DETAILED ACTION
This non-final Office action is responsive to amendments filed May 28th, 2026. Claims 1, 7-8, 14-15, and 21 have been amended. Claims 1-21 are presented for examination.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 05/28/26 has been entered.
Response to Arguments
Applicant’s arguments, see page 1, filed 05/28/26, with respect to claims 7, 14, and 21 have been fully considered and are persuasive. The objection of 01/29/24 has been withdrawn.
Applicant’s arguments, see page 1, filed 05/28/26, with respect to claims 1-21 have been fully considered and are persuasive. The 35 USC 112(b) rejection of 01/29/24 has been withdrawn.
Applicants’ arguments regarding claim rejections under 35 USC 101 filed 05/28/26 have been fully considered but they are not persuasive.
On pages 1-3 of the provided remarks, Applicant argues that the amended claims present “a specific technical improvement to computer system efficiency that was not previously claimed or argued”. Citing to paragraphs [0028] and [0032] of the as-filed Specification, Applicant argues on pages 2-3 of the provided remarks that the amended claims present a technical solution to a technical problem which “provides a specific technical solution that improves computer efficiency by reducing network protocol overhead and database query execution costs.” Examiner respectfully disagrees and asserts that the amended “wherein the graphical user interface comprises a summary portion that aggregates risk data associated with a plurality of disparate entities within the organization into a single network request-response cycle” is not supported by the as-filed Specification as the filed support does not specify or reference the argued “single network request-response cycle” as claimed. Per MPEP 2106.05(a) “That is, the disclosure must provide sufficient details such that one of ordinary skill in the art would recognize the claimed invention as providing an improvement.” Examiner asserts that the disclosures lack of inclusion of the reference to the claimed “single network request-response cycle” lacks the sufficient detail required to present a technical improvement to the functioning of a computer. Therefore, the claims do not present a technical improvement to a technical problem as the argued technical element of the claims is not supported by the as-filed Specification. The 35 USC 101 rejection is maintained. Applicants’ arguments are not persuasive.
Applicant’s arguments, see pages 4-6, filed 05/28/26, with respect to the rejection(s) of claim(s) 1-21 under 35 USC 103 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Cogliandro (U.S 2004/0015375 A1) in view of Rossman (U.S 9,967,285 B1) in view of Hoover (U.S 2017/0286870 A1) in view of Crowley (U.S 2015/0222654 A1).
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-21 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
The first paragraph of 35 U.S.C. 112 requires that the “specification shall contain a written description of the invention.” This requirement is separate and distinct from the enablement requirement. See, e.g., Vas-Cath, Inc. v. Mahurkar, 935 F.2d 1555, 1560, 19 USPQ2d 1111, 1114 (Fed. Cir. 1991). See also Univ. of Rochester v. G.D. Searle & Co., 358 F.3d 916, 920-23, 69 USPQ2d 1886, 1890-93 (Fed. Cir. 2004) (discussing history and purpose of the written description requirement).
To satisfy the written description requirement, a patent specification must describe the claimed invention in sufficient detail that one skilled in the art can reasonably conclude that the inventor had possession of the claimed invention. See, e.g., Moba, B.V. v. Diamond Automation, Inc., 325 F.3d 1306, 1319, 66 USPQ2d 1429, 1438 (Fed. Cir. 2003); Vas-Cath, Inc. v. Mahurkar, 935 F.2d at 1563, 19 USPQ2d at 1116. However, a showing of possession alone does not cure the lack of a written description. Enzo Biochem, Inc. v. Gen-Probe, Inc., 323 F.3d 956, 969-70, 63 USPQ2d 1609, 1617 (Fed. Cir. 2002).
Claims 1, 8, and 15 each recite the phrase “…wherein the graphical user interface comprises a summary portion that aggregates risk data associated with a plurality of disparate entities within the organization into a single network request-response cycle”. Applicant’s specification discloses “….using the example above, instead of the user having to drill down various pages to obtain enterprise-related information for the sub-department, that sub-department's page information can be provided to a "summary portion" or "summary report," along with various other departments or sub-departments, which is described in more detail herein.” (See Applicant’s Specification para. 0029 and fig. 8-9). However, the Examiner is unable to find any generic or specific description, algorithm, or steps in the instant specification that show that Applicant was in possession of a technique that shows how the summary is generated in a single network request-response cycle.
A claim may lack written description support when (1) the claim defines the invention in functional language specifying a desired result but the disclosure fails to sufficiently identify how the function is performed or the result is achieved or (2) a broad genus claim is presented but the disclosure only describes a narrow species with no evidence that the genus is contemplated. See Ariad Pharm., Inc. v. Eli Lilly & Co., 598 F.3d 1336, 1349-50 (Fed. Cir. 2010) en banc. The written description requirement is not necessarily met when the claim language appears in ipsis verbis in the specification. "Even if a claim is supported by the specification, the language of the specification, to the extent possible, must describe the claimed invention so that one skilled in the art can recognize what is claimed. The appearance of mere indistinct words in a specification or a claim, even an original claim, does not necessarily satisfy that requirement." Enzo Biochem, Inc. v. Gen-Probe, Inc., 323 F.3d 956, 968, 63 USPQ2d 1609, 1616 (Fed. Cir. 2002).
