Tailoring Security Evaluation Items to Apparatus Characteristics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security evaluation techniques apply the same set of security evaluation items to all apparatuses within an information system, failing to account for the unique characteristics of each apparatus, such as communication paths and exemptions, leading to unnecessary processes and inappropriate evaluations.
Innovation Solution
An information processing device that acquires and analyzes the characteristics of each apparatus to select appropriate security evaluation items, considering communication paths and exemptions, thereby tailoring the evaluation process to each apparatus.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the same security evaluation items are adopted to all apparatuses, then the evaluation process is simple and uniform, but the evaluation accuracy and appropriateness for each apparatus decreases
Solution Approach 1:
The patent segments the unified security evaluation process into apparatus-specific evaluation sets. The item selection unit divides the comprehensive list of security evaluation items into subsets tailored to each apparatus's characteristics, such as whether it communicates with outside apparatuses or has specific security exemptions. This segmentation allows each apparatus to receive a customized evaluation set rather than a generic one, improving evaluation accuracy while maintaining systematic processing.
Solution Approach 2:
The patent applies local quality by making the security evaluation items apparatus-specific rather than uniform across all systems. Each apparatus receives evaluation items selected according to its local characteristics (communication status, exemptions, security requirements). This ensures that the evaluation process is appropriately tailored to each apparatus's specific context, improving the relevance and accuracy of security assessments for each individual system.
2Measurement precision
If security evaluation items are selected based on apparatus characteristics, then the evaluation appropriateness improves, but the device complexity and processing overhead increases
Solution Approach 1:
The patent implements preliminary action by pre-establishing the criteria and rules for selecting security evaluation items based on apparatus characteristics. The item selection unit uses pre-defined selection rules that consider whether apparatuses communicate with outside systems and what security exemptions apply. These selection criteria are determined in advance, allowing the system to efficiently retrieve and apply appropriate evaluation items without complex real-time analysis, thus reducing processing overhead while maintaining evaluation appropriateness.
Solution Approach 2:
The system enables self-service by allowing each apparatus to effectively select its own relevant security evaluation items based on its characteristics. The item selection unit automatically determines which evaluation items apply to each apparatus without requiring manual configuration or complex external analysis. This self-determination process reduces the burden on external systems and simplifies the overall evaluation workflow while ensuring each apparatus receives appropriate evaluation coverage.
3Stability of the object's composition
If the same security evaluation items are applied to all apparatuses, then consistent evaluation standards are maintained, but unnecessary processes occur for apparatuses where certain evaluations are exempted
Solution Approach 1:
The patent applies the extraction principle by removing unnecessary security evaluation items from the evaluation process for specific apparatuses. The item selection unit identifies and extracts only the relevant evaluation items that apply to each apparatus based on its characteristics and exemptions. For example, if an apparatus has no external communication capability, evaluation items related to external communication security are extracted and excluded from that apparatus's evaluation set. This eliminates unnecessary processing steps while maintaining consistent evaluation standards for the items that are actually applied.
Data Source
AI summary
An evaluation item generation unit (107) acquires a plurality of candidates for security evaluation items to be adopted to a plurality of apparatuses included in an information system. Further, the evaluation item generation unit (107) analyzes at least one of: whether or not each apparatus of the plurality of apparatuses has a communication path with an outside communication apparatus being an apparatus which is in the information system and performs communication with the outside of the information system; and whether or not there exists in each apparatus of the plurality of apparatuses, a security evaluation item an adoption of which is to be exempted due to an adoption of which to another apparatus in the information system, and selects for each apparatus of the plurality of apparatuses, a security evaluation item to be adopted, from the plurality of candidates for the security evaluation items based on an analysis result.


