Security compliance framework deployment

US9699218B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9699218-B1
Application numberUS-201615284099-A
CountryUS
Kind codeB1
Filing dateOct 3, 2016
Priority dateOct 3, 2016
Publication dateJul 4, 2017
Grant dateJul 4, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method and system for improving deployment of a security compliance framework is provided. The method includes deploying a data store that includes an authoritative source of information comprising configuration and operational management requirements associated with IT devices. A component comprising an interface for an authoritative source configured to provide authentication and authorization for access to servers of the IT devices is deployed and configured to enable authentication and privilege management for access to deployed and configured authoritative source components. An API interface and compliance framework management components are deployed and configured and message transfer agent API endpoint components of the compliance framework are identified. In response, operation of the compliance framework is enabled with respect to the data store, the authoritative source components, the API interface, the compliance framework management components, and the API endpoint components.

First claim

Opening claim text (preview).

What is claimed is: 1. A security compliance framework deployment improvement method comprising: deploying, by a processor of a compliance framework, a data store comprising an authoritative source of information comprising configuration and operational management requirements associated with Information Technology (IT) devices; deploying, by said processor, a component comprising an interface for an authoritative source configured to provide authentication and authorization for access to servers of said IT devices; configuring, by said processor, said component for enabling authentication and privilege management for access to authoritative source components comprising said IT devices; deploying, by said processor, said authoritative source components; configuring, by said processor, said authoritative source components for logging security events to a source component data store; deploying and configuring, by said processor, an Application Programming Interface (API) interface; deploying and configuring, by said processor, compliance framework management components; identifying, by said processor, message transfer agent API endpoint components of said compliance framework; and enabling, by said processor, operation of said compliance framework with respect to said data store, said authoritative source components, said API interface, said compliance framework management components, and said API endpoint components. 2. The method of claim 1 , wherein said deploying and configuring said API interface comprises: deploying API components of said API interface with respect to said IT devices, wherein said IT devices comprise managed IT devices; and configuring said API interface to write copies of API requests to said data store. 3. The method of claim 2 , wherein said API components comprise a gateway based router configuration for allowing only approved requests to communicate with tools of said compliance framework. 4. The method of claim 1 , wherein said compliance framework management components comprise user interface components, and wherein said deploying and configuring said compliance framework management components comprises: associating said user interface components with execution keys and associated tokens of said API interface; and configuring via said user interface components, said authoritative source components with respect to specified permission for interaction with said content framework. 5. The method of claim 1 , further comprising: deploying, by said processor, management dashboard components comprising an architectural configuration associated with said IT devices; and configuring, by said processor, specified permission for interaction with said content framework for a hardware/software tool for use with said API interface. 6. The method of claim 1 , further comprising: deploying, by said processor, reporting engine components comprising an architectural configuration associated with said IT devices; and authenticating, by said processor, specified permission for interaction with said content framework for a hardware/software tool for use with said API interface. 7. The method of claim 1 , wherein said API endpoint components are associated with a message transfer agent, and wherein said method further comprises: determining, by said processor, a task completion time for each request associated with said message transfer agent. 8. The method of claim 1 , further comprising: enabling, by said processor, a content framework password for a hardware/software tool for use with said content framework, said content framework password unknown by a user of said content framework. 9. The method of claim 1 , further comprising: aligning, by said processor, a logging configuration of a hardware/software tool with requirements of said content framework. 10. The method of claim 1 , further comprising: configuring, by said processor, said data store such that said data store is only configured to accept write requests from pre-identified hardware sources of said compliance framework. 11. The method of claim 1 , wherein said configuring said authoritative source components further comprises: initializing first credentials for allowing application programming interface (API) servers to interact with compliance framework components of said compliance framework; and initializing second credentials for allowing said compliance framework to interact with said compliance framework components, and accepting default profiles comprising authorization permission. 12. The method of claim 1 , further comprising: providing at least one support service for at least one of creating, integrating, hosting, maintaining, and deploying computer-readable code in the hardware device, said code being executed by the computer processor to implement: said deploying said data store, said deploying said component, said configuring said component, said deploying said authoritative source components, said configuring said authoritative source components, said deploying and configuring said API interface, said deploying and configuring said compliance framework management components, said identifying, and said enabling. 13. A computer program product, comprising a computer readable hardware storage device storing a computer readable program code, said computer readable program code comprising an algorithm that when executed by a processor of a compliance framework implements a security compliance framework deployment improvement method, said method comprising: deploying, by said processor, a data store comprising an authoritative source of information comprising configuration and operational management requirements associated with Information Technology (IT) devices; deploying, by said processor, a component comprising an interface for an authoritative source configured to provide authentication and authorization for access to servers of said IT devices; configuring, by said processor, said component for enabling authentication and privilege management for access to authoritative source components comprising said IT devices; deploying, by said processor, said authoritative source components; configuring, by said processor, said authoritative source components for logging security events to a source component data store; deploying and configuring, by said processor, an Application Programming Interface (API) interface; deploying and configuring, by said processor, compliance framework management components; identifying, by said processor, message transfer agent API endpoint components of said compliance framework; and enabling, by said processor, operation of said compliance framework with respect to said data store, said authoritative source components, said API interface, said compliance framework management components, and said API endpoint components. 14. The computer program product of claim 13 , wherein said deploying and configuring said API interface comprises: deploying API components of said API interface with respect to said IT devices, wherein said IT devices comprise managed IT devices; and configuring said API interface to write copies of API requests to said data store. 15. A compliance framework comprising a processor coupled to a computer-readable memory unit, said memory unit comprising instructions that when executed by the processor implements a security compliance framework deployment improvement method comprising: deploying, by said processor, a data store comprising an authoritative source of information comprising configuration and operational management requirements

Assignees

Inventors

Classifications

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • for controlling access to devices or network resources · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9699218B1 cover?
A method and system for improving deployment of a security compliance framework is provided. The method includes deploying a data store that includes an authoritative source of information comprising configuration and operational management requirements associated with IT devices. A component comprising an interface for an authoritative source configured to provide authentication and authorizat…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 04 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).