Multi-tenant Security Assurance Platform Usage Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions lack an efficient and automated method for monitoring and ensuring compliance with security/privacy policies and frameworks, particularly in responding to RFPs and RFIs, and linking information security entities across a multi-tenant platform.
Innovation Solution
A multi-tenant security assurance platform that uses a data-model to link and track various information security entities, enabling automated or semi-automated responses to security questionnaires, readiness project tracking, and compliance monitoring through usage-tracking across the platform.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual monitoring and compliance checking is performed, then thoroughness of security compliance can be ensured, but time consumption and labor effort increase significantly
Solution Approach 1:
The system enables self-service by allowing the security monitoring system to automatically track and report on security entity usage without requiring manual intervention. The platform autonomously monitors compliance status, generates reports, and updates risk assessments based on usage data, eliminating the need for manual compliance checking while maintaining thoroughness.
Solution Approach 2:
The patent replaces manual mechanical compliance checking processes with an automated electronic system. The system uses software components to automatically monitor security entity usage, track compliance status, and generate reports, substituting human manual processes with automated digital mechanisms that achieve the same thoroughness much faster.
2Reliability
If security entities are tracked across multiple platforms, then comprehensive security assurance can be achieved, but system complexity increases
Solution Approach 1:
The system achieves universality by creating a unified security monitoring platform that can track multiple types of security entities (policies, controls, evidence tasks) across different platforms and contexts. The system serves multiple functions including compliance monitoring, risk assessment, and security assurance through a single integrated architecture, reducing overall system complexity despite the multi-platform scope.
Solution Approach 2:
The patent applies segmentation by dividing the complex security monitoring function into distinct modular components: entity tracking module, compliance checking module, risk assessment module, and reporting module. This segmentation allows each component to handle specific tasks independently, making the overall system more manageable and easier to implement across multiple platforms.
3Productivity
If automated RFP response generation is implemented, then response time improves, but accuracy and customization may be compromised
Solution Approach 1:
The system incorporates feedback mechanisms where automated responses are reviewed and validated against actual security entity usage data. The platform uses feedback loops to ensure accuracy by cross-checking generated responses with real-time compliance status and allowing manual verification, thus maintaining high accuracy while achieving fast automated response times.
Solution Approach 2:
The patent applies preliminary action by pre-configuring security policies, controls, and evidence task templates before RFP responses are needed. The system prepares and stores security entity usage data in advance, so when an RFP comes in, the automated response can be generated quickly by retrieving pre-prepared information rather than collecting data in real-time, both speeding up response time and maintaining accuracy.
Data Source
AI summary
Techniques are disclosed for usage-tracking of various information security (InfoSec) entities for tenants/organization onboarded on an instant multi-tenant security assurance platform. The InfoSec entities include policies, procedures, controls and evidence tasks. A policy or procedure is enforced by implementing one or more controls, and the collection of one or more evidence tasks proves/verifies the implementation of a control. The InfoSec entities are linked to each other across the platform and accrue a number of benefits for the tenants. These include efficiently generating a security questionnaire response (SQR), measuring readiness via a readiness project for an audit project, sharing InfoSec entities across the various products of a tenant organization, risk assessment, automatic collection of evidence tasks, among others.


