IP Library Granted Patent US 11,620,390
Granted Patent B1
US 11,620,390 · App. 17/722,725 · Granted Apr 4, 2023

Risk rating method and system

Inventors: Jonathan D. Stone (Nashville, TN); Tess Array Miller (DPO, AA); Ravneet Singh (State College, PA)
Assignee: CLEARWATER COMPLIANCE LLC
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,620,390
App. No.
17/722,725
Granted
Apr 4, 2023
Kind
B1
Abstract

A risk rating method and system that predicts the risk likelihood, the risk impact, and the risk rating of certain threats and vulnerabilities from exploiting different component groups. In some embodiments, the system's predictions (also referred to herein as inferences) are generated based on data elements provided by a user about its organization's information systems. In further embodiments, the method and system utilizes data mining, historical records, and an AI Engine to provide the predictions for the risk likelihood, the risk impact, and the risk rating posed by the various threat occurrences.

Claims (35)

1. A method for analyzing a risk posed by a threat occurrence to a component group, the method comprising the steps of:

(a) providing a list of data elements to a user via a user interface;

(b) receiving and processing a selection of the data elements from the user via the user interface;

(c) generating a risk impact and a risk likelihood posed by the threat occurrence to the component group based on the selection of the data elements from the user;

(d) providing the risk impact and the risk likelihood to the user via the user interface; and

(e) monitoring changes by the user to the selection of the data elements and modifying the risk impact and the risk likelihood in response to said changes by the user.

2. The method of claim 1 , wherein the risk impact is a number in a range from 1-5 and the risk likelihood is a number in a range from 1-5.

3. The method of claim 2 , further comprising, after performing step “d”, performing the step of generating a risk rating posed by the threat occurrence to the component group, wherein the risk rating is equivalent to the risk impact multiplied by the risk rating and wherein said risk rating is a number in a range from 1-25, and providing the risk rating to the user via the user interface.

4. The method of claim 1 , wherein the data elements are chosen from the group consisting of asset importance, sensitive records, users, component groups, component properties, threat sources, threat events, vulnerabilities, security controls, and control responses.

5. The method of claim 4 , further comprising, after performing the step of monitoring changes and modifying the risk impact and the risk likelihood, receiving a selection of the risk impact and a selection of the risk likelihood from the user via the user interface, generating a database comprising an acceptable minimum risk impact and an acceptable maximum risk impact for a plurality of risk scenarios based on the asset importance selected by the user, said database further comprising an acceptable minimum risk likelihood and an acceptable maximum risk likelihood for said plurality of risk scenarios based on the control responses selected by the user.

6. The method of claim 5 , further comprising, after performing the step of receiving said selection of the risk impact and said selection of the risk likelihood and generating said database, comparing said selection of the risk impact to the acceptable minimum and maximum risk impact and excluding said selection of the risk impact when said selection falls outside of said acceptable minimum and maximum risk impact, and comparing said selection of the risk likelihood to the acceptable minimum and maximum risk likelihood and excluding said selection of the risk likelihood when said selection falls outside of said acceptable minimum and maximum risk likelihood.

7. The method of claim 1 , further comprising, before performing step “a”, generating a database consisting of selections of data elements provided by other users, selections of risk impacts provided by other users, selections of risk likelihoods provided by other users, vulnerabilities, threat events, and threat sources, wherein said generating the database step further comprises assigning the vulnerabilities to the threat events, assigning the threat events to the threat sources, and assigning threat sources to the component group.

8. The method of claim 7 , wherein step “c” further comprises comparing the selection of the data elements from the user to similar selections of data elements provided by other users in the database.

9. A computer implemented method of analyzing a cybersecurity risk posed by a threat occurrence to a component group, the method comprising the steps of:

(a) generating a database comprising a list of data elements;

(b) providing the list of data elements to a user via a user interface by retrieving the list of data elements from the database;

(c) receiving and processing a selection of the data elements from the user via the user interface and storing the selection of the data elements in the database;

(d) generating a risk impact and a risk likelihood posed by the threat occurrence to the component group based on the selection of the data elements from the user;

(e) providing the risk impact and the risk likelihood to the user via the user interface; and

(f) receiving a selection of the risk impact and a selection of the risk likelihood from the user via the user interface; and

(g) monitoring changes by the user to the selection of the data elements and modifying the risk impact and the risk likelihood in response to said changes by the user.

10. The method of claim 9 , wherein the data elements are chosen from the group consisting of asset importance, sensitive records, users, component groups, component properties, threat sources, threat events, vulnerabilities, security controls, and control responses.

11. The method of claim 10 , wherein the database generated in step “a” further comprises selections of data elements provided by other users, selections of risk impacts provided by other users, and selections of risk likelihoods provided by other users, wherein said generating the database step further comprises assigning the vulnerabilities to the threat events, assigning the threat events to the threat sources, and assigning the threat sources to the component group.

12. The method of claim 11 , wherein step “d” further comprises comparing the selection of the data elements from the user to similar selections of data elements provided by other users in the database.

13. One or more non-transitory computer-readable media storing instructions, which, when executed by at least one processor, instruct the at least one processor to perform actions comprising:

(a) generating a database comprising a list of data elements;

(b) providing the list of data elements to a user via a user interface by retrieving the list of data elements from the database;

(c) receiving and processing a selection of the data elements from the user via the user interface and storing the selection of the data elements in the database;

(d) generating a risk impact and a risk likelihood posed by the threat occurrence to the component group based on the selection of the data elements from the user;

(e) providing the risk impact and the risk likelihood to the user via the user interface;

(f) receiving a selection of the risk impact and a selection of the risk likelihood from the user via the user interface; and

(g) performing the step of generating a risk rating posed by the threat occurrence to the component group and providing said risk rating to the user via the user interface, monitoring changes by the user to the selection of the data elements, and modifying the risk impact, the risk likelihood, and the risk rating in response to said changes by the user.

14. The one or more non-transitory computer-readable media storing instructions of claim 13 , wherein the data elements are chosen from the group consisting of asset importance, sensitive records, users, component groups, component properties, threat sources, threat events, vulnerabilities, security controls, and control responses.

15. The one or more non-transitory computer-readable media storing instructions of claim 14 , wherein said one or more non-transitory computer-readable media storing instructions further instruct the at least one processor to perform the action of generating the database consisting of selections of data elements provided by other users, selections of risk impacts provided by other users, and selections of risk likelihoods provided by other users, wherein said generating the database step further comprises assigning the vulnerabilities to the threat events, assigning the threat events to the threat sources, and assigning threat sources to the component group when performing action “a”.

16. The one or more non-transitory computer-readable media storing instructions of claim 15 , wherein said one or more non-transitory computer-readable media storing instructions further instruct the at least one processor to perform the action of comparing the selection of the data elements from the user to similar selections of data elements provided by other users in the database when performing action “d”.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2023
From: MOORE, JONATHAN A.
To: CLEARWATER COMPLIANCE LLC
Reel/Frame 063411/0145 →
CHANGE OF NAME Recorded Feb 22, 2023
From: MILLER, CURTIS RAY
To: MILLER, TESS ARRAY
Reel/Frame 062765/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2022
From: STONE, JONATHAN D.; MILLER, CURTIS RAY; SINGH, RAVNEET
To: CLEARWATER COMPLIANCE LLC
Reel/Frame 059625/0044 →
Cited By (3)
US 12,333,612 US 12,513,167 US 12,670,457