IP Library Patent Application 17723445
Patent Application
App. No. 17/723,445

SCANNING AND REMEDIATING CONFIGURATION SETTINGS OF A DEVICE USING A POLICY-DRIVEN APPROACH

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/723,445
Abstract

The present disclosure relates to systems, methods, and computer-readable media for implementing an efficient and flexible policy-driven approach to securing a computing device. For example, systems disclosed herein can enforce a first security policy of a first security standard. Systems disclosed herein can further audit for a first compliance level with the first security standard. Systems disclosed herein can further audit for a second compliance level with a second security standard. Systems disclosed herein can further determine an overlap between the first security standard and the second security standard, the overlap associated with a second security policy. Systems disclosed herein can further enforce the second security standard. Systems disclosed herein can further determine an update of the first compliance level based on the overlap.

Claims (51)

1 . An apparatus comprising:

at least one memory;

instructions in the apparatus; and

processor circuitry to execute the instructions to:

enforce a first security policy of a first security standard;

audit for a first compliance level with the first security standard;

audit for a second compliance level with a second security standard;

determine an overlap between the first security standard and the second security standard, the overlap associated with a second security policy;

enforce the second security standard; and

determine an update of the first compliance level based on the overlap.

2 . The apparatus of claim 1 , wherein the processor circuitry is to execute the instructions to enforce at least one of the first security policy or the second security policy with an idempotent operation in which a check and a fix of the security policy are the same operation.

3 . The apparatus of claim 1 , wherein the processor circuitry is to execute the instructions to:

determine whether an exemption applies to at least one of the first or second security policies and

in response to a determination that the exemption applies to the at least one of the first or second security policies, bypass enforcement of the at least one of the first or second security policies.

4 . The apparatus of claim 1 , wherein the processor circuitry is to execute the instructions to generate a compliance report indicating a measure of compliance with at least one of the first security standard or the second security standard.

5 . The apparatus of claim 1 , wherein the processor circuitry is to execute the instructions to generate mapping information associating a plurality of security policies to a plurality of security standards.

6 . The apparatus of claim 5 , wherein the mapping information includes information indicating the overlap between the first security standard and the second security standard.

7 . The apparatus of claim 1 , wherein compliance with a security standard includes configuration settings of an application or operating system on a client device.

8 . The apparatus of claim 1 , wherein the processor circuitry is to determine the update of the first compliance level based on the overlap before performing an additional audit of the first compliance level.

9 . A non-transitory computer readable storage medium comprising instructions which, when executed, cause processor circuitry to at least:

enforce a first security policy of a first security standard;

audit for a first compliance level with the first security standard;

audit for a second compliance level with a second security standard;

determine an overlap between the first security standard and the second security standard, the overlap associated with a second security policy;

enforce the second security standard; and

determine an update of the first compliance level based on the overlap.

10 . The non-transitory computer readable storage medium of claim 9 , wherein the instructions, when executed, cause the processor circuitry to enforce at least one of the first security policy or the second security policy with an idempotent operation in which a check and a fix of the security policy are the same operation.

11 . The non-transitory computer readable storage medium of claim 9 , wherein the instructions, when executed, cause the processor circuitry to:

determine whether an exemption applies to at least one of the first or second security policies; and

in response to a determination that the exemption applies to the at least one of the first or second security policies, bypass enforcement of the at least one of the first or second security policies.

12 . The non-transitory computer readable storage medium of claim 9 , wherein the instructions, when executed, cause the processor circuitry to generate a compliance report indicating a measure of compliance with at least one of the first security standard or the second security standard.

13 . The non-transitory computer readable storage medium of claim 9 , wherein the instructions, when executed, cause the processor circuitry to generate mapping information associating a plurality of security policies to a plurality of security standards.

14 . The non-transitory computer readable storage medium of claim 13 , wherein the mapping information includes information indicating the overlap between the first security standard and the second security standard.

15 . The non-transitory computer readable storage medium of claim 9 , wherein compliance with a security standard includes configuration settings of an application or operating system on a client device.

16 . The non-transitory computer readable storage medium of claim 9 , wherein the instructions, when executed, cause the processor circuitry to determine the update of the first compliance level based on the overlap before performing an additional audit of the first compliance level.

17 . A method comprising:

enforcing, by executing an instruction with a processor, a first security policy of a first security standard;

auditing, by executing an instruction with the processor, for a first compliance level with the first security standard;

auditing, by executing an instruction with the processor, for a second compliance level with a second security standard;

determining, by executing an instruction with the processor, an overlap between the first security standard and the second security standard, the overlap associated with a second security policy;

enforcing, by executing an instruction with the processor, the second security standard; and

determining, by executing an instruction with the processor, an update of the first compliance level based on the overlap.

18 . The method of claim 17 , further including enforcing at least one of the first security policy or the second security policy with an idempotent operation in which a check and a fix of the security policy are the same operation.

19 . The method of claim 17 , further including:

determining whether an exemption applies to at least one of the first or second security policies; and

in response to determining that the exemption applies to the at least one of the first or second security policies, bypassing enforcement of the at least one of the first or second security policies.

20 . The method of claim 17 , further including generating a compliance report indicating a measure of compliance with at least one of the first security standard or the second security standard.

21 . The method of claim 17 , further including generating mapping information associating a plurality of security policies to a plurality of security standards.

22 . The method of claim 21 , wherein the mapping information includes information indicating the overlap between the first security standard and the second security standard.

23 . The method of claim 17 , wherein compliance with a security standard includes configuration settings of an application or operating system on a client device.

24 . The method of claim 17 , further including determining the update of the first compliance level based on the overlap before performing an additional audit of the first compliance level.

Assignments (1)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →