Abstract: Determining policy content-based controls for real-time security and compliance monitoring including receiving, from a user computing system, a user-generated policy document associated with an organization; creating a set of user-generated control language records from the user-generated policy document, wherein each user-generated control language record corresponds to a description of a control in the user-generated policy document; converting each user-generated control language record in the set of user-generated control language records into a user-generated control language code; matching each user-generated control language code to a stock control language code within a stock control language code repository; and presenting, on the user computing system, the set of controls associated with the matched stock control language codes as controls for the user-generated policy document.
Abstract: Categorizing policy-based control mapping for real-time security and compliance monitoring including receiving, by a security and compliance monitor, a request for a control mapping score indicating an affinity between a user-generated policy document and a proposed control, wherein the proposed control is a measurable component exposed by a services provider of an organization, and wherein the proposed control is intended to indicate a level of compliance of the organization with the user-generated policy document; determining, by the security and compliance monitor from a group of template policy documents, a best-matching template policy document for the user-generated policy document; generating, by the security and compliance monitor, the control mapping score based on previous mappings between the proposed control and the best-matching template policy document; and providing, by the security and compliance monitor to a user computing system, the control mapping score for the proposed control mapped to t
Abstract: Automated trust center for real-time security and compliance monitoring including maintaining, for an organization, a plurality of control statuses for a trust center report, including: retrieving control status responses from a group of services providers of the organization, wherein each control status response is associated with a control in the trust center report; and determining, based on the control status responses, a control status for each control of the trust center report; receiving a request for the trust center report from an organization client; generating, in real-time, the trust center report using the control statuses for each control; and providing, to the organization client, the trust center report generated in real-time using the control statuses for each control.
Type:
Grant
Filed:
August 29, 2022
Date of Patent:
October 1, 2024
Assignee:
DRATA INC.
Inventors:
Brian S. Elmi, Ross W. Hosman, Adam R. Markowitz, Daniel Zev Marashlian