DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments, see page 11, filed 07/10/2026, with respect to the objection of claim 1 have been fully considered. The objection of claim 1 has been withdrawn in response to Applicant’s amendment resolving the previous typo.
Applicant's arguments, see pages 11-14 filed 07/10/2026, with respect to the priority documents Application Nos. 63/347,389 and 63/457,671 supporting the claimed invention have been fully considered but they are not persuasive.
As in the Non-Final Rejection mailed 04/10/2026 (see pages 2-3), The later-filed application must be an application for a patent for an invention which is also disclosed in the prior application (the parent or original nonprovisional application or provisional application). The disclosure of the invention in the parent application and in the later-filed application must be sufficient to comply with the requirements of 35 U.S.C. 112(a) or the first paragraph of pre-AIA 35 U.S.C. 112, except for the best mode requirement. See Transco Products, Inc. v. Performance Contracting, Inc., 38 F.3d 551, 32 USPQ2d 1077 (Fed. Cir. 1994).
The claim limitation at issue lacking support in the priority document is “generate, based on the security posture and a plurality of security objectives, a set of cybersecurity attributes of the entity” within independent claims 1, 16, and 20. The claim therefore requires generating a set of cybersecurity attributes of the entity. Priority document 63/457,671 does not contain any written description support for the claimed generating a set of cybersecurity attributes of the entity. Applicant points to paragraphs [0048] and [0100] of priority document 63/347,389 for support for the claim limitation, however, neither paragraph describe generating a set of cybersecurity attributes of the entity as paragraph [0048] merely describes data gathering and data structures which does not adequately support generating a set of cybersecurity attributes of the entity as claimed; and paragraph [0100] only refers to Figure 54 which depicts interconnectivity of devices communicating over network 120. Applicant then tries to point to Figure 55 of priority document 63/347,389 and allege that it “provides at least one non-limiting example of how such aspects can be generated based on the entity’s posture and security objectives”. The Examiner respectfully submits that Figure 55 does not describe any “how such aspects can be generated” for purposes of § 112(a) written description as it only displays an “org user focused overview” that has the subtitle “Identify the organization objective, capabilities, limitations and residual risk as well as what to do to close the gaps and preserve the new known good state”, but does not describe in accordance with § 112(a) how the claimed invention generates a set of cybersecurity attributes of the entity. Applicant next points to paragraphs [0039-0040] of priority document 63/347,389 for support, but paragraph [0039] only describes training a machine learning model and collected data can be used to train a machine-learning model and paragraph [0040] merely describes an analysis circuit configured to perform source testing to identify malfunctions and exceptions; neither of which adequately describe for purposes of § 112(a) how the claimed invention generates a set of cybersecurity attributes of the entity. Applicant lastly points to Figs. 23A and 23F-23J of priority document 63/347,389 for support, however as in pages 2-3 of the Non-Final Rejection mailed 04/10/2026, the figures do not display security objectives and instead merely display lorem ipsum placeholder language which cannot adequately support the written description requirement for the claimed generating a set of cybersecurity attributes of the entity. Lastly to clarify the record, Applicant has not provided any evidence that the priority document 63/457,671 supports the claim limitation at issue.
Applicant’s arguments, see pages 14-16, filed 07/10/2026, with respect to the rejection of claims 1-4, 8, 16-17, and 20 under 35 U.S.C. § 112(a) and § 112(b) have been fully considered.
The previous rejections of claims 1-4, 8, 16-17, and 20 under 35 U.S.C. § 112(b) have been withdrawn in response to the Applicant removing the respective limitations at issue.
The previous rejection of claim 1 under 35 U.S.C. § 112(a) reciting “one or more graphical elements configured to cause a selection, … the at least one cybersecurity protection plan” has been withdrawn in response to Applicant’s amendment to the claim comprising “one or more graphical elements configured to receive an input that causes a selection”.
