US2013055342A1PendingUtilityA1

Risk-based model for security policy management

Assignee: IBMPriority: Aug 24, 2011Filed: Oct 2, 2012Published: Feb 28, 2013
Est. expiryAug 24, 2031(~5.1 yrs left)· nominal 20-yr term from priority
G06F 21/577
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A security policy management solution (such as a Data Loss Prevention (DLP) system) is augmented to enable a user to model and visualize how changes in a security policy may impact (positively or negatively) the effectiveness of a policy configuration as well as the risk associated with its deployment. This technique enables a user (e.g., a security policy administrator) to evolve enterprise information technology (IT) security policies and, in particular, to generate and display “what-if” scenarios by which the user can determine trade-offs between, on the one hand, the effectiveness of a proposed change to a policy, and on the other hand, the risk associated with the proposed change.

Claims

exact text as granted — not AI-modified
1 . A method of policy change management, comprising:
 defining a version of a policy;   quantifying an effectiveness of the policy version;   quantifying a risk associated with the policy version;   mapping, on a machine-implemented graphical display, the effectiveness and the risk for the policy version; and   comparing the policy version with a prior version of the policy to determine whether the policy version is to be implemented.   
     
     
         2 . The method as described in  claim 1  further including mapping, on the graphical display, the effectiveness and the risk for the prior version of the policy. 
     
     
         3 . The method as described in  claim 2  wherein the comparing step is performed visually, using the graphical display. 
     
     
         4 . The method as described in  claim 1  wherein the effectiveness is quantified by assigning a value to an attribute associated with the policy version. 
     
     
         5 . The method as described in  claim 4  wherein the attribute comprises a plurality of effectiveness attributes combined into a single effectiveness attribute. 
     
     
         6 . The method as described in  claim 1  wherein the risk is quantified by assigning a measure of a negative impact of the policy on an attribute therewith. 
     
     
         7 . The method as described in  claim 6  wherein the attribute comprises a plurality of risk attributes combined into a single risk attribute. 
     
     
         8 . The method as described in  claim 1  wherein the effectiveness and the risk for the policy version are mapped in an n-dimensional space.

Join the waitlist — get patent alerts

Track US2013055342A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.