US2013227696A1PendingUtilityA1

Automated Security Management

Assignee: GOLDMAN SACHS & CO NEW YORKPriority: Feb 12, 2002Filed: Feb 11, 2013Published: Aug 29, 2013
Est. expiryFeb 12, 2022(expired)· nominal 20-yr term from priority
Inventors:Carl Young
G06F 21/577G06Q 30/02G06Q 10/10H04L 63/1433
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computerized method and system for managing security risk, where risk associated with a breach of security is analyzed and quantified according to weighted risk variables. The analysis is accomplished by a computerized security risk management system that receives information relating to physical, informational, communication and surveillance risk, and structures the information such that it can be related to risk variables and a security risk level can be calculated according to a relevance of associated risk variables. The security risk level can be indicative of a likelihood that a breach of security may occur relating to a particular transaction or facility. Similarly, a security confidence level can be indicative of how secure a particular facility or practice is and a security maintenance level can be indicative of a level of security that should be maintained in relation to an analyzed subject.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented method for managing risk related to a security risk event, the method comprising:
 receiving information relating to a security risk event;   structuring the information received according to risk variables; and   calculating a security level using the structured information and a set of relationships established between the risk variables.   
     
     
         2 . The computer-implemented method of  claim 1  wherein the security level comprises an indication of an amount of risk that a breach of security may occur relating to the security risk event. 
     
     
         3 . The computer-implemented method of  claim 1  wherein the security level comprises a security confidence level indicative of how secure a particular facility can be made relative to a particular security risk event. 
     
     
         4 . The computer-implemented method of  claim 1  wherein the security level comprises a security confidence level can be indicative of how secure a particular practice can be made relative to a particular security risk event. 
     
     
         5 . The computer-implemented method of  claim 1  wherein the security level comprises a security maintenance level indicative of a level of security that should be maintained in relation to an analyzed security risk event. 
     
     
         6 . The computer-implemented method of  claim 1  additionally comprising the step of:
 generating a suggested security measure according to the security level and structured information. 
 
     
     
         7 . (canceled) 
     
     
         8 . The computer-implemented method of  claim 6  additionally comprising the step of:
 receiving information relating to security measures executed; and 
 generating a security diligence report. 
 
     
     
         9 . The computer-implemented method of  claim 8  wherein the security diligence report comprises inquiries made relating to the security risk event and security measures executed responsive to the security level. 
     
     
         10 . The computer-implemented method of  claim 6  wherein the suggested security measure comprises physical protection of media containing information relating to the transaction. 
     
     
         11 . The computer-implemented method of  claim 1  wherein the suggested security measure comprises physical protection of a facility associated with the security risk. 
     
     
         12 . (canceled) 
     
     
         13 . The computer-implemented method of  claim 1  wherein the suggested action comprises notifying an authority regarding potential breach of security. 
     
     
         14 . The computer-implemented method of  claim 6  additionally comprising the step of:
 branding the suggested security measure according to the set of relationships between the risk variables. 
 
     
     
         15 . The computer-implemented method of  claim 1  wherein level of analysis utilized in the calculation of the security level is rated according to a classification. 
     
     
         16 - 19 . (canceled) 
     
     
         20 . The computer-implemented method of  claim 1  additionally comprising the step of:
 recalculating the security level responsive to new information received. 
 
     
     
         21 . The computer-implemented method of  claim 1  additionally comprising the step of:
 recalculating the security level responsive to progression of a chronology of events. 
 
     
     
         22 . A computerized system for managing risk related to a security risk event, the system comprising:
 a computer server accessible with a system access device via a communications network; and   executable software stored on the server and executable on demand, the software operative with the server to cause the system to:
 receive information relating to a security risk event; 
 structure the information received according to risk variables; and 
 calculate a security level using the structured information and a set of relationships established between the risk variables. 
   
     
     
         23 . The computerized system of  claim 22  wherein the data is gathered via an electronic feed. 
     
     
         24 - 28 . (canceled) 
     
     
         29 . A system for interacting with a network access device so as to manage risk relating to a risk subject, the system comprising:
 means for initiating interaction with a security risk management server via a communications network;   means for inputting information descriptive of a security risk event;   means for transmitting the information descriptive of security risk event to a security risk management server; and   means for receiving a security level calculated using the information descriptive of a security risk event and a set of relationships established between risk variables associated with the information descriptive of a security risk event.   
     
     
         30 . The system of  claim 29  wherein the risk event is a financial transaction. 
     
     
         31 . The system of  claim 30 , further comprising means for receiving a suggested security measure according to the security level and structured information.

Join the waitlist — get patent alerts

Track US2013227696A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.