IP Library Granted Patent US 12,401,692
Granted Patent B2
US 12,401,692 · App. 18/304,777 · Granted Aug 26, 2025

System and method for quantification of standard compliance and risk tolerance to select remediation

Inventors: Stav Sapir (Beer Sheba, IL); Maxim Balin (Gan-Yavne, IL)
Assignee: Dell Products L.P.
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,692
App. No.
18/304,777
Granted
Aug 26, 2025
Kind
B2
Abstract

Methods and systems for managing computing infrastructure compliance with standards are disclosed. The computing infrastructure may provide computer implemented services that may be at elevated risk if the computing infrastructure fails to comply with various standards such as security or redundancy standards. To manage compliance with standards, a cross-standard compliance coverage model may be used. The cross-standard compliance coverage model may use information regarding infrastructure components of the computing infrastructure to ascertain compliance with any number of standards. The information and risk tolerance may be used to identify a risk profile presented by computing infrastructure.

Claims (59)

1. A method for managing computing infrastructure, the method comprising:

obtaining a compliance information element for an infrastructure component of the computing infrastructure;

dynamically processing the compliance information element to update a cross-standard compliance coverage model to obtain an updated cross-standard compliance coverage model;

obtaining, using the updated cross-standard compliance coverage model, standard compliance data for a security standard enforced on the infrastructure;

obtaining a likelihood estimate for the infrastructure component using the standard compliance data;

obtaining, using the likelihood estimate, confidentiality-integrity-availability classifications for the infrastructure, and a rating system, a confidentiality-integrity-availability rating for the infrastructure component;

making a determination, using the confidentiality-integrity-availability rating, regarding whether the infrastructure has undergone a change in compliance with the security standard; and

in an instance of the determination where the infrastructure has undergone a change in compliance with the security standard:

performing an action set to manage an impact of the change in compliance with the security standard.

2. The method of claim 1 , wherein using the confidentiality-integrity-availability rating to make the determination comprises:

presenting, using the confidentiality-integrity-availability rating, a dashboard;

obtaining, using the dashboard, user input responsive to the confidentiality-integrity-availability rating; and

using the user input to make the determination.

3. The method of claim 2 , wherein the confidentiality-integrity-availability classifications comprise a first classification for confidentiality, the first classification indicating a numerical value within a range for confidentiality concern for the infrastructure component.

4. The method of claim 3 , wherein obtaining the confidentiality-integrity-availability rating comprises:

obtaining a quantification using the numerical value and the likelihood estimate.

5. The method of claim 4 , wherein obtaining the confidentiality-integrity-availability rating further comprises:

obtaining a second quantification using a second numerical value and the likelihood estimate, the second numerical value being within a range for integrity concern for the infrastructure component.

6. The method of claim 1 , wherein the confidentiality-integrity-availability rating comprises three sub-ratings, the sub-ratings being for confidentiality concern, integrity concern, and availability concern for the infrastructure component, respectively.

7. The method of claim 6 , wherein each of the three sub-ratings are set by a manager of the infrastructure component.

8. The method of claim 1 , wherein the likelihood is a likelihood of the infrastructure component becoming compromised.

9. A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing computing infrastructure, the operations comprising:

obtaining a compliance information element for an infrastructure component of the computing infrastructure;

dynamically processing the compliance information element to update a cross-standard compliance coverage model to obtain an updated cross-standard compliance coverage model;

obtaining, using the updated cross-standard compliance coverage model, standard compliance data for a security standard enforced on the infrastructure;

obtaining a likelihood estimate for the infrastructure component using the standard compliance data;

obtaining, using the likelihood estimate, confidentiality-integrity-availability classifications for the infrastructure, and a rating system, a confidentiality-integrity-availability rating for the infrastructure component;

making a determination, using the confidentiality-integrity-availability rating, regarding whether the infrastructure has undergone a change in compliance with the security standard; and

in an instance of the determination where the infrastructure has undergone a change in compliance with the security standard:

performing an action set to manage an impact of the change in compliance with the security standard.

