Dynamic optimizing scanner for identity and access management (IAM) compliance verification

    公开(公告)号:US09942261B2

    公开(公告)日:2018-04-10

    申请号:US15464746

    申请日:2017-03-21

    IPC分类号: G06F12/14 H04L29/06

    摘要: An identity and access management (IAM) system is associated with a set of data sources from which data is collected. A set of vulnerabilities that the IAM system should attempt to detect is identified. For each vulnerability to be detected, a prioritized list of strategies used to detect that vulnerability is generated. Preferably, each strategy specifies the type(s) of data required to detect that vulnerability. An algorithm to determine a best strategy to be used for detecting each vulnerability, preferably based on the data available from the data sources, is then identified. The IAM system then collects data in an optimized manner. In particular, during the collection process, the IAM system preferably collects only what is necessary based on the configuration, even if the data source is capable of providing additional data. The collected data is then processed to detect security vulnerabilities associated with the IAM accounts.

    SELF-PUBLISHED SECURITY RISK MANAGEMENT
    69.
    发明申请

    公开(公告)号:US20180083999A1

    公开(公告)日:2018-03-22

    申请号:US15271655

    申请日:2016-09-21

    发明人: Mathew S. Cherian

    IPC分类号: H04L29/06

    摘要: A method and system for creating a security rating for a sub-entity of an entity. The security rating of the sub-entity is calculated based on an entity map provided by a representative of the entity. The sub-entity map details which assets of an entity belong to one or more of its sub-entities. It is advantageous to know the security rating of a sub-entity of an entity when an at-risk company is making a decision on whether or not to conduct business with a sub-entity whose security rating may different than that of the entity to which it belongs.

    Method and System for Facilitating Management of Service Agreements for Consumer Clarity Over Multiple Channels

    公开(公告)号:US20180083843A1

    公开(公告)日:2018-03-22

    申请号:US15707905

    申请日:2017-09-18

    申请人: Anand Sambandam

    发明人: Anand Sambandam

    IPC分类号: H04L12/24 H04W8/18 G06F21/57

    摘要: Disclosed is a method for facilitating management of at least one service agreement associated with a user and at least one service provider. The method may include receiving, using a communication device, a service agreement from a service provider system. Further, the method may include performing, using a processing device, one or more of analyzing the service agreement, identifying at least one collectable data associated with the user account and identifying at least one action associated with the at least one collectable data. Further, the method may include storing, using a storage device, each of the at least one collectable data and the at least one action in association with the service agreement. Further, the method may include transmitting, using the communication device, each of the at least one collectable data and the at least one action to a user device associated with the user account.