Applicant lastly argues on pages 15-16 that the originally filed disclosure and the priority documents support the claim limitation “generate, based on the security posture and a plurality of security objectives, a set of cybersecurity attributes of the entity”. The Examiner has fully considered applicant’s arguments and maintains that neither priority document Application Nos. 63/347,389 nor 63/457,671 adequately provide written description support for this claim limitation at least for the reasons set forth above with regard to the priority issues.
Applicant’s reliance upon paragraph [0247] adequately supporting the claim limitation “generate, based on the security posture and a plurality of security objectives, a set of cybersecurity attributes of the entity” is unpersuasive. The only discussion of the claimed generating a set of cybersecurity a set of cybersecurity attributes is “The processing circuits could then map the security posture onto the security objectives, identifying the gaps and generating the set of cybersecurity attributes that represent specific areas for improvement”. This recitation does not adequately provide written description support for the claim limitation at issue because it merely specifies a desired result as the disclosed circuits “could” perform the claimed generation. For computer-implemented inventions, the determination of the sufficiency of disclosure will require an inquiry into the sufficiency of both the disclosed hardware and the disclosed software due to the interrelationship and interdependence of computer hardware and software. The critical inquiry is whether the disclosure of the application relied upon reasonably conveys to those skilled in the art that the inventor had possession of the claimed subject matter as of the filing date.
As in MPEP 2161.01 (I), "The description requirement of the patent statute requires a description of an invention, not an indication of a result that one might achieve if one made that invention." It is not enough that one skilled in the art could write a program to achieve the claimed function because the specification must explain how the inventor intends to achieve the claimed function to satisfy the written description requirement. See, e.g., Vasudevan Software, Inc. v. MicroStrategy, Inc., 782 F.3d 671, 681-683, 114 USPQ2d 1349, 1356, 1357 (Fed. Cir. 2015).
Applicant’s arguments, see page 16, filed 07/10/2026, with respect to the rejection of claims 1-4, 8, 16-17, and 20 under 35 U.S.C. § 101 have been fully considered. The rejection of claims 1-4, 8, 16-17, and 20 under 35 U.S.C. § 101 have been withdrawn in response to the amended claims now reciting that “update, responsive at least in part to the state change, a configuration of at least one of a third-party tool, a third-party product, or a third-party service linked with the at least one cybersecurity protection plan; and record and distribute, via the distributed ledger, at least one of a proof or a ledger record corresponding to the update to the configuration” which incorporates the abstract idea into a practical application. The claims were previously drawn to a distributed ledger recited at a high level of generality such that it previously amounted to merely storage and insignificant extra-solution activity.
Applicant's arguments, see pages 17-18, filed 07/10/2026, with respect to the rejection of claims 1-4, 8, 16-17 and 20 under 35 U.S.C. § 102(a)(1) have been fully considered but they are not persuasive.
Since applicant does not give any further explanation as to how the previously cited art differentiates from the claimed invention other than repeating the amendments made to the claim and alleging that the previously presented Smith reference does not disclose, the examiner defers to the rejection below as a response to this argument.
Priority
Applicant’s claim for the benefit of a prior-filed application under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, 365(c), or 386(c) is acknowledged. Applicant has not complied with one or more conditions for receiving the benefit of an earlier filing date under 35 U.S.C. 119(e) as follows:
The later-filed application must be an application for a patent for an invention which is also disclosed in the prior application (the parent or original nonprovisional application or provisional application). The disclosure of the invention in the parent application and in the later-filed application must be sufficient to comply with the requirements of 35 U.S.C. 112(a) or the first paragraph of pre-AIA 35 U.S.C. 112, except for the best mode requirement. See Transco Products, Inc. v. Performance Contracting, Inc., 38 F.3d 551, 32 USPQ2d 1077 (Fed. Cir. 1994).
