IP Library › Granted Patent US 10,592,675
Granted Patent B2
US 10,592,675 · App. 15/661,678 · Granted Mar 17, 2020

Methods and systems of assessing and managing information security risks in a computer system

Inventors: Jeff Dotson (Provo, UT); Andrew Watanabe (Provo, UT); Joshua Mortensen (Provo, UT); Juan Rodriguez (Sandy, UT)
G06F21/577G06N20/00G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,592,675
App. No.
15/661,678
Granted
Mar 17, 2020
Kind
B2
Abstract

In one aspect, a computerized method for assessing and managing information security risks in a computer system includes the step of receiving a customer security assessment. The method includes the step of obtaining a set of already-answered security assessment questions. The method includes the step of applying one or more machine learning methods to generate a strength of one or more similarities scores. The method includes the step of automatically populating one or more direct mappings between the set of already-answered security assessment questions with the other set of questions in a customer security assessment. The method includes the step of setting a baseline score for the one or more direct mappings to already-answered security assessment questions to a set of answered questions in the customer security assessment by using the strength of one or more similarities scores.

Claims (26)

1. A computerized method useful for assessing and managing information security risks in a computer system comprising:

receiving a customer security assessment, wherein the customer security assessment comprises a set of digitally answered questions answer by an information technology security expert in an entity, and wherein the set of digital answered questions comprises a set of MaxDiff or Choice-Based Conjoint questions;

obtaining a set of already-answered security assessment questions, wherein the set of already-answered security assessment questions comprises a set of security assessments from other vendors that have been answered in the past;

determining a relative rank between a question in the customer security assessment and the set of already-answered security assessment questions;

applying one or more machine learning methods to generate a strength of one or more similarities scores, wherein the one or more similarity scores map a set of already-answered security assessment questions with another set of questions in a customer security assessment;

automatically populating one or more direct mappings between the set of already-answered security assessment questions with the other set of questions in a customer security assessment;

using the strength of the one or more similarities scores to set a baseline for the score that can evolve over time via a set of overrides;

setting the baseline score for the one or more direct mappings to already-answered security assessment questions to a set of answered questions in the customer security assessment by using the strength of one or more similarities scores;

ranking the one or more direct mappings according to a set of baseline scores; and

based on the ranking, automatically populating one or more non-direct mappings between the set of already-answered security assessment questions with the other set of questions in a customer security assessment.

2. The computerized method of claim 1 further comprising the step of:

following up with a survey to determine a relative rank between a question and other similar already answered questions in the customer security assessment.

3. A computer system useful for assessing and managing information security risks in a computer system comprising:

a processor;

a memory containing instructions when executed on the processor, causes the processor to perform operations that:

receive a customer security assessment, wherein the customer security assessment comprises a set of digitally answered questions answer by an information technology security expert in an entity, and wherein the set of digital answered questions comprises a set of MaxDiff or Choice-Based Conjoint questions;

obtain a set of already-answered security assessment questions, wherein the set of already-answered security assessment questions comprises a set of security assessments from other vendors that have been answered in the past;

determine a relative rank between a question in the customer security assessment and the set of already-answered security assessment questions;

apply one or more machine learning methods to generate a strength of one or more similarities scores, wherein the one or more similarity scores map a set of already-answered security assessment questions with another set of questions in a customer security assessment;

automatically populate one or more direct mappings between the set of already-answered security assessment questions with the other set of questions in a customer security assessment;

use the strength of the one or more similarities scores to set a baseline for the score that can evolve over time via a set of overrides;

set a baseline score for the one or more direct mappings to already-answered security assessment questions to a set of answered questions in the customer security assessment by using the strength of one or more similarities scores;

rank the one or more direct mappings according to a set of baseline scores; and

based on the ranking, automatically populate one or more non-direct mappings between the set of already-answered security assessment questions with the other set of questions in a customer security assessment.

4. The computerized system of claim 3 , wherein the memory containing instructions when executed on the processor, causes the processor to perform operations that:

following up with a survey to determine a relative rank between a question and other similar already answered questions in the customer security assessment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2019
From: DOTSON, JEFF; WATANABE, ANDREW; MORTENSEN, JOSHUA; RODRIGUEZ, JUAN
To: WHISTIC INC.
Reel/Frame 048314/0545 →
Continuity (2)
Provisional Application 62378167 · Aug 22, 2016
Related Publication 20180129813A1 · May 10, 2018
Cited By (1)
US 12,481,684