Patent Issued for IT Risk Management Framework And Methods (USPTO 10,083,481) - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
October 5, 2018 Newswires
Share
Share
Post
Email

Patent Issued for IT Risk Management Framework And Methods (USPTO 10,083,481)

Obesity, Fitness & Wellness Week

By a News Reporter-Staff News Editor at Obesity, Fitness & Wellness Week -- A patent by the inventors Futch, Jefre E. (Winter Park, FL); Gonczi, Andrew J. (Woodstock, GA); Mason, Roberta J. (Aylesford, GB); Stuckenberg, Ingrid C. (St Helens, OR), filed on February 2, 2006, was published online on October 8, 2018, according to news reporting originating from Alexandria, Virginia, by NewsRx correspondents (see also Oracle America Inc.).

Patent number 10,083,481 is assigned to Oracle America Inc.

The following quote was obtained by the news editors from the background information supplied by the inventors: "Risk transcends every aspect of business. The need to effectively and efficiently manage risk is a well understood, critical success factor in business, especially in functional disciplines such as finance, insurance, legal, marketing, and so forth. As these and other core business functions have grown more and more dependent on Information Technology (IT), managing IT-related risk has emerged as a critical discipline in running a successful business. Further, IT risk management is becoming a key driver for justifying investments in IT infrastructure and engaging in continuous service improvement programs.

"The complexity of an organization's IT ecosystem makes managing IT risk an immense challenge. It requires specific subject matter knowledge at a component, system, and enterprise level. The knowledge required includes what issues may arise given certain conditions, what the measured consequence of these issues are, and how to prioritize and solve these issues.

"IT Risk Management disciplines have primarily focused on specific issues concerning security, disaster recovery and project-related risks. Many of the existing IT Risk Management tools are based on the qualitative views of IT experts versus quantified analysis of data (such as what is used in more mature risk management disciplines related to credit, insurance, or medical risk management).

"Managing IT risks demands a common means to identify, classify, measure, and communicate risk so that individuals across IT and business organizations gain a shared understanding of the risks and take appropriate actions. Regardless of the approach taken, IT Risk Management should assist in balancing the investment required to improve and upgrade IT with the appropriate return in business value from such an investment."

In addition to the background information obtained for this patent, NewsRx journalists also obtained the inventors' summary information for this patent: "In general, in one aspect, the invention relates to a method for treating information technology (IT) risk of an organization including identifying a plurality of IT risks, where each of the plurality of IT risks is based on a known problem and is associated with an IT asset classification and an IT consequence classification, calculating a plurality of IT risk exposure indices, where each of the plurality of IT risk exposure indices is associated with at least one of the plurality of IT risks, adjusting each of the plurality of IT risk exposure indices based on a business impact factor to obtain a business impact index, prioritizing the plurality of IT, risks by adjusting the business impact index based on a risk treatment factor to obtain a prioritized risk treatment index, and selecting at least one of the plurality of IT risks for treatment based upon the prioritized risk treatment index.

"In general, in one aspect, the invention relates to a computer system for treating a plurality of information technology (IT) risks including a processor, a memory, and software instructions stored in the memory for enabling the computer system under the control of the processor, to calculate a plurality of IT risk exposure indices, where each of the plurality of IT risk exposure indices is associated with at least one of the plurality of IT risks, where each of the plurality of IT risk exposure indices is adjusted based on a business impact factor to obtain a business impact index, where the business impact index is adjusted based on a risk treatment factor to obtain a prioritized risk treatment index, and where at least one of the plurality of IT risks is selected for treatment based on the prioritized risk treatment index.

"In general, in one aspect, the invention relates to a computer readable medium storing instructions for treating a plurality of information technology (IT) risks, the instructions including functionality to calculate a plurality of IT risk exposure indices, where each of the plurality of IT risk exposure indices is associated with at least one of the plurality of IT risks, where each of the plurality of IT risk exposure indices is adjusted based on a business impact factor to obtain a business impact index, where the business impact index is prioritized based on a risk treatment factor to obtain a prioritized risk treatment index.

