IP Library Granted Patent US 9,679,158
Granted Patent B2
US 9,679,158 · App. 14/833,819 · Granted Jun 13, 2017

Limiting exposure to compliance and risk in a cloud environment

Inventors: Corville O. Allen (Morrisville, NC); Arthur R. Francis (Raleigh, NC); Eduardo A. Patrocinio (Cary, NC)
Assignee: International Business Machines Corporation
G06F21/6245H04L63/10H04L67/1097G06F21/6227H04L9/085
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,679,158
App. No.
14/833,819
Granted
Jun 13, 2017
Kind
B2
Abstract

Minimizing data security risks may be provided. A number and type of confidential data in a computing environment may be determined to generate a metric for the type of confidential data in the computing environment. The metric of the type of confidential data may be compared to a predetermined metric for the type. Responsive to determining the metric for the type of confidential data exceeding a predetermined metric for the type, an action may be performed to prevent more entries of the type of confidential data in the computing environment.

Claims (15)

1. A method of minimizing data security risks, comprising:

determining a number and type of confidential data stored in a computing environment to generate a metric for the type of confidential data in the computing environment, the type of confidential data determined from a plurality of types comprising at least social security number (SSN), patient data, personal information, and credit card number;

comparing the metric of the type of confidential data to a predetermined threshold for the type; and

responsive to determining the metric for the type of confidential data exceeding a predetermined threshold for the type, performing an action to prevent more entries of the type of confidential data to be stored in the computing environment,

the metric measured by at least one of a count of the type of confidential data in the computing environment and a volume size taken up by the type of confidential data in the computing environment,

the predetermined threshold being different for different types of confidential data in the computing environment,

the performing an action to prevent more entries of the type of confidential data in the computing environment comprising closing an access port in the computing environment to requests associated with new data of the type of confidential data, and automatically performing removal of data of the type stored in the computing environment to make room for accepting said more entries of the type of confidential data.

2. The method of claim 1 , wherein the action comprises at least one of pacing and preventing work from entering the computing environment.

3. The method of claim 1 , wherein the action comprises scheduling work associated with the type of confidential data into a different computing environment.

4. The method of claim 1 , wherein the computing environment comprises one or more of a virtual environment, a virtual machine (VM), a logical partition (LPAR), a workload partition (WPAR), a machine, a node, or public cloud, or combinations thereof.

5. The method of claim 1 , wherein the predetermined metric is configured based on a policy that is set for processing the type of confidential data.

6. The method of claim 1 , wherein the type of confidential data comprises social security number, wherein responsive to determining that the metric associated with the data comprising social security number meets the predetermined threshold for the type of confidential data, the predetermined threshold defined as a count of the social security number, preventing the computing environment from servicing requests associated with new data having the type of confidential data.

7. The method of claim 1 , wherein the type of confidential data comprises patient data, wherein responsive to determining that the metric associated with the data comprising patient data meets the predetermined threshold for the type of confidential data, the predetermined threshold defined as a count of the patient data, preventing the computing environment from servicing requests associated with new data having the type of confidential data.

8. The method of claim 1 , wherein the type of confidential data comprises personal information, wherein responsive to determining that the metric associated with the data comprising personal information meets the predetermined threshold for the type of confidential data, the predetermined threshold defined as a count of the personal information, preventing the computing environment from servicing requests associated with new data having the type of confidential data.

9. The method of claim 1 , wherein the type of confidential data comprises credit card information, wherein responsive to determining that the metric associated with the data comprising credit card information meets the predetermined threshold for the type of confidential data, the predetermined threshold defined as a count of the credit card information, preventing the computing environment from servicing requests associated with new data having the type of confidential data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2015
From: ALLEN, CORVILLE O.; FRANCIS, ARTHUR R.; PATROCINIO, EDUARDO A.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 036403/0951 →
Continuity (2)
Continuation 14591578 · Jan 7, 2015
Related Publication 20160196446A1 · Jul 7, 2016