IP Library Granted Patent US 11,755,761
Granted Patent B2
US 11,755,761 · App. 17/163,307 · Granted Sep 12, 2023

Determining a combined compliance assessment metric

Inventors: Tiffany Joy Chin (San Mateo, CA); Chad Richard Holdorf (San Rafael, CA); Anubha Dubey (Sunnyvale, CA); Matthew Wilbert Parin (New Richmond, WI)
Assignee: Salesforce, Inc.
G06F21/6218G06F16/214G06F21/6245G06Q10/06393G06Q30/018H04L67/10G06F3/0482
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,755,761
App. No.
17/163,307
Granted
Sep 12, 2023
Kind
B2
Abstract

According to some implementations, compliance assessment metrics in a subset of two or more compliance assessment metrics are combined to form a combined compliance assessment metric. Each compliance assessment metric in the subset reflects a level of compliance of a set of rules with a different type of data privacy and/or data security laws, regulations, and/or policy. The set of rules are to manage personal data in an organization instance of a customer of a cloud-based software provider capable of hosting the organization instance in one or more datacenters in a plurality of different geographic regions. In addition, a dashboard, which is part of a data policy compliance service provided by the cloud-based software provider, is caused to be displayed and includes at least the combined compliance assessment metric.

Claims (49)

1. An article of manufacture comprising:

a non-transitory machine-readable storage medium that provides instructions that, if executed by a set of one or more processors, are configurable to cause the set of processors to perform operations comprising,

combining compliance assessment metrics in a subset of two or more compliance assessment metrics to form a combined compliance assessment metric, wherein each compliance assessment metric in the subset reflects a level of compliance of a set of rules with a different type of data privacy and/or data security laws, regulations, and/or policy, wherein the set of rules are to manage personal data in an organization instance of a customer of a cloud-based software provider capable of hosting the organization instance in one or more datacenters in a plurality of different geographic regions, wherein the combining includes setting the combined compliance assessment metric to:

a first tier when each of the compliance assessment metrics in the subset are in a first state,

a second tier when a first compliance assessment metric and a second compliance assessment metric of the subset are in the first state, but a third compliance assessment metric of the subset is in a second state, and

a third tier when the first compliance assessment metric or the second compliance assessment metric of the subset is in the second state;

gating an ability to migrate the organization instance from a first geographic region of the plurality of different geographic regions to a second geographic region of the plurality of different geographic regions based on the combined compliance assessment metric, the gating including:

causing a migration only after a user affirms acceptance of a risk of migration when the combined compliance assessment metric was set to the second tier, and

preventing the migration when the combined compliance assessment metric was set to the third tier; and

causing the display of a dashboard, which is part of a data policy compliance service provided by the cloud-based software provider, including at least the combined compliance assessment metric.

2. The article of manufacture of claim 1 , wherein the first state indicates compliant and the second state indicates not compliant, and wherein the first, second, and third compliance assessment metrics respectively reflect the level of compliance of the set of rules with data privacy and/or data security laws, regulations, and/or policy of one of the plurality of different geographic regions, an industry of the customer, and a company policy of the customer.

3. The article of manufacture of claim 1 , wherein a first compliance assessment metric in the subset reflects the level of compliance of the set of rules with data privacy and/or data security laws, regulations, and/or policy of one of the plurality of different geographic regions, wherein a second compliance assessment metric in the subset reflects the level of compliance of the set of rules with data privacy and/or data security laws, regulations, and/or policy of an industry of the customer.

4. The article of manufacture of claim 3 , wherein a third compliance assessment metric in the subset reflects the level of compliance of the set of rules with a company policy of the customer relative to data privacy and/or data security laws, regulations, and/or policy of the one of the plurality of geographic regions and/or the industry of the customer.

5. The article of manufacture of claim 1 , wherein the operations also comprise:

determining the subset of two or more compliance assessment metrics, the determining including:

determining a first compliance assessment metric that reflects the level of compliance of the set of rules with a first type of data privacy and/or data security laws, regulations, and/or policy; and

determining a second compliance assessment metric that reflects the level of compliance of the set of rules with a second type of data privacy and/or data security laws, regulations, and/or policy.

6. The article of manufacture of claim 1 , wherein the organization instance includes data, metadata, and/or configuration of the customer hosted within a service of the cloud-based software provider.

7. The article of manufacture of claim 1 , wherein the data policy compliance service allows the customer of the cloud-based software provider to choose in which of a plurality of geographic regions data of the customer will be at least one of hosted and processed.

8. The article of manufacture of claim 1 , wherein the operations further comprise:

responsive to user input, causing the display of the dashboard to include information regarding a plurality of geographic regions.

9. The article of manufacture of claim 1 , wherein the operations further comprise:

responsive to user interaction, causing the display of the dashboard to reflect a set of acts to be performed before migrating the organization instance to another geographic region.

