Risk information output device, information output system, risk information output method, and recording medium
US-2024414180-A1 · Dec 12, 2024 · US
US2016234239A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016234239-A1 |
| Application number | US-201514871136-A |
| Country | US |
| Kind code | A1 |
| Filing date | Sep 30, 2015 |
| Priority date | Feb 11, 2015 |
| Publication date | Aug 11, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
This disclosure provides systems and methods for tying cyber-security risk analysis to common risk methodologies and risk levels. A method includes identifying a plurality of connected devices that are vulnerable to cyber-security risks and identifying cyber-security risks in the connected devices. The method includes assigning a risk level to each of the risks and comparing the risk levels to a first threshold and to a second threshold. The method includes assigning each identified cyber-security risk to a risk classification and displaying a user interface that includes a notification according to the identified cyber-security risks and the corresponding assigned risk classifications.
Opening claim text (preview).
What is claimed is: 1 . A method comprising: identifying, by a risk manager system, a plurality of connected devices that are vulnerable to cyber-security risks; identifying, by the risk manager system, cyber-security risks in the connected devices; assigning, by the risk manager system, a risk level to each of the identified cyber-security risks; for each identified cyber-security risk, comparing by the risk manager system the assigned risk level to a first threshold and to a second threshold; based on the comparisons, assigning, by the risk manager system, each identified cyber-security risk to a risk classification; and displaying, by the risk manager system, a user interface that includes a notification according to the identified cyber-security risks and the corresponding assigned risk classifications. 2 . The method of claim 1 , wherein the first threshold is a risk appetite and the second threshold is a risk tolerance. 3 . The method of claim 1 , wherein the risk manager system also receives the first and second threshold from a user. 4 . The method of claim 1 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is less than both the first threshold and the second threshold to a low-priority classification or a notification classification. 5 . The method of claim 1 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is greater than or equal to the first threshold but is less than the second threshold to a warning classification. 6 . The method of claim 1 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is greater than or equal to both the first threshold and the second threshold to an alert classification. 7 . The method of claim 1 , wherein the risk manager system prompts a user for an action in response to displaying the notification. 8 . A risk manager system comprising: a controller; and a display, the risk manager system configured to identify a plurality of connected devices that are vulnerable to cyber-security risks; identify cyber-security risks in the connected devices; assign a risk level to each of the identified cyber-security risks; for each identified cyber-security risk, compare the assigned risk level to a first threshold and to a second threshold; based on the comparisons, assign each identified cyber-security risk to a risk classification by the risk manager system; and display a user interface that includes a notification according to the identified cyber-security risks and the corresponding assigned risk classifications. 9 . The risk manager system of claim 8 , wherein the first threshold is a risk appetite and the second threshold is a risk tolerance. 10 . The risk manager system of claim 8 , wherein the risk manager system also receives the first and second threshold from a user. 11 . The risk manager system of claim 8 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is less than both the first threshold and the second threshold to a low-priority classification or a notification classification. 12 . The risk manager system of claim 8 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is greater than or equal to the first threshold but is less than the second threshold to a warning classification. 13 . The risk manager system of claim 8 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is greater than or equal to both the first threshold and the second threshold to an alert classification. 14 . The risk manager system of claim 8 , wherein the risk manager system prompts a user for an action in response to displaying the notification. 15 . A non-transitory machine-readable medium encoded with executable instructions that, when executed, cause one or more processors of a risk manager system to: identify a plurality of connected devices that are vulnerable to cyber-security risks; identify cyber-security risks in the connected devices; assign a risk level to each of the identified cyber-security risks; for each identified cyber-security risk, compare the assigned risk level to a first threshold and to a second threshold; based on the comparisons, assign each identified cyber-security risk to a risk classification by the risk manager system; and display a user interface that includes a notification according to the identified cyber-security risks and the corresponding assigned risk classifications. 16 . The non-transitory machine-readable medium of claim 15 , wherein the first threshold is a risk appetite and the second threshold is a risk tolerance. 17 . The non-transitory machine-readable medium of claim 15 , wherein the risk manager system also receives the first and second threshold from a user. 18 . The non-transitory machine-readable medium of claim 15 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is less than both the first threshold and the second threshold to a low-priority classification or a notification classification. 19 . The non-transitory machine-readable medium of claim 15 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is greater than or equal to the first threshold but is less than the second threshold to a warning classification. 20 . The non-transitory machine-readable medium of claim 15 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is greater than or equal to both the first threshold and the second threshold to an alert classification.
Management of faults, events, alarms or notifications · CPC title
Assessing vulnerabilities and evaluating computer system security · CPC title
Vulnerability analysis · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.