Third-Party Data Security Score Assessment System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for assessing the security of data managed by third-party providers are inadequate, as they often rely on manual questionnaires, static certifications, or resource-intensive external security scans, which fail to provide real-time insights into the current state of data security for clients.

Innovation Solution

A system and method that involves receiving vulnerability scan data, determining vulnerability metrics based on where client data is stored, calculating a security score for the third-party provider using a risk profile, and displaying this score to control data security, allowing for real-time assessment and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual questionnaires are used to assess third-party provider security, then the assessment process is simple to implement, but it cannot provide real-time security information and only reflects static procedures rather than current security state

Engineering Contradiction:
Improveease of implementationVSAvoidreal-time information availability
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent introduces an intermediary system that automatically collects vulnerability scan data from third-party providers and processes it into security scores. This intermediary mechanism bridges the gap between static questionnaire methods and real-time security assessment, enabling continuous monitoring without manual intervention while maintaining ease of implementation through automated data exchange protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical manual questionnaire process with an automated electronic system that continuously collects vulnerability scan data, processes it through algorithms, and generates real-time security scores. This substitution eliminates the time delay inherent in manual methods while maintaining simplicity through standardized data interfaces and automated processing

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If external security scans are commissioned to assess third-party provider infrastructure, then comprehensive security information can be obtained, but it requires significant resources, trained personnel, and time making it impractical for small entities

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidresource requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent enables third-party providers to perform self-service vulnerability scanning of their own infrastructure and automatically share the scan results with clients through the intermediary system. This eliminates the need for external security scan teams, reducing resource requirements and complexity while maintaining comprehensive security assessment capabilities through the providers' own scanning operations

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal platform where a single intermediary system serves multiple clients and third-party providers simultaneously. This multi-functional system handles data collection, processing, and distribution for numerous entities, reducing the per-entity resource requirements and making comprehensive security assessment practical for small entities that would otherwise find external scans prohibitively expensive

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If vulnerability scan results are shared with clients for security assessment, then real-time security information becomes available, but sensitive information in the scan results may compromise third-party provider security

Engineering Contradiction:
Improvesecurity information availabilityVSAvoidinfrastructure security risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential security metrics and vulnerability information needed for client risk assessment from the comprehensive vulnerability scan results, while leaving out sensitive details about the third-party provider's infrastructure architecture, configurations, and other proprietary information. This extraction process provides clients with actionable security intelligence without exposing the provider's sensitive infrastructure data

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different levels of information disclosure to different parties: the full vulnerability scan results remain with the third-party provider for their security team, the intermediary system holds processed security scores and metrics, and clients receive customized security information relevant to their risk assessment needs. This localized quality approach ensures each party receives appropriate information without compromising overall security

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240323219A1System, method and computer readable storage medium for controlling security of data available to third-party providers
Publication Date: 2024.09.26 NSAA SECURITY PTY LTD
  • US20240323219A1 patent drawing
  • US20240323219A1 patent drawing
  • US20240323219A1 patent drawing

AI summary

The disclosure relates to a method, system and computer readable storage medium for determining and/or controlling security of data available to a third-party provider. For example, the method controls security of data belonging to a client and available to a third-party provider by receiving vulnerability scan data, determining a plurality of vulnerability metrics for the data of the client at the third-party provider using the vulnerability scan data, wherein the plurality of vulnerability metrics are based on where the data belonging to the client is stored at the third-party provider, determining a security score for the third-party provider based on the plurality of vulnerability metrics and a risk profile of the client; and causing a display device to display the security score determined for the third-party provider to control security of the data belonging to the client and available to the third-party provider.