"Other aspects of the invention will be apparent from the following description and the appended claims."

The claims supplied by the inventors are:

"The invention claimed is:

"1. A computer system for selecting an information technology (IT) risk for treatment, comprising: a processor; a memory; and software instructions stored in the memory and configured to be executed by the processor to perform a method, the method comprising: identifying a plurality of IT risks to one or more hardware servers, wherein the plurality of IT risks are risks of outages of a hardware server of the one or more hardware servers, and wherein each of the plurality of IT risks is based on a known problem and is associated with one of a plurality of IT asset classifications and one of a plurality of IT consequence classifications; for each of the plurality of IT risks: determining a probability value (P) to measure a probability of the IT risk occurring, determining a severity value (S) to measure a severity of an impact of IT risk, calculating a subclass IT risk exposure index based on a square root of (P.sup.2+S.sup.2), obtaining a subclass significance value for the subclass IT risk exposure index quantifying the significance of the subclass IT risk to a parent IT risk, calculating a composite IT risk exposure index for the parent IT risk based on a plurality of IT risk exposure indexes and a plurality of significance values, wherein the subclass IT risk exposure index is one of the plurality of IT risk exposure indexes, wherein the subclass significance value is one of the plurality of significance values, and wherein the composite IT risk exposure index is a first quantitative score associated with the IT risk, generating a business impact index based on the composite IT risk exposure index and at least one business impact associated with the IT risk, wherein the business impact index is a second quantitative score associated with the IT risk, and generating a risk treatment index based on the business impact index and at least one factor affecting an ability to treat the IT risk, wherein the risk treatment index is a third quantitative score associated with the IT risk; prioritizing the plurality of IT risks based on the risk treatment index of each IT risk; selecting at least one of the plurality of IT risks for treatment based upon the priority of each of the plurality of IT risks and at least one risk acceptance policy; and treating the selected at least one of the plurality of IT risks by changing one or more system parameters on the hardware server implicated by the at least one of the plurality of IT risks, wherein the one or more system parameters address a corresponding known problem associated with the at least one of the plurality of IT risks causing an outage of the hardware server.

"2. The computer system of claim 1, further comprising software instructions to determine the plurality of IT risk exposure indices, wherein the software instructions enable the computer system to: wherein calculating the subclass IT risk exposure index comprises: plotting a first point representing the IT risk on a risk exposure square, wherein the risk exposure square is a graph having a vertical axis measuring probability values and a horizontal axis measuring severity values.

"3. The computer system of claim 2, wherein calculating the subclass IT risk exposure index further comprises: determining a distance between the first point and a second point on the risk exposure square, wherein the second point corresponds to a zero probability value and a zero severity value.

"4. The computer system of claim 1, wherein the at least one business impact associated with the IT risk comprises at least one selected from a group consisting of business size, market, business system criticality, and risk perception.

"5. The computer system of claim 1, wherein the at least one factor comprises at least one selected from a group consisting of recovery effectiveness, mitigation cost, and risk treatment alternatives.

"6. The computer system of claim 1, wherein treating the selected at least one of the plurality of IT risks comprises treating the at least one of the plurality of IT risks according to a best practice knowledgebase.

"7. The computer system of claim 1, wherein each of the plurality of IT asset classifications comprises one selected from a group consisting of system execution, service operations, solution development, and IT governance.

