Security Capability Reference Model for Goal-based Gap Analysis
Abstract
Gap analysis is performed on security capabilities of a computer system compared to a desired or targeted security model according to one or more security requirement by providing a data structure of security capabilities of a computer system under analysis, wherein each capability is classified in a formal security capability reference model with a mean having a set of attributes and a goal; determining the security capabilities of the deployed system-under-analysis; matching the security capabilities of the deployed system-under-analysis with the security capabilities defined in the data structure; determining one or more gaps in security capabilities between the deployed system and a security reference model goal; and displaying the gaps to a user in a report.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for matching and performing gap analysis of security capabilities of a computer system comprising:
accessing in a tangible, computer readable storage memory device a data structure of available security capabilities of a computer system under analysis, wherein each capability is classified in a formal security capability reference model with a mean having a set of attributes and a goal; determining by a computer system the utilization level of the security capabilities of the system under analysis in its currently deployed state; matching by a computer system the security capabilities of the system under analysis with the available security capabilities defined in the data structure; determining by a computer one or more gaps in security capabilities between the deployed system under analysis and a security reference model goal according to the utilization levels; and producing a report indicating the gaps.
2 . The method as set forth in claim 1 wherein the security reference model goal comprises security requirements which comply with at least one requirement selected from the group consisting of a statutory requirement, a regulatory requirement, a standardization body recommendation, a corporate policy and a client policy.
3 . The method as set forth in claim 1 further comprising performing by a computer system a correction analysis to determine one or more potential corrective actions, and wherein the report includes the one or more potential corrective actions to correct the identified one or more gaps in security capabilities.
4 . The method as set forth in claim 1 wherein the security capability reference model catalog comprises a plurality of types of security features by category and by capabilities within the category.
5 . The method as set forth in claim 4 wherein one or more categories and capabilities are selected from the group consisting of a firewall category with a protocol capability, a firewall category with a content capability, a data authorization category with a vertical filtering capability, a data authorization category with a horizontal filtering capability, a data authorization category with a value-based capability, and a data authorization category with a token-based capability.
6 . The method as set forth in claim 4 wherein, for each capability in the security capability reference model, there is defined in the data structure at least a tuple selected from the group consisting of an activity, a mean, a domain, and a goal, wherein an activity contains one or more tasks to be done to address a security requirement, wherein a mean contains one or more methods for providing a feature of the implementation of the capability, wherein a domain contains one or more details associated with a mean including a list of attributes further characterizing the mean, and wherein a goal contains one or more target outcomes of using the mean for the activity.
7 . The method as set forth in claim 1 wherein the matching and determining of one or more gaps comprises, responsive to finding no matching capability for a requirement, recommending in the report adding a capability to the computing system-under-analysis, responsive to finding one match between a capability and a requirement, recommending in the report designating the capability as a candidate capability to engage, and responsive to finding multiple matches, selecting one or more best candidates for recommending in the report to engage.
8 . The method as set forth in claim 7 wherein the selecting one or more best candidates comprises selecting one or more capabilities according to one or more criteria selected from the group consisting of a cost associated with an internal contract, proximity of the capability, availability of the capability, system ownership by a department or organization of the capability.
9 . The method as set forth in claim 7 wherein each of the criteria are assigned a weight for determining a final recommendation.Join the waitlist — get patent alerts
Track US2014143879A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.