Security Control Verification Subsystem for Database Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in efficiently verifying and continuously monitoring security control settings across multiple managed computers, particularly due to varying security requirements and frequent changes in computer group memberships and configurations, which are time-consuming and complex to manage.
Innovation Solution
A security control verification and monitoring subsystem that associates appropriate security benchmarks with computer groups, verifies compliance through clientless profiling, and continuously monitors settings by comparing them against defined benchmarks, using a tree-structured database management system to produce reports and update records.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual computers are manually checked against security benchmarks, then compliance verification can be performed, but the process becomes time-consuming and complex, especially when computer group memberships and configurations change frequently
Solution Approach 1:
The system automatically performs security compliance verification without requiring manual intervention. The verification subsystem continuously monitors computer security settings, compares them against applicable benchmarks, and generates compliance reports automatically, eliminating the need for manual checking while maintaining reliable verification
Solution Approach 2:
The system continuously monitors security control settings and provides feedback by comparing current settings against security benchmarks. When changes occur, the system detects them and updates compliance status accordingly, enabling continuous verification without manual re-checking
2Reliability
If security control settings are manually verified on each computer, then compliance can be assessed, but the complexity increases significantly when computers are re-assigned among different groups or when group security requirements change
Solution Approach 1:
The verification subsystem serves multiple functions: it automatically identifies applicable security benchmarks based on computer group membership, retrieves the appropriate benchmark criteria, performs compliance comparison, and generates reports. This multi-functional approach simplifies the verification process while maintaining reliable compliance assessment across dynamically changing computer groups
Solution Approach 2:
The system introduces a central verification subsystem that acts as an intermediary between computers and security benchmarks. This subsystem manages the complexity by automatically determining which benchmarks apply to each computer based on its group assignment, eliminating the need for manual determination of applicable requirements
3Reliability
If continuous monitoring of security controls is implemented, then ongoing compliance can be ensured, but the system complexity and resource requirements increase
Solution Approach 1:
The verification subsystem operates continuously to monitor security control settings and compare them against applicable benchmarks. The system maintains persistent monitoring without interruption, ensuring ongoing compliance detection while using efficient comparison algorithms to minimize resource consumption
Data Source
AI summary
A security control verification and monitoring subsystem of a managed computer system performs security control verification operations regularly and for each security control verification operation determines the applicable security benchmark level for use by a given computer. The subsystem assigns security risk categories to groups of computers based, for example, on overall system or group administrator supplied potential impact settings and/or system type and business or information type selections. The subsystem further associates the security risk categories with security benchmark levels based on mapping information supplied by the overall system or group administrator. The subsystem then directs the computer to benchmark definition files based on the assigned security risk category, the associated security benchmark level and attributes of the computer. The subsystem performs the security control verification operations whenever the computer performs computer profile data update operations, and thus, monitors essentially continuously the security control compliance of the computer. The subsystem stores the results of the security verification operations and includes the results in reports for the system, group or computer.