10. The non-transitory machine-readable medium of claim 9 , wherein using the confidentiality-integrity-availability rating to make the determination comprises:

presenting, using the confidentiality-integrity-availability rating, a dashboard;

obtaining, using the dashboard, user input responsive to the confidentiality-integrity-availability rating; and

using the user input to make the determination.

11. The non-transitory machine-readable medium of claim 10 , wherein the confidentiality-integrity-availability classifications comprise a first classification for confidentiality, the first classification indicating a numerical value within a range for confidentiality concern for the infrastructure component.

12. The non-transitory machine-readable medium of claim 11 , wherein obtaining the confidentiality-integrity-availability rating comprises:

obtaining a quantification using the numerical value and the likelihood estimate.

13. The non-transitory machine-readable medium of claim 12 , wherein obtaining the confidentiality-integrity-availability rating further comprises:

obtaining a second quantification using a second numerical value and the likelihood estimate, the second numerical value being within a range for integrity concern for the infrastructure component.

14. The non-transitory machine-readable medium of claim 9 , wherein the confidentiality-integrity-availability rating comprises three sub-ratings, the sub-ratings being for confidentiality concern, integrity concern, and availability concern for the infrastructure component, respectively.

15. The non-transitory machine-readable medium of claim 14 , wherein each of the three sub-ratings are set by a manager of the infrastructure component.

16. The non-transitory machine-readable medium of claim 9 , wherein the likelihood is a likelihood of the infrastructure component becoming compromised.

17. A data processing system, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing computing infrastructure, the operations comprising:

obtaining a compliance information element for an infrastructure component of the computing infrastructure;

dynamically processing the compliance information element to update a cross-standard compliance coverage model to obtain an updated cross-standard compliance coverage model;

obtaining, using the updated cross-standard compliance coverage model, standard compliance data for a security standard enforced on the infrastructure;

obtaining a likelihood estimate for the infrastructure component using the standard compliance data;

obtaining, using the likelihood estimate, confidentiality-integrity-availability classifications for the infrastructure, and a rating system, a confidentiality-integrity-availability rating for the infrastructure component;

making a determination, using the confidentiality-integrity-availability rating, regarding whether the infrastructure has undergone a change in compliance with the security standard; and

in an instance of the determination where the infrastructure has undergone a change in compliance with the security standard:

performing an action set to manage an impact of the change in compliance with the security standard.

18. The data processing system of claim 17 , wherein using the confidentiality-integrity-availability rating to make the determination comprises:

presenting, using the confidentiality-integrity-availability rating, a dashboard;

obtaining, using the dashboard, user input responsive to the confidentiality-integrity-availability rating; and

using the user input to make the determination.

19. The data processing system of claim 18 , wherein the confidentiality-integrity-availability classifications comprise a first classification for confidentiality, the first classification indicating a numerical value within a range for confidentiality concern for the infrastructure component.

