Transient Cloud Resource GRC Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing environments face challenges in ensuring secure and compliant management of cloud resources, as existing methods are either manual, reactive, or require custom proactive compliance capabilities, making them difficult to scale and manage effectively.

Innovation Solution

The method involves maintaining cloud resources in a transient state, making them invisible to other resources for a configured duration to apply Governance, Risk, and Compliance (GRC) and security validations, and provisioning them only after passing these checks, leveraging reactive validations and API-based lifecycle events to derive configurable actions for continuous compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud resources are made visible immediately after provisioning, then other cloud resources can access and utilize them promptly, but security validations and GRC compliance checks cannot be applied effectively before exposure

Engineering Contradiction:
Improvesecurity complianceVSAvoidresource provisioning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by maintaining cloud resources in a transient state where security validations and GRC compliance checks are performed before the resources are made visible and accessible to other cloud resources. This ensures that all necessary security checks are completed in advance, resolving the contradiction between ensuring security compliance and enabling prompt resource utilization.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual or reactive compliance methods are used, then custom proactive compliance capabilities can be implemented, but the system becomes difficult to scale and manage effectively

Engineering Contradiction:
Improvecompliance assuranceVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the cloud resource provisioning system to automatically perform security validations and GRC compliance checks during the transient state, without requiring manual intervention. This automated approach ensures consistent compliance assurance while reducing management complexity and enabling effective scaling of the system.

Inventive Principle:
Principle #25Self-service

3Reliability

If cloud resources remain in transient state for extended periods, then thorough GRC and security validations can be performed, but resource provisioning time increases

Engineering Contradiction:
Improvevalidation thoroughnessVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies the skipping principle by optimizing the transient state duration to be the minimum necessary time required to complete essential security validations and GRC compliance checks. This approach rushes through the validation process efficiently, ensuring thoroughness while minimizing the time resources remain in the transient state, thus reducing overall provisioning time.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11765032B1Shifting left GRC and security compliance leveraging transient cloud resources
Publication Date: 2023.09.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11765032B1 patent drawing
  • US11765032B1 patent drawing
  • US11765032B1 patent drawing

AI summary

A method for Governance, Risk, Compliance (GRC) and security compliance in a cloud computing environment is provided. The method includes maintaining a cloud resource to be in a transient state that keeps the cloud resource from being visible to other cloud resources for a configured rule driven duration during which validations comprising the GRC and security compliance are applied to the cloud resource. The method further includes provisioning the cloud resource responsive to the cloud resource meeting a time-in-transient-state requirement and passing the GRC and security compliance. The maintaining step includes reusing reactive validations for further GRC and security compliance in a resource lifecycle leveraging Application Programming Interface (API) based lifecycle events during the transient state, and deriving a next set of configurable actions for provisioned resources by providing hooks to a provisioning service to get a compliance posture for the cloud resource in the transient state.