Unified Compliance Control Framework for Overlapping Security Requirements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current compliance frameworks for IT systems are complex and time-consuming to implement, often requiring months or years, and software developers frequently overlook overlapping requirements, leading to inefficiencies and potential security vulnerabilities.

Innovation Solution

A computer-implemented method for incremental regulatory compliance that compares multiple regulatory documents to identify overlapping requirements not met by existing security controls, recommending additional security controls to be implemented, thereby streamlining compliance and enhancing system security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If compliance requirements are implemented individually for each framework, then each framework's requirements are addressed, but overlapping requirements are ignored and implementation time increases

Engineering Contradiction:
Improvecompliance coverageVSAvoidimplementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple compliance frameworks into a unified compliance program by identifying and consolidating overlapping requirements. The system maps requirements from different frameworks (e.g., PCI DSS, HIPAA, GDPR) to common security controls, allowing organizations to address multiple frameworks simultaneously through a single set of implemented controls rather than treating each framework separately.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal compliance control framework where a single security control can satisfy requirements across multiple compliance frameworks. By establishing a hierarchy of framework-specific requirements, common security controls, and control implementations, the system enables one control to serve multiple compliance purposes, reducing redundant implementation efforts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive security controls are implemented to meet all requirements, then security coverage is improved, but system complexity and implementation cost increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidcontrol implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments compliance requirements into a hierarchical structure with framework-specific requirements at the top level, common security controls in the middle layer, and specific control implementations at the bottom level. This segmentation allows organizations to identify which high-level security controls address multiple requirements without implementing every possible control, thereby reducing overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables organizations to implement a core set of common security controls that provide substantial compliance coverage across multiple frameworks, rather than implementing every possible control required by each framework individually. The system identifies the essential controls that address the majority of requirements, allowing for efficient implementation with adequate security coverage.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If developers focus on individual framework requirements, then specific framework compliance is achieved, but overlapping requirements remain unsatisfied prolonging security risks

Engineering Contradiction:
Improvecompliance implementation efficiencyVSAvoidsecurity risk exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism that automatically identifies unsatisfied requirements by comparing implemented controls against the full set of framework requirements. The system provides visibility into which overlapping requirements are not yet addressed and guides developers to implement additional controls needed to achieve complete compliance, thereby reducing security risk exposure while maintaining efficient implementation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12130927B2Incremental regulatory compliance
Publication Date: 2024.10.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12130927B2 patent drawing
  • US12130927B2 patent drawing
  • US12130927B2 patent drawing

AI summary

Methods, systems, and computer program products for incremental regulatory compliance are provided herein. A computer-implemented method includes obtaining at least one first document indicative of a first set of requirements, at least one second document indicative of a second set of requirements, and a baseline document indicative of one or more security controls currently implemented in a system architecture; performing a document comparison between the at least one first document, the at least one second document, and the baseline document to identify overlapping requirements across the first set and the second set that are not satisfied by the one or more security controls; and recommending at least one additional security control to be implemented in said system architecture for satisfying at least one of the identified overlapping requirements.