Systems, methods, and user interfaces for intelligent and expedited generation of cybersecurity artifacts using cybersecurity control data objects
Abstract
In some embodiments, a cybersecurity data handling and governance service displays a cybersecurity artifact generation object. In some embodiments, while displaying the cybersecurity artifact generation object, the cybersecurity data handling and governance service receives a first input selecting the cybersecurity artifact generation object. In some embodiments, in accordance with a determination that the first input is directed to generating a first cybersecurity artifact corresponding to a first authoritative information security standard and in accordance with a determination that the first user interface is dedicated to displaying information directed to a respective cybersecurity data catalogue, the cybersecurity data handling and governance service generates the first cybersecurity artifact based on a first set of cybersecurity control data objects included in the respective cybersecurity data catalogue in accordance with submittal-criteria defined by the first authoritative information security standard.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method comprising:
at a data governance service:
receiving, by one or more computers, a request to automatically generate a digital cybersecurity artifact based on submittal-criteria of a target information security standard; and
based on receiving the request:
(1) automatically identifying, by the one or more computers, a target cybersecurity program that includes one or more cybersecurity control data objects; and
(2) automatically generating, by the one or more computers, the digital cybersecurity artifact based on the one or more cybersecurity control data objects, wherein the digital cybersecurity artifact at least partially satisfies the submittal-criteria of the target information security standard
2 . The method of claim 1 , further comprising:
after generating the digital cybersecurity artifact and based on receiving a second request, automatically transmitting the digital cybersecurity artifact to a target assessment entity associated with the target information security standard.
3 . The method of claim 1 , further comprising:
after generating the digital cybersecurity artifact:
modifying, based on user input, one or more attributes of one of the one or more cybersecurity control data objects from having a first value to having a second value; and
generating, by the one or more computers, an updated cybersecurity artifact that includes installing, by the one or more computers, the second value of the one of the one or more cybersecurity control data objects at a corresponding portion in the updated cybersecurity artifact.
4 . The method of claim 1 , further comprising:
before receiving the request to automatically generate the digital cybersecurity artifact, receiving a second request to upload a second cybersecurity artifact to the data governance service, wherein the second cybersecurity artifact at least partially satisfies submittal-criteria of a respective information security standard; and in response to receiving the second request:
automatically creating, by the one or more computers, the target cybersecurity program, wherein creating the target cybersecurity program includes creating the one or more cybersecurity control data objects based on the second cybersecurity artifact.
5 . The method of claim 4 , further comprising:
based on receiving the second request, automatically evaluating the second cybersecurity artifact for possible anomalies.
6 . The method of claim 5 , further comprising:
in accordance with a determination that at least one anomaly exists in the second cybersecurity artifact, displaying a user interface element indicating that the second cybersecurity artifact includes the at least one anomaly; and in accordance with a determination that the second cybersecurity artifact does not include at least one anomaly, forgoing displaying the user interface element.
7 . The method of claim 1 , wherein:
the one or more cybersecurity control data objects includes a first cybersecurity control data object that is associated with a plurality of cybersecurity attributes, a first subset of the plurality of cybersecurity attributes corresponds to the target information security standard, and a second subset of the plurality of cybersecurity attributes does not correspond to the target information security standard.
8 . The method of claim 7 , wherein:
the generating the digital cybersecurity artifact based on the one or more cybersecurity control data objects includes generating the digital cybersecurity artifact based on the first subset of the plurality of cybersecurity attributes and not based on the second subset of the plurality of cybersecurity attributes.
9 . The method of claim 1 , wherein
the one or more cybersecurity control data objects of the target cybersecurity program includes a first plurality of cybersecurity control data objects that maps to the target information security standard and a second plurality of cybersecurity control data objects that maps to a second information security standard, distinct from the target information security standard.
10 . The method of claim 9 , wherein
the generating the digital cybersecurity artifact includes generating the digital cybersecurity artifact based on the first plurality of cybersecurity control data objects and not based on the second plurality of cybersecurity control data objects.
11 . A method comprising:
at a cybersecurity governance service:
while a first cybersecurity data catalogue includes a first set of cybersecurity control data objects:
after generating, based on the first set of cybersecurity control data objects, a first cybersecurity artifact that at least partially satisfies submittal-criteria of a first information security standard:
modifying, based on a first user input, a first cybersecurity control data object in the first set of cybersecurity control data objects, wherein modifying the first cybersecurity control data object includes modifying a first cybersecurity attribute of the first cybersecurity control data object from having a first value to having a second value; and
generating, based on a second user input, an updated cybersecurity artifact based on the first set of cybersecurity control data objects, wherein (1) the updated cybersecurity artifact at least partially satisfies the submittal-criteria of the first information security standard and (2) generating the updated cybersecurity artifact includes installing the second value of the first cybersecurity attribute at a corresponding portion in the updated cybersecurity artifact.
12 . The method of claim 11 , wherein:
generating the first cybersecurity artifact includes installing the first value of the first cybersecurity attribute at a corresponding portion in the first cybersecurity artifact, each cybersecurity control data object of the first set of cybersecurity control data objects comprises one or more first respective cybersecurity attributes that correspond to the first information security standard, and the each cybersecurity control data object of the first set of cybersecurity control data objects comprises one or more second respective cybersecurity attributes that do not correspond to the first information security standard.
13 . A method comprising:
displaying, via a first user interface, a cybersecurity artifact generation object; while displaying the cybersecurity artifact generation object, receiving a first input selecting the cybersecurity artifact generation object; and based on receiving the first input:
in accordance with a determination that the first user interface is displaying a characteristic associated with a first cybersecurity program, generating, by one or more computers, a first cybersecurity artifact based on one or more cybersecurity control data objects of the first cybersecurity program.
14 . The method of claim 13 , further comprising:
while displaying the cybersecurity artifact generation object:
displaying, via the first user interface, one or more distinct selectable representations of at least a subset of the one or more cybersecurity control data objects.
15 . The method of claim 13 , further comprising:
while displaying the cybersecurity artifact generation object:
displaying, via the first user interface, a metric that indicates a numerical quantity of cybersecurity control data objects that is available to use when generating the first cybersecurity artifact.
16 . The method of claim 13 , further comprising:
automatically updating, by the one or more computers, one or more attribute values of the one or more cybersecurity control data objects based on receiving an updated cybersecurity artifact.
17 . The method of claim 13 , wherein (1) the first cybersecurity program includes a first subset of cybersecurity control data objects and a second subset of cybersecurity control data objects and (2) generating the first cybersecurity artifact is not based on the second subset of cybersecurity control data objects, the method further comprising:
in accordance with a determination that one or more criteria are satisfied, generating a second cybersecurity artifact based on the first subset and the second subset of cybersecurity control data objects.
18 . The method of claim 17 , wherein the first cybersecurity artifact corresponds to a first information security standard and the second cybersecurity artifact corresponds to a second information security standard, different from the first information security standard.
19 . The method of claim 13 , further comprising:
after generating the first cybersecurity artifact:
in accordance with a determination that one or more criteria is satisfied, automatically transmitting the first cybersecurity artifact to a target assessment entity associated with the target information security standard.
20 . The method of claim 13 , further comprising:
receiving a second input corresponding to a request to upload a second cybersecurity artifact associated with a first information security standard, and based on receiving the second input:
creating the first cybersecurity program, wherein creating the first cybersecurity program includes creating the one or more cybersecurity control data objects and digitally mapping the one or more cybersecurity control data objects to one or more objectives of the first information security standard.Join the waitlist — get patent alerts
Track US2022405400A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.