Data processing and scanning systems for assessing vendor risk
Abstract
Data processing systems and methods, according to various embodiments, are adapted for automatically assessing the level of security and/or privacy risk associated with doing business with a particular vendor or other entity and for generating training material for such vendors. In various embodiments, the systems may automatically obtain and use any suitable information to assess such risk levels including, for example: (1) any security and/or privacy certifications held by the vendor; (2) the terms of one or more contracts between a particular entity and the vendor; (3) the results of one or more privacy impact assessments for the vendor; and/or (4) any other suitable data. The system may be configured to automatically approve or reject a particular vendor based on the assessed risk level associated with the vendor and this information may be automatically communicated to an entity considering doing business with the vendor and/or the vendor itself.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 .- 20 . (canceled)
21 . A method comprising:
monitoring, by computing hardware, a plurality of attributes of a plurality of data assets for a vendor, wherein the plurality of data assets is used by the vendor in handling personal data for an entity; detecting, by the computing hardware, a change in a particular attribute of the plurality of attributes; and responsive to detecting the change in the particular attribute:
generating, by the computing hardware, an updated privacy risk rating for the vendor based on the change in the particular attribute, wherein the updated privacy risk rating represents a risk to the entity in having the vendor use the plurality of data assets to handle the personal data; and
providing, by the computing hardware, the updated privacy risk rating for the vendor for display on a graphical user interface.
22 . The method of claim 21 , wherein each of the plurality of data assets comprises at least one of a software application or a computing system used by the vendor in handling the personal data.
23 . The method of claim 21 , wherein generating the updated privacy risk rating comprises:
determining a plurality of risk factors based on the plurality of attributes and a respective weighting for each risk factor of the plurality of risk factors based on a relative importance of the risk factor; and generating the updated privacy risk rating based on the plurality of risk factors and the respective weighting for each of the plurality of risk factors.
24 . The method of claim 21 , wherein:
a data asset of the plurality of data assets comprises a webpage associated with the vendor; monitoring the plurality of attributes comprises scanning the webpage; and the particular attribute comprises at least one of a privacy policy displayed on the webpage, a security certification displayed on the webpage, a cookie policy published on the webpage, or a privacy control center available on the webpage.
25 . The method of claim 24 , wherein the scanning of the webpage comprises scanning at least one of computer code, content, or images associated with the webpage.
26 . The method of claim 21 , wherein detecting the change in the particular attribute comprises:
detecting that a previous version of the particular attribute has expired; and responsive to detecting that the previous version of the particular attribute has expired:
obtaining an updated version of the particular attribute; and
comparing the updated version of the particular attribute with the previous version of the particular attribute.
27 . The method of claim 21 , wherein detecting the change in the particular attribute comprises:
determining that a time has elapsed; and responsive to determining that the time has elapsed:
obtaining an updated version of the particular attribute; and
comparing the updated version of the particular attribute with a previous version of the particular attribute.
28 . The method of claim 21 further comprising:
determining, by the computing hardware, an approval of a use of the vendor in handling the personal data for the entity based on the updated privacy risk rating; and
responsive to determining the approval of the use of the vendor, providing, by the computing hardware, an indication of the approval for display on the graphical user interface.
29 . The method of claim 21 further comprising:
determining, by the computing hardware, a disapproval of a use of the vendor in handling the personal data for the entity based on the updated privacy risk rating; and
responsive to determining the disapproval of the use of the vendor, providing, by the computing hardware, an indication of the disapproval for display on the graphical user interface.
30 . A system comprising:
a non-transitory computer-readable medium storing instructions; and a processing device communicatively coupled to the non-transitory computer-readable medium, wherein, the processing device is configured to execute the instructions and thereby perform operations comprising:
obtaining a current version of an attribute of a data asset for a vendor, wherein the data asset is used by the vendor in handling personal data for an entity;
comparing the current version of the attribute to a previous version of the attribute to detect a change in the attribute; and
responsive to detecting the change in the attribute:
generating an updated privacy risk rating for the vendor based on the current version of the attribute, wherein the updated privacy risk rating represents a risk to the entity in having the vendor use the data asset to handle the personal data; and
providing, for display on a graphical user interface, the updated privacy risk rating for the vendor.
31 . The system of claim 30 , wherein the data asset comprises at least one of a software application or a computing system used by the vendor in handling the personal data.
32 . The system of claim 30 , wherein the current version of the attribute is obtained due to the previous version of the attribute being expired.
33 . The system of claim 30 , wherein the current version of the attribute is obtained due to an elapsed time.
34 . The system of claim 30 , wherein the operations further comprise assigning a weighting to a factor for the attribute based on the current version of the attribute, and the updated privacy risk rating is generated based on the weighting of the factor.
35 . The system of claim 30 , wherein the operations further comprise:
determining an approval of a use of the vendor in handling the personal data for the entity based on the updated privacy risk rating; and responsive to determining the approval of the use of the vendor, providing an indication of the approval for display on the graphical user interface.
36 . A non-transitory computer-readable medium having program code that is stored thereon, the program code being executable by one or more processing devices for performing operations comprising:
monitoring an attribute of a data asset for a vendor, wherein the data asset is used by the vendor in handling personal data for an entity; detecting a change in the attribute; and responsive to detecting the change in the attribute:
generating an updated privacy risk rating for the vendor based on the change in the attribute, wherein the updated privacy risk rating represents a risk to the entity in having the vendor use the data asset to handle the personal data; and
providing, for display on a graphical user interface, the updated privacy risk rating for the vendor.
37 . The non-transitory computer-readable medium of claim 36 , wherein the data asset comprises at least one of a software application or a computing system used by the vendor in handling the personal data.
38 . The non-transitory computer-readable medium of claim 36 , wherein generating the updated privacy risk rating for the vendor comprises:
determining a risk factor based on the attribute and a respective weighting for the risk factor based on a relative importance of the risk factor with respect to a plurality of risk factors; and generating the updated privacy risk rating based on the plurality of risk factors and the respective weighting for the risk factor.
39 . The non-transitory computer-readable medium of claim 36 , wherein detecting the change in the attribute of the vendor comprises:
detecting that a current privacy-related risk rating has expired; and responsive to detecting that the current privacy-related risk rating has expired:
obtaining an updated version of the attribute; and
comparing the updated version of the attribute with a previous version of the attribute.
40 . The non-transitory computer-readable medium of claim 36 , wherein the data asset comprises a webpage associated with the vendor, monitoring the attribute comprises scanning the webpage, and the attribute comprises at least one of a privacy policy displayed on the webpage, a security certification displayed on the webpage, a cookie policy published on the webpage, and/or a privacy control center available on the webpage.Join the waitlist — get patent alerts
Track US2022043894A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.