Automated Risk Evaluation for Configuration Changes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex information systems face risks and unforeseen consequences during configuration changes, such as hardware malfunctions or application downtime, due to the lack of effective risk assessment and management tools.
Innovation Solution
A method and system that automatically evaluates risks associated with configuration changes by calculating a risk score based on historical change data, using a receiving module, database access module, and risk evaluation module to assess and authorize changes, thereby preventing or allowing changes based on predefined thresholds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If configuration changes are performed without risk assessment, then change implementation speed is improved, but system reliability deteriorates due to malfunctions and downtime
Solution Approach 1:
The system performs risk assessment before configuration changes are implemented. Historical change data is retrieved and analyzed in advance to calculate risk scores, allowing administrators to make informed decisions about whether to proceed with changes or modify them to reduce risk.
Solution Approach 2:
The system uses historical change data and risk assessment results as feedback to guide future configuration changes. The risk score calculation incorporates information about previous changes and their outcomes, creating a feedback loop that learns from past experiences to improve future change decisions.
2Reliability
If automated risk evaluation is implemented, then configuration change reliability is improved, but device complexity increases due to additional modules and data structures
Solution Approach 1:
The risk evaluation module serves multiple functions: it retrieves historical data, calculates risk scores, and provides authorization recommendations. By consolidating these functions into a single module that leverages existing CMDB data structures, the system avoids proportionally increasing complexity while achieving reliable automated risk assessment.
3Device complexity
If manual risk assessment is performed, then system complexity remains low, but time consumption increases and productivity decreases
Solution Approach 1:
The system performs self-assessment by automatically retrieving its own historical change data from the CMDB and calculating risk scores without requiring manual analysis. This self-service capability eliminates the need for human analysts to manually review past changes, dramatically reducing assessment time while maintaining low system complexity.
Data Source
AI summary
A system and method to manage configuration of an information system comprises an automated risk evaluation for a requested change of a configuration item in an information system. Change history information indicative of the effects of multiple historical changes to respective configuration items may accessed, and the automated risk evaluation may be based at least in part on the change history information. The requested change may be authorized or as part based on an assessment of a risk value which is calculated in the automated risk evaluation. Additional apparatus, systems, and methods are described.


