IP Library › Granted Patent US 11,875,288
Granted Patent B2
US 11,875,288 · App. 17/541,864 · Granted Jan 16, 2024

Discovering and using application deployment dependencies to augment governance and compliance policy

Inventors: Anca Sailer (Scarsdale, NY); Christopher John Butler (Hawthorne East, AU); Arun Kumar (Noida, IN); Malgorzata Steinder (Leonia, NJ); James R. Doran (New Milford, CT); Philippe Mulet (Saint-Nazaire, FR)
Assignee: International Business Machines Corporation
G06Q10/06313G06F8/22G06F8/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,875,288
App. No.
17/541,864
Granted
Jan 16, 2024
Kind
B2
Abstract

A compliance discovery and integration process is implemented in association with a cloud-based security and compliance platform and associated CI/CD framework. The process assumes an existing DevOps-based deployment of a product, such as an enterprise application that executes in a runtime production environment. The technique of this disclosure addresses the problem of misalignment between a compliance policy and the product's post-deployment regulation posture by providing tools and methods that enable pro-active augmentation of governance and compliance policy during the pre-deployment phase and with respect to a next deployment of the product (e.g., a next or updated version). Thus, when the product is later deployed in its next deployment, its regulation posture (post-deployment) is already consistent with the compliance policy.

Claims (45)

1. A method for continuous integration and deployment (CI/CD) in association with an enterprise application in a computing environment, comprising:

in association with a sequence of automated stages comprising a CI/CD pipeline, and prior to a next deployment of the enterprise application, the enterprise application comprising code that passes through the sequence of automated stages during its development:

discovering one or more software supply chain artifacts associated with the pipeline;

for at least one software supply chain artifact, discovering one or more tasks responsible for handling the software supply chain artifact, together with any associated dependencies;

retrieving a compliance policy associated with a development side of the computing environment;

registering the discovered software supply chain artifact, the one or more tasks, and the one or more associated dependencies with the compliance policy; and

within the development side of the computing environment, and based on at least one of the discovered software supply chain artifact, the one more tasks, and the one or more associated dependencies, updating one or more values associated with one or more policy check parameters associated with the compliance policy, wherein the one or more values associated with one or more policy check parameters are updated in an automated manner using pre-defined or pre-configured values; and

thereafter, deploying the enterprise application in a production environment.

2. The method as described in claim 1 wherein discovering the one or more software supply chain artifacts includes identifying one or more runtime monitoring artifacts.

3. The method as described in claim 2 wherein the one or more runtime monitoring artifacts include one of: properties, parameters, vulnerabilities, codes and lists.

4. The method as described in claim 1 wherein at least one associated dependency is associated with an Application Programming Interface (API)-named data model.

5. The method as described in claim 1 wherein the one or more values associated with one or more policy check parameters are updated responsive to receipt of values identified by compliance personnel within a compliance side of the computing environment, the compliance side being distinct from the development side.

6. The method as described in claim 1 wherein at least one discovery operation is recursive.

7. The method as described in claim 1 wherein the software supply chain artifact is a Software Development Kit (SDK) artifact, the SDK enabling direct changes to the computing environment.

8. The method as described in claim 1 further including validating that the enterprise application is compliant with the compliance policy as updated prior to deployment of the enterprise application in the production environment.

9. Apparatus, comprising:

at least one hardware processor;

computer memory holding computer program instructions executed by the at least one hardware processor for continuous integration and deployment (CI/CD) in association with an enterprise application in a computing environment, the computer program instructions comprising program code configured in association with a sequence of automated stages comprising a CI/CD pipeline to:

prior to a next deployment of the enterprise application, the enterprise application comprising code that passes through the sequence of automated stages during its development:

discover one or more software supply chain artifacts associated with the pipeline;

for at least one software supply chain artifact, discover one or more tasks responsible for handling the runtime artifact, together with any associated dependencies;

retrieve a compliance policy associated with a development side of the computing environment;

register the discovered software supply chain artifact, the one or more tasks, and the one or more associated dependencies with the compliance policy; and

within the development side of the computing environment, and based on at least one of: the discovered software supply chain artifact, the one more tasks, and the one or more associated dependencies, update one or more values associated with one or more policy check parameters associated with the compliance policy, wherein the one or more values associated with one or more policy check parameters are updated in an automated manner using pre-defined or pre-configured values; and

thereafter, deploy the enterprise application in a production environment.

10. The apparatus as described in claim 9 wherein the program code configured to discover the one or more software supply chain artifacts includes program code to identify one or more runtime monitoring artifacts.

11. The apparatus as described in claim 10 wherein the one or more runtime monitoring artifacts include one of: properties, parameters, vulnerabilities, codes and lists.

12. The apparatus as described in claim 9 wherein at least one associated dependency is associated with an Application Programming Interface (API)-named data model.

13. The apparatus as described in claim 9 wherein the one or more values associated with one or more policy check parameters are updated responsive to receipt of values identified by compliance personnel within a compliance side of the computing environment, the compliance side being distinct from the development side.

14. The apparatus as described in claim 9 wherein at least one discovery operation is recursive.

15. The apparatus as described in claim 9 wherein the program code is further configured to validate that the enterprise application is compliant with the compliance policy as updated prior to deployment of the enterprise application in the production environment.

16. A computer program product in a non-transitory computer-readable medium for use in a data processing system, the computer program product holding computer program instructions executed by the data processing system for continuous integration and deployment (CI/CD) in association with an enterprise application in a computing environment, the computer program instructions comprising program code configured in association with a sequence of automated stages comprising a CI/CD pipeline to:

prior to a next deployment of the enterprise application, the enterprise application comprising code that passes through the sequence of automated stages during its development:

discover one or more software supply chain artifacts associated with the pipeline;

for at least one software supply chain artifact, discover one or more tasks responsible for handling the software supply chain artifact, together with any associated dependencies;

retrieve a compliance policy associated with a development side of the computing environment;

register the discovered software supply chain artifact, the one or more tasks, and the one or more associated dependencies with the compliance policy; and

within the development side of the computing environment, and based on at least one of the discovered software supply chain artifact, the one more tasks, and the one or more associated dependencies, update one or more values associated with one or more policy check parameters associated with the compliance policy, wherein the one or more values associated with one or more policy check parameters are updated in an automated manner using pre-defined or pre-configured values; and

thereafter, deploy the enterprise application in a production environment.

17. The computer program product as described in claim 16 wherein the program code configured to discover the one or more software supply chain artifacts includes program code to identify one or more runtime monitoring artifacts.

18. The computer program product as described in claim 17 wherein the one or more runtime monitoring artifacts include one of: properties, parameters, vulnerabilities, codes and lists.

19. The computer program product as described in claim 16 wherein at least one associated dependency is associated with an Application Programming Interface (API)-named data model.

20. The computer program product as described in claim 16 wherein the one or more values associated with one or more policy check parameters are updated responsive to receipt of values identified by compliance personnel within a compliance side of the computing environment, the compliance side being distinct from the development side.

21. The computer program product as described in claim 16 wherein at least one discovery operation is recursive.

22. The computer program product as described in claim 16 wherein the program code is further configured to validate that the enterprise application is compliant with the compliance policy as updated prior to deployment of the enterprise application in the production environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2021
From: SAILER, ANCA; BUTLER, CHRISTOPHER JOHN; KUMAR, ARUN; STEINDER, MALGORZATA; DORAN, JAMES R.; MULET, PHILIPPE
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058284/0478 →
Continuity (1)
Related Publication 20230177426A1 · Jun 8, 2023
Cited By (3)
US 12,260,207 US 12,585,445 US 12,717,892