Usage-tracking for Security Assurance Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information security (InfoSec) solutions lack automated business risk guidance aligned with industry standards like SOC 2, ISO 27001, and GDPR, and fail to provide real-time continuous monitoring of operational states, leading to inefficient risk assessments and compliance monitoring across multiple products and assets.

Innovation Solution

A multi-tenant security assurance platform that links InfoSec entities for real-time risk assessment and compliance monitoring, enabling automated risk and control recommendations, usage-tracking, and asset management across various products, using a relational data-model to connect policies, procedures, controls, and evidence tasks for consistent compliance reporting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual monitoring and assessment of security controls is performed, then detailed compliance verification can be achieved, but the process is time-consuming and labor-intensive

Engineering Contradiction:
Improvecompliance verification accuracyVSAvoidtime for compliance monitoring
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables self-service monitoring where the platform automatically tracks usage of security controls, policies, and procedures without requiring manual intervention. The usage-tracking mechanism autonomously collects data on control effectiveness and compliance status, allowing the system to monitor itself and generate compliance reports automatically.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical monitoring processes with automated digital tracking mechanisms. The usage-tracking system electronically monitors and records interactions with security controls, substituting human manual verification with automated system-based tracking that continuously monitors compliance status.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive tracking of InfoSec entities is implemented, then real-time compliance monitoring is enabled, but system complexity increases

Engineering Contradiction:
Improvereal-time compliance monitoringVSAvoidsystem structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The usage-tracking system serves multiple functions simultaneously: it tracks compliance status, monitors control effectiveness, generates reports, and provides real-time alerts. This multi-functional approach consolidates what would otherwise require separate systems into a single unified platform, reducing overall system complexity while maintaining comprehensive monitoring capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary usage-tracking layer between security controls and compliance reporting. This intermediary component simplifies the system architecture by providing a standardized interface that monitors all InfoSec entities and translates their operations into compliance metrics, reducing the complexity of direct monitoring relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated RFP answering capability is added, then response time improves, but integration with compliance monitoring becomes more complex

Engineering Contradiction:
ImproveRFP response speedVSAvoidintegration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges the RFP answering capability with the compliance monitoring system into a unified platform. The usage-tracking mechanism integrates both functions, allowing the system to automatically answer RFPs while simultaneously tracking compliance status, thereby reducing integration complexity through consolidation rather than separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified platform performs multiple functions including RFP response generation, compliance monitoring, usage tracking, and reporting within a single system. This multi-functional design eliminates the need for separate integration layers between RFP answering and compliance monitoring, simplifying the overall architecture while improving productivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12184685B2Usage-tracking of assets for security assurance
Publication Date: 2024.12.31 ONETRUST LLC
  • US12184685B2 patent drawing
  • US12184685B2 patent drawing
  • US12184685B2 patent drawing

AI summary

Techniques are disclosed for usage-tracking of various information security (InfoSec) entities for tenants/organization onboarded on an instant multi-tenant security assurance platform. The InfoSec entities include policies, procedures, controls and evidence tasks. A policy or procedure is enforced by implementing one or more controls, and the collection of one or more evidence tasks proves/verifies the implementation of a control. The InfoSec entities are linked to each other across the platform and accrue a number of benefits for the tenants. These include automatically/continuously creating asset populations and drawing samples from the asset populations for auditing. The population samples may be generated by entering natural language queries in the platform. Asset data from the asset populations is used to feed/populate various other modules and systems used by the tenant of the platform.