Thus, there is no evidence of a complete specific application or embodiment to satisfy the requirement that the description is set forth “in such full, clear, concise, and exact terms” to show possession of the claimed invention. Fields v. Conover, 443 F.2d 1386, 1392, 170 USPQ 276, 280 (CCPA 1971).
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-21 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter;
When considering subject matter eligibility under 35 U.S.C. 101, it must be determined whether the claim is directed to one of the four statutory categories of invention, i.e., process, machine, manufacture, or composition of matter. If the claim does fall within one of the statutory categories, it must then be determined whether the claim is directed to a judicial exception (i.e., law of nature, natural phenomenon, and abstract idea), and if so, it must additionally be determined whether the claim is a patent-eligible application of the exception. If an abstract idea is present in the claim, any element or combination of elements in the claim must be sufficient to ensure that the claim amounts to significantly more than the abstract idea itself.
Step 1: Independent claims 1 (method), 8 (system), and 15 (medium) and dependent claims 2-7, 9-14, and 16-21, respectively, fall within at least one of the four statutory categories of 35 U.S.C. 101: (i) process; (ii) machine; (iii) manufacture; or (iv) composition of matter. Claim 1 is directed to a method (i.e. process), claim 8 is directed to a system (i.e. machine), and claim 15 is directed to a memory (i.e. manufacture).
Step 2A Prong 1: The independent claims recite rendering a graphical user interface for simultaneous presentation of disparate compliance subjects, the method comprising: determining a risk score for an entity in an organization, wherein the risk score indicates a likelihood of misconduct associated with a compliance subject by an employee within the entity, wherein the compliance subject is indicative of a category of rules or regulations with which the organization is required to comply; determining a consequence score associated with the compliance subject; generating a graphical user interface comprising a risk plot region; wherein the graphical user interface comprises a summary portion that aggregates risk data associated with a plurality of disparate entities within the organization into a single network request-response cycle, thereby reducing packet generation costs and database query execution plan calculations that would otherwise be required for separate navigation requests to pages associated with each of the plurality of disparate entities; and at least partially in response to the determining of the risk score and the determining of the consequence score, creating a rendering, within the graphical user interface, of a plurality of graphical indicators each graphical indicator of the plurality of graphical indicators located at an intersection of a risk score of a plurality of risk scores represented on a first axis of the plot region and a consequence score of a plurality of consequence scores represented on a second axis of the plot region, and comprising a hyperlink with a numeric value label representing a number of compliance subjects having the associated risk score and corresponding consequence score (Organizing Human Activity & Mental Process), which are considered to be abstract ideas (See PEG 2019 and MPEP 2106.05).
The steps/functions disclosed above and in the independent claims recite the abstract idea of Organizing Human Activity because the claimed limitations are determining a risk score for an entity in an organization in which that score indicates a likelihood of misconduct, which is mitigation of risk. The claimed limitations also determine a risk score of an entity based on compliance subjects which is indicative of a category of rules or regulations with which the organization is required to comply, which is managing of personal behavior. The Applicant’s claimed limitations are determining a risk score for an entity or organization, which recites the abstract idea of Certain Methods of Organizing Human Activity.
The steps/functions disclosed above and in the independent claims recite the abstract idea of Mental Process because the claimed limitations are determining a risk score for an entity in an organization and determining a consequence score associated with the compliance subject, which could be performed as functions of the human mind in the form of observation, judgement, and evaluation. These functions could also be performed utilizing pen and paper. The Applicant’s claimed limitations are determining a risk score and consequence score for an entity or organization, which recites the abstract idea of Mental Process.
Dependent claims 3 and 17 recite determining the risk score as a summation of numerical values of the rationalization component score, the opportunity component score, and the pressure component score. The steps/functions disclosed above and in the independent claims recite the abstract idea of Mathematical Concept because the claimed limitations are determining a risk score for an entity in an organization by performing a summation of numerical values, which is a mathematical calculation. The Applicant’s claimed limitations are determining a risk score using summation, which recites the abstract idea of Mathematical Concept.
Dependent claims 2, 9, and 16 recite determining a rationalization component score representing an ability of the employee to justify an act of misconduct; determining an opportunity component score representing a difficulty with which the employee can commit the act of misconduct; determining a pressure component score representing a motive for the employee to commit the act of misconduct; and determining the risk score based on the rationalization component score, the opportunity component score, and the pressure component score. The steps/functions disclosed above and in the independent claims recite the abstract idea of Certain Methods of Organizing Human Activity because the claimed limitations are determining a risk score for an entity in an organization in which that score indicates a likelihood of misconduct, which is mitigation of risk. The claimed limitations also determine a risk score of an entity based on compliance subjects which is indicative of a category of rules or regulations with which the organization is required to comply, which is managing of personal behavior. In addition, these steps/functions recite the abstract idea of Mental Process because the claimed limitations are determining a risk score for an entity in an organization based on a determined rationalization component, opportunity component, and pressure component score. The steps/functions disclosed above and in the independent claims recite the abstract idea of Mental Process because the claimed limitations are determining a risk score for an entity in an organization and determining a consequence score associated with the compliance subject, which could be performed as functions of the human mind in the form of observation, judgement, and evaluation. These functions could also be performed utilizing pen and paper. The Applicant’s claimed limitations are determining a risk score based on a determined rationalization component, opportunity component, and pressure component score, which recites the abstract idea of Mental Process.
