US2022247793A1PendingUtilityA1

Scanning and remediating configuration settings of a device using a policy-driven approach

Assignee: VMWARE INCPriority: Sep 7, 2018Filed: Apr 18, 2022Published: Aug 4, 2022
Est. expirySep 7, 2038(~12.1 yrs left)· nominal 20-yr term from priority
Inventors:Thomas S. Hatch
H04L 41/0866H04L 41/0816H04L 41/0894H04L 63/20H04L 63/205
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present disclosure relates to systems, methods, and computer-readable media for implementing an efficient and flexible policy-driven approach to securing a computing device. For example, systems disclosed herein can enforce a first security policy of a first security standard. Systems disclosed herein can further audit for a first compliance level with the first security standard. Systems disclosed herein can further audit for a second compliance level with a second security standard. Systems disclosed herein can further determine an overlap between the first security standard and the second security standard, the overlap associated with a second security policy. Systems disclosed herein can further enforce the second security standard. Systems disclosed herein can further determine an update of the first compliance level based on the overlap.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An apparatus comprising:
 at least one memory;   instructions in the apparatus; and   processor circuitry to execute the instructions to:
 enforce a first security policy of a first security standard; 
 audit for a first compliance level with the first security standard; 
 audit for a second compliance level with a second security standard; 
 determine an overlap between the first security standard and the second security standard, the overlap associated with a second security policy; 
 enforce the second security standard; and 
 determine an update of the first compliance level based on the overlap. 
   
     
     
         2 . The apparatus of  claim 1 , wherein the processor circuitry is to execute the instructions to enforce at least one of the first security policy or the second security policy with an idempotent operation in which a check and a fix of the security policy are the same operation. 
     
     
         3 . The apparatus of  claim 1 , wherein the processor circuitry is to execute the instructions to:
 determine whether an exemption applies to at least one of the first or second security policies and   in response to a determination that the exemption applies to the at least one of the first or second security policies, bypass enforcement of the at least one of the first or second security policies.   
     
     
         4 . The apparatus of  claim 1 , wherein the processor circuitry is to execute the instructions to generate a compliance report indicating a measure of compliance with at least one of the first security standard or the second security standard. 
     
     
         5 . The apparatus of  claim 1 , wherein the processor circuitry is to execute the instructions to generate mapping information associating a plurality of security policies to a plurality of security standards. 
     
     
         6 . The apparatus of  claim 5 , wherein the mapping information includes information indicating the overlap between the first security standard and the second security standard. 
     
     
         7 . The apparatus of  claim 1 , wherein compliance with a security standard includes configuration settings of an application or operating system on a client device. 
     
     
         8 . The apparatus of  claim 1 , wherein the processor circuitry is to determine the update of the first compliance level based on the overlap before performing an additional audit of the first compliance level. 
     
     
         9 . A non-transitory computer readable storage medium comprising instructions which, when executed, cause processor circuitry to at least:
 enforce a first security policy of a first security standard;   audit for a first compliance level with the first security standard;   audit for a second compliance level with a second security standard;   determine an overlap between the first security standard and the second security standard, the overlap associated with a second security policy;   enforce the second security standard; and   determine an update of the first compliance level based on the overlap.   
     
     
         10 . The non-transitory computer readable storage medium of  claim 9 , wherein the instructions, when executed, cause the processor circuitry to enforce at least one of the first security policy or the second security policy with an idempotent operation in which a check and a fix of the security policy are the same operation. 
     
     
         11 . The non-transitory computer readable storage medium of  claim 9 , wherein the instructions, when executed, cause the processor circuitry to:
 determine whether an exemption applies to at least one of the first or second security policies; and   in response to a determination that the exemption applies to the at least one of the first or second security policies, bypass enforcement of the at least one of the first or second security policies.   
     
     
         12 . The non-transitory computer readable storage medium of  claim 9 , wherein the instructions, when executed, cause the processor circuitry to generate a compliance report indicating a measure of compliance with at least one of the first security standard or the second security standard. 
     
     
         13 . The non-transitory computer readable storage medium of  claim 9 , wherein the instructions, when executed, cause the processor circuitry to generate mapping information associating a plurality of security policies to a plurality of security standards. 
     
     
         14 . The non-transitory computer readable storage medium of  claim 13 , wherein the mapping information includes information indicating the overlap between the first security standard and the second security standard. 
     
     
         15 . The non-transitory computer readable storage medium of  claim 9 , wherein compliance with a security standard includes configuration settings of an application or operating system on a client device. 
     
     
         16 . The non-transitory computer readable storage medium of  claim 9 , wherein the instructions, when executed, cause the processor circuitry to determine the update of the first compliance level based on the overlap before performing an additional audit of the first compliance level. 
     
     
         17 . A method comprising:
 enforcing, by executing an instruction with a processor, a first security policy of a first security standard;   auditing, by executing an instruction with the processor, for a first compliance level with the first security standard;   auditing, by executing an instruction with the processor, for a second compliance level with a second security standard;   determining, by executing an instruction with the processor, an overlap between the first security standard and the second security standard, the overlap associated with a second security policy;   enforcing, by executing an instruction with the processor, the second security standard; and   determining, by executing an instruction with the processor, an update of the first compliance level based on the overlap.   
     
     
         18 . The method of  claim 17 , further including enforcing at least one of the first security policy or the second security policy with an idempotent operation in which a check and a fix of the security policy are the same operation. 
     
     
         19 . The method of  claim 17 , further including:
 determining whether an exemption applies to at least one of the first or second security policies; and   in response to determining that the exemption applies to the at least one of the first or second security policies, bypassing enforcement of the at least one of the first or second security policies.   
     
     
         20 . The method of  claim 17 , further including generating a compliance report indicating a measure of compliance with at least one of the first security standard or the second security standard. 
     
     
         21 . The method of  claim 17 , further including generating mapping information associating a plurality of security policies to a plurality of security standards. 
     
     
         22 . The method of  claim 21 , wherein the mapping information includes information indicating the overlap between the first security standard and the second security standard. 
     
     
         23 . The method of  claim 17 , wherein compliance with a security standard includes configuration settings of an application or operating system on a client device. 
     
     
         24 . The method of  claim 17 , further including determining the update of the first compliance level based on the overlap before performing an additional audit of the first compliance level.

Join the waitlist — get patent alerts

Track US2022247793A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.