DETAILED ACTION
Claims 1-20 are pending in Instant Application.
Priority
Examiner acknowledges Applicant’s claim to priority benefits of provisional application 63305082 filed 01/31/2022.
Information Disclosure Statement
The information disclosure statement(s) (IDS) submitted on 01/15/2025 is/are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement(s) is/are being considered if signed and initialed by the Examiner.
Double Patenting
A rejection based on double patenting of the "same invention" type finds its support in the language of 35 U.S.C. 101 which states that "whoever invents or discovers any new and useful process ... may obtain a patent therefor ..." (Emphasis added). Thus, the term "same invention," in this context, means an invention drawn to identical subject matter. See Miller v. Eagle Mfg. Co., 151 U.S. 186 (1894); In re Ockert, 245 F.2d 467, 114 USPQ 330 (CCPA 1957); and In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970).
A statutory type (35 U.S.C. 101) double patenting rejection can be overcome by canceling or amending the conflicting claims so they are no longer coextensive in scope. The filing of a terminal disclaimer cannot overcome a double patenting rejection based upon 35 U.S.C. 101.
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement.
Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b).
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12282564. Although the claims at issue are not identical, they are not patentably distinct from each other because:
U.S. Patent 12282564
Instant Application
Diagnosis
1. A computer-implemented method for providing a cyber resilience rating for an entity of a plurality of entities, the method comprising:
obtaining a plurality of entity indicators corresponding to the plurality of entities, wherein each of the plurality of entity indicators comprises characteristic information for a respective entity of the plurality of entities, and wherein each of the plurality of entities corresponds to a respective entity indicator of the plurality of entity indicators;
determining a peer group for the entity based on the respective characteristic information for the entity, wherein the peer group comprises a subset of the plurality of entities;
obtaining a plurality of loss event records for the peer group, wherein each loss event record comprises a respective loss value and corresponds to a cyber event associated with a respective entity of the peer group, wherein respective groups of loss event records selected from the plurality of loss event records correspond to a data disclosure type, a business interruption type, and a fraud type;
executing, for each group of loss event records, a plurality of Monte Carlo simulations to generate respective loss simulation data based on the respective loss values of the loss event records included in the group and results for a cyber security assessment of the entity;
identifying, based on the respective loss simulation data for each group of loss event records, an expected probability value corresponding to a materiality loss value of the entity;
providing a risk factor score indicative of a cyber security risk of the entity based on the identified expected probability value; and
providing a cyber resilience rating for the entity based on a combination of the risk factor score, a fortitude factor score, and a governance factor score, wherein the fortitude factor score is indicative of a cyber security control posture of the entity, and wherein the governance factor score is indicative of an administration of cyber security controls by the entity.
1. A computer-implemented method for providing a cyber resilience rating for an entity of a plurality of entities, the method comprising:
determining a peer group for an entity of a plurality of entities based on characteristic information for the entity, wherein the peer group comprises at least one entity of the plurality of entities different from the entity;
obtaining a plurality of loss event records, wherein each loss event record comprises a respective loss value corresponding to a cyber event associated with a respective entity of the peer group, wherein respective groups of loss event records selected from the plurality of loss event records correspond to a data disclosure type, a business interruption type, and a fraud type;
executing, for each group of loss event records, a Monte Carlo simulation to generate respective loss simulation data for that group of loss event records;
providing a risk factor score indicative of a cyber security risk of the entity based on the respective loss simulation data for each group of loss event records; and
providing a cyber resilience rating for the entity based on a combination of the risk factor score, a fortitude factor score, and a governance factor score, wherein the fortitude factor score is indicative of a cyber security control posture of the entity, and wherein the governance factor score is indicative of an administration of cyber security controls by the entity.
Similar scope
2. The method of claim 1, wherein the characteristic information comprises an industry indicator, a geography indicator, and a size indicator for the respective entity.
2. The method of claim 1, wherein the characteristic information comprises an industry indicator, a geography indicator, and a size indicator for the entity.
