Method and apparatus for system protection technology analysis
A method includes determining, by an analysis system, a system aspect of a system for a protection evaluation. The method further includes determining, by the analysis system, at least one evaluation perspective for use in performing the protection evaluation on the system aspect. The method further includes determining, by the analysis system, at least one evaluation viewpoint for use in performing the protection analysis on the system aspect. The method further includes obtaining, by the analysis system, protection data regarding the system aspect in accordance with the at least one evaluation perspective and the at least one evaluation viewpoint. The method further includes calculating, by the analysis system, a protection rating as a measure of protection maturity for the system aspect based on the protection data, the at least one evaluation perspective, the at least one evaluation viewpoint, and at least one evaluation rating metric.
1 . A method comprises:
determining, by an analysis system that includes one or more computing entities, a system aspect of an enterprise system for system protective technology evaluation;
determining, by the analysis system, an implementation evaluation perspective for use in performing the system protective technology evaluation;
determining, by the analysis system, a disclosed evaluation viewpoint for use in performing the system protective technology evaluation;
obtaining, by the analysis system, protective technology information in accordance with the system aspect, the implementation evaluation perspective and the disclosed evaluation viewpoint;
determining, by the analysis system, data gathering parameters regarding the system aspect in accordance with the implementation evaluation perspective, the disclosed evaluation viewpoint, and at least one evaluation rating metric;
engaging, by the analysis system, with the enterprise system to obtain protective technology data based upon the implementation evaluation perspective, the disclosed evaluation viewpoint, and the protective technology information; and
calculating, by the analysis system, a protective technology rating regarding the protective technology for the system aspect based on the protective technology information, the protective technology data, the implementation evaluation perspective, the disclosed evaluation viewpoint, the data gathering parameters, and at least one evaluation rating metric.
2 . The method of claim 1 , wherein the protective technology information is representative of an organization's understanding of the enterprise system, or portion thereof, with respect to audit and recording, removable media protection and use, system and asset access control, and communications and control network protection.
3 . The method of claim 1 , wherein the protective technology information is:
obtained from a system admin computing entity; or
obtained from one or more computing entities of the enterprise system.
4 . The method of claim 1 , wherein the protective technology data is based upon enterprise system audit and recording, enterprise system removable media protection and use, enterprise system asset access control, and/or enterprise system communications and control networks protection.
5 . The method of claim 1 , wherein the protective technology rating regarding the protective technology of the enterprise system, or portion thereof, is based on at least one of:
the protective technology information;
the protective technology data;
protective technology processes;
protective technology policies;
protective technology documentation; or
protective technology automation.
6 . The method of claim 1 , wherein the protective technology rating indicates how well the protective technology information reflects an understanding of the protective technology with respect to at least one of:
assets of the enterprise system, or portion thereof;
system functions of the enterprise system, or portion thereof; or
security functions of the system, or portion thereof.
7 . The method of claim 1 , wherein the protective technology rating indicates how well the protective technology information reflects intended implementation of the protective technology with respect to at least one of:
assets of the enterprise system, or portion thereof;
system functions of the enterprise system, or portion thereof; or
security functions of the system, or portion thereof.
8 . The method of claim 1 , wherein the protective technology rating indicates how well the protective technology information reflects intended operation of the protective technology with respect to at least one of:
assets of the enterprise system, or portion thereof;
system functions of the enterprise system, or portion thereof; or
security functions of the system, or portion thereof.
9 . The method of claim 1 , wherein determining the system aspect comprises:
determining at least one system element of the enterprise system;
determining at least one system criteria of the enterprise system;
determining at least one system mode of the enterprise system; and
determining the system aspect based on the at least one system element, the at least one system criteria, and the at least one system mode.
10 . The method of claim 9 , wherein:
a system element of the at least one system element includes an enterprise identifier, an organization identifier, a division identifier, a department identifier, a group identifier, a sub-group identifier, a device identifier, a software identifier, or an internet protocol address identifier;
a system criteria of the at least one system criteria being system guidelines, system requirements, system design, system build, or resulting system; and
a system mode of the at least one system mode being assets, system functions, or security functions.
