Method and system for assessing, managing and monitoring information technology risk
Abstract
A method for information technology and information asset risk assessment of a business relationship between a client and a third party. The method includes establishing a database. The database includes a plurality of IT information risk factors stored in the database are associated with certain risks the client may be exposed to based on an action the client follows or based upon who the client uses as their third party provider. The database is configured to receive IT risk information. The IT risk information is associate with the plurality of IT information risk factors. The database is also configured to receive updated risk information for storage thereon. The method includes receiving risk information corresponding to the subset of relationship risk factors. The method continues with generating a relationship risk score. The relationship risk score is determined in response to evaluating the subset of relationship risk factors using the IT risk
Claims
exact text as granted — not AI-modified1 . A method for information technology (IT) and information asset risk assessment of a business relationship between a client and a third party, the method comprising:
establishing a database having a plurality of IT information risk factors, the database configured to receive IT risk information associated with the plurality of IT information risk factors, the plurality of IT information risk factors including a subset of relationship risk factors for evaluating the business relationship risk between the client and the third party receiving IT risk information corresponding to the subset of relationship risk factors; generating a relationship risk score in response to evaluating the subset of relationship risk factors based upon the IT risk information corresponding to the subset of relationship risk factors; and monitoring the database for updated IT risk information for revising the relationship risk score to reflect evaluation of the subset of relationship risk factors with the updated IT risk information.
2 . The method of claim 1 , wherein the database is a computer server configured to received IT risk information via a computer network.
3 . The method of claim 1 , wherein the subset of relationship risk factors are representative of: monetary value, length of relationship, location, contract terms, content sensitivity, regulated data, business processes, intellectual property competitiveness, fraud, reporting and compliance, relationship insurance coverage.
4 . The method of claim 1 , further comprising:
compiling IT risk information on the database corresponding to a subset of business profile risk factors from the plurality of IT information risk factors, the subset of business profile risk factors for evaluating the business profile risk of the third party, the IT risk information corresponding to the subset of business profile risk factors being compiled from public record information associated with the third party; generating a business profile risk score in response to evaluating the subset of business profile risk factors; and monitoring the database for updated IT risk information corresponding to the subset of business profile risk factors for revising the business profile risk score.
5 . The method of claim 4 , wherein the subset of business profile risk factors are representative of: information regarding prior security breaches, financial history, credit history, and legal history.
6 . The method of claim 4 , further comprising:
a subset of IT control risk factors from the plurality of IT information risk factors; receiving IT risk information on the database corresponding to the subset of IT control risk factors, the IT risk information corresponding to the subset of IT control risk factors being associated with the third party for evaluating the subset of IT control risk factors; generating an IT controls risk score in response to evaluating the subset of IT control risk factors; and monitoring the database for updated IT risk information corresponding to the subset of IT control risk factors for revising the IT controls risk score.
7 . The method of claim 6 , wherein the subset of IT control risk factors are representative of: insurance coverage, industry compliance, legal compliance, regulatory compliance, risk management, IT environment, outsourcing, security policy, information security organization, third party management, asset management, information assets, human resources security, physical and environmental security, communications and operations management, system logs, laptops/desktops, mobile devices, information backup, network, removable media, electronic messaging, web applications, access control, password management, secure login and remote access, information systems acquisition, testing security controls, information security incident management, business continuity management, and compliance.
8 . The method of claim 6 , wherein an IT risk score is generated as a function of the relationship risk score, the business profile risk score, and the IT controls risk score.
9 . The method of claim 1 , further comprising:
associating the relationship risk score between the client and the third party with the type of service being provided to the client by the third party.
10 . The method of claim 6 , further comprising: associating the IT controls risk score of the third party with the type of service being provided to the client by the third party.
11 . The method of claim 1 , further comprising:
evaluating a client relationship risk tolerance level in response to receiving information responsive to a plurality of client relationship risk tolerance criteria, the client relationship risk tolerance level corresponding to a plurality of relationship risk mitigation actions; and identifying a relationship risk mitigation action dependent upon the relationship risk score.
12 . The method of claim 4 , further comprising:
evaluating a client business profile risk tolerance level in response to receiving information responsive to a plurality of client business profile risk tolerance criteria, the client business profile risk tolerance level corresponding to a plurality of business profile risk mitigation actions; and identifying a business profile risk mitigation action dependent upon the business profile risk score.
13 . The method of claim 6 , further comprising:
evaluating a client IT controls risk tolerance level in response to receiving information responsive to a plurality of client IT controls risk tolerance criteria, the client IT controls risk tolerance level corresponding to a plurality of IT controls risk mitigation actions; and identifying an IT controls risk mitigation action dependent upon the IT controls risk score.
14 . The method of claim 1 , wherein the IT risk information is transmitted to the database from the client.
15 . The method of claim 4 , further comprising a web based application hosted on the database for compiling IT risk information.
16 . The method of claim 6 , wherein the IT risk information is transmitted to the database from the third party.
17 . The method of claim 6 , further comprising:
receiving IT risk information corresponding to the subset of IT control risk factors on the database from an independent auditor, the received IT risk information from the independent auditor for validating the IT risk information associated with the third party; and generating a revised IT controls risk score.
18 . The method of claim 1 , wherein a plurality of business relationships between the client and a plurality of third parties is assessed.
19 . A method for assessing compliance associated with a contract between a client and a third party, a government regulation, a law or an industry standard, the method comprising:
establishing a database for storing a plurality of obligations for the third party associated with the contract with the client, the government regulation, the law or the industry standard; receiving on the database information corresponding to the plurality of obligations; evaluating the plurality of obligations in response to receiving the information; and generating a compliance score.
20 . The method of claim 19 , wherein the database is continuously monitored for information corresponding to the plurality of obligations.Join the waitlist — get patent alerts
Track US2015066577A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.