10. The article of manufacture of claim 1 , wherein cloud services provided by the cloud-based software provider include one or more of Software-as-a-Service (SaaS), Data-as-a-Service (DAAS or DaaS), and Platform-as-a-service (PAAS or PaaS).

11. The article of manufacture of claim 1 , wherein at least one of the datacenters is a third-party datacenter, and wherein the cloud-based software provider is a customer of an operator of the third-party datacenter.

12. A computer-implemented method comprising:

combining compliance assessment metrics in a subset of two or more compliance assessment metrics to form a combined compliance assessment metric, wherein each compliance assessment metric in the subset reflects a level of compliance of a set of rules with a different type of data privacy and/or data security laws, regulations, and/or policy, wherein the set of rules are to manage personal data in an organization instance of a customer of a cloud-based software provider capable of hosting the organization instance in one or more datacenters in a plurality of different geographic regions, wherein the combining includes setting the combined compliance assessment metric to:

a first tier when each of the compliance assessment metrics in the subset are in a first state,

a second tier when a first compliance assessment metric and a second compliance assessment metric of the subset are in the first state, but a third compliance assessment metric of the subset is in a second state, and

a third tier when the first compliance assessment metric or the second compliance assessment metric of the subset is in the second state;

gating an ability to migrate the organization instance from a first geographic region of the plurality of different geographic regions to a second geographic region of the plurality of different geographic regions based on the combined compliance assessment metric, the gating including:

causing a migration only after a user affirms acceptance of a risk of migration when the combined compliance assessment metric was set to the second tier, and

preventing the migration when the combined compliance assessment metric was set to the third tier; and

causing the display of a dashboard, which is part of a data policy compliance service provided by the cloud-based software provider, including at least the combined compliance assessment metric.

13. The computer-implemented method of claim 12 , wherein the first state indicates compliant and the second state indicates not compliant, and wherein the first, second, and third compliance assessment metrics respectively reflect the level of compliance of the set of rules with data privacy and/or data security laws, regulations, and/or policy of one of the plurality of different geographic regions, an industry of the customer, and a company policy of the customer.

14. The computer-implemented method of claim 12 , wherein a first compliance assessment metric in the subset reflects the level of compliance of the set of rules with data privacy and/or data security laws, regulations, and/or policy of one of the plurality of different geographic regions, wherein a second compliance assessment metric in the subset reflects the level of compliance of the set of rules with data privacy and/or data security laws, regulations, and/or policy of an industry of the customer.

15. The computer-implemented method of claim 14 , wherein a third compliance assessment metric in the subset reflects the level of compliance of the set of rules with a company policy of the customer relative to data privacy and/or data security laws, regulations, and/or policy of the one of the plurality of geographic regions and/or the industry of the customer.

16. The computer-implemented method of claim 12 further comprising:

determining the subset of two or more compliance assessment metrics, the determining including:

determining a first compliance assessment metric that reflects the level of compliance of the set of rules with a first type of data privacy and/or data security laws, regulations, and/or policy; and

determining a second compliance assessment metric that reflects the level of compliance of the set of rules with a second type of data privacy and/or data security laws, regulations, and/or policy.

17. The computer-implemented method of claim 12 , wherein the organization instance includes data, metadata, and/or configuration of the customer hosted within a service of the cloud-based software provider.

18. The computer-implemented method of claim 12 , wherein the data policy compliance service allows the customer of the cloud-based software provider to choose in which of a plurality of geographic regions data of the customer will be at least one of hosted and processed.

19. The computer-implemented method of claim 12 further comprising:

responsive to user input, causing the display of the dashboard to include information regarding a plurality of geographic regions.

20. The computer-implemented method of claim 12 further comprising:

responsive to user interaction, causing the display of the dashboard to reflect a set of acts to be performed before migrating the organization instance to another geographic region.

21. The computer-implemented method of claim 12 , wherein cloud services provided by the cloud-based software provider include one or more of Software-as-a-Service (SaaS), Data-as-a-Service (DAAS or DaaS), and Platform-as-a-service (PAAS or PaaS).

22. The computer-implemented method of claim 12 , wherein at least one of the datacenters is a third-party datacenter, and wherein the cloud-based software provider is a customer of an operator of the third-party datacenter.

Assignments (2)
CHANGE OF NAME Recorded Feb 17, 2023
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 062794/0656 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2021
From: CHIN, TIFFANY JOY; HOLDORF, CHAD RICHARD; DUBEY, ANUBHA; PARIN, MATTHEW WILBERT
To: SALESFORCE.COM, INC.
Reel/Frame 055189/0204 →
Continuity (3)
Provisional Application 63120721 · Dec 2, 2020
Provisional Application 63120201 · Dec 1, 2020
Related Publication 20220172222A1 · Jun 2, 2022