IP Library Granted Patent US 8,713,173
Granted Patent B2
US 8,713,173 · App. 13/564,809 · Granted Apr 29, 2014

System and method for ensuring compliance with organizational policies

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,713,173
App. No.
13/564,809
Granted
Apr 29, 2014
Kind
B2
Abstract

A method for ensuring compliance with organizational policies is described herein. The method can include the step of monitoring one or more parameters of a managed computing device for compliance with one or more policies of an organization in which the organizational policies may include limitations on the managed computing device. The method can also include the step of detecting a non-conformance event at the managed computing device with respect to at least one organizational policy. In response to the detection of the non-conformance event, the operation of the managed computing device may be restricted with respect to features or data associated with the organization.

Claims (45)

1. A method for ensuring compliance with organizational policies, comprising the following computer-implemented steps:

monitoring one or more parameters of a managed computing device for compliance with one or more policies of an organization, wherein the organizational policies include limitations on the managed computing device, wherein the managed computing device has a work profile that includes settings, applications and programs associated with or owned by the organization and a personal profile that includes settings, applications and programs associated with a personal lifestyle of or owned by a user of the managed computing device;

detecting a non-conformance event at the managed computing device with respect to at least one organizational policy; and

in response to the detection of the non-conformance event, restricting operation of the work profile of the managed computing device by locking the settings, applications or programs associated with or owned by the organization without impacting the settings, applications and programs of the personal profile.

2. The method according to claim 1 , wherein the organizational policies include one or more of the following: password rules compliance; blacklisted application compliance; installation of default applications or bundle compliance; data roaming compliance; system modification compliance; or administrator control compliance.

3. The method according to claim 2 , wherein the non-conformance event comprises one or more of the following: selecting an unauthorized password; downloading an unauthorized application; failing to install one or more default applications or bundles; roaming on an unauthorized network; modifying the managed computing device in an unauthorized manner; or blocking administrator control of the managed computing device.

4. The method according to claim 1 , wherein restricting operation of the managed computing device further comprises one or more of the following: removing data from the managed computing device, removing wireless communication settings or credentials from the managed computing device; removing network settings or credentials from the managed computing device; removing a proxy configuration from the managed computing device; removing an email or messaging configuration from the managed computing device; disabling device configuration updates from the managed computing device; locking out one or more profiles of the managed computing device; or messaging a user of the managed computing device.

5. The method according to claim 1 , further comprising:

detecting a conformance event at the managed computing device with respect to at least one organizational policy; and

in response to the detection of the conformance event, enabling an operation of the managed computing device with respect to features or data associated with the organization.

6. The method according to claim 5 , wherein the conformance event comprises one or more of the following: selecting an authorized password; downloading an authorized application; installing a required set of default applications or bundles; operating on an authorized network; avoiding the unauthorized modification of the managed computing device; or permitting administrator control of the managed computing device.

7. The method according to claim 1 , further comprising:

detecting a conformance event at the managed computing device with respect to at least one organizational policy, wherein the conformance event corrects the non-conformance event; and

in response to detecting the conformance event, removing the operational restriction of the managed computing device.

8. The method according to claim 1 , further comprising reporting the non-conformance event, wherein the non-conformance event has been previously assigned a severity level.

9. The method according to claim 1 , further comprising waiting a predetermined amount of time before restricting operation of the managed computing device with respect to features or data associated with the organization.

10. The method according to claim 1 , wherein an organizational policy is associated with an individual, a bundle or a node.

11. A method for ensuring compliance with organizational policies, comprising the following computer-implemented steps:

setting one or more policies of an organization, wherein the organizational policies are applicable to a managed computing device associated with the organization and include limitations on the managed computing device, wherein the managed computing device has a work profile that includes settings, applications and programs associated with or owned by the organization and a personal profile that includes settings, applications and programs associated with a personal lifestyle of or owned by a user of the managed computing device;

receiving a report of a non-conformance event at the managed computing device, wherein the non-conformance event indicates that the managed computing device is violating one or more organizational policies; and

in response to the receipt of the reporting of the non-conformance event, restricting operation of the work profile of the managed computing device by locking the settings, applications or programs associated with or owned by the organization without impacting the settings, applications and programs of the personal profile.

