Enterprise Security Architecture Design AND RE_DESIGN PRACTICE CONSULTANTS EXPERTS PROFESSIONALS

The objective of enterprise security architecture is to provide the conceptual design of the network security infrastructure, related security mechanisms, and related security policies and procedures. The enterprise security architecture links the components of the security infrastructure as one cohesive unit. The goal of this cohesive unit is to protect corporate information.

This structured approach saves time, resources, and money by providing guidelines to reduce the repeated security practices and processes that should be performed with each IT project. A strategic and effective enterprise security architecture of today needs to be based on Defense in Depth which is a concept used to describe layers of defense strategies. The components at each layer work in tandem to provide one cohesive security mechanism.

Our security architects and/or consultants assist clients in the development of an enterprise security architecture which is business-driven and which describes a structured inter-relationship between the technical and procedural solutions to support the long-term needs of the business. If the architecture is to be successful, then it must provide a rational framework within which decisions can be made upon the selection of security solutions.

We derive our decision criteria from a thorough understanding of the business requirements, including – the need for cost reduction, Modularity, Scalability, Ease of component re-use, Operability, Usability, Inter-operability both internally and externally, Integration with the enterprise IT architecture and its legacy systems. Our security architecture service is designed to align with your enterprise architecture. We focus on ensuring that the security impacts of the business, information, application and technology architectures are addressed.

Methodology

Our methodology for information security architecture engagements can be summarised as follows:

  1. High level information security risk assessment. By engaging with key client executives, stakeholders, and IT we can assist with determining an organisations key information assets that are in need of protection, and then design appropriate solutions within budget constraints to mitigate the risks they are exposed to.
  2. Information security architecture review.
    • Current state review. Review of the existing IT security architecture, policies and governance and re-use considerations.
    • Target state development. Develop the target information security architecture addressing both the current and future requirements, but mindful of short term drivers.
    • Gap analysis between target state and the current state. We prioritise the gap items according to business risk drivers. This then leads to the development of a roadmap to progressively close the gap over time, aligned with business priorities.
  3. Roadmap. This will include the IT security governance and policies required to ensure that security is built-in as the organisation plans, designs, deploys and manages their IT infrastructure and applications.

Top 5 Concerns

Below are the top five concerns that we address in client engagements:

  1. Lack of an over-arching enterprise security architecture framework. There is a consensus that enterprise security architecture is a methodology for addressing security concerns at every and each architecture domain (business, data, application and technology) and layer of abstraction (contextual, conceptual, logical, physical and implementation).
  2. A need to transform the security organisation. Information security has been traditionally dealt at the information security management, operational security and solution design level, resulting in lack of alignment with both business and IT and operational imbalance. Our approach to resolving this issue is what we call “architecting a security organisation”. We define the security capabilities starting at the governance level through architecture and planning to build, delivery and monitoring. We position the security capabilities as a subset of the business reference model to give understanding of how they fit within the organisational units, business functions and processes.
  3. Enterprise-wide regulatory and internal compliance. The increasing number and scope of regulatory requirements can affect the products and service delivery. At Enterprise Architects, we use enterprise architecture to resolve conflicts between business objectives, internal compliance requirements and regulatory and legislative requirements. Gaining clarity around what these are, what are their conflicts and how are they affecting the core business capabilities facilitates business decision making.
  4. A need for business-outcome-focused and risk-driven security reference architectures. In our enterprise security architecture framework, risk and business objectives are the key drivers for the selection of security controls. As this is a top-down approach, it ensures that all policies and controls are identified and owned.
  5. Data privacy concerns in relation to emerging trends and technologies, such as cloud, BYOD and mobility security. The key challenge here is not around infrastructure architecture and design, but around gaining clarity and resolving conflicts in relation to data privacy requirements, threat and vulnerability vectors and business objectives. The architectural approach to security allows one to gain clarity around the aforementioned, at the business, data and infrastructure security level.

Implementing security architecture is often a confusing process in enterprises. Traditionally, security architecture consists of some preventive, detective and corrective controls that are implemented to protect the enterprise infrastructure and applications. Some enterprises are doing a better job with security architecture by adding directive controls, including policies and procedures. Many information security professionals with a traditional mind-set view security architecture as nothing more than having security policies, controls, tools and monitoring.

The world has changed; security challenges faced by our clients are not as before - Always evolving. Today’s risk factors and threats are not the same, nor as simple as they used to be. New emerging technologies and possibilities, e.g., the Internet of Things, change a lot about how companies operate, what their focus is and their goals. It is important for all security professionals to understand business objectives and try to support them by implementing proper controls that can be simply justified for stakeholders and linked to the business risk. Enterprise frameworks, such as Sherwood Applied Business Security Architecture (SABSA), COBIT and The Open Group Architecture Framework (TOGAF), can help achieve this goal of aligning security needs with business needs.

Including software security assurance methodology at the beginning of the software development life cycle (SDLC) is the most effective path to secure applications. It’s also the least expensive, because you’re stopping flaws from being built in rather than fixing them after the fact. We use established software security assurance models and frameworks such as the Software Assurance Maturity Model (SAMM), BSIMM3 Scorecard, and Capability Maturity Model Integration (CMMI).

ADVANCED ICT » Consultants and Auditors LLP.