IP Library › Granted Patent US 12,505,244
Granted Patent B1
US 12,505,244 · App. 18/677,816 · Granted Dec 23, 2025

Categorizing policy-based control mapping for real-time security and compliance monitoring

Inventor: Lior Solomon (Haworth, NJ)
Assignee: DRATA INC.
G06F21/6218G06Q10/0635
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,244
App. No.
18/677,816
Granted
Dec 23, 2025
Kind
B1
Abstract

Categorizing policy-based control mapping for real-time security and compliance monitoring including receiving, by a security and compliance monitor, a request for a control mapping score indicating an affinity between a user-generated policy document and a proposed control, wherein the proposed control is a measurable component exposed by a services provider of an organization, and wherein the proposed control is intended to indicate a level of compliance of the organization with the user-generated policy document; determining, by the security and compliance monitor from a group of template policy documents, a best-matching template policy document for the user-generated policy document; generating, by the security and compliance monitor, the control mapping score based on previous mappings between the proposed control and the best-matching template policy document; and providing, by the security and compliance monitor to a user computing system, the control mapping score for the proposed control mapped to the user-generated policy document.

Claims (38)

1 . A method comprising:

receiving, by a security and compliance monitor, a request for a control mapping score indicating an affinity between a user-generated policy document and a proposed control, wherein the proposed control is a measurable component exposed by a services provider of an organization, and wherein the proposed control is intended to indicate a level of compliance of the organization with the user-generated policy document;

determining, by the security and compliance monitor from a group of template policy documents, a best-matching template policy document for the user-generated policy document;

generating, by the security and compliance monitor, the control mapping score based on previous mappings between the proposed control and the best-matching template policy document; and

providing, by the security and compliance monitor to a user computing system, the control mapping score for the proposed control mapped to the user-generated policy document.

2 . The method of claim 1 , further comprising:

accessing, from the services provider of the organization based on the control mapping score, the proposed control to retrieve a control status; and

generating a trust center report using the control status indicating the level of compliance with the user-generated policy document.

3 . The method of claim 1 , wherein generating the control mapping score based on the previous mappings between the proposed control and the best-matching template policy document comprises accessing an entry in a data structure for the best-matching template policy document that includes values for previously mapped controls.

4 . The method of claim 3 , wherein each value for previously mapped controls in the data structure indicates a frequency that each previously mapped control has been mapped to a template policy document by other users.

5 . The method of claim 1 , wherein determining, from the group of template policy documents, the best-matching template policy document for the user-generated policy document comprises matching the user-generated policy document to the best-matching template policy document using a vector database.

6 . The method of claim 1 , wherein the proposed control is identified by matching language within the user-generated policy document to a stock control language record describing the proposed control.

7 . The method of claim 1 , wherein providing, to the user computing system, the control mapping score for the proposed control mapped to the user-generated policy document comprises providing a recommendation to employ the proposed control based on a comparison of the control mapping score to a threshold value.

8 . The method of claim 1 , wherein the best-matching template policy document is a privacy policy document.

9 . The method of claim 1 , wherein at least one of the services providers of the organization comprise a cloud services provider.

10 . The method of claim 1 , wherein the user-generated policy document comprises a plurality of obligations assigned to the organization.

11 . A system comprising:

a memory; and

a processing device, operatively coupled to the memory, the processing device configured to:

receive a request for a control mapping score indicating an affinity between a user-generated policy document and a proposed control, wherein the proposed control is a measurable component exposed by a services provider of an organization, and wherein the proposed control is intended to indicate a level of compliance of the organization with the user-generated policy document;

determine, from a group of template policy documents, a best-matching template policy document for the user-generated policy document;

generate the control mapping score based on previous mappings between the proposed control and the best-matching template policy document; and

provide, to a user computing system, the control mapping score for the proposed control mapped to the user-generated policy document.

12 . The system of claim 11 , wherein the processing device is further configured to:

accessing, from the services provider of the organization based on the control mapping score, the proposed control to retrieve a control status; and

generating a trust center report using the control status indicating the level of compliance with the user-generated policy document.

13 . The system of claim 11 , wherein generating the control mapping score based on the previous mappings between the proposed control and the best-matching template policy document comprises accessing an entry in a data structure for the best-matching template policy document that includes values for previously mapped controls.

14 . The system of claim 13 , wherein each value for previously mapped controls in the data structure indicates a frequency that each previously mapped control has been mapped to a template policy document by other users.

15 . The system of claim 11 , wherein determining, from the group of template policy documents, the best-matching template policy document for the user-generated policy document comprises matching the user-generated policy document to the best-matching template policy document using a vector database.

16 . The system of claim 11 , wherein the proposed control is identified by matching language within the user-generated policy document to a stock control language record describing the proposed control.

17 . The system of claim 11 , wherein providing, to the user computing system, the control mapping score for the proposed control mapped to the user-generated policy document comprises providing a recommendation to employ the proposed control based on a comparison of the control mapping score to a threshold value.

18 . The system of claim 11 , wherein the best-matching template policy document is a privacy policy document.

19 . The system of claim 11 , wherein at least one of the services providers of the organization comprise a cloud services provider.

20 . A non-transitory computer readable storage medium storing instructions which, when executed, cause a processing device to:

receive a request for a control mapping score indicating an affinity between a user-generated policy document and a proposed control, wherein the proposed control is a measurable component exposed by a services provider of an organization, and wherein the proposed control is intended to indicate a level of compliance of the organization with the user-generated policy document;

determine, from a group of template policy documents, a best-matching template policy document for the user-generated policy document;

generate the control mapping score based on previous mappings between the proposed control and the best-matching template policy document; and

provide, to a user computing system, the control mapping score for the proposed control mapped to the user-generated policy document.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2024
From: SOLOMON, LIOR
To: DRATA INC.
Reel/Frame 067654/0951 →
References Cited (4)
US 7536456B2 · Williams · 2009 [cited by examiner]
US 10205593B2 · Biesinger · 2019 [cited by examiner]
US 20070180490A1 · Renzi · 2007 [cited by examiner]
US 20250131093A1 · Sharieh · 2025 [cited by examiner]