IP Library Granted Patent US 8,893,283
Granted Patent B2
US 8,893,283 · App. 13/755,876 · Granted Nov 18, 2014

Performing an automated compliance audit by vulnerabilities

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,893,283
App. No.
13/755,876
Granted
Nov 18, 2014
Kind
B2
Abstract

An automated enterprise compliance auditing by vulnerabilities system including an enterprise asset database, a compliance regulation including compliance controls, a known asset vulnerabilities database including details of publicly known asset vulnerabilities, compliance control associating functionality to associate each of a set of audited assets with at least a subset of compliance controls of the compliance regulation, the audited assets being a subset of the enterprise assets, vulnerability mapping functionality to map each compliance control to a subset of the known asset vulnerabilities which may impact compliance of at least one of the audited assets therewith, asset scanning functionality to scan each audited asset to ascertain to which publicly known asset vulnerabilities the audited asset is vulnerable to, and numeric compliance score calculating functionality to, responsive to the associating, mapping and scanning, calculate for each audited asset, a numeric compliance score for each compliance control associated therewith.

Claims (37)

1. An automated enterprise compliance auditing by vulnerabilities system comprising:

an enterprise asset database comprising details of assets of said enterprise;

at least one compliance regulation, each of said at least one compliance regulation comprising at least one compliance control;

a known asset vulnerabilities database comprising details of publicly known asset vulnerabilities;

compliance control associating functionality to associate each of a set of audited assets with at least a subset of compliance controls of said at least one compliance regulation, said set of audited assets being at least a subset of said assets of said enterprise;

vulnerability mapping functionality to map each compliance control of said at least one compliance regulation to a subset of said publicly known asset vulnerabilities which may potentially impact compliance of at least one of said audited assets therewith;

asset scanning functionality to scan each audited asset of said set of audited assets to ascertain to which of said publicly known asset vulnerabilities said audited asset is vulnerable to; and

numeric compliance score calculating functionality to, responsive to said associating, said mapping and said scanning, calculate for each of said set of audited assets, a numeric compliance score for each compliance control associated therewith, said numeric compliance score being within a range of possible numeric compliance scores.

2. An automated enterprise compliance auditing by vulnerabilities system according to claim 1 and wherein said database also comprises a hierarchical structure of said assets.

3. An automated enterprise compliance auditing by vulnerabilities system according to claim 1 and wherein each of said publicly known asset vulnerabilities has a severity value associated therewith.

4. An automated enterprise compliance auditing by vulnerabilities system according to claim 1 and wherein when calculating said numeric compliance score for each of said set of audited assets, said numeric compliance score calculating functionality is operative to consider at least one of:

a preexisting compliance score for said audited asset;

a number of said publicly known asset vulnerabilities to which said audited asset is vulnerable to; and

a severity of each of said publicly known asset vulnerabilities to which said audited asset is vulnerable to.

5. An automated enterprise compliance auditing by vulnerabilities system according to claim 4 and wherein when calculating said numeric compliance score for each of said set of audited assets, a high severity publicly known asset vulnerability has a higher impact on said numeric compliance score of an audited asset vulnerable thereto than a low severity publicly known asset vulnerability.

6. An automated enterprise compliance auditing by vulnerabilities system according to claim 4 and wherein when calculating said numeric compliance score for each of said set of audited assets, a publicly known asset vulnerability having a highest severity among said publicly known asset vulnerabilities to which said audited asset is vulnerable to, has a highest impact on said numeric compliance score of an audited asset.

7. A computer product for automatic asset compliance auditing in an enterprise, including a non-transitory, tangible computer-readable medium in which computer program instructions are stored, which instructions, when read by a computer, cause the computer to associate each of a set of audited assets with at least a subset of compliance controls of at least one compliance regulation, said set of audited assets being at least a subset of said assets of said enterprise, to map each compliance control of said at least one compliance regulation to a subset of a collection of publicly known asset vulnerabilities which may potentially impact compliance of at least one of said audited assets therewith, to scan each audited asset of said set of audited assets to ascertain to which of said collection of publicly known asset vulnerabilities said audited asset is vulnerable to, and responsive to said associating, said mapping and said scanning, to calculate, for each of said set of audited assets, a numeric compliance score for each compliance control associated therewith, said numeric compliance score being within a range of possible numeric compliance scores.

