In the previous chapter, we described securing the supply chain optimization example through secure networking and alluded to the other approaches we would need to take to secure the rest of the infrastructure. To ensure that our solution will remain available and avoid security compromises, we should make sure that our architecture follows appropriate guidelines and standards and that a GRC strategy can be put into place.
We begin with an assessment of governance and certifications requirements already in place at the organization that must be followed. We then assess any additional standards that we must comply with.
In the CEMENTruck Inc. example, a relevant industry group is the National Ready Mixed Concrete Association (NRMCA). Such industry groups sometimes self-regulate, determine best practices, educate members regarding relevant...