IP Library › Granted Patent US 12,739,284
Granted Patent B1
US 12,739,284 · App. 19/552,344 · Granted Sep 15, 2026

Cloud environment compliance automation methods and systems

Inventors: Adam Burroughs (Arlington, VA); Sean Osborne (Arlington, VA)
Assignee: MERIDIAN KNOWLEDGE SOLUTIONS, LLC
H04L63/20G06F9/45512
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,284
App. No.
19/552,344
Granted
Sep 15, 2026
Kind
B1
Abstract

An automated compliance assessment method for a cloud environment includes obtaining compliance framework requirements from declarative framework configurations; executing multi-source validation through command-line interface (CLI) commands for each of a plurality of controls from a control plane of the cloud environment to obtain raw results; selecting service-specific primitive extractors from a plurality of service-specific classes; aggregating the raw results using the service-specific primitive extractors and producing a plurality of normalized compliance facts based on the raw results; correlating the plurality of normalized compliance facts and detecting contradictions amongst the plurality of normalized compliance facts; using compliance outcome judges, evaluating the plurality of normalized compliance facts against the compliance framework requirements, and producing at least one automated attestation based on the evaluating; producing machine-readable output with evidence sources and compliance determinations; and repeating the method continuously at predetermined intervals.

Claims (40)

1 . An automated compliance assessment method for a cloud environment, the method comprising:

a) obtaining compliance framework requirements from declarative framework configurations;

b) executing multi-source validation through command-line interface (CLI) commands for each of a plurality of controls from a control plane of the cloud environment to obtain raw results;

c) selecting service-specific primitive extractors from a plurality of service-specific classes;

d) aggregating the raw results using the service-specific primitive extractors and producing a plurality of normalized compliance facts based on the raw results;

e) correlating the plurality of normalized compliance facts and detecting contradictions amongst the plurality of normalized compliance facts;

f) using compliance outcome judges, evaluating the plurality of normalized compliance facts against the compliance framework requirements, and producing at least one automated attestation based on the evaluating;

g) producing machine-readable output with evidence sources and compliance determinations; and

h) repeating a) through g) continuously at predetermined intervals.

2 . The method of claim 1 , wherein the repeating is triggered when detecting infrastructure change events from the cloud environment.

3 . The method of claim 1 , wherein the correlating comprises comparing facts from at least three validation layers including a policy layer representing intended security configuration, an enforcement layer representing control plane enforcement state, and a runtime layer representing observed runtime behavior, and wherein the detecting of contradictions comprises identifying at least one enforcement gap whereby the policy layer mandates a security control but the enforcement layer does not implement the security control.

4 . The method of claim 1 , wherein the declarative framework configurations further comprise metric profile definitions, each of the metric profile definitions specifying: a boundary classification identifying a control of the plurality of controls as belonging to a boundary; an aggregation strategy; one or more primary metrics each having a threshold and a directionality indicator; and one or more secondary metrics providing contextual data; and wherein the evaluating further comprises aggregating raw data from the compliance outcome judges across all resources for the control, computing aggregate metrics, and evaluating the aggregate metrics against the thresholds defined in the metric profile definition.

5 . The method of claim 1 , wherein the method provides compliance determinations without code modifications of the cloud environment.

6 . The method of claim 1 , wherein the predetermined intervals are every 6 hours.

7 . One or more computer-readable non-transitory storage media embodying software that is operable when executed to perform the method of claim 1 .

8 . A method of multi-command validation and critical findings detection for automated compliance assessment of a cloud environment, the method comprising:

a) executing multiple command-line interface (CLI) commands for each of a plurality of controls from a control plane of the cloud environment;

b) extracting security configuration states from multiple data sources in response to the executing of the multiple CLI commands;

c) aggregating extracted data via service-specific primitive extractors and evaluating the aggregated extracted data using compliance outcome judges to produce compliance determinations;

d) evaluating, using a critical findings handler, each of a plurality of resources of the cloud environment against confidentiality-integrity-availability (CIA) impact rules to detect potentially severe security conditions, and overriding the compliance determinations to immediate failure when the potentially severe security conditions are detected;

e) classifying the detected potentially severe security conditions by severity levels and by CIA impact;

f) monitoring, using a circuit breaker mechanism, validation execution and automatically halting further validation when failure rate exceeds a configurable failure rate threshold after minimum samples, or when consecutive failures exceed a consecutive failures limit; and

g) calculating compliance scores for each of the plurality of controls based on a ratio of passing resources to total resources scanned.

9 . The method of claim 8 , further comprising producing machine-readable output with evidence sources and recommended remediation actions.

