IP Library Granted Patent US 11,792,222
Granted Patent B2
US 11,792,222 · App. 17/869,144 · Granted Oct 17, 2023

Automated risk assessment module with real-time compliance monitoring

Inventors: Patrick Glenn Murray (Kula, HI); Carman Kwong (Calgary, CA); Christopher Cross (Calgary, CA); Jose Costa Moreno (Calgary, CA); Harpreet Shergill (Calgary, CA); Keegan Callin (Calgary, CA)
Assignee: OneTrust LLC
H04L63/1433H04L63/0414H04L63/20H04L63/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,792,222
App. No.
17/869,144
Granted
Oct 17, 2023
Kind
B2
Abstract

Techniques are disclosed for usage-tracking of various information security (InfoSec) entities for tenants/organization onboarded on an instant multi-tenant security assurance platform. The InfoSec entities include policies, procedures, controls and evidence tasks. A policy or procedure is enforced by implementing one or more controls, and the collection of one or more evidence tasks proves/verifies the implementation of a control. The InfoSec entities are linked to each other across the platform and accrue a number of benefits for the tenants. These include generating a security questionnaire response (SQR), defining a readiness project and an audit project, sharing InfoSec entities encompassing the various products of a tenant, automating risk assessment, automatic collection of evidence tasks for verifying the implementation and/or operational state/status of various mitigating controls, etc.

Claims (70)

1. A method comprising:

performing, with processing hardware of a computing system, operations comprising:

establishing a session between a server computing system and a client computing system;

providing, via the session, an objective identification interface to the client computing system;

accessing first mapping data that links (a) a set of objectives identified via input to the objective identification interface with (b) a set of risks associated with operations using the client computing system;

accessing second mapping data that links the set of risks with a set of control operations;

associating, based on the first mapping data and the second mapping data, the set of risks and the set of control operations with the client computing system;

determining that a first software configuration and a second software configuration have been implemented, wherein the first software configuration and the second software configuration respectively monitor a first state and a second state of data applicable to the set of control operations;

performing a risk assessment operation that comprises determining that the first state of the data tracked via the first software configuration indicates an update within a specified time period and that the second state of the data tracked via the second software configuration indicates no updates within the specified time period; and

providing, via the session and based on the risk assessment operation, a risk assessment interface comprising (a) indications of mitigation of the set of risks and (b) interface elements configured for performing operations with respect to the client computing system that modify the mitigation of the set of risks.

2. The method of claim 1 , wherein:

the server computing system includes a multi-tenant computing platform having a tenant authorized for use by the client computing system, and

establishing the session includes the client computing system communicating with the server computing system via the tenant.

3. The method of claim 2 , wherein associating the set of risks and the set of control operations includes:

(1) providing a confirmation menu to the client computing system that includes interface elements configured for instructing that mitigation of the set of risks should occur,

(2) receiving instructions to mitigate the set of risks via the confirmation menu, and

(3) updating, in the tenant of the client computing system, a project data object to include the set of risks, the set of control operations, and evidence task objects for storing data applicable to the set of control operations.

4. The method of claim 1 , wherein determining that the first software configuration and the second software configuration have been implemented comprises determining that a first integration with third-party software and a second integration with the third-party software have been configured to retrieve the data applicable to the set of control operations.

5. The method of claim 4 , wherein determining that at least one of the first integration or the second integration is configured includes:

identifying, in a tenant authorized for use by the client computing system, a computer-executable program or script specifying a data source within the client computing system and a destination accessible via the tenant, and

determining that the computer-executable program or script is associated with at least one evidence task object for storing data applicable to the set of control operations.

6. The method of claim 4 , wherein performing the risk assessment operation further comprises determining that:

(a) the first integration has been used to retrieve the data within the specified time period, and (b) no data has been retrieved using the second integration within the specified time period.

7. The method of claim 6 , wherein determining that the first integration has been used to retrieve the data within the specified time period and that no data has been retrieved using the second integration with the specified time period comprises:

determining that a first evidence task object associated with the first integration has been updated within the specified time period, and

determining that a second evidence task object associated with the second integration has not been updated within the specified time period.

8. The method of claim 1 , wherein the interface elements include:

a first interface element configured to update the risk assessment interface with data from an evidence data object, and

a second interface element configured to execute an integration associated with the evidence data object.

9. A computing system comprising:

processing hardware; and

a non-transitory computer-readable medium communicatively coupled to the processing hardware, wherein the processing hardware is configured for executing instructions stored in the non-transitory computer-readable medium and thereby performing operations comprising:

providing a multi-tenant computing platform having a tenant authorized for use by a client computing system;

providing, via the tenant, an objective identification interface to the client computing system;

identifying, based on input to the objective identification interface, a set of risks associated with operations using the client computing system;

determining that a first software configuration and a second software configuration have been implemented, wherein the first software configuration and the second software configuration respectively monitor a first state and a second state of data applicable to a set of control operations associated with the set of risks;

performing a risk assessment operation that comprises determining that the first state of the data tracked via the first software configuration indicates an update within a specified time period and that the second state of the data tracked via the second software configuration indicates no updates within the specified time period; and

providing, via the tenant, a risk assessment interface comprising (a) indications of mitigation of the set of risks and (b) interface elements configured for performing operations with respect to the client computing system that modify the mitigation of the set of risks.

