Self-learning automated information technology change risk prediction
US-2024414064-A1 · Dec 12, 2024 · US
US10282702B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10282702-B2 |
| Application number | US-65164510-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jan 4, 2010 |
| Priority date | Jan 4, 2010 |
| Publication date | May 7, 2019 |
| Grant date | May 7, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Embodiments of the invention relate to systems, methods, and computer program products that provide for an employee security risk score. The security risk score is presented as an extensible composite vector that supports an arbitrary number of risk categories. The risk categories can be aggregated at any level in the business hierarchy or according to any employee parameter. The simplistic, highly normalized approach to employee security risk scoring reduces redundancies and dependencies and provides for real-time updates, As such, the employee security risk scoring system provides for easily identifiable recognition of employees who pose security threats and for a means to track and monitor security risks posed by the employee based on their security risk score.
Opening claim text (preview).
The invention claimed is: 1. An apparatus for quantifying employee security risk, the apparatus comprising: a computing platform including at least one processor and a memory; an employee security risk scoring module that is stored in the memory, executable by the processor, configured to: receive a plurality of security risk facts, each fact associated with one of a plurality of employees, wherein one or more of the security risk facts are received within real-time of an event associated with a security risk fact, consolidate the plurality of security risk facts to (1) determine one of a plurality of security risk categories to assign to each of the security risk facts, and (2) determine security risk facts that are redundant and remove the redundant risk facts from further employee risk score processing, wherein the security risk categories include (1) access to non-public information, (2) volume of non-public information consumed within a predetermined time period, (3) ability to export data, (4) behaviors associated with a security risk and (5) volume of hardware accessed within a predetermined time period, and transform the plurality of security risk facts to a standard format prior to the employees security risk score processing; an employee security risk scoring logic configured to determine an employee security risk score for each of the employees that meet a predetermined employee parameter, based on the plurality of security risk facts, wherein the employee security risk scoring logic further comprises: a security risk category scoring routine configured to determine, for each of the employees that meet the employee parameter, an employee-specific security risk category score for each of the plurality of security risk categories, a security risk category average routine configured to determine a security risk category average for each of the plurality of security risk categories and for the employees that meet the predetermined employee parameter, a security risk category standard deviation routine configured to determine a security risk category standard deviation for each of the plurality of security risk categories and for the employees that meet by a predetermined employee parameter, a sigma scoring routine configured to determine a sigma score, which is specific to the employee parameter, for each of the security risk categories, wherein the sigma score is determined by subtracting the security risk category average from the security risk category score to result in a remainder and dividing the remainder by the security risk category standard deviation, and an employee risk scoring routine configured to determine, for each of the employees that meet the employee parameter, the employee security risk score by aggregating all positive-valued sigma scores for each of the security risk categories; a graphical user interface module configured to dynamically display, via a network connection, employee security risk scores for each of the employees, to thereby providing tracking a security risk of employees in terms of their respective security risk scores for the predetermined employee parameter; a security risk reporting application configured to automatically generate a dynamic employee security risk report indicating employees that are determined to pose security risks based on their scores exceeding a predetermined threshold; and a reporting application configured to initiate communication of the report to a remote electronic device. 2. The apparatus of claim 1 , wherein the employee security category routine is further configured to aggregate the security risk facts associated with a security risk category to determine the security risk category score. 3. The apparatus of claim 1 , wherein the employee security risk scoring module further comprises a security risk fact weighting mechanism configured to apply a predetermined weighting factor to one or more of the security risk facts based on security risk significance prior to determining the security risk category score. 4. The apparatus of claim 1 , wherein the employee risk scoring logic is further configured to apply a predetermined weighting factor to each of the positive-valued parameter-specific sigma scores, wherein the predetermined weighting factor is based on the significance of the security risk category associated with the sigma score in determining the employee risk score. 5. The apparatus of claim 1 , wherein the plurality of risk categories include (6) high-risk user indicators. 6. The apparatus of claim 1 , wherein the employee security risk scoring module is further configured to provide for dynamic user-addition or user-subtraction to the plurality of security risk categories without requiring change to the employee security risk scoring logic. 7. The apparatus of claim 1 , wherein the predetermined employee parameter is further defined as a level within an employer hierarchy. 8. The apparatus of claim 7 , wherein the predetermined employee parameter is further defined as one of job title or business unit.
Personal security, identity or safety · CPC title
Office automation; Time management · CPC title
Human resources · CPC title
Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.