Similar scope
3. The method of claim 2, wherein the determining the peer group for the entity based on the respective entity characteristics of the entity further comprises: selecting, from the plurality of entities, the[[a]] subset of the plurality of entities for inclusion in the peer group based on the respective characteristic information corresponding to each entity of the subset of the plurality of entities comprising at least one of: the industry indicator, the geography indicator, and the size indicator corresponding to the entity.
3. The method of claim 2, wherein the determining the peer group for the entity based on the respective entity characteristics of the entity further comprises: selecting, from the plurality of entities, the at least one entity of the plurality of entities different from the entity for inclusion in the peer group based on respective characteristic information corresponding to each entity of the at least one entity of the plurality of entities comprising at least one of: the industry indicator, the geography indicator, and the size indicator for the entity.
Similar scope
4. The method of claim 1, wherein the peer group comprises a first peer group and a second peer group, wherein the first peer group and the second peer group comprise different subsets of the plurality of entities.
4. The method of claim 1, wherein the peer group comprises a first peer group and a second peer group, wherein the first peer group and the second peer group comprise different subsets of the plurality of entities.
Similar scope
5. The method of claim 1, wherein each loss event record of the plurality of loss event records comprises a respective loss event type corresponding to one of: the data disclosure type, the business interruption type, or the fraud type, and further comprising: selecting the respective groups of loss event records from the plurality of loss event records based on the respective loss event type of each loss event record included in the respective groups of loss event records.
5. The method of claim 1, wherein each loss event record of the plurality of loss event records comprises a respective loss event type corresponding to one of: the data disclosure type, the business interruption type, or the fraud type, and further comprising: selecting the respective groups of loss event records from the plurality of loss event records based on the respective loss event type of each loss event record included in the respective groups of loss event records.
Similar scope
6. The method of claim 1, wherein the data disclosure type corresponds to at least one of: a data breach; a data theft; a data loss; and an unintentional data disclosure.
6. The method of claim 1, wherein the data disclosure type corresponds to at least one of: a data breach; a data theft; a data loss; and an unintentional data disclosure.
Similar scope
7. The method of claim 1, wherein the business interruption type corresponds to at least one of: a cyber extortion event; a network disruption; and a website disruption.
7. The method of claim 1, wherein the business interruption type corresponds to at least one of: a cyber extortion event; a network disruption; and a website disruption.
Similar scope
8. The method of claim 1, wherein the fraud type corresponds to at least one of: an identity fraud event; a phishing event; and a skimming event.
8. The method of claim 1, wherein the fraud type corresponds to at least one of: an identity fraud event; a phishing event; and a skimming event.
Similar scope
9. The method of claim 1, wherein the executing, for each group of loss event records, the plurality of Monte Carlo simulations to generate the respective loss simulation data further comprises: determining a statistic from the respective loss values of the loss event records included in the group; weighting the statistic based on the results for the cyber security assessment of the entity to determine a weighted statistic; and executing the plurality of Monte Carlo simulations based on the weighted statistic.
9. The method of claim 1, wherein the executing, for each group of loss event records, the Monte Carlo simulation to generate the respective loss simulation data further comprises: determining a statistic from the respective loss values of the loss event records included in the group; weighting the statistic based on results for a cyber security assessment of the entity to determine a weighted statistic; and executing the Monte Carlo simulation based on the weighted statistic.
Similar scope
10. The method of claim 1, wherein the cyber security assessment comprises an outside-in cyber security assessment or an inside-out cyber security assessment.
10. The method of claim 1, wherein the cyber security assessment comprises an outside-in cyber security assessment of the entity or an inside-out cyber security assessment of the entity.
Similar scope
11. The method of claim 1, wherein the materiality loss value is based on an industry indicator corresponding to the entity and a revenue corresponding to the entity, and further comprising: determining a respective materiality ratio for each respective loss simulation data, wherein the each of the respective materiality ratios are based on the loss materiality loss value corresponding to the entity; and selecting the respective loss simulation data corresponding to a largest materiality ratio of the materiality ratios.