"8. A non-transitory computer-readable storage medium storing instructions for selecting an information technology (IT) risk for treatment, the instructions executing on a processor and comprising functionality to: identify a plurality of IT risks to one or more hardware servers, wherein the plurality of IT risks are risks of outages of a hardware server of the one or more hardware servers, and wherein each of the plurality of IT risks is based on a known problem and is associated with one of a plurality of IT asset classifications and one of a plurality of IT consequence classifications; for each of the plurality of IT risks: determine a probability value (P) to measure a probability of the IT risk occurring, determine a severity value (S) to measure a severity of an impact of IT risk, calculate a subclass IT risk exposure index based on a square root of (P.sup.2 +S.sup.2), obtain a subclass significance value for the subclass IT risk exposure index quantifying the significance of the subclass IT risk to a parent IT risk, calculate a composite IT risk exposure index for the parent IT risk based on a plurality of IT risk exposure indexes and a plurality of significance values, wherein the subclass IT risk exposure index is one of the plurality of IT risk exposure indexes, wherein the subclass significance value is one of the plurality of significance values, and wherein the composite IT risk exposure index is a first quantitative score associated with the IT risk, generate a business impact index based on the composite IT risk exposure index and at least one business impact associated with the IT risk, wherein the business impact index is a second quantitative score associated with the IT risk, and generate a risk treatment index based on the business impact index and at least one factor affecting an ability to treat the IT risk, wherein the risk treatment index is a third quantitative score associated with the IT risk; prioritize the plurality of IT risks based on the risk treatment index of each IT risk; and select at least one of the plurality of IT risks for treatment based upon the priority of each of the plurality of IT risks and at least one risk acceptance policy; and treat the selected at least one of the plurality of IT risks by changing one or more system parameters on the hardware server implicated by the at least one of the plurality of IT risk, wherein the one or more system parameters address a corresponding known problem associated with the at least one of the plurality of IT risks causing an outage of the hardware server.

"9. The non-transitory computer-readable medium of claim 8, wherein calculating the subclass IT risk exposure index comprises: plotting a first point representing the IT risk on a risk exposure square, wherein the risk exposure square is a graph having a vertical axis measuring probability values and a horizontal axis measuring severity values.

"10. The non-transitory computer-readable medium of claim 9, wherein calculating the subclass IT risk exposure index further comprises: determining a distance between the first point and a second point on the risk exposure square, wherein the second point corresponds to a zero probability value and a zero severity value.

"11. The non-transitory computer-readable medium of claim 8, wherein at least one business impact associated with the IT risk comprises at least one selected from a group consisting of business size, market, business system criticality, and risk perception.

"12. The non-transitory computer-readable medium of claim 8, wherein the at least one factor comprises at least one selected from a group consisting of recovery effectiveness, mitigation cost, and risk treatment alternatives.

"13. The non-transitory computer-readable medium of claim 8, wherein the functionality to treat the at least one of the plurality of IT risks comprises functionality to treat the selected at least one of the plurality of IT risks according to a best practice knowledgebase.

"14. The non-transitory computer-readable medium of claim 8, wherein each of the plurality of IT asset classifications comprises one selected from a group consisting of system execution, service operations, solution development, and IT governance.

"15. The non-transitory computer-readable medium of claim 8, wherein each of the plurality of IT consequence classifications comprises one selected from a group consisting of continuity and availability, security and integrity, agility and capacity, manageability and serviceability, development project, and governance control.

"16. The non-transitory computer-readable medium of claim 8, wherein identifying the plurality of IT risks comprises using a service excellence index based upon at least one selected from a group consisting of best practice knowledge bases and maturity models.

"17. The non-transitory computer-readable medium of claim 8, wherein identifying the plurality of IT risks comprises generating a plurality of linkages between a plurality of IT service assets and at least one business value effect.

"18. The computer system of claim 1, wherein each known problem associated with each of the plurality of IT risks is an ordered pair, wherein a first element of the ordered pair is the severity of the impact of the IT risk associated with the known problem, represented by the severity value (S), and a second element of the ordered pair is the probability of the IT risk associated with the known problem occurring, represented by the probability value (P).

"19. The non-transitory computer-readable medium of claim 8, wherein each known problem associated with each of the plurality of IT risks is an ordered pair, wherein a first element of the ordered pair is the severity of the impact of the IT risk associated with the known problem, represented by the severity value (S), and a second element of the ordered pair is the probability of the IT risk associated with the known problem occurring, represented by the probability value (P)."

