IP Library Granted Patent US 11,258,828
Granted Patent B2
US 11,258,828 · App. 16/573,175 · Granted Feb 22, 2022

Systems and methods for monitoring and correcting computer system security practices

Inventor: Jack Jones (Spokane, WA)
Assignee: Risklens, Inc.
H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,258,828
App. No.
16/573,175
Granted
Feb 22, 2022
Kind
B2
Abstract

Systems and methods for monitoring and correcting security measures taken for a computer system are disclosed. Exemplary implementations may: determine a set of risk parameters of the computing system; collect sets of values of the security parameters at various times and determine the efficacy adjustments based on a comparison of the sets of values and an elapsed time between collection of the sets of values.

Claims (25)

1. A system configured for monitoring and correcting cyber security practices on a computing environment having computing assets, the system comprising:

one or more hardware processors configured by machine-readable instructions to:

(a) receive a cyber security policy defining changes to be applied to computing assets, the cyber security policy further defining procedures to be taken by an organization for effecting the changes, the cyber security policy further defining timing at which the procedures should be implemented;

(b) determine a set of risk management parameters which indicate a state of the computing environment at a time of collection of the risk management parameters, wherein the set of risk management parameters is determined based on at least one of the procedures;

(c) collect successive sets of values of the risk management parameters at predetermined times;

(d) determine, based on at least two of the sets of values of the risk management parameters, that at least one of the procedures has not resulted in the corresponding changes being applied to the computing assets based on the timing at which the procedures should be implemented defined by the cyber security policy such that expected changes associated with the defined procedures to be taken at the defined timing by the organization for effecting the changes have not been affected as it should be according to the received cyber security policy; and

(e) in response to (d) after determining what causes to the corresponding changes have not occurred based on the analysis of (d), adjust at least one of the procedures of the security policy to create an adjusted security policy and apply the adjusted security policy to the computing environment accordingly.

2. The system of claim 1 , wherein (e) indicates that at least one of the changes has not been effected on an intended computing asset at an intended time.

3. The system of claim 1 , wherein (e) indicates changes occurred to at least one computing asset that do not correspond to a change specified by the cyber security policy.

4. The system of claim 1 , wherein (e) comprises adjusting at least one of the procedures of the security policy based on a prioritization of the computing assets.

5. The system of claim 1 , wherein (e) comprises adjusting at least one of the procedures of the security policy based on a prioritization of detected threats to the computing assets.

6. The system of claim 1 , wherein an elapsed time between successive collections of sets of values of the risk management parameters varies.

7. The system of claim 1 , wherein the set of risk management parameters includes parameters related to asset existence, asset value, control conditions, network traffic volume, software status, and/or threat landscape.

8. A computer-implemented method for monitoring and correcting a cyber security policy on a computing environment having computing assets, the method comprising:

(a) receiving a cyber security policy defining changes to be applied to computing assets, the cyber security policy further defining procedures to be taken by an organization for effecting the changes, the cyber security policy further defining timing at which the procedures should be implemented;

(b) determining a set of risk management parameters which indicate a state of the computing environment at a time of collection of the risk management parameters, wherein the set of risk management parameters is determined based on at least one of the procedures;

(c) collecting successive sets of values of the risk management parameters at predetermined times;

(d) determine, based on at least two of the sets of values of the risk management parameters, that at least one of the procedures has not resulted in the corresponding changes being applied to the computing assets based on the timing at which the procedures should be implemented defined by the cyber security policy such that expected changes associated with the defined procedures to be taken at the defined timing by the organization for effecting the changes have not been affected as it should be according to the received cyber security policy; and

(e) in response to (d) after determining what causes to the corresponding changes have not occurred based on the analysis of (d), adjust at least one of the procedures of the security policy to create an adjusted security policy and apply the adjusted security policy to the computing environment accordingly.

9. The method of claim 8 , wherein (e) indicates that at least one of the changes has not been effected on an intended computing asset at an intended time.

10. The method of claim 8 , wherein (e) indicates changes occurred to at least one computing asset that do not correspond to a change specified by the cyber security policy.

11. The method of claim 8 , wherein (e) comprises adjusting at least one of the procedures of the security policy based on a prioritization of the computing assets.

12. The method of claim 8 , wherein (e) comprises adjusting at least one of the procedures of the security policy based on a prioritization of detected threats to the computing assets.

13. The method of claim 8 , wherein an elapsed time between successive collections of sets of values of the risk management parameters varies.

14. The method of claim 8 , wherein the set of risk management parameters includes parameters related to asset existence, asset value, control conditions, network traffic volume, software status, and/or threat landscape.

Assignments (8)
SECURITY INTEREST Recorded Dec 1, 2025
From: SAFE SECURITIES INC.
To: WTI FUND X, INC.; WTI FUND XI, INC.
Reel/Frame 073075/0685 →
MERGER Recorded Dec 18, 2023
From: RISKLENS, INC.
To: BULLDOG MERGER SUB II, LLC
Reel/Frame 065901/0212 →
CHANGE OF NAME Recorded Dec 18, 2023
From: BULLDOG MERGER SUB II, LLC
To: RISKLENS, LLC
Reel/Frame 065901/0239 →
RELEASE OF SECURITY INTEREST Recorded Jul 17, 2023
From: RCF3, LLC
To: RISKLENS, INC.
Reel/Frame 064285/0528 →
RELEASE OF SECURITY INTEREST Recorded Jul 13, 2023
From: PACIFIC WESTERN BANK
To: RISKLENS, INC.
Reel/Frame 064247/0485 →
SECURITY INTEREST Recorded May 8, 2023
From: RISKLENS, INC.
To: RCF3, LLC
Reel/Frame 063568/0561 →
SECURITY INTEREST Recorded Apr 12, 2021
From: RISKLENS, INC.
To: PACIFIC WESTERN BANK
Reel/Frame 055890/0911 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2019
From: JONES, JACK
To: RISKLENS, INC.
Reel/Frame 050402/0080 →
Continuity (2)
Continuation In Part 15990739 · May 28, 2018
Related Publication 20200014728A1 · Jan 9, 2020