Software Security Maturity Scoring for Risk-Based Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current testing methods for software and IT products are inefficient in assessing the risk of changes due to their inability to consider the inherent risk of the change, the development environment, and the operational environment, leading to inadequate testing strategies that do not account for potential unintended consequences.

Innovation Solution

A system and method for evaluating the maturity of organizational processes, system and software architecture, and implementation to determine risk, using machine learning models to generate maturity scores and inform tailored test plans.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full retesting is conducted for any change, then reliability is improved, but productivity deteriorates due to time and cost consumption

Engineering Contradiction:
Improvetesting thoroughnessVSAvoidtesting efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the parameter of testing scope from fixed (full retest) to dynamic (risk-based scope). It introduces maturity scores as a parameter to determine the extent of testing required, allowing the system to adjust testing parameters based on the assessed risk level of changes and organizational maturity, thereby resolving the contradiction between thoroughness and efficiency

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent performs preliminary risk assessment and maturity scoring before actual testing. By evaluating organizational maturity, change risk, and domain criticality in advance, the system determines the appropriate testing scope beforehand, avoiding unnecessary full retests and improving productivity while maintaining reliability through targeted testing

Inventive Principle:
Principle #10Preliminary action

2Productivity

If automated testing is used, then productivity is improved through rapid execution, but reliability deteriorates due to lack of flexibility in finding novel concerns

Engineering Contradiction:
Improvetesting speedVSAvoiddetection capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces dynamic test plan generation based on risk assessment results. The testing approach transitions from static automated scripts to dynamic, risk-adapted test strategies that can incorporate both automated and manual testing elements, allowing the system to maintain speed while improving detection capability through flexible test selection

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback loops where test results and risk assessments inform future testing strategies. The system learns from previous testing outcomes and adjusts the mix of automated versus manual testing, continuously improving reliability while maintaining productivity through data-driven test plan optimization

Inventive Principle:
Principle #23Feedback

3Reliability

If extensive manual testing is performed, then reliability is improved through human expertise, but productivity deteriorates due to high cost and time requirements

Engineering Contradiction:
Improvetesting accuracyVSAvoidtesting cost and time
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by directing human expertise specifically to high-risk areas identified through the maturity scoring system. Instead of uniform manual testing across all components, the system concentrates human analytical capabilities where they are most needed (high-risk, high-criticality areas) while using automated testing for lower-risk areas, optimizing both reliability and productivity

Inventive Principle:
Principle #3Local quality

4Reliability

If comprehensive testing is conducted across entire system, then reliability is improved, but productivity deteriorates due to expense and time consumption

Engineering Contradiction:
Improvesystem-wide coverageVSAvoidtesting resource consumption
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the testing process into distinct risk-based categories and domains. By dividing the system into manageable segments with different risk profiles and criticality levels, the system can apply appropriate testing intensity to each segment, achieving comprehensive coverage of high-risk areas while reducing resource consumption in low-risk areas, thus resolving the contradiction between coverage and resource usage

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12445479B2Testing software and IT products by evaluating security maturity and risk of change
Publication Date: 2025.10.14 CENTER FOR INTERNET SECURITY INC
  • US12445479B2 patent drawing
  • US12445479B2 patent drawing
  • US12445479B2 patent drawing

AI summary

Systems and methods for testing, evaluating, and scoring IT products (e.g., software) and product updates from a technology provider are disclosed herein. More specifically, organizational assessment may be performed to evaluate the provider's development lifecycle processes and generate organization maturity scores. Architecture assessment may be performed to evaluate the system-level and software-level architectures associated with the application and generate architecture maturity scores. Product verification may be performed via automated testing and penetration testing to generate verification maturity scores. The organization maturity scores, architecture maturity scores, and verification maturity scores may be used to provide recommendations to the provider and also combined into an overall maturity score, which may serve as a comprehensive summary of the evaluation. These generated scores inform and expedite testing of future iterations of the product.