Historical Security Awareness Data Reporting With PII Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity tools struggle to detect new and unknown security threats involving social engineering, relying on employee awareness, and there is a need for efficient management of personally identifiable information (PII) in security awareness training data.
Innovation Solution
A system and method for efficiently storing and removing PII by replacing data items with links in a data storage system, using a PII user identifier to manage and validate PII removal, with tables for PII and joined PII data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PII data items are stored in data records for security awareness training, then training effectiveness is improved, but data exposure risks increase
Solution Approach 1:
The patent segments PII data items from the main data records and stores them in a separate PII data table. Each data record contains only a reference (pointer) to the PII table, not the actual PII values. This segmentation isolates sensitive information, reducing data exposure risks while maintaining training effectiveness through controlled access to the PII data.
Solution Approach 2:
The patent introduces a PII user identifier as an intermediary between the data records and the actual PII data. This identifier acts as a reference key that links data records to the PII data table without exposing the actual PII values in the main data storage, thereby reducing data exposure risks while preserving the ability to access PII when needed for training purposes.
2Object-affected harmful factors
If PII data items are removed from data records to reduce data exposure risks, then data security is improved, but training effectiveness deteriorates
Solution Approach 1:
The PII user identifier serves as an intermediary that maintains the link between data records and PII data even after removal from the main records. This allows the system to reduce data exposure by removing PII from data records while preserving training effectiveness through controlled access via the PII data table using the identifier as a key.
Solution Approach 2:
The patent creates a reference copy mechanism where the PII user identifier copies the essential linking information without copying the actual PII data values into the main data records. This allows data records to function without exposing sensitive information, while the PII data table maintains the actual values for authorized access, balancing security and training effectiveness.
3Object-affected harmful factors
If PII data items are stored in separate PII data table with links, then data security is improved, but system complexity increases
Solution Approach 1:
While segmentation into separate PII data table improves security, the patent mitigates the resulting complexity by using a simple reference mechanism (PII user identifier) that maintains straightforward relationships between data records and PII data. The segmentation is logical rather than physical in terms of access patterns, keeping the system manageable despite the separated storage structure.
Data Source
AI summary
The present disclosure describes systems and methods for efficient reporting of data which includes personally identifiable information (PII) and which is collected and processed by a security awareness system. The data may be stored in a data storage system. The data may include a time stamp and queries of an historical nature may be supported. In the event that PII is removed from the data storage system, then the removal may propagate through all aspects of the data storage system, including the historical data.


