Determining a combined compliance assessment metric
Abstract
According to some implementations, compliance assessment metrics in a subset of two or more compliance assessment metrics are combined to form a combined compliance assessment metric. Each compliance assessment metric in the subset reflects a level of compliance of a set of rules with a different type of data privacy and/or data security laws, regulations, and/or policy. The set of rules are to manage personal data in an organization instance of a customer of a cloud-based software provider capable of hosting the organization instance in one or more datacenters in a plurality of different geographic regions. An ability to move data from the organization instance from a first geographic region to a second geographic region is gated based on the combined compliance assessment metric. In addition, the combined compliance assessment metric is displayed as part of a data policy compliance service provided by the cloud-based software provider.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An article of manufacture comprising:
a non-transitory machine-readable storage medium that provides instructions that, if executed by a set of one or more processors, are configurable to cause the set of processors to perform operations comprising,
combining compliance assessment metrics in a subset of two or more compliance assessment metrics to form a combined compliance assessment metric, wherein each compliance assessment metric in the subset reflects a level of compliance of a set of rules with a different type of data privacy and/or data security laws, regulations, and/or policy, wherein the set of rules are to manage personal data in an organization instance of a customer of a cloud-based software provider capable of hosting the organization instance in one or more datacenters in a plurality of different geographic regions;
gating an ability to move data from the organization instance from a first geographic region of the plurality of different geographic regions to a second geographic region of the plurality of different geographic regions based on the combined compliance assessment metric; and
displaying at least the combined compliance assessment metric as part of a data policy compliance service provided by the cloud-based software provider.
2 . The article of manufacture of claim 1 , wherein a first compliance assessment metric in the subset reflects the level of compliance of the set of rules with data privacy and/or data security laws, regulations, and/or policy of one of the plurality of different geographic regions, wherein a second compliance assessment metric in the subset reflects the level of compliance of the set of rules with data privacy and/or data security laws, regulations, and/or policy of an industry of the customer.
3 . The article of manufacture of claim 2 , wherein a third compliance assessment metric in the subset reflects the level of compliance of the set of rules with a company policy of the customer relative to data privacy and/or data security laws, regulations, and/or policy of the one of the plurality of geographic regions and/or the industry of the customer.
4 . The article of manufacture of claim 1 , wherein the operations also comprise:
determining the subset of two or more compliance assessment metrics, the determining including:
determining a first compliance assessment metric that reflects the level of compliance of the set of rules with a first type of data privacy and/or data security laws, regulations, and/or policy; and
determining a second compliance assessment metric that reflects the level of compliance of the set of rules with a second type of data privacy and/or data security laws, regulations, and/or policy.
5 . The article of manufacture of claim 1 , wherein the data from the organization instance includes data, metadata, and/or configuration of the customer hosted within a service of the cloud-based software provider.
6 . The article of manufacture of claim 1 , wherein the data policy compliance service allows the customer of the cloud-based software provider to choose in which of a plurality of geographic regions data of the customer will be at least one of hosted and processed.
7 . The article of manufacture of claim 1 , wherein the displaying further comprises:
responsive to user input, displaying information regarding a plurality of geographic regions.
8 . The article of manufacture of claim 1 , wherein the displaying further comprises:
responsive to user interaction, displaying a set of acts to be performed before moving data from the organization instance to another geographic region.
9 . The article of manufacture of claim 1 , wherein cloud services provided by the cloud-based software provider include one or more of Software-as-a-Service (SaaS), Data-as-a-Service (DAAS or DaaS), and Platform-as-a-service (PAAS or PaaS).
10 . The article of manufacture of claim 1 , wherein at least one of the datacenters is a third-party datacenter, and wherein the cloud-based software provider is a customer of an operator of the third-party datacenter.
11 . A computer-implemented method comprising:
combining compliance assessment metrics in a subset of two or more compliance assessment metrics to form a combined compliance assessment metric, wherein each compliance assessment metric in the subset reflects a level of compliance of a set of rules with a different type of data privacy and/or data security laws, regulations, and/or policy, wherein the set of rules are to manage personal data in an organization instance of a customer of a cloud-based software provider capable of hosting the organization instance in one or more datacenters in a plurality of different geographic regions; gating an ability to move data from the organization instance from a first geographic region of the plurality of different geographic regions to a second geographic region of the plurality of different geographic regions based on the combined compliance assessment metric; and displaying at least the combined compliance assessment metric as part of a data policy compliance service provided by the cloud-based software provider.
12 . The computer-implemented method of claim 11 , wherein a first compliance assessment metric in the subset reflects the level of compliance of the set of rules with data privacy and/or data security laws, regulations, and/or policy of one of the plurality of different geographic regions, wherein a second compliance assessment metric in the subset reflects the level of compliance of the set of rules with data privacy and/or data security laws, regulations, and/or policy of an industry of the customer.
13 . The computer-implemented method of claim 12 , wherein a third compliance assessment metric in the subset reflects the level of compliance of the set of rules with a company policy of the customer relative to data privacy and/or data security laws, regulations, and/or policy of the one of the plurality of geographic regions and/or the industry of the customer.
14 . The computer-implemented method of claim 11 further comprising:
determining the subset of two or more compliance assessment metrics, the determining including:
determining a first compliance assessment metric that reflects the level of compliance of the set of rules with a first type of data privacy and/or data security laws, regulations, and/or policy; and
determining a second compliance assessment metric that reflects the level of compliance of the set of rules with a second type of data privacy and/or data security laws, regulations, and/or policy.
15 . The computer-implemented method of claim 11 , wherein the data from the organization instance includes data, metadata, and/or configuration of the customer hosted within a service of the cloud-based software provider.
16 . The computer-implemented method of claim 11 , wherein the data policy compliance service allows the customer of the cloud-based software provider to choose in which of a plurality of geographic regions data of the customer will be at least one of hosted and processed.
17 . The computer-implemented method of claim 11 , the displaying further comprising:
responsive to user input, displaying information regarding a plurality of geographic regions.
18 . The computer-implemented method of claim 11 , the displaying further comprising:
responsive to user interaction, displaying a set of acts to be performed before moving data from the organization instance to another geographic region.
19 . The computer-implemented method of claim 11 , wherein cloud services provided by the cloud-based software provider include one or more of Software-as-a-Service (SaaS), Data-as-a-Service (DAAS or DaaS), and Platform-as-a-service (PAAS or PaaS).
20 . The computer-implemented method of claim 11 , wherein at least one of the datacenters is a third-party datacenter, and wherein the cloud-based software provider is a customer of an operator of the third-party datacenter.Join the waitlist — get patent alerts
Track US2023359756A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.