Showing posts with label Enterprise Security Architecture. Show all posts
Showing posts with label Enterprise Security Architecture. Show all posts

Monday, 20 June 2016

GENERIC ARCHITECTURE DESIGN PRINCIPLES

When designing any architecture there are certain principles need to be considered and followed. They will assure the architecture is aligned with business strategy, vision and goals. Usually Enterprise architect team is responsible of defining those principles with senior management help and guidance. Below are some principles to be used when designing security architecture.
  • Principle 1: Comprehensive Documentation
  • Principle 2: No plan is fool-proof
  • Principle 3: Successful business operation supported by reasonable and appropriate controls
  • Principle 4: Business requirements require translation into forms that technical architecture designers can form into conceptual models
  • Principle 5: It makes no sense to design something the engineers can’t build
  • Principle 6: Partial understanding results in incomplete designs
  • Principle 7: Use attach trees
  • Principles 8: Business and technical users will avoid complex and hard to use security controls
  • Principle 9: Testing models and final architecture implementations must take into consideration design
  • Principle 10: Ensure architecture constraints are reviewed during the change management process
  • Principle 11: Frequently assess risk
  • Principle 12: Meeting security requirements means the architecture is compliant with regulatory and best practise constraints

Gartner’s Six Principles of Resilience for Digital Business Risk and Security


There are 6 main principles when talking about information security. These principles first introduced in 2016 by Gartner risk and security division.

Principles are:

  • Principle No. 1: Stop Focusing on Check Box Compliance, and Shift to Risk-Based Decision Making
    • Security is not the same old beast. Information security must be a top down approach and driven from identified business risk. Risk management and risk analysis is the first big step of any information security work.
  • Principle No. 2: Stop Solely Protecting Infrastructure, and Begin Supporting Business Outcomes
    • Information security is a business enabler. Security is there to help business achieve its goals and targets. The only way of having a successful information security architecture is to make sure it is aligned with business strategy.
  • Principle No. 3: Stop Being a Defender, and Become a Facilitator
    • Again, the aim of information security is to facilitate business to hit the targets. Of-course security is important, but if we are blocking business process, it is useless.
  • Principle No. 4: Stop Trying to Control Information; Instead, Determine How It Flows
    • Big shift in security mind set is moving away from local and limited controls and have a holistic approach looking at flows and process.
  • Principle No. 5: Accept the Limits of Technology and Become People-Centric
    • These days more and more attacks are result of lack of user awareness. Training people and using resources is as important as having technical controls.
  • Principle No. 6: Stop Trying to Perfectly Protect Your Organization, and Invest in Detection and Response
    • We all know it is impossible to have a complete safe environment. Threats and vulnerabilities are always there. Proper incident response plan and operation is crucial for any business.