Security Control Maturity Assessment via Event Enrichment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in efficiently assessing the maturity and effectiveness of security controls in their IT environments, lacking a non-intrusive and automated method to evaluate compliance with standards like CIS Top 20 or NIST 800-171, which hinders their ability to improve cybersecurity posture.

Innovation Solution

A system and method for assessing security control maturity by monitoring security events, generating enriched events with metadata, classifying events to security controls, calculating activity metrics, and providing maturity scores, which allows for automated reporting and recommendations without installing agents, enabling compliance validation and improvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated security control assessment systems are implemented, then assessment efficiency and speed are improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improveassessment efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an event processor as an intermediary component that receives security events from multiple sensors, enriches them with metadata, and classifies them to security controls. This intermediary layer manages the complexity of data collection and analysis, enabling automated assessment without requiring direct complex interactions between all system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The assessment system is divided into distinct functional modules: sensors for data collection, an event processor for enrichment and classification, and a maturity calculator for assessment. This segmentation allows each component to perform its specific function independently, improving overall system efficiency while managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If non-intrusive assessment methods are used, then ease of operation and acceptance are improved, but measurement precision and detection capability may be reduced

Engineering Contradiction:
Improveease of deploymentVSAvoidcontrol assessment accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system enables security controls to self-report their status and activity through security events generated by the controls themselves. Sensors collect data directly from the security controls without requiring external intrusion or agent installation, allowing controls to provide information about their own operation and effectiveness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback loops where security events are continuously collected, processed, and used to calculate maturity scores that are fed back to stakeholders. This continuous feedback mechanism maintains measurement precision by using actual control performance data rather than static assessments.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive security control monitoring is implemented, then reliability and security posture assessment are improved, but loss of time and processing overhead increase

Engineering Contradiction:
Improveassessment reliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The event processor performs preliminary actions by enriching security events with metadata and classifying them to appropriate security controls before maturity calculation. This pre-processing organizes data in advance, reducing the time required for final assessment computations and improving overall processing efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous monitoring and processing of security events, maintaining constant assessment of control maturity rather than periodic batch processing. This continuous action ensures reliable, up-to-date assessment results while distributing processing load over time, reducing peak processing demands.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11212316B2Control maturity assessment in security operations environments
Publication Date: 2021.12.28 FORTINET INC
  • US11212316B2 patent drawing
  • US11212316B2 patent drawing
  • US11212316B2 patent drawing

AI summary

Method and system embodiments for assessing control maturity in security operations environments are described. According to some embodiments, the method facilitates a nonintrusive, automated means to configure and detect security controls installed in an Information Technology (IT) environment. The system verifies that these controls function as expected over a specified period of time and then maps each security control to a cell in a matrix of operational functions crossed with asset classes. The system captures metrics for security control activity that are displayed in the matrix to facilitate an assessment of security control architectural maturity. The system automatically generates visual and textual reports that provide recommendations to improve cybersecurity by enhancing existing and adding new controls, specify a suggested timeline for introducing those controls, and document gaps in compliance. The reports include automated remediation recommendations per compliance framework, including the ability to apply custom frameworks.