×

Method and a software system for end-to-end security assessment for security and CIP professionals

  • US 20070143849A1
  • Filed: 12/19/2005
  • Published: 06/21/2007
  • Est. Priority Date: 12/19/2005
  • Status: Abandoned Application
First Claim
Patent Images

1. A method for implementing end-to-end security assessment (EESA) for use by Security and CIP professionals for large, complex, critical infrastructure (LCCI) systems, comprsing:

  • determining security policy and sensitivity levels of data;

    identifying and analyzing critical business-derived information flows for the layers, security mechanisms, formats and communications protocols of the system;

    assessing each of said information flows for security gaps;

    determining the risk level of each of said information flows by applying a formula that takes into account the threat, its likelihood and its potential impact on the system;

    comparing the required defence levels to said security mechanisms, listing all gaps found according to a prioritization process that determines the urgency of closing each gap and creating a detailed list of the prioritized gaps; and

    offering specific countermeasures to close each of said gaps, wherein emphasis is put on optimizing said countermeasures.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×