In addition, dependent claims 4-7, 10-14, and 18-21 further narrow the abstract idea and recite the generation of risk mitigation plans; training summaries of employees; mitigation status; and further defining compliance subjects. These processes are similar to the abstract idea noted in the independent claims because they further the limitations of the independent claims which recite a certain method for organizing human activity managing human interactions as well as mental processes. Accordingly, these claim elements do not serve to confer subject matter eligibility to the claims since they are directed to abstract ideas.
Step 2A Prong 2: In this application, the above “rendering a graphical user interface for simultaneous presentation of disparate compliance subjects; generating a graphical user interface comprising a risk plot region; wherein the graphical user interface comprises a summary portion that aggregates risk data associated with a plurality of disparate entities within the organization into a single network request-response cycle, thereby reducing packet generation costs and database query execution plan calculations that would otherwise be required for separate navigation requests to pages associated with each of the plurality of disparate entities; creating a rendering, within the graphical user interface, of a plurality of graphical indicators, each graphical indicator of the plurality of graphical indicators located at an intersection of a risk score of a plurality of risk scores represented on a first axis of the plot region and a consequence score of a plurality of consequence scores represented on a second axis of the plot region, and comprising a hyperlink with a numeric value label representing a number of compliance subjects having the associated risk score and corresponding consequence score” steps/functions of the independent claims would not account for additional elements that integrate the judicial exception (e.g. abstract idea) into a practical application because receiving/storing data and displaying data merely add insignificant extra-solution activity and merely adds the words to apply it with the judicial exception. Also, the claimed “a graphical user interface; A system for monitoring status of compliance subjects using a graphical user interface, the system comprising: a display device; and a processor configured to; A non-transitory computer readable medium comprising computer executable instructions for monitoring status of compliance subjects using a graphical user interface” would not account for additional elements that integrate the judicial exception (e.g. abstract idea) into a practical application because the claimed structure merely adds the words to apply it with the judicial exception and mere instructions to implement an abstract idea on a computer (See PEG 2019 and MPEP 2106.05).
In addition, dependent claims 2-7, 9-14, and 16-21 further narrow the abstract idea and dependent claims 4, 7, 11, 14, 18, and 21 additionally recite “generating a second graphical user interface associated with a risk mitigation plan for a first compliance subject of the compliance subjects”, “receiving a user selection of a first graphical indicator of the plurality of graphical indicators, the first graphical indicator equating to a first risk score and a first consequence score”; “generating, in response to receiving the user selection of the first graphical indicator, a second graphical user interface by moving the risk plot region to a first potion of the second graphical user interface and creating a listing of the compliance subjects having the first risk score and the first consequence score in a second portion of the second graphical user interface”; “receiving a user selection of the numeric value label representing the number of compliance subjects having the associated risk score and the corresponding consequence score”, and “generating, in response to receiving the user selection of the numeric value label, a second graphical user interface comprising a listing of the compliance subjects having the associated risk score and the corresponding consequence score” which do not account for additional elements that integrate the judicial exception (e.g. abstract idea) into a practical application because receiving/storing data and displaying data merely add insignificant extra-solution activity and the claimed “graphical user interface” which do not account for additional elements that integrate the judicial exception (e.g. abstract idea) into a practical application because the claimed structure merely adds the words to apply it with the judicial exception and mere instructions to implement an abstract idea on a computer (See PEG 2019 and MPEP 2106.05).
The claimed “a graphical user interface; A system for monitoring status of compliance subjects using a graphical user interface, the system comprising: a display device; and a processor configured to; A non-transitory computer readable medium comprising computer executable instructions for monitoring status of compliance subjects using a graphical user interface” are recited so generically (no details whatsoever are provided other than that they are general purpose computing components and regular office supplies) that they represent no more than mere instructions to apply the judicial exception on a computer. These limitations can also be viewed as nothing more than an attempt to generally link the use of the judicial exception to the technological environment of a computer. Even when viewed in combination, the additional elements in the claims do no more than use the computer components as a tool. There is no change to the computers and other technology that is recited in the claim, and thus the claims do not improve computer functionality or other technology (See PEG 2019).
Step 2B: When analyzing the additional element(s) and/or combination of elements in the claim(s) other than the abstract idea per se the claim limitations amount(s) to no more than: a general link of the use of an abstract idea to a particular technological environment and merely amounts to the application or instructions to apply the abstract idea on a computer (See MPEP 2106.05 and PEG 2019). Further, method claims 1-7; system claims 8-14; and non-transitory computer-readable medium claims 15-21 recite “a graphical user interface; A system for monitoring status of compliance subjects using a graphical user interface, the system comprising: a display device; and a processor configured to; A non-transitory computer readable medium comprising computer executable instructions for monitoring status of compliance subjects using a graphical user interface”; however, these elements merely facilitate the claimed functions at a high level of generality and they perform conventional functions and are considered to be general purpose computer components which is supported by Applicant’s specification in Paragraphs 0066 and 0069 and Figures 1 and 15. The Applicant’s claimed additional elements are mere instructions to implement the abstract idea on a general purpose computer and generally link of the use of an abstract idea to a particular technological environment. Also, the above “rendering a graphical user interface for simultaneous presentation of disparate compliance subjects; generating a graphical user interface comprising a risk plot region; wherein the graphical user interface comprises a summary portion that aggregates risk data associated with a plurality of disparate entities within the organization into a single network request-response cycle, thereby reducing packet generation costs and database query execution plan calculations that would otherwise be required for separate navigation requests to pages associated with each of the plurality of disparate entities; creating a rendering, within the graphical user interface, of a plurality of graphical indicators, each graphical indicator of the plurality of graphical indicators located at an intersection of a risk score of a plurality of risk scores represented on a first axis of the plot region and a consequence score of a plurality of consequence scores represented on a second axis of the plot region, and comprising a hyperlink with a numeric value label representing a number of compliance subjects having the associated risk score and corresponding consequence score” steps/functions of the independent claims would not account for significantly more than the abstract idea because receiving data and displaying/presenting data (See MPEP 2106.05) have been identified as well-known, routine, and conventional steps/functions to one of ordinary skill in the art. When viewed as a whole, these additional claim element(s) do not provide meaningful limitation(s) to transform the abstract idea into a patent eligible application of the abstract idea such that the claim(s) amounts to significantly more than the abstract idea itself.
