Third-Party Data Security Score Assessment System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for assessing the security of data managed by third-party providers are inadequate, as they often rely on manual questionnaires, static certifications, or resource-intensive external security scans, which fail to provide real-time insights into the current state of data security for clients.
Innovation Solution
A system and method that involves receiving vulnerability scan data, determining vulnerability metrics based on where client data is stored, calculating a security score for the third-party provider using a risk profile, and displaying this score to control data security, allowing for real-time assessment and management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual questionnaires are used to assess third-party provider security, then the assessment process is simple to implement, but it cannot provide real-time security information and only reflects static procedures rather than current security state
Solution Approach 1:
The patent introduces an intermediary system that automatically collects vulnerability scan data from third-party providers and processes it into security scores. This intermediary mechanism bridges the gap between static questionnaire methods and real-time security assessment, enabling continuous monitoring without manual intervention while maintaining ease of implementation through automated data exchange protocols
Solution Approach 2:
The patent replaces the mechanical manual questionnaire process with an automated electronic system that continuously collects vulnerability scan data, processes it through algorithms, and generates real-time security scores. This substitution eliminates the time delay inherent in manual methods while maintaining simplicity through standardized data interfaces and automated processing
2Measurement precision
If external security scans are commissioned to assess third-party provider infrastructure, then comprehensive security information can be obtained, but it requires significant resources, trained personnel, and time making it impractical for small entities
Solution Approach 1:
The patent enables third-party providers to perform self-service vulnerability scanning of their own infrastructure and automatically share the scan results with clients through the intermediary system. This eliminates the need for external security scan teams, reducing resource requirements and complexity while maintaining comprehensive security assessment capabilities through the providers' own scanning operations
Solution Approach 2:
The patent creates a universal platform where a single intermediary system serves multiple clients and third-party providers simultaneously. This multi-functional system handles data collection, processing, and distribution for numerous entities, reducing the per-entity resource requirements and making comprehensive security assessment practical for small entities that would otherwise find external scans prohibitively expensive
3Loss of information
If vulnerability scan results are shared with clients for security assessment, then real-time security information becomes available, but sensitive information in the scan results may compromise third-party provider security
Solution Approach 1:
The patent extracts only the essential security metrics and vulnerability information needed for client risk assessment from the comprehensive vulnerability scan results, while leaving out sensitive details about the third-party provider's infrastructure architecture, configurations, and other proprietary information. This extraction process provides clients with actionable security intelligence without exposing the provider's sensitive infrastructure data
Solution Approach 2:
The patent applies different levels of information disclosure to different parties: the full vulnerability scan results remain with the third-party provider for their security team, the intermediary system holds processed security scores and metrics, and clients receive customized security information relevant to their risk assessment needs. This localized quality approach ensures each party receives appropriate information without compromising overall security
Data Source
AI summary
The disclosure relates to a method, system and computer readable storage medium for determining and/or controlling security of data available to a third-party provider. For example, the method controls security of data belonging to a client and available to a third-party provider by receiving vulnerability scan data, determining a plurality of vulnerability metrics for the data of the client at the third-party provider using the vulnerability scan data, wherein the plurality of vulnerability metrics are based on where the data belonging to the client is stored at the third-party provider, determining a security score for the third-party provider based on the plurality of vulnerability metrics and a risk profile of the client; and causing a display device to display the security score determined for the third-party provider to control security of the data belonging to the client and available to the third-party provider.


