Software Security Maturity Scoring for Risk-Based Retesting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current testing methodologies for software and IT products are inadequate in assessing the risk of changes due to their inability to consider the inherent risk of the change, the development environment, and the operational environment, leading to inefficient and incomplete testing processes.

Innovation Solution

A system and method for evaluating the maturity of organizational processes and software architecture using machine learning models to generate maturity scores, which are combined to determine a comprehensive maturity score for risk-based decision-making and tailored test planning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full retesting is conducted with any change, then reliability of testing is improved, but productivity deteriorates due to time and cost consumption

Engineering Contradiction:
Improvetesting reliabilityVSAvoidtesting productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the parameter of testing scope from fixed (full retest) to dynamic (risk-based selective retest). It introduces risk parameters including change risk assessment, organizational maturity level, and architectural maturity level to determine the appropriate testing scope, thereby reducing unnecessary testing while maintaining reliability

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent makes the testing process dynamic by continuously assessing risk parameters and adjusting testing scope accordingly. The system dynamically determines whether to perform full retesting, partial retesting, or no retesting based on real-time evaluation of change risk, organizational maturity, and architectural maturity, optimizing productivity while maintaining reliability

Inventive Principle:
Principle #15Dynamics

2Productivity

If testing scope is reduced to save time and cost, then productivity is improved, but measurement precision of risk assessment deteriorates

Engineering Contradiction:
Improvetesting productivityVSAvoidrisk assessment precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary risk assessment actions before determining testing scope. It pre-establishes risk parameters including change risk, organizational maturity, and architectural maturity, and uses these pre-assessed parameters to guide the testing scope determination, ensuring precise risk assessment while maintaining productivity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where testing results and risk assessment outcomes are fed back into the system to continuously refine the risk model. This feedback loop improves the precision of risk assessment over time while maintaining optimized testing productivity

Inventive Principle:
Principle #23Feedback

3Ease of operation

If traditional testing types are used, then ease of operation is maintained, but adaptability to different risk scenarios deteriorates

Engineering Contradiction:
Improvetesting ease of operationVSAvoidtesting adaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal testing framework that can adapt to different risk scenarios while maintaining ease of operation. The system integrates multiple testing types (smoke testing, regression testing, security testing) into a single risk-based framework that automatically selects and configures appropriate testing based on assessed risk parameters, achieving both universality and ease of operation

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260019444A1Testing software and it products by evaluating security maturity and risk of change
Publication Date: 2026.01.15 CENTER FOR INTERNET SECURITY INC
  • US20260019444A1 patent drawing
  • US20260019444A1 patent drawing
  • US20260019444A1 patent drawing

AI summary

Systems and methods for testing, evaluating, and scoring IT products (e.g., software) and product updates from a technology provider are disclosed herein. More specifically, organizational assessment may be performed to evaluate the provider's development lifecycle processes and generate organization maturity scores. Architecture assessment may be performed to evaluate the system-level and software-level architectures associated with the application and generate architecture maturity scores. Product verification may be performed via automated testing and penetration testing to generate verification maturity scores. The organization maturity scores, architecture maturity scores, and verification maturity scores may be used to provide recommendations to the provider and also combined into an overall maturity score, which may serve as a comprehensive summary of the evaluation. These generated scores inform and expedite testing of future iterations of the product.