In addition, claims 2-7, 9-14, and 16-21 further narrow the abstract idea identified in the independent claims. The Examiner notes that the dependent claims merely further define the data being analyzed and how the data is being analyzed. Similarly, claims 4, 7, 11, 14, 18, and 21 additionally recite “generating a second graphical user interface associated with a risk mitigation plan for a first compliance subject of the compliance subjects”, “receiving a user selection of a first graphical indicator of the plurality of graphical indicators, the first graphical indicator equating to a first risk score and a first consequence score”; “generating, in response to receiving the user selection of the first graphical indicator, a second graphical user interface by moving the risk plot region to a first potion of the second graphical user interface and creating a listing of the compliance subjects having the first risk score and the first consequence score in a second portion of the second graphical user interface”; “receiving a user selection of the numeric value label representing the number of compliance subjects having the associated risk score and the corresponding consequence score”, and “generating, in response to receiving the user selection of the numeric value label, a second graphical user interface comprising a listing of the compliance subjects having the associated risk score and the corresponding consequence score” which do not account for additional elements that amount to significantly more than the abstract idea because receiving data and displaying/presenting data (See MPEP 2106.05) have been identified as well-known, routine, and conventional steps/functions to one of ordinary skill in the art and the claimed “graphical user interface” which do not account for additional elements that amount to significantly more than the abstract idea because the claimed structure merely amounts to the application or instructions to apply the abstract idea on a computer and does not move beyond a general link of the use of an abstract idea to a particular technological environment (See MPEP 2106.05). The additional limitations of the independent and dependent claim(s) when considered individually and as an ordered combination do not amount to significantly more than the abstract idea. The examiner has considered the dependent claims in a full analysis including the additional limitations individually and in combination as analyzed in the independent claim(s). Therefore, the claim(s) are rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1, 4, 7-8, 10-11, 14-15, 18, and 21 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cogliandro (U.S 2004/0015375 A1) in view of Rossman (U.S 9,967,285 B1) in view of Hoover (U.S 2017/0286870 A1) in view of Crowley (U.S 2015/0222654 A1).
Claims 1, 8, and 15
Regarding Claim 1, Cogliandro discloses the following:
A method for rendering a graphical user interface for simultaneous presentation of disparate compliance subjects, the method comprising [see at least Paragraph 0002 for reference to the invention relating to a method for reducing risk to a firm and a firm program, and more particularly, reducing risk and improving yield or performance by considering firm strategic intent, program phase, and integrated visuals; Paragraph 0118 for reference to the user interface comprising an inputer for monitoring and directing and/or controlling processor and a displayer for displaying processor prompts and results; Figure 10 and related text regarding item 1030 ‘user interface’]
determining a risk score for an entity in an organization, wherein the risk score indicates a likelihood of misconduct associated with a compliance subject by an employee within the entity, wherein the compliance subject is indicative of a category of rules or regulations with which the organization is required to comply [see at least Paragraph 0051 for reference to the risk score for an identified risk element which is graded based on two factors: likelihood and consequence; likelihood which is measured on five levels is the likelihood or probability that the risk will happen; Figure 2 for reference to the likelihood quantification chart in which employees are performing tasks to meet milestones]
determining a consequence score associated with the compliance subject [see at least Paragraph 0052 for reference to the second grading factor used to quantify the risk associated with a risk element being consequence, which measures, by levels, the magnitude of the impact of the risk, against cost, schedule, and technical performance; Figure 3 for reference to the Consequence Chart that displays the level of consequences from 1-5 and corresponding schedule, cost, and technical performance factors]
generating a graphical user interface comprising a risk plot region [see at least Paragraph 0056 for reference to stop light chart comprises a y-axis, which corresponds to likelihood levels and an x-axis, which corresponds to consequence levels; Paragraph 0118 for reference to the user interface including artificial intelligence or simple input queries to obtain risk management input to predefined questions; Figure 4 for reference to the Risk Assessment Guide which displays the consequence score on the x-axis and the risk item likelihood score on the y-axis; Figure 10 and related text regarding item 1030 ‘user interface’]
at least partially in response to the determining of the risk score and the determining of the consequence score, creating a rendering, within the graphical user interface, of a plurality of graphical indicators, each graphical indicator of the plurality of graphical indicators located at an intersection of a risk score of a plurality of risk scores represented on a first axis of the plot region and a consequence score of a plurality of consequence scores represented on a second axis of the plot region, and a label representing having the associated risk score and corresponding consequence score [see at least Paragraph 0056 for reference to the stop light chart in which the y-axis corresponds to likelihood levels and the x-axis corresponds to consequence levels; Paragraph 0056 for reference to each grid unit on the chart corresponding to high, moderate, or low risk assessment rank; Paragraph 0077 for reference to the risk management method utilizing a visual stop-light chart to assist in the transformation from risk score to risk assessment value; Paragraph 0118 for reference to the user interface including artificial intelligence or simple input queries to obtain risk management input to predefined questions; Figure 4 for reference to the Risk Assessment Guide which displays the consequence score on the x-axis and the risk item likelihood score on the y-axis; Figure 10 and related text regarding item 1030 ‘user interface’]
While Cogliandro discloses the limitations above, it does not disclose wherein the graphical user interface comprises a summary portion that aggregates risk data associated with a plurality of disparate entities within the organization into a single network request-response cycle, thereby reducing packet generation costs and database query execution plan calculations that would otherwise be required for separate navigation requests to pages associated with each of the plurality of disparate entities; the plurality of graphical indicators comprising a hyperlink with a numeric value label representing a number of compliance subjects having the associated risk score and corresponding consequence score.