20. The data processing system of claim 17 , wherein the likelihood is a likelihood of the infrastructure component becoming compromised.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2023
From: SAPIR, STAV; BALIN, MAXIM
To: DELL PRODUCTS L.P.
Reel/Frame 063547/0438 →
Continuity (1)
Related Publication 20240356976A1 · Oct 24, 2024
References Cited (54)
US 8104077B1 · Gauvin et al. · 2012 [cited by applicant]
US 8584247B1 · Patil · 2013 [cited by applicant]
US 8590050B2 · Nagpal · 2013 [cited by applicant]
US 8689282B1 · Oprea · 2014 [cited by applicant]
US 8788442B1 · Sculley, II et al. · 2014 [cited by applicant]
US 8910241B2 · Pollutro · 2014 [cited by applicant]
US 10171510B2 · O'Reilly · 2019 [cited by applicant]
US 10318628B2 · Le Bescond de Coatpont · 2019 [cited by applicant]
US 10693902B1 · Haverty · 2020 [cited by applicant]
US 11128654B1 · Joyce · 2021 [cited by applicant]
US 11184404B1 · Hatch · 2021 [cited by applicant]
US 11256777B2 · Brannon et al. · 2022 [cited by applicant]
US 11726890B2 · Abraham · 2023 [cited by applicant]
US 20050010819A1 · Williams · 2005 [cited by applicant]
US 20050187963A1 · Markin · 2005 [cited by applicant]
US 20070180490A1 · Renzi · 2007 [cited by applicant]
US 20110289588A1 · Sahai · 2011 [cited by applicant]
US 20130104236A1 · Ray et al. · 2013 [cited by applicant]
US 20140164184A1 · Akolkar · 2014 [cited by applicant]
US 20150047032A1 · Hannis · 2015 [cited by applicant]
US 20150106873A1 · Marsh · 2015 [cited by applicant]
US 20150200958A1 · Muppidi · 2015 [cited by applicant]
US 20160080422A1 · Belgodere · 2016 [cited by applicant]
US 20160359915A1 · Gupta · 2016 [cited by applicant]
US 20180176254A1 · Lam · 2018 [cited by examiner]
US 20180322510A1 · Cleaver · 2018 [cited by examiner]
US 20190354690A1 · Brigandi · 2019 [cited by examiner]
US 20200125962A1 · von Trapp · 2020 [cited by applicant]
US 20200125963A1 · von Trapp · 2020 [cited by applicant]
US 20200358826A1 · Helander · 2020 [cited by examiner]
US 20200389469A1 · Litichever · 2020 [cited by applicant]
US 20210035116A1 · Berrington · 2021 [cited by applicant]
US 20210367963A1 · Murray · 2021 [cited by applicant]
US 20220094596A1 · Jagannathan · 2022 [cited by examiner]
US 20220101221A1 · Hari · 2022 [cited by applicant]
US 20220210195A1 · Parekh · 2022 [cited by applicant]
US 20220263856A1 · King-Wilson · 2022 [cited by applicant]
US 20220286475A1 · Mullaney · 2022 [cited by applicant]
US 20220353289A1 · Witschey · 2022 [cited by applicant]
US 20230044695A1 · Brandy · 2023 [cited by applicant]
US 20230117225A1 · Porto Guedes · 2023 [cited by applicant]
US 20230275932A1 · Brotherson · 2023 [cited by applicant]
US 20230283643A1 · Manuel-Devadoss · 2023 [cited by applicant]
US 20230421616A1 · Lahiri · 2023 [cited by applicant]
US 20240061939A1 · Pieczul · 2024 [cited by examiner]
US 20240073238A1 · Lang · 2024 [cited by applicant]
US 20240214424A1 · Ossipov · 2024 [cited by applicant]
US 20240259416A1 · Miyake · 2024 [cited by applicant]
US 20240311208A1 · Kandasamy · 2024 [cited by examiner]
US 20250023918A1 · Sethi · 2025 [cited by applicant]
“Microsoft Purview Compliance Manager,” Web Page <https://learn.microsoft.com/en-us/microsoft-365/compliance/compliance-manager?view=o365-worldwide> accessed on Jan. 7, 2023. [cited by applicant]
“Configuration Analyzer for Microsoft Purview (CAMP),” Web Page <https://learn.microsoft.com/en-us/microsoft-365/compliance/compliance-manager-mcca?view=o365-worldwide> accessed on Jan. 7, 2023. [cited by applicant]
“GDPR Compliance Software,” Web Page <https://www.solarwinds.com/access-rights-manager/use-cases/gdpr-compliance-software> accessed on Jan. 7, 2023. [cited by applicant]
“Understanding the NIST 800-53 Risk Management Framework,” Web Page <https://www.apptega.com/frameworks/nist-800-53-compliance> accessed on Jan. 7, 2023. [cited by applicant]