8. A computer product for automatic asset compliance auditing in an enterprise according to claim 7 and wherein each of said publicly known asset vulnerabilities has a severity value associated therewith.

9. A computer product for automatic asset compliance auditing in an enterprise according to claim 7 and wherein said numeric compliance score is calculated for each of said set of audited assets by considering at least one of:

a preexisting compliance score for said audited asset;

a number of said publicly known asset vulnerabilities to which said audited asset is vulnerable to; and

a severity of each of said publicly known asset vulnerabilities to which said audited asset is vulnerable to.

10. A computer product for automatic asset compliance auditing in an enterprise according to claim 9 and wherein when calculating said numeric compliance score for each of said set of audited assets, a high severity publicly known asset vulnerability has a higher impact on said numeric compliance score of an audited asset vulnerable thereto than a low severity publicly known asset vulnerability.

11. A computer product for automatic asset compliance auditing in an enterprise according to claim 9 and wherein when calculating said numeric compliance score for each of said set of audited assets, a publicly known asset vulnerability having a highest severity among said publicly known asset vulnerabilities to which said audited asset is vulnerable to, has a highest impact on said numeric compliance score of an audited asset.

12. A method for asset compliance auditing in an enterprise, said method comprising:

associating each of a set of audited assets with at least a subset of compliance controls of at least one compliance regulation, said set of audited assets being at least a subset of said assets of said enterprise;

mapping each compliance control of said at least one compliance regulation to a subset of a collection of publicly known asset vulnerabilities which may potentially impact compliance of at least one of said assets therewith;

scanning each audited asset of said set of audited assets to ascertain to which of said collection of publicly known asset vulnerabilities said audited asset is vulnerable to; and

responsive to said associating, said mapping and said scanning, calculating via at least one processor, for each of said set of audited assets, a numeric compliance score corresponding to each compliance control associated therewith, a numeric compliance score for each compliance control associated therewith, said numeric compliance score being within a range of possible numeric compliance scores.

13. A method for asset compliance auditing in an enterprise according to claim 12 and wherein each of said publicly known asset vulnerabilities has a severity value associated therewith.

14. A method for asset compliance auditing in an enterprise according to claim 12 and wherein said numeric compliance score is calculated for each of said set of audited assets by considering at least one of:

a preexisting compliance score for said audited asset;

a number of said publicly known asset vulnerabilities to which said audited asset is vulnerable to; and

a severity of each of said publicly known asset vulnerabilities to which said audited asset is vulnerable to.

15. A method for asset compliance auditing in an enterprise according to claim 12 and wherein:

when calculating said numeric compliance score for each of said set of audited assets, a high severity publicly known asset vulnerability has a higher impact on said numeric compliance score of an audited asset vulnerable thereto than a low severity publicly known asset vulnerability; and

when calculating said numeric compliance score for each of said set of audited assets, a publicly known asset vulnerability having a highest severity among said publicly known asset vulnerabilities to which said audited asset is vulnerable to, has a highest impact on said numeric compliance score of an audited asset.

Assignments (13)
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 063546/0181) Recorded Jun 21, 2024
From: BARCLAYS BANK PLC
To: MICRO FOCUS LLC
Reel/Frame 067807/0076 →
SECURITY INTEREST Recorded Aug 30, 2023
From: MICRO FOCUS LLC
To: THE BANK OF NEW YORK MELLON
Reel/Frame 064760/0862 →
SECURITY INTEREST Recorded May 4, 2023
From: MICRO FOCUS LLC
To: BARCLAYS BANK PLC
Reel/Frame 063546/0181 →
SECURITY INTEREST Recorded May 4, 2023
From: MICRO FOCUS LLC
To: BARCLAYS BANK PLC
Reel/Frame 063546/0190 →
SECURITY INTEREST Recorded May 4, 2023
From: MICRO FOCUS LLC
To: BARCLAYS BANK PLC
Reel/Frame 063546/0230 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2013
From: RAZ, BARAK; FEHER, BEN
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029959/0468 →