However, Rossman discloses the following:
wherein the graphical user interface comprises a summary portion that aggregates risk data associated with a plurality of disparate entities within the organization into a single network request-response cycle, thereby reducing packet generation costs and database query execution plan calculations that would otherwise be required for separate navigation requests to pages associated with each of the plurality of disparate entities [see at least Col 8 lines 34-39 for reference to the request/response interface being provided with a web browser for reporting a summary; Col 17 lines 28-31 for reference to the process beginning by a request for providing a virtual computing service providers compliance evidence; Col 17 lines 56-58 for reference to a summary response being provided indicating regulatory confidence level with the compliance evidence having a set of digital signatures; Col 18 lines 2-6 for reference to the request-response cycle (e.g., a cycle that starts with a request and ends with a response and then starts again with a request) being conducted to produce the said summary response; Figure 2 and related text regarding item 210 ‘request/response interface’]
Before the effective filing date, it would have been obvious to one of ordinary skill in the art to modify the risk plot display of Cogliandro to include the risk summary within a single request-response cycle of Rossman. Doing so would offer end users on-demand access to information, such as compliance evidence, on a global basis, as stated by Rossman (Col 2 lines 20-21).
While the combination of Cogliandro and Rossman disclose the limitations above, they do not disclose the plurality of graphical indicators comprising a hyperlink with a numeric value label representing a number of compliance subjects having the associated risk score and corresponding consequence score.
However, Hoover discloses the following:
the plurality of graphical indicators comprises a number of compliance subjects having the associated risk score and corresponding consequence score [see at least Paragraph 0130 for reference to Figure 12A displaying the frequency of price risk scores, Figure 12B displaying the frequency of the supplier risk scores, and Figure 12C displaying the frequency of item risk scores; Figures 12A-C and related text regarding the examples of price risk scores, supplier risk scores, and item risk scores on a scoring scale]
Before the effective filing date, it would have been obvious to one of ordinary skill in the art to modify the monitoring method of Cogliandro to include the graphical indication of frequency count of Hoover. Doing so would facilitate quickly identifying which bids are high risk, as stated by Hoover (Paragraph 0096).
While the combination of Cogliandro, Rossman, and Hoover disclose the limitations above, they do not disclose the plurality of graphical indicators comprising a hyperlink with a numeric value label.
However, Crowley discloses the following:
the plurality of graphical indicators comprising a hyperlink with a numeric value label [see at least Paragraph 0087 for reference to the individual numbers within the examining profiler output representing hyperlinks to tables where details about the assets and evidence in the form of forensics and attributes pertaining to their level of infected state can be presented; Figure 4 and related text regarding the cross-tabular chart displaying the composite risk score on the x-axis and the byte range as the y-axis and the byte out attribute item 352 representing the total number of assets in every range]
Before the effective filing date, it would have been obvious to one of ordinary skill in the art to modify the graphical indicators of Cogliandro to include the hyperlink capabilities of Crowley. Doing so would alert corporate asset administrators of high-risk behaviors associated with important assets, as stated by Crowley (Paragraph 0089).
Regarding claims 8 and 15, the claims recite limitations already addressed by the rejection of claim 1. Regarding claim 8, Cogliandro teaches a system comprising a display device; and a processor [Figure 10 item 1010, 1030, and 1032]. Regarding claim 15, Hoover teaches a non-transitory computer readable medium comprising computer executable instructions [Paragraph 0057 and Figure 7 item 704]. Therefore, claims 8 and 15 are rejected as being unpatentable in view of Cogliandro, Rossman, Hoover, and Crowley.
