发明名称 ASSESSMENT TYPE-VARIABLE ENTERPRISE SECURITY IMPACT ANALYSIS
摘要 A data management service identifies sensitive data stored on enterprise databases according to record classification rules that classify a data record as having a sensitive data type if the data record includes fields matching at least one of the record classification rules. Methods and systems rely on a set of impact factors each having a set of set of value bands representing a range for the impact factor and a corresponding value (between 0 and 1). The factors, ranges, and values all are customizable for an organization. Impact scoring calculations take into account each of the impact factors, and each is weighted to represent a specific risk perception or assessment type. A similar impact scoring is applied to data quality using volume of data as a key attribute of the quality.
申请公布号 US2015326601(A1) 申请公布日期 2015.11.12
申请号 US201514708089 申请日期 2015.05.08
申请人 Informatica Corporation 发明人 Grondin Richard;Gupta Rahul;Kumaresan Bala
分类号 H04L29/06;G06F21/57;G06F17/30 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method of determining an impact of a selected data element on enterprise security, comprising: retrieving data comprising a set of data elements for risk analysis; receiving for each of a plurality of impact factors in the analysis, a set of value bands, each value band representing a predetermined range for an impact factor and an associated value, wherein the impact factors comprise: at least one risk factor associated with a measure of a magnitude of a risk to the enterprise attributable to the at least one risk factor;at least one impression metric magnitude factor associated with a measure of a magnitude of an impression metric on the enterprise; for each impact factor for a selected data element from the set of data elements: determining the value band range that matches the value of the data element; andobtaining the value associated with the determined value band; receiving a set of assessment type weights for a selected assessment type, wherein each weight in the set of assessment type weights pairs with a corresponding at least one risk factor or at least one impression metric magnitude factor of the plurality of impact factors; and determining an element impact for the selected data element according to the selected assessment type by: applying the set of assessment type weights to the obtained values for the impact factors to calculate at least one risk factor score corresponding to the at least one risk factor and at least one impression metric magnitude factor score corresponding to the at least one impression metric magnitude factor; andcalculating the element impact as the product of the at least one risk factor score and the at least one impression metric magnitude factor score.
地址 Redwood City CA US