Smart Scheduler for Dynamic Compliance Check Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprises face challenges in consistently and reliably detecting and remediating policy violations across their data sources due to equal treatment of all data sources, pre-defined compliance check schedules, and the need for user intervention, which can lead to inefficiencies and reduced compliance readiness.

Innovation Solution

A method that computes a priority score for each data source based on factors like recent changes, identified hotspots, remediation history, user-defined priority, and time since last scan, to automatically schedule and prioritize compliance checks and remediation actions, ensuring that high-risk data sources are addressed promptly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If all data sources are treated equally with pre-defined compliance check schedules, then the compliance checking process is simple to implement, but the productivity and compliance readiness are reduced due to inefficiencies in resource allocation

Engineering Contradiction:
Improvecompliance checking efficiencyVSAvoidscheduling system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements dynamic scheduling by computing priority scores for data sources based on multiple factors including sensitivity levels, recent changes, identified hotspots, remediation history, and time since last scan. This dynamic priority scoring system replaces static pre-defined schedules, allowing the system to adaptively allocate compliance checking resources to high-risk data sources while maintaining automated operation without excessive complexity

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of scheduling from fixed time-based intervals to dynamic priority-based scheduling. By computing priority scores that incorporate multiple variables (sensitivity, recent changes, hotspots, remediation history, time since scan), the system transforms the scheduling approach to optimize productivity while managing complexity through automated score computation

Inventive Principle:
Principle #35Parameter changes

2Reliability

If compliance checks are scheduled based on pre-defined schedules, then the scheduling process is simple, but the reliability of detecting policy violations is reduced due to equal treatment of all data sources

Engineering Contradiction:
Improvepolicy violation detection reliabilityVSAvoidscheduling operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by treating different data sources differently based on their specific characteristics. Each data source receives a customized priority score computed from its unique attributes including sensitivity level, recent changes, identified hotspots, remediation history, and time since last scan. This localized approach improves detection reliability for high-risk sources while the automated computation maintains operational simplicity

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system incorporates feedback mechanisms by considering remediation history and identified hotspots in priority score computation. Past compliance issues and remediation effectiveness feed into future scheduling decisions, improving detection reliability for data sources with problematic histories while the automated feedback loop maintains ease of operation

Inventive Principle:
Principle #23Feedback

3Extent of automation

If user intervention is required for compliance checks, then the system is easier to control, but the extent of automation is reduced leading to inefficiencies

Engineering Contradiction:
Improvecompliance check automationVSAvoiduser control capability
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The system implements self-service by automatically computing priority scores and generating compliance check schedules without requiring user intervention. The automated system evaluates multiple factors (sensitivity, recent changes, hotspots, remediation history, time since scan) and autonomously determines scanning priorities, maximizing automation extent while maintaining operational simplicity through rule-based decision-making

Inventive Principle:
Principle #25Self-service

4Reliability

If high-risk data sources are prioritized using dynamic scoring, then the compliance readiness is enhanced, but the computational complexity increases

Engineering Contradiction:
Improvecompliance readinessVSAvoidscoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the compliance checking process into distinct priority score components: sensitivity level, recent changes, identified hotspots, remediation history, and time since last scan. Each component is evaluated separately and aggregated into an overall priority score, enhancing compliance readiness through comprehensive assessment while managing computational complexity through modular segmentation of the scoring process

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230130206A1Achieving the best compliance results while minimizing sensitive data placement policy violations with a smart scheduler
Publication Date: 2023.04.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20230130206A1 patent drawing
  • US20230130206A1 patent drawing
  • US20230130206A1 patent drawing

AI summary

Ensuring that there is a consistent and reliable manner for detecting and remedying potential policy violations from enterprise data sources by automating the scheduling of compliance checks on these enterprise data sources. These enterprise data sources include documents that are used by an enterprise that must be in compliance with a particular regulation.