11. The method of claim 1, further comprising: identifying, based on the respective loss simulation data for each group of loss event records, an expected probability value corresponding to a materiality loss value of the entity; determining a respective materiality ratio for each respective loss simulation data, wherein the each of the respective materiality ratios are based on the materiality loss value corresponding to the entity; and selecting the respective loss simulation data corresponding to a largest materiality ratio of the materiality ratios.
Similar scope
12. The method of claim 11, wherein the identifying the expected probability value corresponding to the materiality loss value of the entity further comprises: generating a loss exceedance curve indicative of a probability of loss potential for the entity based on the selected loss simulation data; and identifying, from the loss exceedance curve, the expected probability value corresponding to the materiality loss value of the entity.
12. The method of claim 11, wherein the identifying the expected probability value corresponding to the materiality loss value of the entity further comprises: generating a loss exceedance curve indicative of a probability of loss potential for the entity based on the selected loss simulation data; and identifying, from the loss exceedance curve, the expected probability value corresponding to the materiality loss value of the entity.
Similar scope
13. (Original) The method of claim 1, further comprising: obtaining signal data indicative of a cyber resilience of the entity; generating, based on a first subset of the signal data, the fortitude factor score, wherein the first subset of the signal data is indicative of the cyber security control posture of the entity; and generating, based on a second subset of the signal data, the governance factor score, wherein the second subset of the signal data is indicative of the administration of cyber security controls by the entity.
13. The method of claim 1, further comprising: obtaining signal data indicative of a cyber resilience of the entity; generating, based on a first subset of the signal data, the fortitude factor score, wherein the first subset of the signal data is indicative of the cyber security control posture of the entity; and generating, based on a second subset of the signal data, the governance factor score, wherein the second subset of the signal data is indicative of the administration of cyber security controls by the entity.
Similar scope
14. A system for providing a cyber resilience rating for an entity of a plurality of entities, the system comprising: one or more computing systems programmed to perform operations comprising:
obtaining a plurality of entity indicators corresponding to the plurality of entities, wherein each of the plurality of entity indicators comprises characteristic information for a respective entity of the plurality of entities, and wherein each of the plurality of entities corresponds to a respective entity indicator of the plurality of entity indicators;
determining a peer group for the entity based on the respective characteristic information for the entity, wherein the peer group comprises a subset of the plurality of entities;
obtaining a plurality of loss event records for the peer group, wherein each loss event record comprises a respective loss value and corresponds to a cyber event associated with a respective entity of the peer group, wherein respective groups of loss event records selected from the plurality of loss event records correspond to a data disclosure type, a business interruption type, and a fraud type;
executing, for each group of loss event records, a plurality of Monte Carlo simulations to generate respective loss simulation data based on the respective loss values of the loss event records included in the group and results for a cyber security assessment of the entity;
identifying, based on the respective loss simulation data for each group of loss event records, an expected probability value corresponding to a materiality loss value of the entity;
providing a risk factor score indicative of a cyber security risk of the entity based on the identified expected probability value; and
providing a cyber resilience rating for the entity based on a combination of the risk factor score, a fortitude factor score, and a governance factor score, wherein the fortitude factor score is indicative of a cyber security control posture of the entity, and wherein the governance factor score is indicative of an administration of cyber security controls by the entity.
14. A system for providing a cyber resilience rating for an entity of a plurality of entities, the system comprising: one or more computing systems programmed to perform operations comprising:
determining a peer group for an entity of a plurality of entities based on characteristic information for the entity, wherein the peer group comprises at least one of the plurality of entities;
obtaining a plurality of loss event records, wherein each loss event record comprises a respective loss value corresponding to a cyber event associated with a respective entity of the peer group, wherein respective groups of loss event records selected from the plurality of loss event records correspond to a data disclosure type, a business interruption type, and a fraud type;
executing, for each group of loss event records, a Monte Carlo simulation to generate respective loss simulation data for that group of loss event records;
providing a risk factor score indicative of a cyber security risk of the entity based on the respective loss simulation data for each group of loss event records; and providing a cyber resilience rating for the entity based on a combination of the risk factor score, a fortitude factor score, and a governance factor score, wherein the fortitude factor score is indicative of a cyber security control posture of the entity, and wherein the governance factor score is indicative of an administration of cyber security controls by the entity.
