Automated Risk Evaluation for Configuration Changes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex information systems face risks and unforeseen consequences during configuration changes, such as hardware malfunctions or application downtime, due to the lack of effective risk assessment and management tools.

Innovation Solution

A method and system that automatically evaluates risks associated with configuration changes by calculating a risk score based on historical change data, using a receiving module, database access module, and risk evaluation module to assess and authorize changes, thereby preventing or allowing changes based on predefined thresholds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If configuration changes are performed without risk assessment, then change implementation speed is improved, but system reliability deteriorates due to malfunctions and downtime

Engineering Contradiction:
Improvechange implementation speedVSAvoidsystem stability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs risk assessment before configuration changes are implemented. Historical change data is retrieved and analyzed in advance to calculate risk scores, allowing administrators to make informed decisions about whether to proceed with changes or modify them to reduce risk.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses historical change data and risk assessment results as feedback to guide future configuration changes. The risk score calculation incorporates information about previous changes and their outcomes, creating a feedback loop that learns from past experiences to improve future change decisions.

Inventive Principle:
Principle #23Feedback

2Reliability

If automated risk evaluation is implemented, then configuration change reliability is improved, but device complexity increases due to additional modules and data structures

Engineering Contradiction:
Improveconfiguration change success rateVSAvoidsystem structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The risk evaluation module serves multiple functions: it retrieves historical data, calculates risk scores, and provides authorization recommendations. By consolidating these functions into a single module that leverages existing CMDB data structures, the system avoids proportionally increasing complexity while achieving reliable automated risk assessment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If manual risk assessment is performed, then system complexity remains low, but time consumption increases and productivity decreases

Engineering Contradiction:
Improvesystem structure simplicityVSAvoidrisk assessment time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The system performs self-assessment by automatically retrieving its own historical change data from the CMDB and calculating risk scores without requiring manual analysis. This self-service capability eliminates the need for human analysts to manually review past changes, dramatically reducing assessment time while maintaining low system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9111235B2Method and system to evaluate risk of configuration changes in an information system
Publication Date: 2015.08.18 HCL AMERICA INC
  • US9111235B2 patent drawing
  • US9111235B2 patent drawing
  • US9111235B2 patent drawing

AI summary

A system and method to manage configuration of an information system comprises an automated risk evaluation for a requested change of a configuration item in an information system. Change history information indicative of the effects of multiple historical changes to respective configuration items may accessed, and the automated risk evaluation may be based at least in part on the change history information. The requested change may be authorized or as part based on an assessment of a risk value which is calculated in the automated risk evaluation. Additional apparatus, systems, and methods are described.