IP Library Granted Patent US 9,729,398
Granted Patent B1
US 9,729,398 · App. 14/615,608 · Granted Aug 8, 2017

Techniques for compliance testing

Inventors: Thomas L. Watson (Richardson, TX); Fredrick A. Crable (Allen, TX)
Assignee: EMC IP Holding Company LLC
H04L41/0869G06F8/71G06Q40/025H04L43/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,729,398
App. No.
14/615,608
Filed
Feb 6, 2015
Granted
Aug 8, 2017
Kind
B1
Art Unit
2199
USPC
717/124
Abstract

Described are techniques for performing compliance testing. Configuration state information is received for one or more devices managed using a configuration management system. The configuration state information is stored in a data container. One or more compliance tests are executed using the configuration state information to determine if the one or more devices are compliant. The one or more compliance tests are defined using one or more queries and one or more compliance rules. The one or more queries are used for retrieving a portion of said configuration state information from said data container and generating one or more result sets. The one or more compliance rules specifying compliance criteria are used for determining whether the one or more result sets include configuration state information which is compliant.

Claims (50)

1. A method for compliance testing comprising:

receiving collected information for one or more entities;

executing one or more compliance tests using the collected information to determine whether the one or more entities are compliant with specified compliance criteria;

determining whether a first of the one or more entities fails a first of the compliance tests; and

responsive to determining that the first entity fails the first compliance test, automatically generating a corresponding remedial action, wherein first metadata describes a hierarchical object model including a first object and a second object included in the first object, the first metadata including a first remedial action atomicity level indicator for the first object indicating it is allowable for remedial action processing to generate the first object, the first metadata including a second remedial action atomicity level indicator for the second object indicating whether it is allowable for remedial action processing to generate the second object, said second object including a first portion corresponding to corrected information of the first entity, wherein said automatically generating the corresponding remedial action includes performing first processing comprising:

generating an object representation of expected information corresponding to successful compliance with the first compliance test, the expected information including the first portion corresponding to corrected information for the first entity, wherein said generating the object representation uses the first metadata and includes:

determining whether the second remedial action atomicity level indicator indicates it is allowable to generate the second object;

if the second remedial action atomicity level indicator indicates it is not allowable to generate the second object, generating the first object including the second object; and

if the second remedial action atomicity level indicator indicates it is allowable to generate the second object, generating the second object without requiring generation of other portions of the first object; and

processing the corresponding remedial action.

2. The method of claim 1 , wherein each of the one or more entities is a loan applicant, the one or more compliance tests use the collected information to determine whether each of the one or more loan applicants are compliant with specified compliance criteria to obtain a loan.

3. The method of claim 2 , wherein the corresponding remedial action includes any of adjusting a loan condition, increasing a loan interest rate, and increasing a down payment amount requirement.

4. The method of claim 1 , wherein each of the one or more entities is a code entity, the one or more compliance tests use the collected information to determine whether the one or more code entities are compliant with specified compliance criteria representing coding standards.

5. The method of claim 4 , wherein the first entity is a first code entity and the corresponding remedial action includes generating a revised code portion of the first code entity.

6. The method of claim 1 , wherein the collected information is stored in a data container and the one or more compliance tests are defined using one or more queries and one or more compliance rules.

7. The method of claim 6 , wherein the one or more queries retrieve a portion of the collected information from the data container and generate one or more result sets.

8. The method of claim 7 , wherein the one or more compliance rules specify compliance criteria used to determine whether the one or more result sets include information which is compliant.

9. The method of claim 1 , wherein the one or more compliance rules include any of a first type of rule defining one or more rows of information which are required to be included in the one or more result sets in order to determine that the one or more results sets include information which is compliant, a second type of rule defining rows of information which are required not to be included in the one or more result sets in order to determine that the one or more results sets include information which is compliant, and a third type of rule defining one or more attributes which are required to be included in each row of the one or more result sets in order to determine that the one or more results sets include information which is compliant.

