17544431. COMPLIANCE AGGREGATION simplified abstract (INTERNATIONAL BUSINESS MACHINES CORPORATION)

From WikiPatents
Jump to navigation Jump to search

COMPLIANCE AGGREGATION

Organization Name

INTERNATIONAL BUSINESS MACHINES CORPORATION

Inventor(s)

Anca Sailer of Scarsdale NY (US)

Ramamurthy Vaidhyanathan of Cupertino CA (US)

Nataraj Nagaratnam of Cary NC (US)

COMPLIANCE AGGREGATION - A simplified explanation of the abstract

This abstract first appeared for US patent application 17544431 titled 'COMPLIANCE AGGREGATION

Simplified Explanation

The patent application describes a method for assessing the compliance of a cloud deployment with security definitions provided by the owner, based on the customer's profile and intended use of the cloud deployment. The method uses automated assessment tools to generate a compliance posture, which is then provided to a reviewer.

  • The method receives security definitions from the owner of a cloud deployment.
  • It also receives a customer profile with the customer's intents for using the cloud deployment.
  • Automated assessment tools are used to assess the compliance of the cloud deployment with the security definitions, taking into account the customer's intents.
  • Based on the assessment, a compliance posture is generated.
  • The compliance posture is then provided to a reviewer.

Potential Applications

  • Cloud service providers can use this method to ensure that their cloud deployments comply with the security requirements of their customers.
  • Customers can use this method to assess the compliance of a cloud deployment before using it, ensuring that their security needs are met.

Problems Solved

  • Ensures that a cloud deployment meets the security requirements defined by the owner.
  • Provides an automated and efficient way to assess compliance with security definitions.
  • Allows customers to have visibility into the compliance posture of a cloud deployment before using it.

Benefits

  • Streamlines the process of assessing compliance with security definitions.
  • Reduces the manual effort required for compliance assessment.
  • Provides customers with confidence in the security posture of a cloud deployment.


Original Abstract Submitted

A method includes receiving, by a computing device, security definitions from an owner of a cloud deployment; receiving, by the computing device, a customer profile having intents to use the cloud deployment; assessing, by the computing device and using automated assessment tools, compliance of the cloud deployment with the security definitions in view of the intents; generating, by the computing device, a compliance posture using the assessment; and providing, by the computing device, the compliance posture to a reviewer.