IP Library › Granted Patent US 12,481,768
Granted Patent B1
US 12,481,768 · App. 18/767,063 · Granted Nov 25, 2025

Cybersecurity vulnerability management program evaluation system

Inventor: Michael Emil Lonigro (Canyon Lake, TX)
Assignee: United Services Automobile Association (USAA)
G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,481,768
App. No.
18/767,063
Granted
Nov 25, 2025
Kind
B1
Abstract

Methods and systems described herein are directed to measuring cybersecurity vulnerability management programs and readiness. A vulnerability management program evaluation system can define vulnerability management capabilities and technologies supporting execution of those capabilities. Once defined, the system can conduct an initial assessment including scoring for the capabilities representing a depth of vulnerability management, as well as scoring for the technologies representing a breadth of vulnerability management. To update the initial assessment, the system can track the ongoing progress of projects that can affect the depth and/or breadth of vulnerability management, and then recalculate the scoring. At any time, the system can combine the depth and breadth to determine a comprehensive vulnerability management score.

Claims (64)

1 . A method for measuring vulnerability management program readiness, the method comprising:

defining two or more maturity tiers each designating a level of progression for one or more vulnerability management capabilities;

determining one or more technologies respectively supporting execution of the one or more vulnerability management capabilities;

assessing a current vulnerability management status of an organization by:

computing a depth of current vulnerability management by scoring each of the one or more vulnerability management capabilities according to values corresponding to maturity tiers assigned to each of the one or more vulnerability management capabilities;

computing a breadth of current vulnerability management based on scores for each of the one or more technologies, across capabilities; and

combining the depth and the breadth scores to calculate a comprehensive vulnerability management score;

recalculating the comprehensive vulnerability management score based on completion and/or projected completion of one or more vulnerability management projects that each correspond to an effort for optimizing the current vulnerability management status,

wherein the recalculating the comprehensive vulnerability management score is based on receiving a time indicator, identifying the one or more vulnerability management projects for the time indicator, and applying one or more effects of the one or more vulnerability management projects to the computed depth and breadth of vulnerability management; and

providing an output including the recalculated comprehensive vulnerability management score.

2 . The method of claim 1 ,

wherein metrics are defined for assigning vulnerability management capabilities to maturity tiers; and

wherein the metrics comprise at least one or more of (a) a level of completion for a capability, (b) a scheduling status for a capability, (c) a priority status for a capability, or (d) any combination thereof.

3 . The method of claim 1 ,

wherein one or more support states are used to score technologies for a capability; and

wherein each of the one or more support states corresponds to an operational status, a deployment status, or a development status of a respective technology for enabling performance of a respective vulnerability management capability of the one or more vulnerability management capabilities.

4 . The method of claim 1 ,

wherein the depth of current vulnerability management corresponds to an extent of execution of the one or more vulnerability management capabilities; and

wherein the breadth of current vulnerability management corresponds to a degree to which the one or more vulnerability management capabilities are supported for their respective executions by the one or more technologies.

5 . The method of claim 1 ,

wherein the output comprises each of current individual depth and breadth scores defined by the recalculated comprehensive vulnerability management score.

6 . A computer-readable storage medium storing instructions, for measuring vulnerability management program readiness, the instructions, when executed by a computing system, cause the computing system to:

define two or more maturity tiers each designating a level of progression for one or more vulnerability management capabilities;

determine one or more technologies respectively supporting execution of the one or more vulnerability management capabilities;

assess a current vulnerability management status of an organization by:

computing a depth of current vulnerability management by scoring each of the one or more vulnerability management capabilities according to values corresponding to maturity tiers assigned to each of the one or more vulnerability management capabilities;

computing a breadth of current vulnerability management based on scores for each of the one or more technologies, across capabilities; and

combining the depth and the breadth scores to calculate a comprehensive vulnerability management score; and

recalculate the comprehensive vulnerability management score based on completion and/or projected completion of one or more vulnerability management projects that each correspond to an effort for optimizing the current vulnerability management status,

wherein the recalculating the comprehensive vulnerability management score is based on receiving a time indicator, identifying the one or more vulnerability management projects for the time indicator, and applying one or more effects of the one or more vulnerability management projects to the computed depth and breadth of vulnerability management; and

provide an output including the recalculated comprehensive vulnerability management score.

7 . The computer-readable storage medium of claim 6 ,

wherein metrics are defined for assigning vulnerability management capabilities to maturity tiers; and

wherein the metrics comprise at least one or more of (a) a level of completion for a capability, (b) a scheduling status for a capability, (c) a priority status for a capability, or (d) any combination thereof.

8 . The computer-readable storage medium of claim 6 ,

wherein one or more support states are used to score technologies for a capability; and

wherein each of the one or more support states corresponds to an operational status, a deployment status, or a development status of a respective technology for enabling performance of a respective vulnerability management capability of the one or more vulnerability management capabilities.

9 . The computer-readable storage medium of claim 6 ,

wherein the depth of current vulnerability management corresponds to an extent of execution of the one or more vulnerability management capabilities; and

wherein the breadth of current vulnerability management corresponds to a degree to which the one or more vulnerability management capabilities are supported for their respective executions by the one or more technologies.

10 . The computer-readable storage medium of claim 6 , wherein the output comprises each of current individual depth and breadth scores for the recalculated comprehensive vulnerability management score.

