IP Library › Granted Patent US 10,769,379
Granted Patent B1
US 10,769,379 · App. 16/459,429 · Granted Sep 8, 2020

Automatic compliance tools

Inventors: Dorian J. Cougias (Oakland, CA); Vicki McEwen (Oakland, CA); Steven Piliero (Oakland, CA); Lucian Hontau (Oakland, CA); Zike Huang (Oakland, CA); Sean Kohler (Oakland, CA)
Assignee: Unified Compliance Framework (Network Frontiers)
G06F40/295G06F40/242G06F40/30G06Q30/018
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,769,379
App. No.
16/459,429
Granted
Sep 8, 2020
Kind
B1
Abstract

A facility for representing a mandate occurring in an authority document with a control is described. For each of one or more controls in a set of existing controls, the facility determines a similarity score measuring the similarity of the mandate and the control; where the similarity score exceeds a similarity threshold, the facility links the mandate to the control. Where the mandate is not linked to any control in the set of controls, the facility adds a control to the set of controls that is based on the mandate, and links the mandate to the added control.

Claims (47)

1. A method in a computing system, comprising:

accessing a common control having a primary noun definition;

selecting a node of a semantic graph representing the primary noun definition of the accessed common control;

identifying a set of nodes of the semantic graph, wherein each node in the set of nodes is directly or indirectly connected to the selected node, wherein the connection between selected node and each particular node in the set of nodes includes at least one connection indicating that particular node represents a term that is a type-of another term represented by the selected node or another node in the set of nodes, and wherein each node in the set of nodes represents a noun definition different from the primary noun definition of the accessed common control;

for each of the identified nodes of the set of nodes, creating a copy of the accessed common control in which the primary noun definition of the accessed common control is replaced with the noun definition represented by the identified node; and

supplementing the accessed common control with the created common controls.

2. The method of claim 1 ,

wherein the accessing is accessing within a group of common controls, and

wherein the supplementing comprises adding the created common controls to the group of common controls.

3. The method of claim 2 , wherein the created common controls are added to the group of common controls in a hierarchy in an inferior position with respect to the accessed common control.

4. The method of claim 1 , wherein the nodes of the set of nodes are each directly connected to the selected node via a single “type-of” relationship.

5. The method of claim 1 , wherein at least some of the nodes of the set are indirectly connected to the selected node via multiple “type-of” relationships, and wherein the number of nodes in the set of nodes is no larger than a configurable limit.

6. The method of claim 1 , wherein at least some of the nodes of the set are indirectly connected to the selected node via multiple “type-of” relationships, and wherein the indirectly connected nodes are no more than a specified number of connections away from the selected node.

7. The method of claim 1 , wherein the semantic graph is a collection of nodes, each node representing term, with connections between nodes, each connection representing a nature of a relationship between the terms represented by the connected nodes.

8. The method of claim 1 ,

wherein the created common controls are added to a hierarchy in an inferior position with respect to the accessed common control; and

wherein the hierarchy is used to audit compliance with a set of controls by traversing the hierarchy and providing audit questions based on the common control and the created common controls.

9. A non-transitory computer-readable medium storing instructions that, when executed by a computing system, cause the computing system to perform operations comprising:

accessing a common control having a primary noun definition;

selecting a node of a semantic graph representing the primary noun definition of the accessed common control;

identifying a set of nodes of the semantic graph, wherein each node in the set of nodes is directly or indirectly connected to the selected node, wherein the connection between selected node and each particular node in the set of nodes includes at least one connection indicating that particular node represents a term that is a type-of another term represented by the selected node or another node in the set of nodes, and wherein each node in the set of nodes represents a noun definition different from the primary noun definition of the accessed common control;

for each of the identified nodes of the set of nodes, creating a copy of the accessed common control in which the primary noun definition of the accessed common control is replaced with the noun definition represented by the identified node; and

supplementing the accessed common control with the created common controls.

10. The non-transitory computer-readable medium of claim 9 ,

wherein the accessing is accessing within a group of common controls, and

wherein the supplementing comprises adding the created common controls to the group of common controls.

11. The non-transitory computer-readable medium of claim 10 , wherein the created common controls are added to the group of common controls in a hierarchy in an inferior position with respect to the accessed common control.

12. The non-transitory computer-readable medium of claim 9 , wherein the nodes of the set of nodes are each directly connected to the selected node via a single “type-of” relationship.

13. The non-transitory computer-readable medium of claim 9 , wherein at least some of the nodes of the set are indirectly connected to the selected node via multiple “type-of” relationships, and wherein the number of nodes in the set of nodes is no larger than a configurable limit.

14. The non-transitory computer-readable medium of claim 9 , wherein at least some of the nodes of the set are indirectly connected to the selected node via multiple “type-of” relationships, and wherein the indirectly connected nodes are no more than a specified number of connections away from the selected node.

15. The non-transitory computer-readable medium of claim 9 , wherein the semantic graph is a collection of nodes, each node representing term, with connections between nodes, each connection representing a nature of a relationship between the terms represented by the connected nodes.

16. The non-transitory computer-readable medium of claim 9 ,

wherein the created common controls are added to a hierarchy in an inferior position with respect to the accessed common control; and

wherein the hierarchy is used to audit compliance with a set of controls by traversing the hierarchy and providing audit questions based on the common control and the created common controls.

17. A computing system comprising:

one or more processors; and

one or more memories storing instructions that, when executed by the one or more processors, cause the computing system to perform operations comprising:

accessing a common control having a primary noun definition;

selecting a node of a semantic graph representing the primary noun definition of the accessed common control;

identifying a set of nodes of the semantic graph, wherein each node in the set of nodes is directly or indirectly connected to the selected node, wherein the connection between selected node and each particular node in the set of nodes includes at least one connection indicating that particular node represents a term that is a type-of another term represented by the selected node or another node in the set of nodes, and wherein each node in the set of nodes represents a noun definition different from the primary noun definition of the accessed common control;

for each of the identified nodes of the set of nodes, creating a copy of the accessed common control in which the primary noun definition of the accessed common control is replaced with the noun definition represented by the identified node; and

supplementing the accessed common control with the created common controls.

18. The computing system of claim 17 , wherein at least some of the nodes of the set are indirectly connected to the selected node via multiple “type-of” relationships, and wherein the indirectly connected nodes are no more than a specified number of connections away from the selected node.

19. The computing system of claim 17 , wherein the semantic graph is a collection of nodes, each node representing term, with connections between nodes, each connection representing a nature of a relationship between the terms represented by the connected nodes.

20. The computing system of claim 17 ,

wherein the created common controls are added to a hierarchy in an inferior position with respect to the accessed common control; and

wherein the hierarchy is used to audit compliance with a set of controls by traversing the hierarchy and providing audit questions based on the common control and the created common controls.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2020
From: COUGIAS, DORIAN J.; MCEWEN, VICKI; PILIERO, STEVEN; HONTAU, LUCIAN; HUANG, ZIKE; KOHLER, SEAN
To: UNIFIED COMPLIANCE FRAMEWORK (NETWORK FRONTIERS)
Reel/Frame 054612/0231 →
Cited By (4)
US 12,204,861 US 12,217,006 US 12,530,383 US 12,541,539