Software Risk Assessment Tool for Application Control Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in identifying and measuring risk exposures and implementing effective risk controls across various software applications, leading to inefficient resource allocation and potential oversight of critical risks.

Innovation Solution

A software tool that collects and analyzes risk and control data for software applications, computing risk and control scores based on input from users, and providing filtering capabilities to prioritize resource allocation and identify areas for improvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual risk assessment methods are used across multiple software applications, then flexibility and adaptability are maintained, but consistency and completeness of risk identification deteriorate

Engineering Contradiction:
Improveflexibility in risk assessmentVSAvoidconsistency of risk identification
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent implements a universal risk assessment framework that can be applied consistently across different software applications while accommodating application-specific characteristics. The system provides standardized risk categories and control measures that work universally, yet allows customization for different application types and organizational contexts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables dynamic adjustment of risk assessment parameters based on application characteristics, organizational risk appetite, and control effectiveness. Risk scores are calculated by combining multiple parameters including likelihood, impact, and control maturity, allowing flexible weighting and threshold settings while maintaining consistent evaluation methodology.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If comprehensive risk data collection is performed across all software applications, then complete risk visibility is achieved, but resource requirements and system complexity increase

Engineering Contradiction:
Improvecompleteness of risk informationVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The risk assessment system is segmented into modular components: risk identification module, risk analysis module, control assessment module, and reporting module. Each software application can be assessed independently through standardized forms, and results are aggregated at higher organizational levels. This segmentation allows comprehensive data collection without requiring a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces standardized risk registers and control frameworks as intermediary structures between individual application assessments and enterprise-wide risk management. These intermediaries normalize diverse application-specific data into consistent formats, enabling comprehensive aggregation without direct complex interactions between all system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If detailed risk and control analysis is conducted for all software applications, then accurate risk prioritization is achieved, but time and resource consumption increase

Engineering Contradiction:
Improveaccuracy of risk prioritizationVSAvoidtime for risk assessment
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables risk assessors to perform detailed analysis on high-priority applications while using streamlined assessment approaches for lower-priority applications. Risk scoring thresholds and control maturity levels allow organizations to focus resources on applications that pose the greatest risk, performing exhaustive analysis only where necessary while maintaining adequate assessment coverage across the entire portfolio.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements dynamic risk scoring that adjusts assessment depth based on preliminary risk indicators. Applications with inherently low risk profiles can be assessed with fewer parameters and less detailed analysis, while high-risk applications trigger more comprehensive evaluation protocols. This adaptive parameter adjustment reduces overall assessment time while maintaining accuracy for critical applications.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If risk assessment framework is customized for each software application, then application-specific risks are captured, but consistency across the portfolio deteriorates

Engineering Contradiction:
Improveapplication-specific risk captureVSAvoidportfolio-wide consistency
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent implements a risk assessment framework where the overall structure and methodology remain consistent across the portfolio, while allowing local customization of risk categories, control measures, and assessment criteria specific to each application type. This enables capture of application-specific risks through tailored questionnaires and evaluation metrics while maintaining uniform scoring methodologies and aggregation approaches for portfolio-wide comparison.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8135605B2Application risk and control assessment tool
Publication Date: 2012.03.13 BANK OF AMERICA CORP
  • US8135605B2 patent drawing
  • US8135605B2 patent drawing
  • US8135605B2 patent drawing

AI summary

A tool to assess risks associated with software applications, and controls implemented to mitigate these risks, includes a first software component configured to gather information about the risks and controls, and a second software component configured to display the gathered information. The first software component includes a self-assessment tool which is invoked by a user to enter information reflective of risk levels over a number of risk categories. These risk levels are used to calculate a risk score associated with a particular application. The user also enters information as to whether or not a number of specific control attributes have been implemented, and this information is used to calculate a control score.