IP Library › Granted Patent US 11,431,740
Granted Patent B2
US 11,431,740 · App. 16/227,109 · Granted Aug 30, 2022

Methods and systems for providing an integrated assessment of risk management and maturity for an organizational cybersecurity/privacy program

Inventors: Robert Carl Heckman (Vienna, VA); Daniel Keith Chandler (Vienna, VA)
Assignee: Criterion Systems, Inc.
H04L63/1425G06Q10/0635H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,431,740
App. No.
16/227,109
Granted
Aug 30, 2022
Kind
B2
Abstract

Embodiments include a computing device with a memory and a processor configured to perform operations including computing a cybersecurity and privacy (CS&P) framework profile (or risk factor) for a cybersecurity program implemented by an enterprise, computing a CS&P maturity level (or maturity factor) for the cybersecurity program, determining an integrated result for the cybersecurity program based at least in part on a combination of the CS&P framework profile and the maturity factor.

Claims (97)

1. A computing device comprising:

a memory; and

a processor coupled to the memory, wherein the processor is configured with processor executable software instructions to perform operations comprising:

implement an automated supervised learning comprising:

monitoring technical activities of an organization to collect technical activity information;

generating feature vector information structures based on the collected technical activity information;

applying the generated feature vector information structures to machine learning models to generate analysis results; and

using the generated analysis results to assign risk management level scores in one or more domains, wherein each domain includes:

a core area comprising a plurality of categories,

a category comprising a plurality of subcategories, and

a subcategory;

determining a cybersecurity and privacy (CS&P) framework profile for a cybersecurity program implemented by the organization;

determining a CS&P maturity level for the cybersecurity program;

determining an integrated result for the cybersecurity program based on a combination of the determined CS&P framework profile and the determined CS&P maturity level; and

using the determined integrated result to:

generate a corrective action plan that includes one or more remediation activities;

invoke the remediation activities; and

monitor the remediation activities, changes to a current risk management level of cybersecurity program, and changes to a current maturity level the cybersecurity program.

2. The computing device of claim 1 ,

wherein the processor is configured to perform operations such that determining the CS&P framework profile for the cybersecurity program implemented by the organization comprises:

determining the current risk management level for the cybersecurity program; and

determining a target risk management level for the cybersecurity program; and

wherein the processor is configured to perform operations such that determining the CS&P maturity level for the cybersecurity program comprises:

determining the current maturity level for the cybersecurity program; and

determining a target maturity level for the cybersecurity program.

3. The computing device of claim 1 , wherein the processor is configured to perform operations such that:

determining the CS&P framework profile for the cybersecurity program implemented by the organization comprises determining the current risk management level and a target risk management level within each of a plurality of core areas, wherein each core area includes an identify core area information structure, a protect core area information structure, a detect core area information structure, a respond core area information structure, and a recover core area information structure; and

determining the CS&P maturity level for the cybersecurity program comprises determining the current maturity level and a maturity level within each of the plurality of core areas.

4. The computing device of claim 1 , wherein the processor is configured to perform operations further comprising:

using the integrated result to generate recommendations for improvements to the cybersecurity program.

5. The computing device of claim 1 , wherein the processor is configured to perform operations such that determining the CS&P framework profile for the cybersecurity program implemented by the organization comprises:

identifying applicable criteria within each of a plurality of subcategories, wherein the subcategories comprise criteria relevant to risk management; and

assigning a weight to the identified criteria under the plurality of subcategories.

6. The computing device of claim 5 , wherein the processor is configured to perform operations such that the subcategories are divided among a plurality of categories, and wherein a sum of the weights assigned to the subcategories within each category equals 1.

7. The computing device of claim 6 , wherein the processor is configured to perform operations such that determining the CS&P framework profile for the cybersecurity program implemented by the organization comprises:

determining a risk management level for each category based on a weighted sum of values given to the subcategories within the category.

8. The computing device of claim 1 ,

wherein the processor is configured to perform operations such that determining the CS&P maturity level for the cybersecurity program comprises:

identifying applicable criteria within each of a plurality of subcategories,

wherein the plurality of subcategories comprise criteria relevant to maturity of the cybersecurity program, and

wherein the subcategories are divided among a plurality of categories.

9. The computing device of claim 1 , wherein:

the processor is configured to perform operations further comprising receiving data input from the organization, and

the processor is configured to perform operations such that:

determining the CS&P framework profile for the cybersecurity program implemented by the organization comprises using the received data input from the organization to determine the CS&P framework profile; and

determining the CS&P maturity level for the cybersecurity comprises using the received data input from the organization to determine the CS&P maturity level for the cybersecurity.