Claims 4, 11, and 18
While the combination of Cogliandro, Rossman, Hoover, and Crowley discloses the limitations above, regarding Claim 4, Cogliandro discloses the following:
generating a second graphical user interface associated with a risk mitigation plan for a first compliance subject of the compliance subjects [see at least Paragraph 0057 for reference to a mitigation plan being developed for an associated risk element after the risk assessment value is identified for the primary driver; Paragraph 0117 for reference to the processor containing a mitigator to develop possible mitigation plans for the assessed risk; Paragraph 0118 for reference to the user interface including artificial intelligence or simple input queries to obtain risk management input to predefined questions as well as a displayer for displaying processor prompts and results; Figures 6-8 and related text regarding the modification of consequence factors and the corresponding second graphical user interface which displays the modification definition table and sample modified consequence chart]
the second user interface comprises a first portion for receiving input specifying one or more activities to be completed to reduce a risk level of the first compliance subject [see at least Paragraph 0058 for reference to the project risk rating which is determined by plotting all the project primary drivers and analyzing them determining that the risk assessment value for the majority of the primary drivers is the program risk assessment value which are then given mitigation plans to focus on mitigating risk to the individual risk element; Paragraph 0117 for reference to the processor containing a mitigator to develop possible mitigation plans for the assessed risk; Paragraph 0118 for reference to the user interface including artificial intelligence or simple input queries to obtain risk management input to predefined questions as well as a displayer for displaying processor prompts and results; Figure 6 and related text regarding item 620 ‘Identify phase expectations’]
a second portion for receiving input specifying a risk mitigation point that represents a future risk assessment for the first compliance subject after the risk mitigation plan has been completed [see at least Paragraph 0059 for reference to the managing of the mitigation plan once completed including monitoring the risk items and potentially recalculating due to a significant event in the project occurring or a change in the risk item; Paragraph 0086 for reference to management of the mitigation plan including monitoring the risk items for example adding resources, re-training personnel, looking for an alternate vendor, etc.; Paragraph 0117 for reference to the processor containing a mitigator to develop possible mitigation plans for the assessed risk; Paragraph 0118 for reference to the user interface including artificial intelligence or simple input queries to obtain risk management input to predefined questions as well as a displayer for displaying processor prompts and results; Figure 10 and related text regarding item 1030 ‘user interface’]
Regarding claims 11 and 18, the claims recite limitations already addressed by the rejection of claim 4.
Claim 7
While the combination of Cogliandro, Rossman, Hoover, and Crowley discloses the limitations above, regarding Claim 7, Cogliandro discloses the following:
the first graphical indicator equating to a first risk score and a first consequence score [see at least Paragraph 0056 for reference to the stop light chart in which the y-axis corresponds to likelihood levels and the x-axis corresponds to consequence levels; Paragraph 0056 for reference to each grid unit on the chart corresponding to high, moderate, or low risk assessment rank; Paragraph 0077 for reference to the risk management method utilizing a visual stop-light chart to assist in the transformation from risk score to risk assessment value; Paragraph 0118 for reference to the user interface including artificial intelligence or simple input queries to obtain risk management input to predefined questions; Figure 4 for reference to the Risk Assessment Guide which displays the consequence score on the x-axis and the risk item likelihood score on the y-axis]
While Cogliandro discloses the limitations above, it does not disclose receiving a user selection of a first graphical indicator of the plurality of graphical indicators and generating, in response to receiving the user selection of the first graphical indicator, a second graphical user interface by moving the risk plot region to a first potion of the second graphical user interface and creating a listing of the compliance subjects having the first risk score and the first consequence score in a second portion of the second graphical user interface.
Regarding Claim 7, Crowley discloses the following:
receiving a user selection of a first graphical indicator of the plurality of graphical indicators [see at least Paragraph 0087 for reference to the individual numbers within the examining profiler output representing hyperlinks to tables where details about the assets and evidence in the form of forensics and attributes pertaining to their level of infected state can be presented; Paragraph 0088 for reference to any attribute being expanded and compared against the composite risk score; Figure 4 and related text regarding the cross-tabular chart displaying the composite risk score on the x-axis and the byte range as the y-axis and the byte out attribute item 352 representing the total number of assets in every range]
generating, in response to receiving the user selection of the first graphical indicator, a second graphical user interface by moving the risk plot region to a first potion of the second graphical user interface and creating a listing of the compliance subjects having the first risk score and the first consequence score in a second portion of the second graphical user interface [see at least Paragraph 0087 for reference to the individual numbers within the examining profiler output representing hyperlinks to tables where details about the assets and evidence in the form of forensics and attributes pertaining to their level of infected state can be presented; Paragraph 0087 for reference to the selection of dashed square 490 resulting in the interface display of the highest concentration of numbers for this environment and all numbers within this square being prioritized for remediation efforts; Figure 4 and related text regarding the cross-tabular chart displaying the composite risk score on the x-axis and the byte range as the y-axis and the byte out attribute item 352 representing the total number of assets in every range]
Before the effective filing date, it would have been obvious to one of ordinary skill in the art to modify the graphical indicators of Cogliandro to include the selection and interface presentation capabilities of Crowley. Users can thus prioritize remediation efforts by concentrating on areas of the chart where the highest concentration of relative risk, based on a user's perspective, is displayed, as stated by Crowley (Paragraph 0087).
Claims 14 and 21
While the combination of Cogliandro, Rossman, Hoover, and Crowley disclose the limitations above, Cogliandro does not disclose receiving a user selection of the numeric value label representing the number of compliance subjects having the associated risk score and the corresponding consequence score; generating, in response to receiving the user selection of the numeric value label, a second graphical user interface comprising a listing of the compliance subjects having the associated risk score and the corresponding consequence score.