URL and more information on this patent, see: Futch, Jefre E.; Gonczi, Andrew J.; Mason, Roberta J.; Stuckenberg, Ingrid C. IT Risk Management Framework And Methods. U.S. Patent Number 10,083,481, filed February 2, 2006, and published online on October 8, 2018. Patent URL: http://patft.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=HITOFF&d=PALL&p=1&u=%2Fnetahtml%2FPTO%2Fsrchnum.htm&r=1&f=G&l=50&s1=10,083,481.PN.&OS=PN/10,083,481RS=PN/10,083,481

(Our reports deliver fact-based news of research and discoveries from around the world.)

Older

Assurant Inc. Files SEC Form SC 13D/A, General Statement of Acquisition of Beneficial Ownership: (Sept. 20, 2018)

Newer

Heffernan Foundation Benefit ‘Diamonds Are Forever’ Raises Over $1.6 Million

Advisor News

  • Amid slew of corporate tax ideas, Newsom chose one likely to hit people’s premiums
  • The biggest risk to your clients’ financial plans isn’t market volatility
  • Initiative looks at how caregiving impacts workplace benefits
  • Will rising retirement needs spark an annuity boom?
  • Living longer, retiring poorer: Why fragmented systems are failing Americans
More Advisor News

Annuity News

  • Globe Life Inc. (NYSE: GL) Records 52-Week High Thursday Morning
  • Fortitude Re Completes $500 Million FABN Issuance
  • Reframing retirement income for greater certainty
  • Jackson Introduces Dow Jones Industrial Average Index Option, Flexible Premiums, Six-Year Rate Guarantee in Latest Registered Index-Linked Annuity Launch
  • Senior Market Sales® Fortifies Annuity Reach With Acquisition of Retirement Planning Firm Stratton & Company
More Annuity News

Health/Employee Benefits News

  • Health Care Notes: Clover star rating raised after court-ordered recalculation
  • NORTH CAROLINA WOMAN CHARGED WITH CONSPIRACY TO COMMIT IMMIGRATION FRAUD, VA DISABILITY FRAUD
  • Cigna tops Conn. Fortune 500
  • ACA premium shock: Health insurers request hikes up to 30% for 2027
  • More Hoosiers go uninsured, resulting in higher emergency department usage
More Health/Employee Benefits News

Life Insurance News

  • Globe Life Inc. (NYSE: GL) Records 52-Week High Thursday Morning
  • Greg Lindberg moves to halt $1.65B restitution order, claims he ‘overpaid’
  • Fidelity Investments® to Expand Target Date Lineup With Launch of Guaranteed Income Solution
  • KBRA Releases Research – Private Credit: Much Ado About Nothing – Perspectives on Columbia Business School Paper About Private Ratings
  • VUL sales skyrocket in Q1, signaling major market shift
More Life Insurance News

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Maximize Your FIA Case Results
Learn a repeatable process to review, reposition, and present FIA opportunities with confidence.

Aim higher during Annuity Awareness Month
Raise the bar with our diverse portfolio of Ascend annuities, backed by superior financial strength

You Could Be Losing Up to 20% of Your Commissions
GreenWave helps you find, fix, and prevent commission errors.

True Independence Means Having Choices
Cambridge offers flexibility, stability, proven tools—no private equity strings attached.

Life moves fast. Your BGA should, too.
Stay ahead with Modern Life's AI-powered tech and expert support.

Looking for stronger rates, amplified growth & real results?
Sentinel's Accumulation Protector Plus℠ Annuity is for clients wanting more from retirement planning

Press Releases

  • Senior Market Sales® Fortifies Annuity Reach With Acquisition of Retirement Planning Firm Stratton & Company
  • RFP #T01625
  • Rockwood Programs Appoints Kerry Ladouceur as Vice President, Financial Lines
  • JP Insurance Group Launches Commercial Property & Casualty Division; Appoints Joe Webster as Managing Director
  • Sequent Planning Recognized on USA TODAY’s Best Financial Advisory Firms 2026 List
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet