IP Library › Granted Patent US 12,301,624
Granted Patent B2
US 12,301,624 · App. 18/304,760 · Granted May 13, 2025

System and method for dynamic resolution of standard compliance

Inventors: Stav Sapir (Beer Sheba, IL); Maxim Balin (Gan-Yavne, IL)
Assignee: Dell Products L.P.
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,624
App. No.
18/304,760
Granted
May 13, 2025
Kind
B2
Abstract

Methods and systems for managing computing infrastructure compliance with standards are disclosed. The computing infrastructure may provide computer implemented services that may be at elevated risk if the computing infrastructure fails to comply with various standards such as security or redundancy standards. To manage compliance with standards, a cross-standard compliance coverage model may be used. The cross-standard compliance coverage model may use information regarding infrastructure components of the computing infrastructure to ascertain compliance with any number of standards.

Claims (73)

1. A method for managing computing infrastructure, the method comprising:

obtaining a compliance information element for an infrastructure component of the computing infrastructure;

dynamically processing the compliance information element obtained for the infrastructure component to update a cross-standard compliance coverage model to obtain an updated cross-standard compliance coverage model;

obtaining compliance standard data for a security standard enforced on the computing infrastructure using the updated cross-standard compliance coverage model;

making a determination, based on the compliance standard data obtained using the updated cross-standard compliance coverage model, whether the computing infrastructure has undergone a change in compliance with the security standard;

in an instance of the determination made based on the compliance standard data obtained using the updated cross-standard compliance coverage model where the computing infrastructure has undergone the change in compliance with the security standard resulting in a compliance failure specified by the standard compliance data:

performing an action set to manage an impact of the change in compliance with the security standard that the computing infrastructure has undergone and to reduce a divergence of an operation of the computing infrastructure from the security standard enforced on the computing infrastructure.

2. The method of claim 1 , wherein the compliance information element is based on at least one mapping of the cross-standard compliance coverage model, the mapping associating the compliance information element with at least one portion of the security standard.

3. The method of claim 2 , wherein the mapping further specifies a basis for a portion of a state of the cross-standard compliance coverage model associated with the portion of the security standard on the compliance information element.

4. The method of claim 3 , wherein dynamically processing the compliance information element comprises:

updating the portion of the state using the basis and the compliance information element; and

updating a second portion of the state using a second basis associated with a second mapping of the cross-standard compliance coverage model and the compliance information element.

5. The method of claim 4 , wherein the second portion of the state is associated with a portion of second security standard that is different from the security standard.

6. The method of claim 4 , further comprising:

prior to obtaining the compliance information element:

identifying the infrastructure component for standard monitoring;

identifying the mapping as being related to the infrastructure component;

generating a configuration for an agent for the infrastructure component; and

updating operation of an instance of the agent associated with the infrastructure component based on the configuration.

7. The method of claim 6 , wherein updating the operation of the instance of the agent comprises:

specifying collection, by the instance of the agent, of a configuration of the infrastructure component;

specifying collection, by the instance of the agent, a state of the infrastructure component;

specifying collection, by the instance of the agent, an audit result for the infrastructure component; and

specifying generation, by the instance of the agent, of the compliance information element based on the configuration, the state, and/or the audit result.

8. A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing computing infrastructure, the operations comprising:

obtaining a compliance information element for an infrastructure component of the computing infrastructure;

dynamically processing the compliance information element obtained for the infrastructure component to update a cross-standard compliance coverage model to obtain an updated cross-standard compliance coverage model;

obtaining compliance standard data for a security standard enforced on the computing infrastructure using the updated cross-standard compliance coverage model;

making a determination, based on the compliance standard data obtained using the updated cross-standard compliance coverage model, whether the computing infrastructure has undergone a change in compliance with the security standard;

in an instance of the determination made based on the compliance standard data obtained using the updated cross-standard compliance coverage model where the computing infrastructure has undergone the change in compliance with the security standard resulting in a compliance failure specified by the standard compliance data:

performing an action set to manage an impact of the change in compliance with the security standard that the computing infrastructure has undergone and to reduce a divergence of an operation of the computing infrastructure from the security standard enforced on the computing infrastructure.

9. The non-transitory machine-readable medium of claim 8 , wherein the compliance information element is based on at least one mapping of the cross-standard compliance coverage model, the mapping associating the compliance information element with at least one portion of the security standard.

10. The non-transitory machine-readable medium of claim 9 , wherein the mapping further specifies a basis for a portion of a state of the cross-standard compliance coverage model associated with the portion of the security standard on the compliance information element.

11. The non-transitory machine-readable medium of claim 10 , wherein dynamically processing the compliance information element comprises:

updating the portion of the state using the basis and the compliance information element; and

updating a second portion of the state using a second basis associated with a second mapping of the cross-standard compliance coverage model and the compliance information element.

12. The non-transitory machine-readable medium of claim 11 , wherein the second portion of the state is associated with a portion of second security standard that is different from the security standard.

13. The non-transitory machine-readable medium of claim 11 , wherein the operations further comprise:

prior to obtaining the compliance information element:

identifying the infrastructure component for standard monitoring;

identifying the mapping as being related to the infrastructure component;

generating a configuration for an agent for the infrastructure component; and

updating operation of an instance of the agent associated with the infrastructure component based on the configuration.

