US2015332184A1PendingUtilityA1

Application Risk and Control Assessment

Assignee: BANK OF AMERICAPriority: Apr 11, 2006Filed: Feb 23, 2015Published: Nov 19, 2015
Est. expiryApr 11, 2026(expired)· nominal 20-yr term from priority
G06Q 10/0635G06Q 10/0639G06Q 10/00
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are disclosed for assessing risks that may be associated with an application and assessing controls that may be implemented to mitigate the risks associated with the application. The systems and methods may include identifying risk data that may be used at least partially to calculate a risk score. The systems and methods may also include identifying control data that may be used at least partially to calculate a control score. The risk score and the control score may be compared to one another. An assessment of the risks and controls application may be performed at least partially based on the risk score and the control score. A threshold value may be set for the risk score and/or the control score that are compared and used to assess an application.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of assessing a plurality of applications, comprising:
 receiving at a risk analysis server having a processor first information identifying risk data relating to each of the applications, wherein the first information comprises, for each of the plurality of applications, a first indicator identifying whether the application is internal or external facing, a second indicator identifying a first subset of the plurality of applications upon which the application depends, a third indicator identifying a second subset of the plurality of applications that depend on the application, and a fourth indicator identifying a frequency of production code changes associated with the application;   generating by the processor a risk score for each of the applications based at least in part on the corresponding risk data for each of the applications;   receiving at the processor second information identifying control data, which includes objective binary information from a user comprising answers to predetermined questions regarding security controls for each of the applications;   generating by the processor a control score for each of the applications based at least in part on the corresponding control data for each of the applications; and   aggregating by the processor the risk data, risk score, control data, and control score for each of the applications into a database stored in memory communicatively coupled to the server comparing the risk score with a risk threshold and comparing the control score with a control threshold by determining and displaying the difference between the risk score and the control score;   plotting by the processor the plurality of applications into sectors according to the risk score and the control score of each of the plurality of the applications;   receiving at the processor third information answering at least one question relating to at least one application based at least in part on the information aggregated in the database for the at least one application;   assessing by the processor each of the applications based at least in part on at least one of the risk score, the control score, and the answer to the at least one question, and   assigning by the processor a user a priority level according to each user's employment position, wherein each user has access to the database based on the priority level;   wherein the control data comprise scalability information indicating whether or not each of the applications has adequate scalability to accommodate predefined future business needs.   
     
     
         2 . The method of  claim 1 , further comprising generating a report for at least one of the plurality of applications that includes at least one of the risk score, the control score, and the assessment of at least one of the applications. 
     
     
         3 . The method of  claim 1 , where the risk score is commensurate with the control score for at least one of the plurality of applications. 
     
     
         4 . The method of  claim 1 , where assessing each of the applications includes comparing the risk score to the control score. 
     
     
         5 . The method of  claim 1 , where the risk threshold is a range. 
     
     
         6 . The method of  claim 1 , where the control threshold is a range. 
     
     
         7 . The method of  claim 1 , where the plurality of applications is stored on a computer network. 
     
     
         8 . The method of  claim 7 , where the plurality of applications is accessible through a webpage on the computer network. 
     
     
         9 . The method of  claim 1 , further comprising establishing a security for accessing the database. 
     
     
         10 . The method of  claim 9 , where the security includes a password. 
     
     
         11 . The method of  claim 9 , where the security includes encrypting a communication between a user and the database. 
     
     
         12 . An apparatus for assessing a plurality of applications, comprising:
 a memory, storing by a processor at least one module comprising computer-executable instructions, the plurality of modules including:   a risk data module configured to store risk data relating to each of the plurality of applications, wherein the risk data comprises a first indicator of a peak transaction rate associated with each of the plurality of applications, a second indicator of a user access pattern associated with each of the plurality of applications, a third indicator of a percentage of application data associated with each of the plurality of applications periodically reviewed and certified as accurate, a fourth indicator of hours per week an average user works on each of the plurality of applications, and a fifth indicator of a volume of the application data stored for each of the plurality of applications;   a risk score module configured to generate a risk score for each of the plurality of applications based at least in part on the corresponding risk data;   a control data module configured to store control data for each of the plurality of applications wherein the control data comprises scalability information indicating whether or not each of the applications has adequate scalability to accommodate predefined future business needs and objective binary information from a user comprising answers to predetermined questions regarding security controls;   a control score module configured to generate a control score for each of the plurality of applications based at least in part on the corresponding control data; and   a comparison module configured to compare the risk score with a risk threshold and to compare the control score with a control threshold for each of the plurality of applications by determining and displaying the difference between the risk score and the control score;   a plotting module configured to plot the plurality of applications into sectors according to the risk score and the control score of each of the plurality of the applications; and   a processor operationally connected to the memory, the processor configured to execute the computer-executable instructions in the plurality of modules to generate a comparison for each of the plurality of applications based at least in part on the risk score and the control score to aggregate the risk data, the risk score, the control data, the control score, and the comparison for each of the plurality of applications into a database and to assign a user a priority level according to each user's employment position, wherein each user has access to the database based on the priority level.   
     
     
         13 . The apparatus of  claim 12 , where the comparison module is configured to identify at least one of the plurality of applications that has a commensurate relationship between the risk score and the control score. 
     
     
         14 . A non-transitory computer-readable medium comprising computer-executable instructions which when executed perform a method of assessing a plurality of applications, comprising: 
       identifying risk data relating to each of the applications, wherein the risk data comprises a first indicator of a data growth rate associated with each of the applications, a second indicator of a first geographic location of data stores associated with each of the applications, a third indicator of a second geographic location associated with users of each of the applications, a fourth indicator of application patch management associated with each of the applications, a fifth indicator of a batch processing period associated with each of the applications, and a sixth indicator of regulatory scrutiny of business unit activities supported by each of the applications;
 generating a risk score for each of the applications based at least in part on the corresponding risk data for each of the applications; 
 identifying control data for each of the applications wherein the control data comprise scalability information indicating whether or not each of the applications has adequate scalability to accommodate predefined future business needs and objective binary information from a user comprising answers to predetermined questions regarding security controls; 
 generating a control score for each of the applications based at least in part on the corresponding control data for each of the applications; 
 aggregating the risk data, risk score, control data, and control score for each of the applications into a database comparing the risk score with a risk threshold and comparing the control score with a control threshold by determining and displaying the difference between the risk score and the control score; 
 plotting by the server the plurality of applications into sectors according to the risk score and the control score of each of the plurality of the applications; 
 answering at least one question relating to at least one application based at least in part on the information aggregated in the database for the at least one application; 
 assessing the application based at least in part on at least one of the risk score, the control score, and the answer to the at least one question; and 
 plotting by the server the plurality of applications into sectors according to the risk score and the control score of each of the plurality of the applications. 
 
     
     
         15 . The computer-readable medium of  claim 14 , where the risk score is compared to the control score for each of the plurality of applications. 
     
     
         16 . The method of  claim 1 , further comprising identifying at least one of the plurality of applications that is associated with a line of business. 
     
     
         17 . The method of  claim 16 , further comprising sorting the plurality of applications within the database based on the line of business associated with each application.

Join the waitlist — get patent alerts

Track US2015332184A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.