The objective of enterprise security architecture is to provide the conceptual design of the network security infrastructure, related security mechanisms, and related security policies and procedures. The enterprise security architecture links the components of the security infrastructure as one cohesive unit. The goal of this cohesive unit is to protect corporate information.
This structured approach saves time, resources, and money by providing guidelines to reduce the repeated security practices and processes that should be performed with each IT project. A strategic and effective enterprise security architecture of today needs to be based on Defense in Depth which is a concept used to describe layers of defense strategies. The components at each layer work in tandem to provide one cohesive security mechanism.
Our security architects and/or consultants assist clients in the development of an enterprise security architecture which is business-driven and which describes a structured inter-relationship between the technical and procedural solutions to support the long-term needs of the business. If the architecture is to be successful, then it must provide a rational framework within which decisions can be made upon the selection of security solutions.
We derive our decision criteria from a thorough understanding of the business requirements, including – the need for cost reduction, Modularity, Scalability, Ease of component re-use, Operability, Usability, Inter-operability both internally and externally, Integration with the enterprise IT architecture and its legacy systems.
Our security architecture service is designed to align with your enterprise architecture. We focus on ensuring that the security impacts of the business, information, application and technology architectures are addressed.
Methodology
Our methodology for information security architecture engagements can be summarised as follows:
- High level information security risk assessment. By engaging with key client executives, stakeholders, and IT we can assist with determining an organisations key information assets that are in need of protection, and then design appropriate solutions within budget constraints to mitigate the risks they are exposed to.
- Information security architecture review.
- Current state review. Review of the existing IT security architecture, policies and governance and re-use considerations.
- Target state development. Develop the target information security architecture addressing both the current and future requirements, but mindful of short term drivers.
- Gap analysis between target state and the current state. We prioritise the gap items according to business risk drivers. This then leads to the development of a roadmap to progressively close the gap over time, aligned with business priorities.
- Roadmap. This will include the IT security governance and policies required to ensure that security is built-in as the organisation plans, designs, deploys and manages their IT infrastructure and applications.
Top 5 Concerns
Below are the top five concerns that we address in client engagements:
- Lack of an over-arching enterprise security architecture framework. There is a consensus that enterprise security architecture is a methodology for addressing security concerns at every and each architecture domain (business, data, application and technology) and layer of abstraction (contextual, conceptual, logical, physical and implementation).
- A need to transform the security organisation. Information security has been traditionally dealt at the information security management, operational security and solution design level, resulting in lack of alignment with both business and IT and operational imbalance. Our approach to resolving this issue is what we call “architecting a security organisation”. We define the security capabilities starting at the governance level through architecture and planning to build, delivery and monitoring. We position the security capabilities as a subset of the business reference model to give understanding of how they fit within the organisational units, business functions and processes.
- Enterprise-wide regulatory and internal compliance. The increasing number and scope of regulatory requirements can affect the products and service delivery. At Enterprise Architects, we use enterprise architecture to resolve conflicts between business objectives, internal compliance requirements and regulatory and legislative requirements. Gaining clarity around what these are, what are their conflicts and how are they affecting the core business capabilities facilitates business decision making.
- A need for business-outcome-focused and risk-driven security reference architectures. In our enterprise security architecture framework, risk and business objectives are the key drivers for the selection of security controls. As this is a top-down approach, it ensures that all policies and controls are identified and owned.
- Data privacy concerns in relation to emerging trends and technologies, such as cloud, BYOD and mobility security. The key challenge here is not around infrastructure architecture and design, but around gaining clarity and resolving conflicts in relation to data privacy requirements, threat and vulnerability vectors and business objectives. The architectural approach to security allows one to gain clarity around the aforementioned, at the business, data and infrastructure security level.