Automated Security Assessment Scripting for STIG Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual security assessments for compliance with DISA's STIG security requirements are labor-intensive and costly, requiring significant manpower and time, especially for organizations with hundreds or thousands of servers, due to the need for individual assessments of each application or program.

Innovation Solution

An automated system that receives STIG security requirements, identifies applications for assessment, generates scripts for automatic security assessments, conducts the assessments, determines compliance, and generates reports, thereby streamlining the process and reducing manual effort.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual security assessments are conducted for each application on each server, then compliance verification accuracy is improved, but productivity deteriorates due to enormous time and manpower requirements

Engineering Contradiction:
Improvecompliance verification accuracyVSAvoidassessment throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system enables self-service automation where the security assessment system automatically performs assessments without requiring manual human intervention for each application. The system self-manages the entire assessment workflow including evidence collection, analysis, and reporting, thereby maintaining accuracy while dramatically improving productivity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of security assessment with an automated computer-based system. Instead of human assessors manually reviewing each application, the system uses automated scripts and tools to conduct assessments, substituting human labor with machine execution while preserving verification accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive manual assessments are performed across hundreds or thousands of servers, then security compliance reliability is improved, but loss of time increases significantly

Engineering Contradiction:
Improvesecurity compliance reliabilityVSAvoidassessment duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically preparing and executing assessment scripts before formal compliance verification is needed. The automated system proactively conducts assessments across all servers in advance, ensuring compliance status is continuously monitored and verified without requiring time-consuming manual processes when needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous security assessment across all servers simultaneously rather than sequentially. The automated system maintains continuous monitoring and assessment capabilities, ensuring that compliance verification is an ongoing process that provides reliable results without the time delays inherent in manual sequential assessments.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If automated scripts are generated and executed for security assessments, then productivity is improved through automation, but device complexity increases due to script generation and management requirements

Engineering Contradiction:
Improveassessment efficiencyVSAvoidsystem automation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system employs universal, standardized assessment scripts that can be applied across multiple applications and servers. These multi-functional scripts are designed to work with various applications uniformly, reducing the complexity of managing custom scripts for each individual application while maintaining high productivity through automated execution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent utilizes parameter-based script configuration where assessment criteria and parameters can be adjusted through configuration files rather than modifying the underlying script logic. This allows the system to adapt to different applications and compliance requirements by changing parameters rather than restructuring the automated assessment engine, thereby managing complexity while preserving productivity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11509678B2Automated security assessment systems
Publication Date: 2022.11.22 CERNER INNOVATION INC
  • US11509678B2 patent drawing
  • US11509678B2 patent drawing
  • US11509678B2 patent drawing

AI summary

The federal government requires organizations it partners with to comply with a higher level of security requirements and issues guideline detailing vulnerabilities within computer systems, assessments to be conducted, and security requirements. Previously, the security assessments required to be in compliance with the government's security requirements were mostly conducted manually, creating a labor and time intensive process. The present disclosure provides computerized systems and methods that intelligently and dynamically conduct automatic security assessments to determine security compliance for one or more applications. These systems and methods significantly improve the security assessment process and result in significant savings of time, labor, and money. The system receives the security requirements, identifies one or more applications to undergo a security assessment, generates a script comprising commands for conducting an automatic assessment of the one or more applications, conducts the security assessments on the one or more applications, determines whether the one or more application are in compliance with the security requirements and generates a report comprising the security assessment findings.