Automated Security Management
Abstract
A computerized method and system for managing security risk, where risk associated with a breach of security is analyzed and quantified according to weighted risk variables. The analysis is accomplished by a computerized security risk management system that receives information relating to physical, informational, communication and surveillance risk, and structures the information such that it can be related to risk variables and a security risk level can be calculated according to a relevance of associated risk variables. The security risk level can be indicative of a likelihood that a breach of security may occur relating to a particular transaction or facility. Similarly, a security confidence level can be indicative of how secure a particular facility or practice is and a security maintenance level can be indicative of a level of security that should be maintained in relation to an analyzed subject.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method for managing risk related to a security risk event, the method comprising:
receiving information relating to a security risk event; structuring the information received according to risk variables; and calculating a security level using the structured information and a set of relationships established between the risk variables.
2 . The computer-implemented method of claim 1 wherein the security level comprises an indication of an amount of risk that a breach of security may occur relating to the security risk event.
3 . The computer-implemented method of claim 1 wherein the security level comprises a security confidence level indicative of how secure a particular facility can be made relative to a particular security risk event.
4 . The computer-implemented method of claim 1 wherein the security level comprises a security confidence level can be indicative of how secure a particular practice can be made relative to a particular security risk event.
5 . The computer-implemented method of claim 1 wherein the security level comprises a security maintenance level indicative of a level of security that should be maintained in relation to an analyzed security risk event.
6 . The computer-implemented method of claim 1 additionally comprising the step of:
generating a suggested security measure according to the security level and structured information.
7 . (canceled)
8 . The computer-implemented method of claim 6 additionally comprising the step of:
receiving information relating to security measures executed; and
generating a security diligence report.
9 . The computer-implemented method of claim 8 wherein the security diligence report comprises inquiries made relating to the security risk event and security measures executed responsive to the security level.
10 . The computer-implemented method of claim 6 wherein the suggested security measure comprises physical protection of media containing information relating to the transaction.
11 . The computer-implemented method of claim 1 wherein the suggested security measure comprises physical protection of a facility associated with the security risk.
12 . (canceled)
13 . The computer-implemented method of claim 1 wherein the suggested action comprises notifying an authority regarding potential breach of security.
14 . The computer-implemented method of claim 6 additionally comprising the step of:
branding the suggested security measure according to the set of relationships between the risk variables.
15 . The computer-implemented method of claim 1 wherein level of analysis utilized in the calculation of the security level is rated according to a classification.
16 - 19 . (canceled)
20 . The computer-implemented method of claim 1 additionally comprising the step of:
recalculating the security level responsive to new information received.
21 . The computer-implemented method of claim 1 additionally comprising the step of:
recalculating the security level responsive to progression of a chronology of events.
22 . A computerized system for managing risk related to a security risk event, the system comprising:
a computer server accessible with a system access device via a communications network; and executable software stored on the server and executable on demand, the software operative with the server to cause the system to:
receive information relating to a security risk event;
structure the information received according to risk variables; and
calculate a security level using the structured information and a set of relationships established between the risk variables.
23 . The computerized system of claim 22 wherein the data is gathered via an electronic feed.
24 - 28 . (canceled)
29 . A system for interacting with a network access device so as to manage risk relating to a risk subject, the system comprising:
means for initiating interaction with a security risk management server via a communications network; means for inputting information descriptive of a security risk event; means for transmitting the information descriptive of security risk event to a security risk management server; and means for receiving a security level calculated using the information descriptive of a security risk event and a set of relationships established between risk variables associated with the information descriptive of a security risk event.
30 . The system of claim 29 wherein the risk event is a financial transaction.
31 . The system of claim 30 , further comprising means for receiving a suggested security measure according to the security level and structured information.Join the waitlist — get patent alerts
Track US2013227696A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.