×

Apparatus and method for tying cyber-security risk analysis to common risk methodologies and risk levels

  • US 10,298,608 B2
  • Filed: 09/30/2015
  • Issued: 05/21/2019
  • Est. Priority Date: 02/11/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method to provide an action based on cyber-security risk classifications in an industrial process control and automation system comprising:

  • identifying, by a risk manager system, a plurality of connected devices within the industrial process control and automation system that are vulnerable to cyber-security risks;

    identifying, by the risk manager system, cyber-security risks in the connected devices;

    assigning, by the risk manager system, a risk level to each of the identified cyber-security risks;

    for each identified cyber-security risk, comparing by the risk manager system the assigned risk level to a first threshold and to a second threshold based on respective risk zones of the industrial process control and automation system, the first and second thresholds associated with the cyber-security risks in the connected devices, wherein the risks could result in unsafe conditions in the industrial process control and automation system;

    based on the comparisons, assigning, by the risk manager system, each identified cyber-security risk to a risk classification;

    displaying, by the risk manager system, a user interface that includes a plurality of notifications according to the identified cyber-security risks and the corresponding assigned risk classifications, the plurality of notifications comprising a general notification including a first shape displayed in a first color, a warning notification including a second shape displayed in a second color, and an alert notification including a third shape displayed in a third color, each of the plurality of notifications comprising a display of a number of the identified cyber-security risks for a corresponding one of the assigned risk classifications; and

    providing, by the risk manager system, an action based on the displaying of the plurality of notifications to the user.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×