Similar scope
15. The system of claim 14, wherein the characteristic information comprises an industry indicator, a geography indicator, and a size indicator for the respective entity.
15. The system of claim 14, wherein the characteristic information comprises an industry indicator, a geography indicator, and a size indicator for the entity.
Similar scope
16. The system of claim 15, wherein the determining the peer group for the entity based on the respective entity characteristics of the entity further comprises: selecting, from the plurality of entities, the[[a]] subset of the plurality of entities for inclusion in the peer group based on the respective characteristic information corresponding to each entity of the subset of the plurality of entities comprising at least one of: the industry indicator, the geography indicator, and the size indicator corresponding to the entity.
16. The system of claim 15, wherein the determining the peer group for the entity based on the respective entity characteristics of the entity further comprises: selecting, from the plurality of entities, the at least one entity of the plurality of entities different from the entity for inclusion in the peer group based on respective characteristic information corresponding to each entity of the subset of the plurality of entities comprising at least one of: the industry indicator, the geography indicator, and the size indicator for the entity.
Similar scope
17. The system of claim 14, wherein the peer group comprises a first peer group and a second peer group, wherein the first peer group and the second peer group comprise different subsets of the plurality of entities.
17. The system of claim 14, wherein the peer group comprises a first peer group and a second peer group, wherein the first peer group and the second peer group comprise different subsets of the plurality of entities.
Similar scope
18. The system of claim 14, wherein each loss event record of the plurality of loss event records comprises a respective loss event type corresponding to one of: the data disclosure type, the business interruption type, or the fraud type, and wherein the operations further comprise: selecting the respective groups of loss event records from the plurality of loss event records based on the respective loss event type of each loss event record included in the respective groups of loss event records.
18. The system of claim 14, wherein each loss event record of the plurality of loss event records comprises a respective loss event type corresponding to one of: the data disclosure type, the business interruption type, or the fraud type, and wherein the operations further comprise: selecting the respective groups of loss event records from the plurality of loss event records based on the respective loss event type of each loss event record included in the respective groups of loss event records.
Similar scope
19. The system of claim 14, wherein the data disclosure type corresponds to at least one of: a data breach; a data theft; a data loss; and an unintentional data disclosure.
19. The system of claim 14, wherein the data disclosure type corresponds to at least one of: a data breach; a data theft; a data loss; and an unintentional data disclosure.
Similar scope
20. The system of claim 14, wherein the business interruption type corresponds to at least one of: a cyber extortion event; a network disruption; and a website disruption.
20. The system of claim 14, wherein the business interruption type corresponds to at least one of: a cyber extortion event; a network disruption; and a website disruption.
Similar scope
Claim Rejections - 35 USC § 101
Claims 14-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter.
The language of claim 14 raises a question as to whether the claims are directed merely to an abstract idea that is not tied to a technological art, environment or machine which would result in a practical application producing a concrete, useful, and tangible result to form the basis of statutory subject matter under 35 U.S.C. 101.
The applicant claims “A system for providing a cyber resilience rating for an entity of a plurality of entities, the system comprising: one or more computing systems programmed to perform operations comprising” but does not define within the body of the claim the hardware in which the invention runs. Thus, absent recitation of the server or some other hardware, claim 14 is not limited to a tangible embodiment, instead being sufficiently broad to encompass software, per se.
Claims 15-20 are rejected for dependency upon rejected base claim 14 above.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to NORMIN ABEDIN whose telephone number is (571)270-5970. The examiner can normally be reached Monday to Friday from 10 am to 6 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Vivek Srivastava can be reached at 5712727304. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/NORMIN ABEDIN/ Primary Examiner, Art Unit 2449