EP1579290A2

Enhanced system, method and medium for certifying and accrediting requirements compliance utilizing continuous risk assessment

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 26 November 2023, 2.8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

65 claims: 4 independent, 61 dependent

  1. 1
    Claims of equivalent WO 2004051407 A2 CLAIMS Having thus described our invention, what we claim as new and desire to secure by Letters Patent is as follows:1. A computer-implemented method of enabling a user to assess the risk of and/or determine the suitability of a target system to comply with at least one predefined standard, regulation and/or requirement, the target system including hardware and/or software, the method comprising the steps of: a) electronically scanning, on a predetermined basis, hardware and/or software characteristics of components within a target system to obtain and store target system configuration information;b) receiving and storing target system operational environment information;c) using information collected in said steps a) and b) to select, by the computer, one or more security requirements in accordance with the at least one predefined standard, regulation and/or requirement;d) selecting, by the computer, one or more test procedures used to determine target system compliance with the security requirements;and e) producing a risk assessment of the target system.
  2. 19
    The method according to step 18, wherein the adjusted risk levels comprise high, medium-high, medium, medium-low, low, and negligible.
  3. 35
    A computing system for enabling a user to assess the risk of and/or determine the suitability of a target system to comply with at least one predefined standard, regulation and/or requirement, the target system including hardware and/or software, the computing system comprising:a) means for electronically scanning, on a predetermined basis, hardware and/or software characteristics of components within a target system to obtain and store target system configuration information;b) means for receiving and storing target system operational environment information;c) means for using information collected in said steps a) and b) to select, by the computer, one or more security requirements in accordance with the at least one predefined standard, regulation and/or requirement;d) means for selecting, by the computer, one or more test procedures used to determine target system compliance with the security requirements;and e) means for producing a risk assessment of the target system.
  4. 51
    A computer program product residing on a computer readable medium for enabling a user to select at least one of a plurality of predefined process steps to create a tailored sequence of process steps that can be used to assess the risk of and/or determine the suitability of a target system to comply with at least one predefined standard, regulation and/or requirement, the target system including hardware and/or software, the computer program product comprising instructions for causing the computer system to interact with a user and enabling at least one of the computing system and the user to perform the steps of:a) electronically scanning, on a predetermined basis, hardware and/or software characteristics of components within a target system to obtain and store target system configuration information;b) receiving and storing target system operational environment information;c) using information collected in said steps a) and b) to select, by the computer, one or more security requirements in accordance with the at least one predefined standard, regulation and/or requirement;d) selecting, by the computer, one or more test procedures used to determine target system compliance with the security requirements;and e) producing a risk assessment of the target system.