10. The computing system of claim 9 , wherein the operations further comprise:

(1) providing a confirmation menu to the client computing system that includes interface elements configured for instructing that mitigation of the set of risks should occur,

(2) receiving instructions to mitigate the set of risks via the confirmation menu, and

(3) updating, in the tenant of the client computing system, a project data object to include the set of risks, the set of control operations, and evidence task objects for storing data applicable to the set of control operations.

11. The computing system of claim 10 , wherein determining that the first software configuration and the second software configuration have been implemented comprises determining that a first integration with third-party software and a second integration with the third-party software have been configured to retrieve the data applicable to the set of control operations.

12. The computing system of claim 11 , wherein determining that at least one of the first integration or the second integration is configured includes:

identifying, in the tenant, a computer-executable program or script specifying a data source within the client computing system and a destination accessible via the tenant, and

determining that the computer-executable program or script is associated with at least one of the evidence task objects.

13. The computing system of claim 11 , wherein performing the risk assessment operation further comprises determining that:

(a) the first integration has been used to retrieve the data within the specified time period, and (b) no data has been retrieved using the second integration within the specified time period.

14. The computing system of claim 13 , wherein determining that the first integration has been used to retrieve the data within the specified time period and that no data has been retrieved using the second integration with the specified time period comprises:

determining that a first evidence task object associated with the first integration has been updated within the specified time period, and

determining that a second evidence task object associated with the second integration has not been updated within the specified time period.

15. The computing system of claim 9 , wherein the interface elements include:

a first interface element configured to update the risk assessment interface with data from an evidence data object, and

a second interface element configured to execute an integration associated with the evidence data object.

16. A non-transitory computer-readable medium storing instruction that, when executed by processing hardware, configure the processing hardware to perform operations comprising:

providing a multi-tenant computing platform having a tenant authorized for use by a client computing system;

providing, via the tenant, an objective identification interface to the client computing system;

identifying, based on input to the objective identification interface, a set of risks associated with operations using the client computing system;

determining that a first software configuration and a second software configuration have been implemented, wherein the first software configuration and the second software configuration respectively monitor a first state and a second state of data applicable to a set of control operations associated with the set of risks;

performing a risk assessment operation that comprises determining that the first state of the data tracked via the first software configuration indicates an update within a specified time period and that the second state of the data tracked via the second software configuration indicates no updates within the specified time period; and

providing, via the tenant, a risk assessment interface comprising (a) indications of mitigation of the set of risks and (b) interface elements configured for performing operations with respect to the client computing system that modify the mitigation of the set of risks.

17. The non-transitory computer-readable medium of claim 16 , wherein determining that the first software configuration and the second software configuration have been implemented comprises determining that a first integration with third-party software and a second integration with the third-party software have been configured to retrieve the data applicable to the set of control operations.

18. The non-transitory computer-readable medium of claim 17 , wherein determining that at least one of the first integration or the second integration is configured includes:

identifying a computer-executable program or script specifying a data source within the client computing system and a destination accessible via the tenant, and

determining that the computer-executable program or script is associated with at least one evidence task object for storing data applicable to the set of control operations.

19. The non-transitory computer-readable medium of claim 17 , wherein the operations further comprise determining that:

(a) the first integration has been used to retrieve the data within the specified time period, and (b) no data has been retrieved using the second integration within the specified time period.

20. The non-transitory computer-readable medium of claim 16 , wherein the interface elements include:

a first interface element configured to update the risk assessment interface with data from an evidence data object, and

a second interface element configured to execute an integration associated with the evidence data object.

Assignments (3)
SUPPLEMENT TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 3, 2026
From: ONETRUST LLC
To: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 075801/0754 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2022
From: CROSS, CHRISTOPHER; MURRAY, PATRICK GLENN; KWONG, CARMAN; MORENO, JOSE COSTA; SHERGILL, HARPREET; CALLIN, KEEGAN
To: TUGBOAT LOGIC, INC.
Reel/Frame 062016/0459 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2022
From: TUGBOAT LOGIC, INC.
To: ONETRUST LLC
Reel/Frame 062016/0599 →
Continuity (4)
Continuation 17373534 · Jul 12, 2021
Continuation In Part 17191346 · Mar 3, 2021
Continuation In Part 16013037 · Jun 20, 2018
Related Publication 20220368728A1 · Nov 17, 2022
Cited By (2)
US 12,271,681 US 12,563,105