10. The computing device of claim 9 , wherein the processor is configured to perform operations such that the received data input includes information comprising at least one of cybersecurity documentation, technical vulnerability assessment results, blue team assessment, red team assessment, penetration testing team results, operational environmental constraints, or targeted interview responses by personnel of the organization.

11. A method of evaluating a cybersecurity program implemented by an organization, comprising:

implementing an automated supervised learning comprising:

monitoring technical activities of the organization to collect technical activity information;

generating feature vector information structures based on the collected technical activity information;

applying the generated feature vector information structures to machine learning models to generate analysis results; and

using the generated analysis results to assign risk management level scores in one or more domains, wherein each domain includes:

a core area comprising a plurality of categories,

a category comprising a plurality of subcategories, and

a subcategory;

determining a cybersecurity and privacy (CS&P) framework profile for the cybersecurity program;

determining a CS&P maturity level for the cybersecurity program;

determining an integrated result for the cybersecurity program based on a combination of the determined CS&P framework profile and the determined CS&P maturity level; and

using the determined integrated result to:

generate a corrective action plan that includes one or more remediation activities;

invoke the remediation activities; and

monitor the remediation activities, changes to a current risk management level of cybersecurity program, and changes to a current maturity level the cybersecurity program.

12. The method of claim 11 , wherein:

determining the CS&P framework profile for the cybersecurity program comprises:

determining the current risk management level for the cybersecurity program; and

determining a target risk management level for the cybersecurity program; and

determining the CS&P maturity level for the cybersecurity program comprises:

determining the current maturity level for the cybersecurity program; and

determining a target maturity level for the cybersecurity program.

13. The method of claim 11 , wherein:

determining the CS&P framework profile for the cybersecurity program comprises determining the current risk management level and target risk management level within each of a plurality of core areas, wherein each core area includes a an identify core area information structure, a protect core area information structure, a detect core area information structure, a respond core area information structure, and a recover core area information structure; and

determining the CS&P maturity level for the cybersecurity program comprises determining the current maturity level and a maturity level within each of the plurality of core areas.

14. The method of claim 11 , further comprising:

using the integrated result to generate recommendations for improvements to the cybersecurity program.

15. The method of claim 11 , wherein determining the CS&P framework profile for the cybersecurity program comprises:

identifying applicable criteria within each of a plurality of subcategories, wherein the subcategories comprise criteria relevant to risk management; and

assigning a weight to the identified criteria under the plurality of subcategories.

16. The method of claim 15 , wherein the subcategories are divided among a plurality of categories, and wherein a sum of the weights assigned to the subcategories within each category equals 1.

17. The method of claim 16 , wherein determining the CS&P framework profile for the cybersecurity program comprises:

calculating a risk management level for each category based on a weighted sum of values given to the subcategories within the category.

18. A non-transitory processor-readable medium having stored thereon processor-executable instructions to cause a processor of a computing device to perform operations for evaluating a cybersecurity program implemented by an organization, the operations comprising:

implementing an automated supervised learning comprising:

monitoring technical activities of the organization to collect technical activity information;

generating feature vector information structures based on the collected technical activity information;

applying the generated feature vector information structures to machine learning models to generate analysis results; and

using the generated analysis results to assign risk management level scores in one or more domains, wherein each domain includes:

a core area comprising a plurality of categories,

a category comprising a plurality of subcategories, and

a subcategory;

determining a cybersecurity and privacy (CS&P) framework profile for the cybersecurity program;

determining a CS&P maturity level for the cybersecurity program;

determining an integrated result for the cybersecurity program based a combination of the determined CS&P framework profile and the determined CS&P maturity level; and

using the determined integrated result to:

generate a corrective action plan that includes one or more remediation activities;

invoke the remediation activities; and

monitor the remediation activities, changes to a current risk management level of cybersecurity program, and changes to a current maturity level the cybersecurity program.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2022
From: HECKMAN, ROBERT CARL; CHANDLER, DANIEL KEITH
To: CRITERION SYSTEMS, INC.
Reel/Frame 060600/0490 →
Continuity (2)
Provisional Application 62612937 · Jan 2, 2018
Related Publication 20190207968A1 · Jul 4, 2019
Cited By (3)
US 12,511,599 US 12,549,573 US 12,684,001