Third-Party Network Compliance Assessment via Executable Scanning Plugins

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Entities face challenges in ensuring third-party network compliance with their security and control standards without compromising the third party's privacy and security, and existing manual assessment methods are cumbersome and prone to missing vulnerabilities between assessments.

Innovation Solution

A method and system for assessing third-party network compliance by generating a scanning file with compliance standards, executing it at the third-party network to scan for hardware and software compliance, and creating an immutable log file for secure reporting, allowing for ongoing, real-time monitoring and automatic corrections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual weekly, monthly and/or annual assessments are performed, then third party network compliance can be evaluated, but the efforts required are cumbersome and vulnerabilities may incur and build up between assessments

Engineering Contradiction:
Improvecompliance assessment reliabilityVSAvoidassessment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The third party network autonomously executes compliance assessments using self-contained executable files and scanning plugins that run locally on their infrastructure. The system performs self-assessment without requiring external manual intervention, automatically generating reports and identifying vulnerabilities between traditional assessment cycles.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Compliance assessment tools and executable files are prepared and deployed in advance to the third party network. The system performs preliminary scanning and vulnerability identification continuously before formal assessment cycles, ensuring issues are detected early rather than allowing them to accumulate between manual assessments.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If an organization enters the third party network to assess compliance, then compliance standards can be verified, but the third party vendor's privacy and security may be compromised

Engineering Contradiction:
Improvecompliance verification accuracyVSAvoidprivacy and security compromise
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The compliance assessment system uses an intermediary executable file that acts as a trusted mediator between the organization and third party network. This self-contained plugin runs locally on the third party infrastructure, allowing compliance verification without direct organizational access to the network, thus maintaining privacy and security while ensuring accurate assessment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The organization deploys a copy of the compliance assessment engine (executable file with scanning plugin) to the third party network rather than accessing the network directly. This copied assessment tool performs verification locally, eliminating the need for organizational personnel to enter the third party network and compromising their security boundaries.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If specific network compliance standards are created for each third party network, then compliance can be tailored to organizational requirements, but the complexity of managing multiple custom standards increases

Engineering Contradiction:
Improvecompliance standard customizationVSAvoidassessment system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system allows customization of compliance standards at the local level for each third party network while maintaining a centralized framework. Organizations can tailor specific security and compliance requirements for each vendor without redesigning the entire assessment system, enabling adaptable standards with manageable complexity through localized configuration.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12137032B2Systems and methods for identifying and determining third party compliance
Publication Date: 2024.11.05 BANK OF AMERICA CORP
  • US12137032B2 patent drawing
  • US12137032B2 patent drawing
  • US12137032B2 patent drawing

AI summary

A method for determining third party network compliance with a host entity network is provided. The method may include generating a scanning file that includes host entity network compliance standards and transferring the scanning file to an intermediary entity network. The method may further include generating an executable file that may run a plug-in scanning file to scan hardware and software resident at the third-party network for compliance. The method may further include transferring the executable file from the intermediary entity network to the third party network. The method may further include executing the executable file, generating a log file upon the completion of the running of the plug-in scanning file and digitally signing the log file. The method may further include deciphering the log file at the intermediary entity network, generating a readable report based on the deciphering and transferring the readable report to the host entity network.