The disclosure of the prior-filed applications, Application No. 63/457,671 and 63/347,389, both fail to provide adequate support or enablement in the manner provided by 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, first paragraph for one or more claims of this application. Neither provisional application provide adequate written description support for the claim limitation “generate, based on the security posture and a plurality of security objectives, a set of cybersecurity attributes of the entity” found in independent claims 1, 16, and 20.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claim 1-4, 8, 16-17, and 20 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Regarding Claims 1, 16, and 20:
Independent claims 1, 16, and 20 recite “generate, based on the security posture and a plurality of security objectives, a set of cybersecurity attributes of the entity”. The limitations in question do not satisfy the written description requirement under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph. The specification does not describe the limitation in sufficient detail so that one of ordinary skill in the art would recognize that the applicant had possession of the claimed invention. For example, the claim construction in independent claim 1 recites one or more processing circuits comprising memory and processors configured to generate a set of cybersecurity attributes of the entity, based on the security posture and a plurality of security objectives. Neither the priority documents nor the originally filed disclosure adequately describe how such a processing circuit is configured to perform the claimed function generating cybersecurity attributes. While the claims recite what the attributes are based on, one of ordinary skill in the art would not be apprised of how the inventor intended to actually perform the desired function of generation as claimed. The algorithm or steps/procedures for these claimed functions is not explained at all or is not explained in sufficient detail (simply restating the function reciting in the claim is not necessarily sufficient) so that one of ordinary skill in the art would recognize that the applicant had possession of the claimed invention.
For computer-implemented inventions, the determination of the sufficiency of disclosure will require an inquiry into the sufficiency of both the disclosed hardware and the disclosed software due to the interrelationship and interdependence of computer hardware and software. The critical inquiry is whether the disclosure of the application relied upon reasonably conveys to those skilled in the art that the inventor had possession of the claimed subject matter as of the filing date.
As in MPEP 2161.01 (I), "The description requirement of the patent statute requires a description of an invention, not an indication of a result that one might achieve if one made that invention." It is not enough that one skilled in the art could write a program to achieve the claimed function because the specification must explain how the inventor intends to achieve the claimed function to satisfy the written description requirement. See, e.g., Vasudevan Software, Inc. v. MicroStrategy, Inc., 782 F.3d 671, 681-683, 114 USPQ2d 1349, 1356, 1357 (Fed. Cir. 2015).
“The Federal Circuit has explained that a specification cannot always support expansive claim language and satisfy the requirements of 35 U.S.C. 112 "merely by clearly describing one embodiment of the thing claimed." LizardTech v. Earth Resource Mapping, Inc., 424 F.3d 1336, 1346, 76 USPQ2d 1731, 1733 (Fed. Cir. 2005). The issue is whether a person skilled in the art would understand applicant to have invented, and been in possession of, the invention as broadly claimed. In LizardTech, claims to a generic method of making a seamless discrete wavelet transformation (DWT) were held invalid under 35 U.S.C. 112, first paragraph, because the specification taught only one particular method for making a seamless DWT and there was no evidence that the specification contemplated a more generic method. "[T]he description of one method for creating a seamless DWT does not entitle the inventor . . . to claim any and all means for achieving that objective." LizardTech, 424 F.3d at 1346, 76 USPQ2d at 1733.”
The dependent claims fall together accordingly.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1-4, 8, 16-17 and 20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Smith et. al. (US Publication No. US 20190132350 A1), hereinafter Smith.