Regarding Claim 14, Hoover discloses the following:
receiving a user selection of the numeric value label representing the number of compliance subjects having the associated risk score and the corresponding consequence score [see at least Paragraph 131 for reference to scores being selected to provide drill downs to display additional information related to the scores]
generating, in response to receiving the user selection of the numeric value label, a second graphical user interface comprising a listing of the compliance subjects having the associated risk score and the corresponding consequence score [see at least Paragraph 131 for reference to scores being selected to provide drill downs to display additional information related to the scores; Paragraph 0134 for reference to the supplier risk drill down displaying the values for the variables for each company; Paragraph 0135 for reference to the item risk drill down showing key flags which are variables in the item risk down model; Figures 15A-B, 16A-B, 17 and related text regarding drill down methods for price risk and supplier risk]
Before the effective filing date, it would have been obvious to one of ordinary skill in the art to modify the monitoring method of Cogliandro to include the user selection of frequency count and graphical user interface listing of Hoover. Doing so would facilitate quickly identifying which bids are high risk, as stated by Hoover (Paragraph 0096).
Regarding claim 21, the claim recites limitations already addressed by the rejection of claim 14.
Claim 10
While the combination of Cogliandro, Rossman, Hoover, and Crowley discloses the limitations above, regarding Claim 10, Cogliandro discloses the following:
the compliance subjects include categories or types of rules or regulations with which the organization is required to comply [see at least Paragraph 0065 for reference to the risk management method being sensitized to the firm’s strategic intent including a firm’s objectives and goals such as political, regulatory, or geographical issues]
Claims 2-3, 9, and 16-17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cogliandro (U.S 2004/0015375 A1) in view of Rossman (U.S 9,967,285 B1) in view of Hoover (U.S 2017/0286870 A1) in view of Crowley (U.S 2015/0222654 A1), as applied in claims 1, 8, and 15, in view of Fujisawa (U.S 2017/0251007 A1).
Claims 2, 9, and 16
While the combination of Cogliandro, Rossman, Hoover, and Crowley discloses the limitations above, Cogliandro does not disclose determining the risk score further comprises: determining a rationalization component score representing an ability of the employee to justify an act of misconduct; determining an opportunity component score representing a difficulty with which the employee can commit the act of misconduct; determining a pressure component score representing a motive for the employee to commit the act of misconduct; and determining the risk score based on the rationalization component score, the opportunity component score, and the pressure component score.
Regarding Claim 2, Fujisawa discloses the following:
determining the risk score further comprises: determining a rationalization component score representing an ability of the employee to justify an act of misconduct [see at least Paragraph 0037 for reference to the scoring engine being configured to determine risk scores for users based on the monitoring of events which represents an overall measure of risk of the user; Paragraph 0078 for reference to once the IoBs has been indicated an rationalization score is calculated; Figure 3 and related text regarding item 320 ‘Determine a security risk score for the user based on the opportunity score, pressure score, and rationalization score’ and item 312 ‘Determine based on the event log a rationalization IoB for the user’ and item 318 ‘Determine, based on the rationalization IoB, a rationalization score’; Figure 10 and related text regarding ‘Indicators of Behavior: Rationalization’]
determining an opportunity component score representing a difficulty with which the employee can commit the act of misconduct [see at least Paragraph 0037 for reference to the rationalization score providing a measure of a probability or likelihood of fraudulent activity based on the rationalization factors determining an opportunity component score representing a difficulty with which the employee can commit the act of misconduct; Paragraph 0078 for reference to once the IoBs has been indicated an opportunity score is calculated; Figure 3 and related text regarding item 314 ‘Determine, based on the opportunity loB, an opportunity score’; Figure 8 and related text regarding ‘Indicators of Behavior: Opportunity’]
determining a pressure component score representing a motive for the employee to commit the act of misconduct [see at least Paragraph 0037 for reference to pressure score providing a measure of a probability or likelihood of fraudulent activity based on the pressure factors; Paragraph 0078 for reference to once the IoBs has been indicated a pressure score is calculated; Figure 3 and related text regarding item 316 ‘Determine, based on the pressure loB, a pressure score’; Figure 9 and related text regarding ‘Indicators of Behavior: Pressure/Incentive’]
determining the risk score based on the rationalization component score, the opportunity component score, and the pressure component score [see at least Paragraph 0037 for reference to the overall security risk score for the user may then be determined based on an algorithmic transformation of the opportunity, pressure, and rationalization scores; Paragraph 0070 for reference to the scoring engine being configured to determine a security risk score for the user based on the opportunity score, pressure score, and rationalization score based on a combination and/or (e.g., weighted) average of the O, P, and R scores associated with the user; Figure 3 and related text regarding item 320 ‘Determine a security risk score for the user based on the opportunity score, pressure score, and rationalization score’]
Before the effective filing date, it would have been obvious to one of ordinary skill in the art to modify the status monitoring method of Cogliandro to include the risk score calculation of Fujisawa. Calculating the risk score in such a way would allow distinction for detecting different types of attacks, as stated by Fujisawa (Paragraph 0036).
Regarding claims 9 and 16, the claims recite limitations already addressed by the rejection of claim 2.
