Identity Access Maturity Model for IT Risk Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face difficulties in identifying and managing identity and access management risks across their IT environments, as existing measures often fail to distinguish between resources with high and low risks, making it challenging to allocate investments effectively.

Innovation Solution

A computer-implemented process utilizing a maturity model that assesses the state and maturity of identity and access management controls across IT resources, generating maturity scores and an aggregate risk score, and providing a roadmap for improving risk management, with automated application of controls through a governance system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security measures are implemented across IT resources, then security coverage is improved, but the ability to distinguish and prioritize high-risk from low-risk resources deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidrisk differentiation capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the IT environment into distinct risk categories (critical, high, medium, low) and applies differentiated security measures to each segment. The maturity model divides security controls into multiple dimensions (identity management, access control, authentication, authorization, review processes) allowing granular assessment and targeted improvement strategies for different resource types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by tailoring security controls and maturity levels to specific resource characteristics. Different IT resources receive customized security postures based on their risk profiles, with critical resources receiving enhanced controls and low-risk resources receiving appropriate but reduced controls, optimizing both security coverage and resource allocation.

Inventive Principle:
Principle #3Local quality

2Reliability

If comprehensive security controls are applied to all IT resources, then overall security is improved, but the efficiency of security investment deteriorates

Engineering Contradiction:
Improveoverall securityVSAvoidinvestment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by implementing security controls proportionally to risk levels rather than uniformly across all resources. Critical resources receive comprehensive controls while low-risk resources receive targeted controls, preventing excessive security spending on low-value areas while maintaining adequate protection where needed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The maturity model provides feedback mechanisms that continuously monitor security performance and resource risk profiles. This feedback enables dynamic adjustment of security investments based on changing conditions, ensuring optimal allocation of security resources to areas where they provide the greatest risk reduction benefit.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If manual assessment of security maturity is performed, then customization is improved, but the time and resources required for assessment deteriorates

Engineering Contradiction:
Improvecustomization capabilityVSAvoidassessment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The maturity model provides a universal framework that can be applied across diverse IT resources and environments. The standardized dimensions and criteria enable consistent assessment across different resource types while maintaining customization through configurable weightings and thresholds, eliminating the need for separate assessment methodologies for each resource category.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables parameter changes by allowing organizations to customize the maturity model dimensions, weights, and thresholds based on their specific risk tolerance and operational requirements. This flexibility allows the same standardized framework to adapt to different organizational contexts without requiring manual reassessment, reducing time while maintaining customization relevance.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9830568B2Controlling and managing identity access risk
Publication Date: 2017.11.28 BANK OF AMERICA CORP
  • US9830568B2 patent drawing
  • US9830568B2 patent drawing
  • US9830568B2 patent drawing

AI summary

Methods and systems for controlling and managing identity and access management risks are presented. A computing device may generate a maturity model that maps a plurality of access management controls to a plurality of information technology (IT) resources associated with an IT environment. Subsequently, the computing device may determine, for each IT resource of the plurality of IT resources, a plurality of access management maturity scores. Each access management maturity score of the plurality of access management scores may correspond to an access management control of the plurality of access management controls that are associated with the corresponding IT resource. The computing device then may determine an aggregate maturity score for the IT environment based on the plurality of access management maturity scores for the plurality of IT resources. Thereafter, the computing device may provide the maturity model and the aggregate maturity score to at least one governance system.