Apparatus and method for tying cyber-security risk analysis to common risk methodologies and risk levels

US2016234239A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016234239-A1
Application numberUS-201514871136-A
CountryUS
Kind codeA1
Filing dateSep 30, 2015
Priority dateFeb 11, 2015
Publication dateAug 11, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

This disclosure provides systems and methods for tying cyber-security risk analysis to common risk methodologies and risk levels. A method includes identifying a plurality of connected devices that are vulnerable to cyber-security risks and identifying cyber-security risks in the connected devices. The method includes assigning a risk level to each of the risks and comparing the risk levels to a first threshold and to a second threshold. The method includes assigning each identified cyber-security risk to a risk classification and displaying a user interface that includes a notification according to the identified cyber-security risks and the corresponding assigned risk classifications.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising: identifying, by a risk manager system, a plurality of connected devices that are vulnerable to cyber-security risks; identifying, by the risk manager system, cyber-security risks in the connected devices; assigning, by the risk manager system, a risk level to each of the identified cyber-security risks; for each identified cyber-security risk, comparing by the risk manager system the assigned risk level to a first threshold and to a second threshold; based on the comparisons, assigning, by the risk manager system, each identified cyber-security risk to a risk classification; and displaying, by the risk manager system, a user interface that includes a notification according to the identified cyber-security risks and the corresponding assigned risk classifications. 2 . The method of claim 1 , wherein the first threshold is a risk appetite and the second threshold is a risk tolerance. 3 . The method of claim 1 , wherein the risk manager system also receives the first and second threshold from a user. 4 . The method of claim 1 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is less than both the first threshold and the second threshold to a low-priority classification or a notification classification. 5 . The method of claim 1 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is greater than or equal to the first threshold but is less than the second threshold to a warning classification. 6 . The method of claim 1 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is greater than or equal to both the first threshold and the second threshold to an alert classification. 7 . The method of claim 1 , wherein the risk manager system prompts a user for an action in response to displaying the notification. 8 . A risk manager system comprising: a controller; and a display, the risk manager system configured to identify a plurality of connected devices that are vulnerable to cyber-security risks; identify cyber-security risks in the connected devices; assign a risk level to each of the identified cyber-security risks; for each identified cyber-security risk, compare the assigned risk level to a first threshold and to a second threshold; based on the comparisons, assign each identified cyber-security risk to a risk classification by the risk manager system; and display a user interface that includes a notification according to the identified cyber-security risks and the corresponding assigned risk classifications. 9 . The risk manager system of claim 8 , wherein the first threshold is a risk appetite and the second threshold is a risk tolerance. 10 . The risk manager system of claim 8 , wherein the risk manager system also receives the first and second threshold from a user. 11 . The risk manager system of claim 8 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is less than both the first threshold and the second threshold to a low-priority classification or a notification classification. 12 . The risk manager system of claim 8 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is greater than or equal to the first threshold but is less than the second threshold to a warning classification. 13 . The risk manager system of claim 8 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is greater than or equal to both the first threshold and the second threshold to an alert classification. 14 . The risk manager system of claim 8 , wherein the risk manager system prompts a user for an action in response to displaying the notification. 15 . A non-transitory machine-readable medium encoded with executable instructions that, when executed, cause one or more processors of a risk manager system to: identify a plurality of connected devices that are vulnerable to cyber-security risks; identify cyber-security risks in the connected devices; assign a risk level to each of the identified cyber-security risks; for each identified cyber-security risk, compare the assigned risk level to a first threshold and to a second threshold; based on the comparisons, assign each identified cyber-security risk to a risk classification by the risk manager system; and display a user interface that includes a notification according to the identified cyber-security risks and the corresponding assigned risk classifications. 16 . The non-transitory machine-readable medium of claim 15 , wherein the first threshold is a risk appetite and the second threshold is a risk tolerance. 17 . The non-transitory machine-readable medium of claim 15 , wherein the risk manager system also receives the first and second threshold from a user. 18 . The non-transitory machine-readable medium of claim 15 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is less than both the first threshold and the second threshold to a low-priority classification or a notification classification. 19 . The non-transitory machine-readable medium of claim 15 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is greater than or equal to the first threshold but is less than the second threshold to a warning classification. 20 . The non-transitory machine-readable medium of claim 15 , wherein the risk manager system assigns identified cyber-security risks with an assigned risk level that is greater than or equal to both the first threshold and the second threshold to an alert classification.

Assignees

Inventors

Classifications

  • Management of faults, events, alarms or notifications · CPC title

  • Assessing vulnerabilities and evaluating computer system security · CPC title

  • Vulnerability analysis · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016234239A1 cover?
This disclosure provides systems and methods for tying cyber-security risk analysis to common risk methodologies and risk levels. A method includes identifying a plurality of connected devices that are vulnerable to cyber-security risks and identifying cyber-security risks in the connected devices. The method includes assigning a risk level to each of the risks and comparing the risk levels to …
Who is the assignee on this patent?
Honeywell Int Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1433. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Aug 11 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).