10 . The method of claim 9 , comprising sanitizing the machine-readable output by removing credential data from evidence sources prior to storage of the machine-readable output.

11 . The method of claim 8 , wherein the multiple CLI commands are two to ten CLI commands.

12 . The method of claim 8 , wherein the potentially severe security conditions include at least one selected from: open network ingress on non-load-balancer resources, publicly accessible databases, unencrypted data stores, disabled audit logging, missing multi-factor authentication, and overly permissive IAM trust policies.

13 . The method of claim 8 , wherein the severity levels include five severity levels.

14 . The method of claim 8 , wherein the failure rate threshold has a default value of 30% and the consecutive failures limit has a default value of 5.

15 . The method of claim 8 , wherein the command execution metadata includes execution time, exit code, success/failure status, and error messages.

16 . The method of claim 8 , wherein critical findings trigger immediate control failure regardless of overall score.

17 . The method of claim 8 , wherein, in the calculating, scores below a predetermined failure rate threshold result in control failure.

18 . One or more computer-readable non-transitory storage media embodying software that is operable when executed to perform the method of claim 8 .

19 . A compliance attestation method providing integration between cloud security scanning outputs and governance, risk, and compliance platform attestation workflows, the method comprising:

a) executing technical validation commands targeting cloud provider application programming interface (API) to extract security configuration states;

b) mapping command results of the technical validation commands to compliance framework controls through control definitions associating command sequences with control identifiers from one or more compliance frameworks;

c) evaluating the command results against framework-specific requirements through compliance outcome judges implementing framework-specific evaluation rules to generate pass/fail attestations for each of the controls;

d) producing machine-readable attestation output comprising structured data including control identifier from compliance framework, pass/fail determination for each of the controls, evidence sources with executed commands and timestamps, compliance facts dictionary extracted from multiple commands through primitive aggregation, enforcement validation results indicating policy-layer versus enforcement-layer consistency, and automated determination reasoning explaining evaluation logic applied; and

e) providing a programmatic consumption interface including control-level attestations mapped to framework requirements with supporting evidence and severity-classified critical findings.

20 . One or more computer-readable non-transitory storage media embodying software that is operable when executed to perform the method of claim 19 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2026
From: BURROUGHS, ADAM; OSBORNE, SEAN
To: MERIDIAN KNOWLEDGE SOLUTIONS, LLC
Reel/Frame 073925/0031 →
References Cited (23)
US 11070575B2 · Ravindranath · 2021 [cited by examiner]
US 11303666B1 · Peters · 2022 [cited by examiner]
US 11943254B2 · Thompson · 2024 [cited by examiner]
US 12555008B1 · Singh · 2026 [cited by examiner]
US 20140122873A1 · Deutsch · 2014 [cited by examiner]
US 20210058370A1 · Adam · 2021 [cited by examiner]
US 20210352099A1 · Rogers · 2021 [cited by examiner]
US 20220150281A1 · Kanungo · 2022 [cited by examiner]
US 20230059526A1 · Parulekar · 2023 [cited by examiner]
US 20230177169A1 · Bulut · 2023 [cited by examiner]
US 20240012931A1 · Yannuzzi · 2024 [cited by examiner]
US 20250021657A1 · Andriukhin · 2025 [cited by examiner]
US 20250211621A1 · Hejl, Jr. · 2025 [cited by examiner]
US 20250233883A1 · Thompson · 2025 [cited by examiner]
US 20250278490A1 · Farshteindiker · 2025 [cited by examiner]
US 20250294048A1 · Jin · 2025 [cited by examiner]
US 20250315509A1 · Wargo · 2025 [cited by examiner]
US 20250317466A1 · Fry · 2025 [cited by examiner]
US 20250322058A1 · Cross · 2025 [cited by examiner]
US 20250358240A1 · Bhat · 2025 [cited by examiner]
Shuqin Zhang, Guangyao Bai, Hong Li, Peipei Liu, Minzhi Zhang, Shujun Li, “Multi-Source Knowledge Reasoning for Data-Driven IoT Security”, MDPI, Sensors 2021, Nov. 15, 2021. [cited by applicant]
Xinjian Xiang, Kehan Li, Bingqiang Huang, Ying Cao, “A Multi-Sensor Data-Fusion Method Based on Cloud Model and Improved Evidence Theory”, MDPI, Sensors 2022, Aug. 7, 2022. [cited by applicant]
Syed Imran Akhtar, Abdul Rauf, Muhammad Faisal Amjad, Ifra Batool, “Inter-Cloud Data Security Framework to Build Trust Based on Compliance with Controls”, Wiley, IET Information Security, vol. 2024, Article ID 6565102, … [cited by applicant]