11 . The method of claim 1 , wherein obtaining the protective technology data comprises:
identifying system elements of the system aspect based on the data gathering parameters;
obtaining system protective technology information from the system elements in accordance with the data gathering parameters; and
recording the system protective technology information from the system elements to produce the protective technology data.
12 . An analysis system comprises:
one or more computing entities configured to include:
a system user interface module configured to interface with a user to receive one or more inputs regarding evaluation of an enterprise system for system protective technology evaluation;
a control module configured to:
determine a system aspect of the enterprise system for the system protective technology evaluation based upon the one or more inputs;
determine implementation evaluation perspective for use in performing the system protective technology evaluation based on the one or more inputs; and
determine disclosed evaluation viewpoint for use in performing the system protective technology evaluation on the system aspect based on the one or more inputs;
determine data gathering parameters regarding the system aspect in accordance with the implementation evaluation perspective, the disclosed evaluation viewpoint, and at least one evaluation rating metric;
a data input module configured to:
obtain protective technology information in accordance with the system aspect, the at least one evaluation perspective and the at least one evaluation viewpoint;
engage with the enterprise system to obtain protective technology data based upon the implementation evaluation perspective, the disclosed evaluation viewpoint, and the protective technology information; and
a data analysis module configured to calculate a protective technology rating regarding the protective technology for the system aspect based on the protective technology information, the protective technology data, the implementation evaluation perspective, the disclosed evaluation viewpoint, the data gathering parameters, and at least one evaluation rating metric.
13 . The analysis system of claim 12 , wherein the protective technology information is representative of an organization's understanding of the enterprise system, or portion thereof, with respect to audit and recording, removable media protection and use, system and asset access control, and communications and control network protection.
14 . The analysis system of claim 12 , wherein the protective technology information is:
obtained from a system admin computing entity; or
obtained from one or more computing entities of the enterprise system.
15 . The analysis system of claim 12 , wherein the protective technology data is based upon enterprise system audit and recording, enterprise system removable media protection and use, enterprise system asset access control, and/or enterprise system communications and control networks protection.
16 . The analysis system of claim 12 , wherein the protective technology rating regarding the protective technology of the enterprise system, or portion thereof, is based on at least one of:
the protective technology information;
the protective technology data;
protective technology processes;
protective technology policies;
protective technology documentation; or
protective technology automation.
17 . The analysis system of claim 12 , wherein the protective technology rating indicates how well the protective technology information reflects an understanding of the protective technology with respect to at least one of:
assets of the enterprise system, or portion thereof;
system functions of the enterprise system, or portion thereof; or
security functions of the system, or portion thereof.
18 . The analysis system of claim 12 , wherein the protective technology rating indicates how well the protective technology information reflects intended implementation of the protective technology with respect to at least one of:
assets of the enterprise system, or portion thereof;
system functions of the enterprise system, or portion thereof; or
security functions of the system, or portion thereof.
19 . The analysis system of claim 12 , wherein the protective technology rating indicates how well the protective technology information reflects intended operation of the protective technology with respect to at least one of:
assets of the enterprise system, or portion thereof;
system functions of the enterprise system, or portion thereof; or
security functions of the system, or portion thereof.
20 . The analysis system of claim 12 , wherein the control module determine the system aspect by:
determining at least one system element of the enterprise system;
determining at least one system criteria of the enterprise system;
determining at least one system mode of the enterprise system; and
determining the system aspect based on the at least one system element, the at least one system criteria, and the at least one system mode.
21 . The analysis system of claim 20 , wherein:
a system element of the at least one system element includes an enterprise identifier, an organization identifier, a division identifier, a department identifier, a group identifier, a sub-group identifier, a device identifier, a software identifier, or an internet protocol address identifier;
a system criteria of the at least one system criteria being system guidelines, system requirements, system design, system build, or resulting system; and
a system mode of the at least one system mode being assets, system functions, or security functions.
22 . The analysis system of claim 12 , wherein the data input module obtains the protective technology data by:
identifying system elements of the system aspect based on the data gathering parameters;
obtaining system protective technology information from the system elements in accordance with the data gathering parameters; and
recording the system protective technology information from the system elements to produce the protective technology data.