IT Service Security Assurance Level Calculation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for calculating cybersecurity assurance levels in organizations are complex, require extensive subject matter expertise, and are difficult to apply universally, as they do not account for the specific environment and resource allocation effectively.

Innovation Solution

A method and system that assesses criticality and security factors for each information technology service within an organization, determining current and target security assurance levels, and provides a graphical indication of additional security controls needed to align with a desired level, considering factors like confidentiality, integrity, and availability, and system environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current industry techniques for calculating security assurance levels are used, then security assessment can be performed, but the process becomes complex and requires extensive subject matter expertise

Engineering Contradiction:
Improvesecurity assurance level calculationVSAvoidcalculation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security assurance level calculation by dividing the organization's environment into discrete information technology services. Each service is assessed independently using standardized questions, breaking down the complex organizational assessment into manageable service-level units that can be evaluated systematically without requiring extensive expert judgment for the entire organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the assessment parameters from organization-wide qualitative judgments to service-specific quantitative assessments. By using standardized questions with defined response options for each information technology service, the system transforms the calculation from an expert-dependent process to a parameter-driven automated calculation that maintains reliability while reducing complexity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If current industry techniques for calculating security assurance levels are used, then security assessment can be performed, but the method is difficult to apply to different organizations

Engineering Contradiction:
Improvesecurity assurance level calculationVSAvoidapplicability to different organizations
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal assessment framework that can be applied to any organization by focusing on information technology services as the common denominator. The standardized questions and evaluation criteria are designed to work across different organizational types, sizes, and industries, making the security assurance level calculation adaptable and versatile while maintaining reliability through consistent methodology.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

By segmenting the assessment to the information technology service level rather than the organization level, the patent enables the same standardized methodology to be universally applied across different organizations. Each service is assessed using the same criteria, allowing the system to adapt to any organizational context while maintaining calculation reliability through methodological consistency.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If detailed assessment of security factors is performed for each information technology service, then accurate security assurance levels can be determined, but resource allocation and implementation becomes more complex

Engineering Contradiction:
Improvesecurity assurance level determinationVSAvoidresource allocation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent enables automated self-assessment for each information technology service through standardized questions that can be answered using available service documentation and configuration data. This reduces the need for extensive expert intervention while maintaining measurement precision, as the systematic collection of service-specific information automatically feeds into the security assurance level calculation without requiring complex resource coordination.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

By segmenting the assessment to individual information technology services, the patent simplifies resource allocation compared to organization-wide assessments. Each service can be evaluated and prioritized independently, allowing resources to be allocated service-by-service based on calculated security assurance levels and identified gaps, rather than managing complex organization-wide resource distribution.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11308220B2Managing security related information technology services
Publication Date: 2022.04.19 THE BOEING CO
  • US11308220B2 patent drawing
  • US11308220B2 patent drawing
  • US11308220B2 patent drawing

AI summary

A method, apparatus, and system for managing information technology services. A current security assurance level for an information technology service related to security in an organization is determined based on assessment information about security factors for the information technology service and performance information about a group of current security controls for the information technology service. A target security assurance level for the information technology service is determined based on a criticality of the information technology service. A graphical representation of a difference between the current security assurance level and the target security assurance level on a display system is displayed. When the difference is greater than a threshold, a graphical indication of additional security controls is displayed that, if implemented for the information technology service, results in the difference between the current and target security assurance level being within a desired security assurance level for protecting the information technology service.