Security Firewall for IT Asset Divestiture Separation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IT asset divestitures, there is a challenge in securely separating and transitioning IT assets and personnel between the divesting and acquiring entities, with existing methods relying solely on transition services agreements that lack proactive measures to prevent data leakage and compromise, leading to conflicts of interest and complexity in managing co-mingled assets and personnel.

Innovation Solution

The implementation of a systematic methodology using computer hardware and software to differentiate divested assets and employees, deploy separation firewalls, and apply multiple layers of security controls, including email tagging, access lockdown, and network segmentation, to reduce data leakage risks during and after the divestiture process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If divested assets are separated before LD1, then security risk is reduced, but transition complexity and time increase

Engineering Contradiction:
Improvesecurity risk reductionVSAvoidtransition time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security preparations before LD1 by establishing security zones, configuring firewalls, and preparing access control policies. This allows security measures to be in place before the actual separation occurs, reducing security risks without extending the transition period.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system segments the network into security zones (divested zone, non-divested zone, transition zone) that can be quickly activated at LD1. This segmentation allows immediate security separation without requiring physical asset separation, thus reducing security risks while maintaining fast transition.

Inventive Principle:
Principle #1Segmentation

2Productivity

If divested assets remain under divesting entity control after LD1, then transition efficiency improves, but security risk increases

Engineering Contradiction:
Improvetransition efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system applies different access control qualities to different assets and personnel locally. Divested assets remain accessible to divesting entity personnel for transition purposes, but with restricted permissions. This allows continued efficient management while implementing security controls at the local asset level.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces an intermediary security layer (firewalls, security zones, access control policies) between the divesting entity and divested assets. This intermediary enables continued access for transition purposes while blocking unauthorized access and data leakage paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple security layers are deployed, then data protection improves, but system complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses multi-functional security components that perform multiple security functions simultaneously. For example, security zones provide both network segmentation and access control, while firewalls provide both traffic filtering and logging. This reduces the number of separate components needed while maintaining multiple security layers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system combines multiple security functions into integrated policies and configurations. Access control policies combine authentication, authorization, and auditing functions. Security zone configurations combine network segmentation, firewall rules, and monitoring parameters into unified manageable units.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If systematic proactive security measures are implemented, then data leakage prevention improves, but implementation complexity increases

Engineering Contradiction:
Improvedata leakage preventionVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary security configurations before LD1 including establishing security zones, configuring firewall rules, and preparing access control policies. This proactive preparation reduces the complexity of implementing security measures during the actual transition period.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements automated security policy enforcement and monitoring that operates without continuous manual intervention. Security controls are automatically applied based on predefined policies, and the system self-monitors for policy violations, reducing the operational complexity of maintaining proactive security measures.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8782770B1Systems and methods for managing security during a divestiture
Publication Date: 2014.07.15 CITIGROUP TECHNOLOGY INC
  • US8782770B1 patent drawing
  • US8782770B1 patent drawing
  • US8782770B1 patent drawing

AI summary

Methods and systems for managing security during a divestiture may involve, for example, differentiating divested assets and employees from non-divested assets and employees and identifying non-divested assets which divested employees are permitted to access. In addition, divested employee access to the non-divested assets which divested employees are not permitted to access is locked down, and a separation firewall is deployed between divested networks and non-divested networks.