Computing systems for heterogeneous regulatory control compliance monitoring and auditing
Abstract
Systems for centralized processing of regulatory control events. A method embodiment applies regulatory compliance rules against regulatory control events that occur at a plurality of heterogeneous remote cloud-based systems. A centralized cloud-based platform manages the compliance of the plurality of heterogeneous remote cloud-based systems by applying a set of data compliance rules pertaining to regulatory controls. The regulatory controls pertain to data access events and data manipulation events that occur on the plurality of computing systems. The centralized cloud-based platform receives control event messages, the control event messages being raised any one or more of the heterogeneous remote cloud-based systems. Rules are processed against the received control event messages to determine a set of compliance actions. Compliance action occurrences are logged in a log facility such that at any moment in time, an audit can be run over the logged events so as to verify and report compliance or non-compliance.
Claims
exact text as granted — not AI-modified1 . A method to manage operations on data that occur at a plurality of heterogeneous remote cloud-based systems, the method comprising:
maintaining a plurality of data management rules in a common format, wherein the data management rules are applicable to analysis of event messages representing operations on data that occur at a corresponding heterogeneous remote cloud-based system of the plurality of heterogeneous remote cloud-based systems; maintaining a plurality of sets of mapping rules for converting corresponding event messages into a common format, a first set of mapping rules of the plurality of sets of mapping rules corresponding to first heterogeneous remote cloud-based system and being different from a second set of mapping rules of the plurality of sets of mapping rule corresponding to a second heterogeneous remote cloud-based system; processing event messages, wherein an event message is processed at least by:
receiving the event message;
identifying at least one mapping rule of the plurality of sets of mapping rules corresponding to the event message;
converting the event message into the common format using the at least one mapping rule;
identifying at least one data management rule of the plurality of data management rules corresponding to the converted event message converted in the common format; and
analyzing the converted event message using the at least one data management rule.
2 . The method of claim 1 , wherein analyzing the converted event message using the at least one data management rule comprises applying one or more data compliance rules that correspond to a compliance operation to be performed by a centralized cloud-based platform.
3 . The method of claim 2 , wherein the compliance operation comprises one or more logging actions.
4 . The method of claim 2 , wherein the at least one data management rule pertains to data manipulation with respect to a geographical territory, a privacy regulation, or a security regulation.
5 . The method of claim 2 , wherein at least one data management rule of the plurality of data management rules are associated with at least one of, financial services compliance regulations, bio technology compliance regulations, federal government compliance regulations, state government compliance regulations, healthcare compliance regulations, entertainment, automotive compliance regulations, power generation compliance regulations, or oil and gas compliance regulations.
6 . The method of claim 1 , further comprising receiving a request to review adherence to a requested set of compliance regulations.
7 . The method of claim 6 , wherein the request to review adherence to a requested set of compliance regulations is received at an audit portal.
8 . The method of claim 7 , wherein the audit portal generates a visual representation corresponding to a degree of compliance or non-compliance with respect to the requested set of compliance regulations.
9 . The method of claim 8 , further comprising generating a non-compliance alert.
10 . The method of claim 9 , wherein the non-compliance alert comprises at least a portion of the visual representation.
11 . A non-transitory computer readable medium having stored thereon a sequence of instructions which, when stored in memory and executed by a processor causes a set of acts to manage operations on data that occur at a plurality of heterogeneous remote cloud-based systems, the set of acts comprising:
maintaining a plurality of data management rules in a common format, wherein the data management rules are applicable to analysis of event messages representing operations on data that occur at a corresponding heterogeneous remote cloud-based system of the plurality of heterogeneous remote cloud-based systems; maintaining a plurality of sets of mapping rules for converting corresponding event messages into a common format, a first set of mapping rules of the plurality of sets of mapping rules corresponding to first heterogeneous remote cloud-based system and being different from a second set of mapping rules of the plurality of sets of mapping rule corresponding to a second heterogeneous remote cloud-based system; processing event messages, wherein an event message is processed at least by:
receiving the event message;
identifying at least one mapping rule of the plurality of sets of mapping rules corresponding to the event message;
converting the event message into the common format using the at least one mapping rule;
identifying at least one data management rule of the plurality of data management rules corresponding to the converted event message converted in the common format; and
analyzing the converted event message using the at least one data management rule.
12 . The non-transitory computer readable medium of claim 11 , wherein analyzing the converted event message using the at least one data management rule comprises applying one or more data compliance rules that correspond to a compliance operation to be performed by a centralized cloud-based platform.
13 . The non-transitory computer readable medium of claim 12 , wherein the compliance operation comprises one or more logging actions.
14 . The non-transitory computer readable medium of claim 12 , wherein the at least one data management rule pertains to data manipulation with respect to a geographical territory, a privacy regulation, or a security regulation.
15 . The non-transitory computer readable medium of claim 12 , wherein at least one data management rule of the plurality of data management rules are associated with at least one of, financial services compliance regulations, bio technology compliance regulations, federal government compliance regulations, state government compliance regulations, healthcare compliance regulations, entertainment, automotive compliance regulations, power generation compliance regulations, or oil and gas compliance regulations.
16 . The non-transitory computer readable medium of claim 11 , further comprising receiving a request to review adherence to a requested set of compliance regulations.
17 . The non-transitory computer readable medium of claim 16 , wherein the request to review adherence to a requested set of compliance regulations is received at an audit portal.
18 . The non-transitory computer readable medium of claim 17 , wherein the audit portal generates a visual representation corresponding to a degree of compliance or non-compliance with respect to the requested set of compliance regulations.
19 . A system for determining activity-based application recommendations by a content management system, the system comprising:
a storage medium having stored thereon a sequence of instructions; and a processor that execute the sequence of instructions to cause a set of acts, the set of acts comprising:
maintaining a plurality of data management rules in a common format, wherein the data management rules are applicable to analysis of event messages representing operations on data that occur at a corresponding heterogeneous remote cloud-based system of the plurality of heterogeneous remote cloud-based systems;
maintaining a plurality of sets of mapping rules for converting corresponding event messages into a common format, a first set of mapping rules of the plurality of sets of mapping rules corresponding to first heterogeneous remote cloud-based system and being different from a second set of mapping rules of the plurality of sets of mapping rule corresponding to a second heterogeneous remote cloud-based system;
processing event messages, wherein an event message is processed at least by:
receiving the event message;
identifying at least one mapping rule of the plurality of sets of mapping rules corresponding to the event message;
converting the event message into the common format using the at least one mapping rule;
identifying at least one data management rule of the plurality of data management rules corresponding to the converted event message converted in the common format; and
analyzing the converted event message using the at least one data management rule.
20 . The system of claim 19 , wherein analyzing the converted event message using the at least one data management rule comprises applying one or more data compliance rules that correspond to a compliance operation to be performed by a centralized cloud-based platform.Join the waitlist — get patent alerts
Track US2023101053A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.