Intelligence-Driven Security Compliance Policy Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

System administrators face challenges in determining and implementing applicable security and compliance policies for hosted services due to varying regulatory, legal, and industry rules, which can lead to inadequate data protection and configuration inefficiencies.

Innovation Solution

A security and compliance module analyzes a tenant's environment to suggest policy or configuration changes, which can be implemented and customized through a dashboard, encompassing regulatory, legal, industrial, and internal compliance standards, and monitors their effectiveness for data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If system administrators manually determine and implement security and compliance policies, then they can ensure detailed understanding and customization of policies, but the process becomes time-consuming and complex due to varying regulatory, legal, and industry rules

Engineering Contradiction:
Improvepolicy determination accuracyVSAvoidpolicy implementation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system automatically analyzes the tenant's service environment, detects data types, and generates policy suggestions without requiring manual administrator intervention for each policy decision. The security and compliance module autonomously performs environment analysis, data type detection, and policy recommendation generation based on applicable rules

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures policy templates and compliance rules based on various regulatory, legal, and industry standards before they are needed. When analyzing a tenant's environment, the system can quickly match detected data types against pre-prepared policy suggestions, significantly reducing the time required to determine appropriate security and compliance policies

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive security and compliance policies are implemented, then data protection is enhanced, but system complexity and administrative burden increase

Engineering Contradiction:
Improvedata protection effectivenessVSAvoidpolicy configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and applies only the specific security and compliance policies that are relevant to the tenant's actual service environment and data types. Rather than implementing all possible policies, the system identifies and applies only those necessary for protecting the detected data, reducing unnecessary complexity while maintaining adequate protection

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system tailors security and compliance policies to the specific local characteristics of each tenant's environment, data types, and applicable rules. Each policy suggestion is customized based on the actual service components, data sensitivity, and regulatory requirements, rather than applying uniform complex policies across all tenants

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If administrators manually configure security policies for each tenant, then customization to specific needs is achieved, but productivity and efficiency decrease

Engineering Contradiction:
Improvepolicy customization capabilityVSAvoidpolicy implementation efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system automatically adjusts policy parameters based on the detected service environment characteristics, data types, and applicable rules. By dynamically changing policy parameters according to the specific tenant context, the system achieves customization without requiring manual configuration for each tenant, thereby maintaining both adaptability and productivity

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3563284B1Intelligence and analysis driven security and compliance recommendations
Publication Date: 2023.11.01 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3563284B1 patent drawingFigure 1A
  • EP3563284B1 patent drawingFigure 1B
  • EP3563284B1 patent drawingFigure 1C

AI summary

Hosted services provided by service provider tenants to their users are an increasingly common software usage model. The usage of such services and handling of data may be subject to regulatory, legal, and industry-based rules, where different rules may be applicable depending on the particular service, handled data, and organization type, for example. Embodiments are directed to providing intelligence and analysis driven security and compliance suggestions for hosted services to reduce the burden on tenant administrators to determine and implement applicable policies and rules. Claims are directed to determination of a suggestion based on an analysis of a tenant's service environment, presentation of the suggestion along with analysis results and a prompt to confirm implementation of the suggestion, and upon receiving confirmation, presentation of an option to customize the suggestion by modifying settings suggested based on analysis results. The suggestion may be a policy, organization, policy customization, or organization customization.