Security Policy Management with Risk-Effectiveness Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security policy management systems lack the ability to explicitly link security policies to risk management, failing to provide user-defined policy versions and risk assessments, which hampers effective risk-based management and overlooks potential negative impacts of policy changes.

Innovation Solution

A technique that enables users to quantify and visualize the effectiveness and risk of security policy changes, allowing administrators to model and evaluate 'what-if' scenarios by assigning effectiveness and risk scores to policy attributes, and plotting these in a visual format to determine optimal policy configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policy strictness is increased to improve risk management effectiveness, then security effectiveness is improved, but user productivity and satisfaction deteriorate

Engineering Contradiction:
Improvesecurity effectivenessVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different levels of policy enforcement to different users, data types, and contexts rather than uniformly applying strict security controls to all operations. This allows the organization to achieve adequate security effectiveness while minimizing the impact on user productivity through selective, rather than universal, application of security measures.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts security policy parameters based on risk assessments, user roles, data sensitivity levels, and contextual factors. By changing security parameters adaptively rather than maintaining fixed strict controls, the system optimizes the balance between security effectiveness and user productivity across different operational scenarios.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If policy modifications are made to improve security controls, then risk management capability is improved, but policy complexity and implementation difficulty increase

Engineering Contradiction:
Improverisk management capabilityVSAvoidpolicy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides security policies into modular components that can be independently configured, managed, and assessed. This segmentation allows complex risk management capabilities to be built from simpler policy elements, reducing overall policy complexity while maintaining comprehensive risk management functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces policy templates and predefined security control patterns as intermediaries between security requirements and implementation. These intermediaries simplify policy creation and modification by providing reusable, pre-configured security controls that reduce the complexity of implementing risk management capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If quantitative risk assessment is implemented to improve decision-making, then risk-based management effectiveness is improved, but system complexity and implementation overhead increase

Engineering Contradiction:
Improverisk assessment precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system automatically performs risk assessments and generates quantitative risk scores based on policy configurations and organizational risk criteria, rather than requiring manual risk analysis. This self-service approach provides precise risk measurement while minimizing the complexity and overhead of manual risk assessment processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements automated feedback loops that continuously assess risk based on policy changes and operational data, providing real-time risk measurements without requiring complex manual intervention. This feedback mechanism maintains high measurement precision while managing system complexity through automation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9727733B2Risk-based model for security policy management
Publication Date: 2017.08.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9727733B2 patent drawing
  • US9727733B2 patent drawing
  • US9727733B2 patent drawing

AI summary

A security policy management solution (such as a Data Loss Prevention (DLP) system) is augmented to enable a user to model and visualize how changes in a security policy may impact (positively or negatively) the effectiveness of a policy configuration as well as the risk associated with its deployment. This technique enables a user (e.g., a security policy administrator) to evolve enterprise information technology (IT) security policies and, in particular, to generate and display “what-if” scenarios by which the user can determine trade-offs between, on the one hand, the effectiveness of a proposed change to a policy, and on the other hand, the risk associated with the proposed change.