Risk-based model for security policy management
Abstract
A security policy management solution (such as a Data Loss Prevention (DLP) system) is augmented to enable a user to model and visualize how changes in a security policy may impact (positively or negatively) the effectiveness of a policy configuration as well as the risk associated with its deployment. This technique enables a user (e.g., a security policy administrator) to evolve enterprise information technology (IT) security policies and, in particular, to generate and display “what-if” scenarios by which the user can determine trade-offs between, on the one hand, the effectiveness of a proposed change to a policy, and on the other hand, the risk associated with the proposed change.
Claims
exact text as granted — not AI-modified1 . A method of policy change management, comprising:
defining a version of a policy; quantifying an effectiveness of the policy version; quantifying a risk associated with the policy version; mapping, on a machine-implemented graphical display, the effectiveness and the risk for the policy version; and comparing the policy version with a prior version of the policy to determine whether the policy version is to be implemented.
2 . The method as described in claim 1 further including mapping, on the graphical display, the effectiveness and the risk for the prior version of the policy.
3 . The method as described in claim 2 wherein the comparing step is performed visually, using the graphical display.
4 . The method as described in claim 1 wherein the effectiveness is quantified by assigning a value to an attribute associated with the policy version.
5 . The method as described in claim 4 wherein the attribute comprises a plurality of effectiveness attributes combined into a single effectiveness attribute.
6 . The method as described in claim 1 wherein the risk is quantified by assigning a measure of a negative impact of the policy on an attribute therewith.
7 . The method as described in claim 6 wherein the attribute comprises a plurality of risk attributes combined into a single risk attribute.
8 . The method as described in claim 1 wherein the effectiveness and the risk for the policy version are mapped in an n-dimensional space.Join the waitlist — get patent alerts
Track US2013055342A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.