US2022263870A1PendingUtilityA1

Determining relevant security policy data based on cloud environment

Assignee: AT & T IP I LPPriority: May 20, 2020Filed: May 3, 2022Published: Aug 18, 2022
Est. expiryMay 20, 2040(~13.8 yrs left)· nominal 20-yr term from priority
H04L 63/205H04L 69/321H04L 67/10H04L 67/1001
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method for returning security policy requirements data based on user input that identifies a cloud environments, a service model, first or third party responsibilities, and/or code deployment information is disclosed. A user provides answers to straightforward, generally non-expert questions directed to the user's cloud environment, first or third party responsibilities, and/or code deployment information for the user's scenario, e.g., technical workload. The answers result in determining which architecture layers apply (are in-scope architecture layers) relevant to the user's scenario. The in-scope architecture layers map to security requirements maintained in a security policy data store. The security requirements are returned (e.g., as a list) in response to the user's answers.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system, comprising:
 a processor; and   a memory that stores executable instructions which, when executed by the processor, facilitate performance of operations, the operations comprising:
 engaging in a question and answer wizard interaction based on user input associated with a user identity, comprising:
 receiving first user input data, associated with the user identity, identifying a specified cloud environment of available cloud environments, 
 based on the specified cloud environment, presenting a question via a user interface related to identifying in-scope architecture layers for the specified cloud environment, 
 in response to the question, receiving second user input data, associated with the user identity, comprising an answer to the question, 
 based on the answer, determining security policy requirement data corresponding to identified in-scope architecture layers associated with the answer, and 
 presenting the security policy requirement data via the user interface. 
 
   
     
     
         2 . The system of  claim 1 , wherein the security policy requirement data comprises first party enterprise security policy requirement data. 
     
     
         3 . The system of  claim 1 , wherein the security policy requirement data comprises contract-specific security policy requirement data. 
     
     
         4 . The system of  claim 1 , wherein the answer indicates whether the specified cloud environment is a first party enterprise cloud environment or a third party enterprise cloud environment. 
     
     
         5 . The system of  claim 1 , wherein the answer indicates whether the user identity is associated with a cloud tenant identity or a cloud owner identity. 
     
     
         6 . The system of  claim 1 , wherein the answer identifies code deployment implementation information. 
     
     
         7 . The system of  claim 1 , wherein the in-scope architecture layers are selected from a group of architecture layers comprising a data layer, an interface layer, an application layer, a solution stack layer, an operating systems layer, a virtual machines layer, a container layer, a virtual networks layer, a hypervisor layer, a processing and memory layer, a data storage layer, a physical network layer, and a physical facilities layer. 
     
     
         8 . A method, comprising:
 receiving, by a system comprising a processor, first user input identifying a selected cloud environment of cloud environments,   based on the selected cloud environment, displaying, by the system, a question related to identifying in-scope architecture layers for the specified cloud environment,   in response to the question, receiving, by the system, second user input comprising an answer to the question,   based on the answer, determining, by the system, security policy requirement data corresponding to identified in-scope architecture layers associated with the answer, and displaying, by the system, the security policy requirement data.   
     
     
         9 . The method of  claim 8 , wherein the security policy requirement data comprises first party enterprise security policy requirement data. 
     
     
         10 . The method of  claim 8 , wherein the security policy requirement data comprises contract-specific security policy requirement data. 
     
     
         11 . The method of  claim 8 , wherein the answer specifies whether the selected cloud environment is a first party enterprise cloud environment or a third party enterprise cloud environment. 
     
     
         12 . The method of  claim 8 , wherein the answer specifies whether a user identity associated with the first user input is a cloud tenant or a cloud owner. 
     
     
         13 . The method of  claim 8 , wherein the answer identifies first party responsibility information. 
     
     
         14 . The method of  claim 8 , wherein the in-scope architecture layers are selected from a group of architecture layers comprising at least two of a data layer, an interface layer, an application layer, a solution stack layer, an operating systems layer, a virtual machines layer, a container layer, a virtual networks layer, a hypervisor layer, a processing and memory layer, a data storage layer, a physical network layer, or a physical facilities layer. 
     
     
         15 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processor, facilitate performance of operations, comprising:
 receiving, via an interactive user interface, first input information identifying a cloud environment of a group of cloud environments,   based on the cloud environment, outputting, via the interactive user interface, a question related to identifying in-scope architecture layers for the cloud environment,   in response to the question, receiving, via the interactive user interface, second input information comprising an answer to the question,   based on the answer, determining security policy requirement data corresponding to identified in-scope architecture layers associated with the answer, and   outputting, via the interactive user interface, the security policy requirement data.   
     
     
         16 . The non-transitory machine-readable medium of  claim 15 , wherein the security policy requirement data comprises first party enterprise security policy requirement data. 
     
     
         17 . The non-transitory machine-readable medium of  claim 15 , wherein the security policy requirement data comprises contract-specific security policy requirement data. 
     
     
         18 . The non-transitory machine-readable medium of  claim 15 , wherein the answer specifies whether the cloud environment is a first party enterprise cloud environment or a third party enterprise cloud environment. 
     
     
         19 . The non-transitory machine-readable medium of  claim 15 , wherein the answer specifies whether a user identity associated with the first input information identifies a cloud tenant or a cloud owner. 
     
     
         20 . The non-transitory machine-readable medium of  claim 15 , wherein the in-scope architecture layers are selected from any of a data layer, an interface layer, an application layer, a solution stack layer, an operating systems layer, a virtual machines layer, a container layer, a virtual networks layer, a hypervisor layer, a processing and memory layer, a data storage layer, a physical network layer, or a physical facilities layer.

Join the waitlist — get patent alerts

Track US2022263870A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.