Regarding Claims 1, 16, and 20:
Claim 1. Smith discloses a data protection system for protecting data, the data protection system comprising: a plurality of data channels configured to access entity data of an entity; one or more processing circuits communicatively coupled to the plurality of data channels, the one or more processing circuits comprising memory and processors configured to (Smith [0043-0058]; [0171-0174]): determine a security posture based on the entity data (Smith [0142-0143] and Table 5-6 Cloud security includes operational security and secure standardized network protocols are in place to manage the cloud service and resources are classified); tokenize and broadcast the security posture to a distributed ledger (Smith Table 5 Blockchain enumerated); generate, based on the security posture and a plurality of security objectives, a set of cybersecurity attributes of the entity (Smith [0118] use risk evaluation to achieve objectives; Table 6 different cybersecurity attributes); determine, utilizing one or more protection parameters, at least one cybersecurity protection plan corresponding to a new cybersecurity attribute to protect the entity (Smith Table 6 Data security plans and policies enumerated); provide, via a graphical user interface (GUI), the at least one cybersecurity protection plan to an entity computing system of the entity (Smith Table 6 “comprehensive incident response plan exists to identify, manage, respond to, and recover from security (e.g., system breach) and IT operational (e.g., process errors) incidents and is communicated to appropriate stakeholders. The incident response plan is reviewed and modified on a periodic basis.”) wherein the GUI comprises (i) one or more graphical elements configured to receive an input that causes a selection, modification, or update to the at least one cybersecurity protection plan and (ii) at least one indication of the security posture (Smith [0092-0093], [0097] rules engine 428 user interface can enable the user to dynamically toggle rules, add/subtract rules; 0103-0104 web interface; Table 6 Cyber Security Data Security “Data Exchange is controlled, encrypted, and protected while the information is at rest or transferred between systems. Formal information exchange requirements have been established and Blockchain systems are configured to protect the exchange of information through use of all types of communication facilities and interfaces”; Table 7 Cyber Security Programming security “Verify that during the functional requirements gathering phase, the information security requirements are captured and consider the following: … required protection needs of assets involved requirements derived from business processes, such as transaction logging and monitoring, non- repudiation requirements mandated by other security controls, e.g., interfaces to logging and monitoring or data leakage detection systems information users and operators of their duties and responsibilities”; Table 6 “comprehensive incident response plan exists to identify, manage, respond to, and recover from security (e.g., system breach) and IT operational (e.g., process errors) incidents and is communicated to appropriate stakeholders. The incident response plan is reviewed and modified on a periodic basis.”; [0144], [0156], and [0160] interface technologies used) determine, based on accessing data associated with the security posture and broadcast to the distributed ledger, a state change associated with the security posture (Smith Table 7 “Distributes copies of the security plan and communicates subsequent changes to the plan to organization-defined personnel or roles; Reviews the security plan for the information system per organization-defined frequency; Updates the plan to address changes to the information system/environment of operation or problems identified during plan implementation or security control assessments… inspect policies and procedures to confirm they are reviewed and updated based on changes in the environment… Verify if the incident response plan is periodically updated to address system/organizational changes or problems encountered or lessons learned during plan implementation, execution, training, or testing”); update, responsive at least in part to the state change, a configuration of at least one of a third-party tool, a third-party product, or a third-party service linked with the at least one cybersecurity protection plan (Smith Table 1 Third-party risk is contemplated, Table 7 “Requirement to provide notification of changes 2. Evidence that a new to services or controls customer or vendor Requirement to provide notification of 3rd contract addendum or party personnel transfers and terminations new vendor contract… Distributes copies of the security plan and communicates subsequent changes to the plan to organization-defined personnel or roles; Reviews the security plan for the information system per organization-defined frequency; Updates the plan to address changes to the information system/environment of operation or problems identified during plan implementation or security control assessments… inspect policies and procedures to confirm they are reviewed and updated based on changes in the environment… Verify if the incident response plan is periodically updated to address system/organizational changes or problems encountered or lessons learned during plan implementation, execution, training, or testing”); and record and distribute, via the distributed ledger, at least one of a proof or a ledger record corresponding to the update to the configuration (Smith [0144] “In some embodiments, infrastructure layer risk category in the blockchain risk framework covers relevant risks, control objectives and descriptions, testing objectives and procedures, and reporting parameters designed to address assurance and compliance needs for the blockchain infrastructure stack/layer supporting functioning of the underlying hardware, software, servers, databases, networks, interfaces technologies (e.g. APIs etc.)” Table 9 “Change Management controls are defined, established, and enforced”, Table 7 “Distributes copies of the security plan and communicates subsequent changes to the plan to organization-defined personnel or roles; Reviews the security plan for the information system per organization-defined frequency; Updates the plan to address changes to the information system/environment of operation or problems identified during plan implementation or security control assessments”, Table 9 “Changes to Blockchain Application and Operating System/Network and approval configurations and enhancements are adequately tested and approved before being migrated into production and are monitored for appropriateness… As changes to the Blockchain are contemplated, appropriate controls are in place to ensure that they are approved and rolled out across the network in a manner consistent with the Blockchain governance framework”).
