Defining requirements and metrics
In the first section of this chapter, we discussed the steps that an architect must take to define enterprise security. In this section, we will explain how requirements and metrics can be collected, validated, and translated into controls and KPIs.
Business goals
We've talked about this in Chapter 1, Defining the Reference Architecture for Enterprise DevOps, but obviously, it's important to understand the goals a business wants to achieve. What markets are they in, how do they serve customers in these markets, and what is the product portfolio? It does make a huge difference if a business is operating in financial products or healthcare. Their markets define the risk level. The risk for a bank or an investment company could be mainly financial, whereas for healthcare, the biggest risk could be involving the life of patients. The goals will be different too: an investment company might have the goal to support as many businesses with...