IP Library Granted Patent US 10,657,285
Granted Patent B2
US 10,657,285 · App. 16/376,379 · Granted May 19, 2020

Limiting exposure to compliance and risk in a cloud environment

Inventors: Corville O. Allen (Morrisville, NC); Arthur R. Francis (Raleigh, NC); Eduardo A. Patrocinio (Apex, NC)
Assignee: International Business Machines Corporation
G06F21/6245H04L63/10H04L63/20H04L67/1097H04W12/02G06F21/6227H04L9/085
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,657,285
App. No.
16/376,379
Granted
May 19, 2020
Kind
B2
Abstract

Minimizing data security risks may be provided. A number and type of confidential data in a computing environment may be determined to generate a metric for the type of confidential data in the computing environment. The metric of the type of confidential data may be compared to a predetermined metric for the type. Responsive to determining the metric for the type of confidential data exceeding a predetermined metric for the type, an action may be performed to prevent more entries of the type of confidential data in the computing environment.

Claims (37)

1. A method of minimizing data security risks in a computing environment wherein a plurality of types of information are stored, the method comprising:

measuring an amount of data stored for each type of information;

comparing each amount to a predetermined threshold for a corresponding type;

determining that a first amount of data for a first type of information exceeds a first predetermined threshold corresponding to the first type of information;

responsive to determining the first predetermined threshold is exceeded, preventing more entries of the first type of information into the computing environment by closing an access port in the computing environment to requests associated with new data of the first type of information.

2. The method of claim 1 , further comprising:

responsive to determining the first predetermined threshold is exceeded, scheduling work associated with the first type of information into a different computing environment.

3. The method of claim 1 , wherein the computing environment comprises at least a logical partition (LPAR).

4. The method of claim 1 , wherein the computing environment comprises at least virtual environment.

5. The method of claim 1 , wherein the first type of information comprises patient identifying information.

6. The method of claim 1 , wherein the first type of information comprises patient address information.

7. The method of claim 1 , wherein the first type of information comprises patient financial information.

8. A computer program product for minimizing data security risks in a computing environment wherein a plurality of types of information are stored, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a device to cause the device to:

measure an amount of data stored for each type of information;

compare each amount to a predetermined threshold for a corresponding type;

determine that a first amount of data for a first type of information exceeds a first predetermined threshold corresponding to the first type of information;

responsive to determining the first predetermined threshold is exceeded, prevent more entries of the first type of information into the computing environment by closing an access port in the computing environment to requests associated with new data of the first type of information.

9. The computer program product of claim 8 , wherein the device is further caused to:

responsive to determining the first predetermined threshold is exceeded, schedule work associated with the first type of information into a different computing environment.

10. The computer program product of claim 8 , wherein the computing environment comprises at least a logical partition (LPAR).

11. The computer program product of claim 8 , wherein the computing environment comprises at least virtual environment.

12. The computer program product of claim 8 , wherein the computing environment comprises at least a virtual machine (VM).

13. The computer program product of claim 8 , wherein the computing environment comprises at least a workload partition (WPAR).

14. The computer program product of claim 8 , wherein the first type of information comprises at least patient identifying information.

15. The computer program product of claim 8 , wherein the first type of information comprises at least patient address information.

16. The computer program product of claim 8 , wherein the first type of information comprises at least patient financial information.

17. A system of minimizing data security risks in a computing environment, comprising:

a processor executing in the computing environment; and

a storage device couple to the processor in the computing environment, the storage device storing a plurality of types of information;

the processor operable to measure an amount of data stored for each type of information,

the processor further operable to compare each amount to a predetermined threshold for a corresponding type;

the processor further operable to determine that a first amount of data for a first type of information exceeds a first predetermined threshold corresponding to the first type of information;

responsive to determining the first predetermined threshold is exceeded, the processor further operable to prevent more entries of the first type of information into the computing environment by providing an error code that prevents further data from being stored and refusing service associated with requests associated with new data of the first type of information.

18. The system of claim 17 , further comprising:

responsive to determining the first predetermined threshold is exceeded, the processor further operable to schedule work associated with the first type of information into a different computing environment.

19. The system of claim 17 , wherein the computing environment comprises at least a virtual environment.

20. The system of claim 17 , wherein the computing environment comprises at least a logical partition (LPAR).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2019
From: ALLEN, CORVILLE O.; FRANCIS, ARTHUR R.; PATROCINIO, EDUARDO A.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 048806/0902 →
Continuity (4)
Continuation 15464843 · Mar 21, 2017
Continuation 14833819 · Aug 24, 2015
Continuation 14591578 · Jan 7, 2015
Related Publication 20190236308A1 · Aug 1, 2019