Claims 16 and 20 recite substantially the same content and are therefore rejected under the same rationales. Smith discloses a method (Smith [0055]). Smith further discloses a non-transitory computer readable medium comprising one or more instructions stored thereon and executable by one or more processors (Smith [0043-0058]; [0171-0174]).
Regarding Claims 2 and 17:
Claim 2. Smith further discloses the data protection system of claim 1 (Smith [0043-0058]; [0171-0174]), wherein determining the security posture further comprises: determine a plurality of data types based on analyzing data storage systems of the entity (Smith Table 6 “unauthorized leaks of data, specifically PII and PHI, are prevented or detected”; Table 7 Data classification enumerated and compliance with proper documentation enumerated); determine at least one cybersecurity threat based on the entity data (Smith Table 6 “comprehensive incident response plan exists to identify, manage, respond to, and recover from security (e.g., system breach) and IT operational (e.g., process errors) incidents and is communicated to appropriate stakeholders. The incident response plan is reviewed and modified on a periodic basis.”); identify entity assets based on accessing at least one of the plurality of data channels communicatively coupled to at least one of the entity assets (Smith Table 7 Data classification enumerated and compliance with proper documentation enumerated); and wherein the security posture corresponds to an assessment of a cybersecurity risk profile of the entity (Smith [0142-0143] and Table 5-6 Cloud security includes operational security and secure standardized network protocols are in place to manage the cloud service and resources are classified and risk strategy/appetite discussed).
Claim 17 recites substantially the same content and is therefore rejected under the same rationales.
Regarding Claim 3:
Smith further discloses the data protection system of claim 2 (Smith [0043-0058]; [0171-0174]), wherein the security posture comprises a current entity state and a current entity index (Smith Table 6-7), wherein the current entity state corresponds to current cybersecurity conditions of the entity (Smith Table 6 cybersecurity perimeter determined along with current penetration testing conditions and vulnerability scans), and wherein the current entity index corresponds to references or pointers to the entity assets of the entity (Smith Table 7 threat detection encompasses file changes and access-related logging events “continuously writes logs from production servers, network devices, databases and storage management hosts to system logs and forwards them to the logging and alerting system in real- time in order to provide backup media for records other than the audited system; configures the information system to provide the capability to generate audit records for defined auditable events for specified information system components; configures the information system to allow specified personnel to select which auditable events should be audited by specific system components; configures the information system to provide capabilities for specified individuals to change the performed audits on information system components based on defined selectable event criteria within specified thresholds”).
Regarding Claim 4:
Smith further discloses the data protection system of claim 3 (Smith [0043-0058]; [0171-0174]), wherein the security posture corresponds to an aggregate representation of at least two of an entities firmographics, data types, asset locations, cybersecurity safeguards, cybersecurity coverage, cybersecurity gaps compared to the one or more protection parameters or cybersecurity threats, cyber hygiene, third-party attestations, cybersecurity incidents, and cybersecurity claims (Smith [0142-0143] and Table 5-6 Cloud security includes operational security and secure standardized network protocols are in place to manage the cloud service and resources are classified).
Regarding Claim 8:
Smith further discloses the data protection system of claim 1 (Smith [0043-0058]; [0171-0174]), wherein each cybersecurity attribute of the set of cybersecurity attributes is associated with at least one of a required cybersecurity attribute, an additional cybersecurity attribute, or an existing cybersecurity attribute (Smith Table 6 different cybersecurity attributes).
Conclusion
The prior art made of record in the submitted PTO-892 Notice of References Cited and not relied upon is considered pertinent to applicant’s disclosure.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MIGUEL A LOPEZ whose telephone number is (703)756-1241. The examiner can normally be reached 8:00AM-5:00PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge Ortiz-Criado can be reached on 5712727624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/M.A.L./ Examiner, Art Unit 2496
/JORGE L ORTIZ CRIADO/Supervisory Patent Examiner, Art Unit 2496