14. The non-transitory machine-readable medium of claim 13 , wherein updating the operation of the instance of the agent comprises:

specifying collection, by the instance of the agent, of a configuration of the infrastructure component;

specifying collection, by the instance of the agent, a state of the infrastructure component;

specifying collection, by the instance of the agent, an audit result for the infrastructure component; and

specifying generation, by the instance of the agent, of the compliance information element based on the configuration, the state, and/or the audit result.

15. A data processing system, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing computing infrastructure, the operations comprising:

obtaining a compliance information element for an infrastructure component of the computing infrastructure;

dynamically processing the compliance information obtained for the infrastructure component element to update a cross-standard compliance coverage model to obtain an updated cross-standard compliance coverage model;

obtaining compliance standard data for a security standard enforced on the computing infrastructure using the updated cross-standard compliance coverage model;

making a determination, based on the compliance standard data obtained using the updated cross-standard compliance coverage model, whether the computing infrastructure has undergone a change in compliance with the security standard;

in an instance of the determination made based on the compliance standard data obtained using the updated cross-standard compliance coverage model where the computing infrastructure has undergone the change in compliance with the security standard resulting in a compliance failure specified by the standard compliance data:

performing an action set to manage an impact of the change in compliance with the security standard that the computing infrastructure has undergone and to reduce a divergence of an operation of the computing infrastructure from the security standard enforced on the computing infrastructure.

16. The data processing system of claim 15 , wherein the compliance information element is based on at least one mapping of the cross-standard compliance coverage model, the mapping associating the compliance information element with at least one portion of the security standard.

17. The data processing system of claim 16 , wherein the mapping further specifies a basis for a portion of a state of the cross-standard compliance coverage model associated with the portion of the security standard on the compliance information element.

18. The data processing system of claim 17 , wherein dynamically processing the compliance information element comprises:

updating the portion of the state using the basis and the compliance information element; and

updating a second portion of the state using a second basis associated with a second mapping of the cross-standard compliance coverage model and the compliance information element.

19. The data processing system of claim 18 , wherein the operations further comprise:

prior to obtaining the compliance information element:

identifying the infrastructure component for standard monitoring;

identifying the mapping as being related to the infrastructure component;

generating a configuration for an agent for the infrastructure component; and

updating operation of an instance of the agent associated with the infrastructure component based on the configuration.

20. The data processing system of claim 19 , wherein updating the operation of the instance of the agent comprises:

specifying collection, by the instance of the agent, of a configuration of the infrastructure component;

specifying collection, by the instance of the agent, a state of the infrastructure component;

specifying collection, by the instance of the agent, an audit result for the infrastructure component; and

specifying generation, by the instance of the agent, of the compliance information element based on the configuration, the state, and/or the audit result.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2023
From: SAPIR, STAV; BALIN, MAXIM
To: DELL PRODUCTS L.P.
Reel/Frame 063547/0115 →
Continuity (1)
Related Publication 20240356974A1 · Oct 24, 2024
References Cited (22)
US 8104077B1 · Gauvin · 2012 [cited by examiner]
US 8584247B1 · Patil · 2013 [cited by applicant]
US 8590050B2 · Nagpal · 2013 [cited by applicant]
US 8788442B1 · Sculley, II · 2014 [cited by examiner]
US 8910241B2 · Pollutro · 2014 [cited by applicant]
US 10318628B2 · Le Bescond de Coatpont · 2019 [cited by applicant]
US 11184404B1 · Hatch · 2021 [cited by applicant]
US 11256777B2 · Brannon et al. · 2022 [cited by applicant]
US 20130104236A1 · Ray · 2013 [cited by examiner]
US 20180176254A1 · Lam · 2018 [cited by applicant]
US 20180322510A1 · Cleaver · 2018 [cited by applicant]
US 20190354690A1 · Brigandi · 2019 [cited by applicant]
US 20200358826A1 · Helander · 2020 [cited by applicant]
US 20220094596A1 · Jagannathan · 2022 [cited by applicant]
US 20230275932A1 · Brotherson · 2023 [cited by applicant]
US 20230283643A1 · Manuel-Devadoss · 2023 [cited by applicant]
US 20240061939A1 · Pieczul · 2024 [cited by applicant]
US 20240311208A1 · Kandasamy · 2024 [cited by applicant]
“Microsoft Purview Compliance Manager,” Web Page <https://learn.microsoft.com/en-us/microsoft-365/compliance/compliance-manager?view=o365-worldwide> accessed on Jan. 7, 2023. [cited by applicant]
“Configuration Analyzer for Microsoft Purview (CAMP),” Web Page <https://learn.microsoft.com/en-us/microsoft-365/compliance/compliance-manager-mcca?view=o365-worldwide> accessed on Jan. 7, 2023. [cited by applicant]
“GDPR Compliance Software,” Web Page <https://www.solarwinds.com/access-rights-manager/use-cases/gdpr-compliance-software> accessed on Jan. 7, 2023. [cited by applicant]
“Understanding the NIST 800-53 Risk Management Framework,” Web Page <https://www.apptega.com/frameworks/hist-800-53-compliance> accessed on Jan. 7, 2023. [cited by applicant]