THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Tuesday, January 04, 2022
Security architecture has evolved from a threat-driven approach to addressing non-normative faults in systems and applications to a risk-driven and business-outcome-focused technique for enabling a business strategy.
Fremont, CA: Many clients understand the value of investing in data security upfront rather than dealing with the fallout from security breaches, including significant financial loss or negative media coverage. The security strategy is based on enterprise security architecture, a risk-based approach to securing business capabilities, data assets, applications, and platforms. It is an architectural approach that enables the establishment of traceability between business drivers and objectives and products and services, as well as data, applications, and platforms. The clients understand that taking a business-outcomes and risk-driven approach to enterprise security enables them to address breaches and leverage business opportunities, and facilitate security ROI estimations
Many clients understand the value of investing in data security upfront rather than dealing with the fallout from security breaches, including significant financial loss or negative media coverage. The security strategy is based on enterprise security architecture, a risk-based approach to securing business capabilities, data assets, applications, and platforms. It is an architectural approach that enables the establishment of traceability between business drivers and objectives and products and services, as well as data, applications, and platforms. The clients understand that taking a business-outcomes and risk-driven approach to enterprise security enables them to address breaches and leverage business opportunities, and facilitate security ROI estimations.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Here are some of the security concerns that enterprises face in client engagement:
Absence of an enterprise-wide security architecture framework
There is widespread agreement that enterprise security architecture is a methodology for addressing security concerns at every level of abstraction and domain. However, practical experience demonstrates that existing enterprise and security architecture frameworks are not quite there yet.
A requirement for organizational transformation within the security sector
Historically, information security has been addressed at the level of information security management, operational security, and solution design, resulting in a lack of alignment between business and IT, as well as an operational imbalance. The solution to this issue is to architect a security organization. Enterprises define security capabilities beginning with governance and progressing through architecture and planning to design, implement, and monitor. They define security capabilities as a subset of the business reference model to help clarify their relationship to organizational units, business functions, and processes.
Compliance with internal and regulatoy policies and procedures on an enterprise-wide basis
The growing number and breadth of regulatory requirements can have an impact on the products and services delivered. Enterprise Architects leverage enterprise architecture to reconcile business objectives, internal compliance requirements, and regulatory and legislative requirements. Clarifying which of these are present, how they interact, and how they affect core business capabilities facilitates business decision-making.
More in News