12. The method according to claim 11 , wherein the organizational policies include one or more of the following: password rules compliance; blacklisted application compliance; installation of default applications compliance; data roaming compliance; system modification compliance; or administrator control compliance.

13. The method according to claim 12 , wherein the non-conformance event comprises one or more of the following: selecting an unauthorized password; downloading an unauthorized application; failing to install one or more default applications; roaming on an unauthorized network; modifying the managed computing device in an unauthorized manner; or blocking administrator control of the managed computing device.

14. The method according to claim 12 , further comprising:

receiving a report of a conformance event at the managed computing device, wherein the conformance event corrects the non-conformance event; and

in response to the receipt of the report of the conformance event, removing the operational restriction of the managed computing device.

15. The method according to claim 11 , wherein an organizational policy is associated with an individual, a bundle or a node.

16. A managed computing device, comprising:

a display configured to at least display messages;

a communications stack configured to receive communication signals from and transmit communication signals to a management platform; and

a processor, wherein the processor is communicatively coupled to the communications stack and the display and is operable to:

monitor one or more parameters of the managed computing device for compliance with one or more policies of an organization, wherein the organizational policies include limitations on the managed computing device, wherein the managed computing device has a work profile that includes settings, applications and programs associated with or owned by the organization and a personal profile that includes settings, applications and programs associated with a personal lifestyle of or owned by a user of the managed computing device;

detect a non-conformance event associated with the operation of the managed computing device, wherein the non-conformance event violates one or more organizational policies; and

in response to the detection of the non-conformance event, restrict operation of the work profile of the managed computing device by locking the settings, applications or programs associated with or owned by the organization without impacting the settings, applications and programs of the personal profile.

17. The managed computing device according to claim 16 , wherein the organizational policies include one or more of the following: password rules compliance; blacklisted application compliance; installation of default applications or bundle compliance; data roaming compliance; system modification compliance; or administrator control compliance.

18. The managed computing device according to claim 16 , wherein the non-conformance event comprises one or more of the following: selecting an unauthorized password; downloading an unauthorized application; failing to install one or more default applications or bundles; roaming on an unauthorized network; modifying the managed computing device in an unauthorized manner; or blocking administrator control of the managed computing device.

19. The managed computing device according to claim 16 , wherein the processor is operable to further restrict operation of the managed computing device by one or more of the following: removing data from the managed computing device, removing wireless communication settings or credentials from the managed computing device; removing network settings or credentials from the managed computing device; removing a proxy configuration from the managed computing device; removing an email or messaging configuration from the managed computing device; disabling device configuration updates from the managed computing device; locking out one or more profiles of the managed computing device; or generating a message for a user of the managed computing device.

20. The managed computing device according to claim 16 , wherein the processor is further operable to:

detect a conformance event at the managed computing device with respect to at least one organizational policy; and

in response to the detection of the conformance event, enable an operation of the managed computing device with respect to features or data associated with the organization.

21. The managed computing device according to claim 20 , wherein the operation that is enabled is the activation of configuration updates for the managed computing device.

22. The managed computing device according to claim 16 , wherein the processor is further operable to:

detect a conformance event at the managed computing device with respect to at least one organizational policy, wherein the conformance event corrects the non-conformance event; and

in response to detecting the conformance event, remove the operational restriction of the managed computing device.

23. The managed computing device according to claim 16 , wherein an organizational policy is associated with an individual, a bundle or a node.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2018
From: NI, HAO
To: OPENPEAK LLC
Reel/Frame 047675/0378 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2018
From: OPENPEAK, LLC.
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 044543/0554 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: OPENPEAK, INC.
To: OPENPEAK LLC
Reel/Frame 042752/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2012
From: KACHEROV, VADIM; DARE, ROBERT M.; WATSON, GREGORY PAUL; GOEL, PARAG
To: OPENPEAK INC.
Reel/Frame 028707/0653 →