple languages and platforms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple separate correlation engines are deployed to address different compliance areas, then specific compliance needs can be met, but system complexity increases and integration becomes difficult
Solution Approach 1:
The patent combines multiple separate correlation engines into a single unified correlation engine that can handle diverse compliance requirements. The engine uses a modular rule system where different correlation rules can be loaded and executed within the same platform, eliminating the need for multiple separate systems while maintaining comprehensive compliance coverage across security, privacy, and regulatory areas.
Solution Approach 2:
The unified correlation engine is designed with multi-functionality to address various compliance needs through a single platform. It supports multiple correlation rules, event sources, and compliance frameworks simultaneously, allowing one system to perform the functions previously requiring multiple specialized engines.
2Ease of manufacture
If existing correlation solutions focus on specific isolated types of correlation, then they can be simpler to implement, but they fail to provide comprehensive and future-proof solutions for dynamic compliance needs
Solution Approach 1:
The correlation engine implements dynamic adaptability through a rule-based architecture that allows compliance rules to be added, modified, or removed without reconfiguring the entire system. The engine can dynamically load new correlation rules and adapt to changing compliance requirements, making it both simple to implement initially and comprehensive in its future-proof capabilities.
Solution Approach 2:
The system segments compliance requirements into individual, modular correlation rules that can be independently managed. Each rule addresses a specific compliance aspect, but collectively they provide comprehensive coverage. This segmentation allows simple implementation of individual rules while achieving comprehensive compliance through their integration.
3Adaptability or versatility
If a unified correlation solution is implemented to address all compliance areas, then comprehensive coverage is achieved, but system complexity and difficulty of management increase
Solution Approach 1:
The unified correlation engine segments compliance management into modular, independently configurable rules. Each correlation rule can be developed, tested, and deployed separately, making it easier to manage the overall system. The modular structure allows administrators to enable or disable specific rules based on compliance needs without affecting the entire system.
Solution Approach 2:
The system incorporates automated features that reduce manual management overhead, including automatic rule validation, conflict detection, and compliance reporting. These self-service capabilities simplify the operation of the unified system while maintaining comprehensive compliance enforcement across multiple areas.
Data Source
AI summary
Described herein is a system and method for auditing governance, risk, and compliance using an event correlation architecture. In particular, the event correlation architecture may include a solution designer for defining a solution pack that enforces one or more specific governance, risk, or compliance controls, and a solution manager for deploying the solution pack within the event correlation architecture to configure the architecture for enforcement of the one or more controls. Thus, a collection of content defined in the solution pack may be used to enrich one or more events received at the event correlation architecture, and a correlation engine may then correlate the events using the content in the solution pack to enforce the one or more governance, risk, or compliance controls.