11 . A computing system for measuring vulnerability management program readiness, the computing system comprising:

one or more processors; and

one or more memories storing instructions that, when executed by the one or more processors, cause the computing system to:

define two or more maturity tiers each designating a level of progression for one or more vulnerability management capabilities;

determine one or more technologies respectively supporting execution of the one or more vulnerability management capabilities;

assess a current vulnerability management status of an organization by:

computing a depth of current vulnerability management by scoring each of the one or more vulnerability management capabilities according to values corresponding to maturity tiers assigned to each of the one or more vulnerability management capabilities;

computing a breadth of current vulnerability management based on scores for each of the one or more technologies, across capabilities; and

combining the depth and the breadth scores to calculate a comprehensive vulnerability management score;

recalculate the comprehensive vulnerability management score based on completion and/or projected completion of one or more vulnerability management projects that each correspond to an effort for optimizing the current vulnerability management status,

wherein the recalculating the comprehensive vulnerability management score is based on receiving a time indicator, identifying the one or more vulnerability management projects for the time indicator, and applying one or more effects of the one or more vulnerability management projects to the computed depth and breadth of vulnerability management; and

provide an output including the recalculated comprehensive vulnerability management score.

12 . The computing system of claim 11 ,

wherein metrics are defined for assigning vulnerability management capabilities to maturity tiers; and

wherein the metrics comprise at least one or more of (a) a level of completion for a capability, (b) a scheduling status for a capability, (c) a priority status for a capability, or (d) any combination thereof.

13 . The computing system of claim 11 ,

wherein one or more support states are used to score technologies for a capability; and

wherein each of the one or more support states corresponds to an operational status, a deployment status, or a development status of a respective technology for enabling performance of a respective vulnerability management capability of the one or more vulnerability management capabilities.

14 . The computing system of claim 11 ,

wherein the depth of current vulnerability management corresponds to an extent of execution of the one or more vulnerability management capabilities; and

wherein the breadth of current vulnerability management corresponds to a degree to which the one or more vulnerability management capabilities are supported for their respective executions by the one or more technologies.

15 . The computing system of claim 11 ,

wherein the output comprises each of current individual depth and breadth scores for the recalculated comprehensive vulnerability management score.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2024
From: LONIGRO, MICHAEL EMIL
To: UIPCO, LLC
Reel/Frame 067937/0350 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2024
From: UIPCO, LLC
To: UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
Reel/Frame 067937/0490 →
Continuity (1)
Continuation 17717741 · Apr 11, 2022
References Cited (38)
US 5913201A · Kocur · 1999 [cited by applicant]
US 7617117B2 · Starkey · 2009 [cited by applicant]
US 8239249B1 · Belko et al. · 2012 [cited by applicant]
US 8799243B1 · Havlik · 2014 [cited by applicant]
US 8874619B2 · Mack · 2014 [cited by applicant]
US 10346762B2 · Greenspan et al. · 2019 [cited by applicant]
US 11734609B1 · Breckenridge et al. · 2023 [cited by applicant]
US 11930032B2 · Campbell · 2024 [cited by examiner]
US 12056130B1 · Ayala et al. · 2024 [cited by applicant]
US 20020078381A1 · Farley · 2002 [cited by examiner]
US 20030028411A1 · Grenchus, Jr. et al. · 2003 [cited by applicant]
US 20040186852A1 · Rosen · 2004 [cited by applicant]
US 20050055230A1 · Chen · 2005 [cited by applicant]
US 20050055231A1 · Lee · 2005 [cited by applicant]
US 20080086342A1 · Curry et al. · 2008 [cited by applicant]
US 20080288317A1 · Kakar · 2008 [cited by applicant]
US 20080306750A1 · Wunder et al. · 2008 [cited by applicant]
US 20120072460A1 · Friedlander et al. · 2012 [cited by applicant]
US 20120239585A1 · Bailey · 2012 [cited by applicant]
US 20140058801A1 · Deodhar et al. · 2014 [cited by applicant]
US 20140108656A1 · Salinca et al. · 2014 [cited by applicant]
US 20150248532A1 · Rajasenan · 2015 [cited by applicant]
US 20170091670A1 · Gulin et al. · 2017 [cited by applicant]
US 20180322292A1 · Tedeschi · 2018 [cited by examiner]
US 20180341782A1 · Barday · 2018 [cited by examiner]
US 20190156291A1 · Nayak et al. · 2019 [cited by applicant]
US 20190207968A1 · Heckman · 2019 [cited by examiner]
US 20190207981A1 · Sweeney · 2019 [cited by examiner]
US 20200125586A1 · Rezaeian et al. · 2020 [cited by applicant]
US 20200250782A1 · Zaich et al. · 2020 [cited by applicant]
US 20210019665A1 · Gur et al. · 2021 [cited by applicant]
US 20220014169A1 · Caron et al. · 2022 [cited by applicant]
US 20220270021A1 · Glocker · 2022 [cited by applicant]
US 20240086859A1 · Gillam · 2024 [cited by applicant]
US 20240272944A1 · Cooke et al. · 2024 [cited by applicant]
CA 3084760A1 · 2020 [cited by applicant]
Shuo Zhang and Krisztian Balog. Auto-completion for Data Cells in Relational Tables. In Proceedings of the 28th ACM InternationalConference on Information and Knowledge Management (CIKM '19). Association for Computing M… [cited by applicant]
Maria Vaida, et al., “Semi-Supervised Graph Neural Network with Probabilistic Modeling to Mitigate Uncertainty”. In Proceedings of the 2020 the 4th International Conference on Information System and Data Mining, Associa… [cited by applicant]