Ontology-Based Security Control Mapping for Compliance Text
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in efficiently identifying and mapping domain-specific security controls to meet compliance certification requirements due to complexity and the need for substantial manual effort and expertise.
Innovation Solution
A system utilizing n-grams and domain-specific ontologies to match security requirements with corresponding controls, enhanced by embedding models for semantic analysis and continuous ontology improvement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If conventional text analysis is used to identify security controls mapping to requirements, then the process can be automated to some extent, but the identification still requires substantial expertise and manual effort due to the complexity of requirements and controls
Solution Approach 1:
The patent introduces domain-specific ontologies as intermediary structures that bridge requirements and controls. These ontologies contain pre-defined security concepts, relationships, and mappings that serve as a mediator between the complex requirement texts and control descriptions, enabling automated identification without requiring substantial manual expertise
Solution Approach 2:
The patent performs preliminary action by pre-building domain-specific ontologies that capture security knowledge, concepts, and relationships before the actual mapping task. This preliminary structuring of domain knowledge enables subsequent automated identification processes to operate efficiently without requiring expert intervention during the mapping itself
2Measurement precision
If manual identification of control mappings is performed, then high accuracy can be achieved through expert analysis, but the process becomes time-consuming and requires substantial manual effort
Solution Approach 1:
The patent replaces the mechanical process of manual expert analysis with an automated computational system that uses natural language processing, ontology matching, and semantic analysis. This substitution maintains high accuracy through structured domain knowledge while eliminating the time consumption and manual effort associated with expert review
Solution Approach 2:
The patent creates structured copies of domain knowledge in the form of ontologies that replicate security concepts, relationships, and mappings in a machine-readable format. These ontological copies enable automated systems to access and apply expert-level security knowledge without requiring actual human experts to perform the analysis
3Reliability
If the number of compliance certifications and security requirements increases, then the security level and regulatory satisfaction improve, but the complexity of identifying and mapping controls to these requirements increases substantially
Solution Approach 1:
The patent creates universal domain-specific ontologies that can serve multiple compliance certifications and regulatory frameworks simultaneously. These ontologies capture fundamental security concepts and relationships that apply across different standards, enabling a single automated system to handle multiple certifications without proportionally increasing complexity
Solution Approach 2:
The patent segments the complex task of control identification into manageable components: requirement parsing, ontology concept matching, control description analysis, and mapping generation. This segmentation allows the system to handle increased numbers of requirements and certifications through modular processing rather than overwhelming monolithic analysis
Data Source
AI summary
Systems and methods include generation of a set of n-grams of different lengths from each of a plurality of text portions, determination, for each set of n-grams, of matching topic variants of a domain ontology, determination of a topic associated with each of the matching topic variants, wherein a determined topic is associated with the text portion from which n-grams matching an associated topic variant were generated, generation of first n-grams of different lengths from a first text portion, determination, for each of a plurality of the first n-grams, of first matching topic variants of the domain ontology, determination of a first topic associated with each of the first matching topic variants, and determination of mappings between the first text portion and the plurality of text portions based on the topics associated with the plurality of text portions and the determined first topics.


