Invention Application
- Patent Title: AUTOMATED HEALTH-CHECK RISK ASSESSMENT OF COMPUTING ASSETS
-
Application No.: US17078563Application Date: 2020-10-23
-
Publication No.: US20220129560A1Publication Date: 2022-04-28
- Inventor: Muhammed Fatih Bulut , Milton H. Hernandez , Robert Filepp , Sai Zeng , Steven Ocepek , Srinivas Babu Tummalapenta , Daniel S. Riley
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06N20/00

Abstract:
Systems and techniques that facilitate automated health-check risk assessment of computing assets are provided. In various embodiments, a system can comprise a baseline component that can generate a baseline health-check risk score that corresponds to non-compliance of a computing asset with a stipulated control. In various aspects, the system can further comprise an adjustment component that can adjust the baseline health-check risk score based on a weakness factor of the stipulated control. In some cases, the weakness factor can be based on a magnitude by which a state of the computing asset deviates from the stipulated control. In various embodiments, the adjustment component can further adjust the baseline health-check risk score based on an environmental factor of the computing asset. In various cases, the environmental factor can be based on security mechanisms or security protocols associated with the computing asset. In various embodiments, the adjustment component can further adjust the baseline health-check risk score based on a criticality factor. In some instances, the critical factor can be based on a level of importance of the computing asset. In various embodiments, the adjustment component can further adjust the baseline health-check risk score based on a maturity factor. In some aspects, the maturity factor can be based on a difference between the stipulated control and a recommended control.
Public/Granted literature
- US12032702B2 Automated health-check risk assessment of computing assets Public/Granted day:2024-07-09
Information query