IP Library Granted Patent US 8,176,158
Granted Patent B2
US 8,176,158 · App. 11/463,580 · Granted May 8, 2012

Information technology governance and controls methods and apparatuses

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,176,158
App. No.
11/463,580
Filed
Aug 9, 2006
Granted
May 8, 2012
Kind
B2
Art Unit
2443
USPC
709/223
Abstract

Embodiments of the present invention provide methods and systems for automated change audit of an enterprise's IT infrastructure, including independent detection of changes, reconciliation of detected changes and independent reporting, to effectuate a triad of controls on managing changes within the IT infrastructure, preventive controls, detective controls and corrective controls.

Claims (29)

1. An article of manufacture comprising:

a non-transitory computer-readable storage medium; and

a plurality of instructions stored in the storage medium;

wherein the plurality of instructions are adapted to provide one or more control modules segregated from persons or technologies associated with an enterprise's information technology (IT) infrastructure making authorized changes to the enterprise's IT infrastructure, to perform a plurality of audit operations, independent of the persons or technologies making authorized changes, comprising:

independently detecting changes to one or more data processing devices in the IT infrastructure, regardless of source, intent or authorization of the changes;

reconciling the detected changes with intended and authorized changes;

correlating the detected changes to events contained in one or more event logs associated with the one or more data processing devices; and

independently reporting change activities, including the detected changes supplemented with the correlated events, across production systems of the enterprise's IT infrastructure, including reporting detected intended and authorized changes to persons or technologies making authorized changes.

2. The article of manufacture of claim 1 , wherein reconciling comprises determining whether a detected change of state of at least one of a plurality of data with the enterprise's IT infrastructure is conforming, including determining whether the detected change of state is desirable.

3. The article of manufacture of claim 2 , wherein reconciling further comprises changing a baseline state for the at least one data, if the detected change of state is conforming.

4. The article of manufacture of claim 2 , wherein reconciling further comprises determining at least one of a level of severity or non-conformance for the detected change of state, if the detected change of state is not conforming.

5. The apparatus of claim 2 , wherein reconciling further comprises changing a baseline state for the at least one data, if the detected change of state is conforming.

6. The apparatus of claim 2 , wherein reconciling further comprises determining at least one of a level of severity or non-conformance for the detected change of state, if the detected change of state is not conforming.

7. An apparatus comprising:

a processor; and

a control module adapted to be operated by the processor to audit an enterprise's information technology (IT) infrastructure, the control module being segregated from persons or technologies associated with the IT infrastructure making authorized changes to the IT infrastructure to enable the audit to be performed independent of the persons or technologies making authorized changes, the audit comprising:

independent detection of changes to a first production system in the IT infrastructure, regardless of source, intent or authorization of the changes;

reconciliation of the detected changes with intended and authorized changes; correlation of the detected changes to events contained in one or more event logs;

and

in response to a request to demonstrate control of the IT infrastructure, independent reporting of change activities, including the detected changes supplemented with the correlated events, to all production systems of the enterprise's IT infrastructure including reporting detected intended and authorized changes to persons or technologies making authorized changes.

8. The apparatus of claim 7 , wherein reconciling comprises determining whether a detected change of state of at least one of a plurality of data with the enterprise's IT infrastructure is conforming, including determining whether the detected change of state is desirable.

9. A computer-implemented method of auditing an enterprise's information technology (IT) infrastructure, comprising:

independently detecting, by a control module operated by a computing device, a change to a production system of the IT infrastructure, regardless of source, intent or authorization of the change and independent of persons or technologies making authorized changes to the IT infrastructure, the control module being segregated from the persons or technologies making authorized changes;

reconciling, by the control module, the detected change with intended and authorized changes;

correlating, by the control module, the detected change to an event contained in one or more event logs associated with the production system; and

in response to a request to demonstrate control of the IT infrastructure, independently reporting, by the control module, detected changes, including the detected change supplemented with the correlated event, to all production systems of the enterprise's IT infrastructure, including reporting detected intended and authorized changes to persons or technologies making authorized changes.

10. The computer-implemented method of claim 9 , wherein reconciling comprises determining whether a detected change of state of at least one of a plurality of data with the enterprise's IT infrastructure is conforming, including determining whether the detected change of state is desirable.

11. The method of claim 10 , wherein reconciling further comprises changing a baseline state for the at least one data, if the detected change of state is conforming.

12. The method of claim 10 , wherein reconciling further comprises determining at least one of a level of severity or non-conformance for the detected change of state, if the detected change of state is not conforming.

Assignments (14)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0639 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073664/0124 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
RELEASE OF SECURITY INTEREST Recorded Feb 2, 2015
From: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
To: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY INC.
Reel/Frame 034874/0150 →
SECURITY AGREEMENT Recorded Apr 2, 2013
From: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 030132/0101 →
SECURITY AGREEMENT Recorded May 23, 2011
From: TRIPWIRE, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 026322/0580 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2006
From: DIFALCO, ROBERT A.; KEELER, KENNETH L.; WARMACK, ROBERT L.
To: TRIPWIRE, INC.
Reel/Frame 018492/0023 →