发明授权
- 专利标题: Security control verification and monitoring subsystem for use in a computer information database system
- 专利标题(中): 用于计算机信息数据库系统的安全控制验证和监控子系统
-
申请号: US11387424申请日: 2006-03-23
-
公开(公告)号: US08225409B2公开(公告)日: 2012-07-17
- 发明人: Gary H. Newman , Richard M. DeFuria
- 申请人: Gary H. Newman , Richard M. DeFuria
- 申请人地址: US MA Maynard
- 专利权人: Belarc, Inc.
- 当前专利权人: Belarc, Inc.
- 当前专利权人地址: US MA Maynard
- 代理机构: Cesari and McKenna, LLP
- 代理商 Patricia A. Sheehan
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
A security control verification and monitoring subsystem of a managed computer system performs security control verification operations regularly and for each security control verification operation determines the applicable security benchmark level for use by a given computer. The subsystem assigns security risk categories to groups of computers based, for example, on overall system or group administrator supplied potential impact settings and/or system type and business or information type selections. The subsystem further associates the security risk categories with security benchmark levels based on mapping information supplied by the overall system or group administrator. The subsystem then directs the computer to benchmark definition files based on the assigned security risk category, the associated security benchmark level and attributes of the computer. The subsystem performs the security control verification operations whenever the computer performs computer profile data update operations, and thus, monitors essentially continuously the security control compliance of the computer. The subsystem stores the results of the security verification operations and includes the results in reports for the system, group or computer.
公开/授权文献
信息查询