Developing an Information Security Architecture Program
This chapter delves into the fundamentals of creating an information security architecture program for an organization. The chapter defines information security architecture before discussing its integration into the system development life cycle (SDLC) or system engineering life cycle (SELC). The chapter then guides you through conducting an initial information security analysis to inform architectural decisions. Then, we explore how to develop a security architecture advisement program that assists in creating a repeatable process for developing secure architectures. Finally, the chapter outlines the overall information security architecture process, which contributes to an organization’s technical architecture.
The following topics will be covered in this chapter:
- What is information security architecture?
- Information security architecture and SDLC/SELC
- Conducting an initial information security analysis...