10. A non-transitory computer readable medium comprising code stored thereon that, when executed, perform a method of compliance testing comprising:

receiving collected information for one or more entities;

executing one or more compliance tests using the collected information to determine whether the one or more entities are compliant with specified compliance criteria;

determining whether a first of the one or more entities fails a first of the compliance tests; and

responsive to determining that the first entity fails the first compliance test, automatically generating a corresponding remedial action, wherein first metadata describes a hierarchical object model including a first object and a second object included in the first object, the first metadata including a first remedial action atomicity level indicator for the first object indicating it is allowable for remedial action processing to generate the first object, the first metadata including a second remedial action atomicity level indicator for the second object indicating whether it is allowable for remedial action processing to generate the second object, said second object including a first portion corresponding to corrected information of the first entity, wherein said automatically generating the corresponding remedial action includes performing first processing comprising:

generating an object representation of expected information corresponding to successful compliance with the first compliance test, the expected information including the first portion corresponding to corrected information of the first entity, wherein said generating the object representation uses the first metadata and includes:

determining whether the second remedial action atomicity level indicator indicates it is allowable to generate the second object;

if the second remedial action atomicity level indicator indicates it is not allowable to generate the second object, generating the first object including the second object; and

if the second remedial action atomicity level indicator indicates it is allowable to generate the second object, generating the second object without requiring generation of other portions of the first object; and

processing the corresponding remedial action.

11. The non-transitory computer readable medium of claim 10 , wherein each of the one or more entities is a loan applicant, the one or more compliance tests use the collected information to determine whether the one or more loan applicants are compliant with specified compliance criteria to obtain a loan.

12. The non-transitory computer readable medium of claim 11 , wherein the corresponding remedial action includes any of adjusting a loan condition, increasing a loan interest rate, and increasing a down payment amount requirement.

13. The non-transitory computer readable medium of claim 10 , wherein each of the one or more entities is a code entity, the one or more compliance tests use the collected information to determine whether the one or more code entities are compliant with specified compliance criteria representing coding standards.

14. The non-transitory computer readable medium of claim 10 , wherein the first entity is a first code entity and the corresponding remedial action includes generating a revised code portion of the first code entity.

15. The non-transitory computer readable medium of claim 10 , wherein the collected information is stored in a data container and the one or more compliance tests are defined using one or more queries and one or more compliance rules.

16. The non-transitory computer readable medium of claim 15 , wherein the one or more queries retrieve a portion of the collected information from the data container and generate one or more result sets.

17. The non-transitory computer readable medium of claim 16 , wherein the one or more compliance rules specify compliance criteria used to determine whether the one or more result sets include information which is compliant.

18. The non-transitory computer readable medium of claim 10 , wherein the one or more compliance rules include any of a first type of rule defining one or more rows of information which are required to be included in the one or more result sets in order to determine that the one or more results sets include information which is compliant, a second type of rule defining rows of information which are required not to be included in the one or more result sets in order to determine that the one or more results sets include information which is compliant, and a third type of rule defining one or more attributes which are required to be included in each row of the one or more result sets in order to determine that the one or more results sets include information which is compliant.

19. A system comprising:

a processor;

a memory comprising code stored therein that, when executed, performs a method for compliance testing comprising:

receiving configuration state information for one or more devices managed using a configuration management system;

executing one or more compliance tests using the configuration state information to determine if the one or more devices are compliant;

determining whether a first of the one or more devices fails a first of the compliance tests; and

responsive to determining that the first device fails the first compliance test, automatically generating a corresponding remedial action including one or more device commands to make the first device compliant with an expected configuration state, wherein first metadata describes a hierarchical object model including a first object and a second object included in the first object, the first metadata including a first remedial action atomicity level indicator for the first object indicating it is allowable for remedial action processing to generate the first object, the first metadata including a second remedial action atomicity level indicator for the second object indicating whether it is allowable for remedial action processing to generate the second object, said second object including a first portion corresponding to corrected configuration state information of the first device, wherein said automatically generating the corresponding remedial action includes performing first processing comprising:

generating an object representation of expected configuration state information corresponding to successful compliance with the first compliance test, the expected configuration state information including the first portion corresponding to corrected configuration state information of the first device, wherein said generating the object representation uses the first metadata and includes:

determining whether the second remedial action atomicity level indicator indicates it is allowable to generate the second object;

if the second remedial action atomicity level indicator indicates it is not allowable to generate the second object, generating the first object including the second object; and

if the second remedial action atomicity level indicator indicates it is allowable to generate the second object, generating the second object without requiring generation of other portions of the first object; and

processing the corresponding remedial action.

20. The system of claim 19 , where the method further includes:

converting the object representation of the expected configuration state information to the one or more device commands.

Assignments (11)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2015
From: WATSON, THOMAS L.; CRABLE, FREDRICK A.
To: VOYENCE, INC.
Reel/Frame 034905/0106 →
MERGER Recorded Feb 6, 2015
From: VOYENCE, INC.
To: EMC CORPORATION
Reel/Frame 034905/0109 →
Continuity (1)
Continuation 11700388 · Jan 31, 2007