Claims 3 and 17
While the combination of Cogliandro, Rossman, Hoover, Crowley and Fujisawa disclose the limitations above, Cogliandro does not disclose determining the risk score as a summation of numerical values of the rationalization component score, the opportunity component score, and the pressure component score.
Regarding Claim 3, Fujisawa discloses the following:
determining the risk score as a summation of numerical values of the rationalization component score, the opportunity component score, and the pressure component score [see at least Paragraph 0070 for reference to the scoring engine being configured to determine a security risk score for the user based on the opportunity score, pressure score, and rationalization score based on a combination and/or (e.g., weighted) average of the O, P, and R scores associated with the user; Figure 3 and related text regarding item 320 ‘Determine a security risk score for the user based on the opportunity score, pressure score, and rationalization score’]
Before the effective filing date, it would have been obvious to one of ordinary skill in the art to modify the status monitoring method of Cogliandro to include the risk score summation of Fujisawa. Calculating the risk score in such a way would allow distinction for detecting different types of attacks, as stated by Fujisawa (Paragraph 0036).
Regarding claim 17, the claim recites limitations already addressed by the rejection of claim 3.
Claims 5, 12, and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cogliandro (U.S 2004/0015375 A1) in view of Rossman (U.S 9,967,285 B1) in view of Hoover (U.S 2017/0286870 A1) in view of Crowley (U.S 2015/0222654 A1), as applied in claims 1, 8, and 15, in view of Dawson (U.S 2008/0033775 A1).
Claims 5, 12, and 19
While the combination of Cogliandro, Rossman, Hoover, and Crowley discloses the limitations above, Cogliandro does not disclose the graphical user interface further comprises a training summary region indicating a first proportion of employees having completed training related to the compliance subject and a second proportion of remaining employees to complete the training.
Regarding Claim 5, Dawson discloses the following:
the graphical user interface further comprises a training summary region indicating a first proportion of employees having completed training related to the compliance subject and a second proportion of remaining employees to complete the training [see at least Paragraph 0188 for reference to the Training functional area which shows summary information of training courses completed by employees; Paragraph 0188 for reference to the summary information including ID numbers and the start date of the training course; Figure 24-26 for reference to the Training list page]
Before the effective filing date, it would have been obvious to one of ordinary skill in the art to modify the status monitoring method of Cogliandro to include the training summary of Dawson. Doing so would capture information about training programs completed by the employees of entities monitored by compliance professionals which increases employees’ awareness and understanding of their organization’s compliance obligations, as stated by Dawson (Paragraph 0186).
Regarding claims 12 and 19, the claims recite limitations already addressed by the rejection of claim 5.
Claims 6, 13, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Cogliandro (U.S 2004/0015375 A1) in view of Rossman (U.S 9,967,285 B1) in view of Hoover (U.S 2017/0286870 A1) in view of Crowley (U.S 2015/0222654 A1), as applied in claims 1, 8, and 15, in view of Perkins (U.S 2010/0058114 A1).
Claims 6, 13, and 20
While the combination of Cogliandro, Rossman, Hoover, and Crowley discloses the limitations above, Cogliandro does not disclose the graphical user interface further comprises a mitigation status region indicating a first proportion of open mitigation plans for reducing risk of misconduct, a second proportion of completed mitigation plans, and a third proportion of past due mitigation plans.
Regarding Claim 6, Perkins discloses the following:
the graphical user interface further comprises a mitigation status region indicating a first proportion of open mitigation plans for reducing risk of misconduct, a second proportion of completed mitigation plans, and a third proportion of past due mitigation plans [see at least Paragraph 0113 for reference to the program management created by the Test Event Manager including the mitigation response to the milestone and the status of the plan of action such as open; Paragraph 0206 for reference to the input/out interfaces including communications interfaces such as a graphical user interfaces; Figure 8 item 338 for reference to the mitigation region of the model]
Before the effective filing date, it would have been obvious to one of ordinary skill in the art to modify the status monitoring method of Cogliandro to include the mitigation status of Perkins. Doing so would display the findings for all the systems in which the user is a member, as stated in Perkins (Paragraph 0099). This display would allow users to view the status of the mitigation plans that focus on mitigating risk of to the individual risk element, as stated in Cogliandro (Paragraph 0058).
Regarding claims 13 and 20, the claims recite limitations already addressed by the rejection of claim 6.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Ouchani, Samir, Otmane Ait Mohamed, and Mourad Debbabi. "A security risk assessment framework for SysML activity diagrams." 2013 IEEE 7th International Conference on Software Security and Reliability. IEEE, 2013.
DOCUMENT ID
INVENTOR(S)
TITLE
US 9,747,570 B1
Vescio, Robert
METHOD AND SYSTEM FOR RISK MEASUREMENT AND MODELING
US 2012/0053981 A1
Lipps et al.
Risk Governance Model For An Operation Or An Information Technology System
EP 2383689 A1
Roncolato, Laura
System And Method To Estimate The Effects Of Risks On The Time Progression Of Projects
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KRISTIN ELIZABETH GAVIN whose telephone number is (571)270-7019. The examiner can normally be reached M-F 7:30-4:30 PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jerry O'Connor can be reached at 571-272-6787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KRISTIN E GAVIN/Primary Examiner, Art Unit 3624