Blog-N-Play.com
Anytime a feature of a framework gives me something for free that I don't need to manually implement I'm a happy camper. One such feature of ASP.NET MVC 2 is jQuery client-side validation. The
Read Digital Edition


ADS BY GOOGLE
Top Three Links You Must Click On


How To Design and Implement an Enterprise Open Source Security Architecture
Ensure Your IT Assets Are Available, Reliable, and Safe

Information security is a top priority for many companies. Protecting information from external threats such as hackers, viruses, and spam, as well as governmental regulation requirements (SOX, HIPAA, NISPOM, etc.), are driving IT purchases beyond ROI as C-level executives seek to assure shareholders (and themselves) that assets are secure within the company complex. Viewed as today's growth market, many software/hardware/service companies are creating offerings to mitigate perceived risk or actual liability.

The security environment within some organizations may be somewhat lax - "safe" behind the routers, IDS, and firewalls. In this article, I'll discuss how to create a security architecture, including analysis, planning and prioritizing security needs, and I'll examine the following topics:

  • Understanding security architecture
  • Balancing threats, costs, and the value of secured assets
  • Creating an architecture that fits the business framework
  • A layered examination of security, including network access, application access, external access, and physical access
In addition, references are provided at the end of the article with links to useful information.

Understanding Security
Security architecture differs from other kinds of security in that it addresses requirements from a high-level perspective as opposed to a tactical perspective. When possible, you should understand your company's security requirements before specific security issues are implemented. It's as important to know your own assets, where they are deployed, and what they're worth to your company, as it is to know what threats they are facing.

Security architecture can become very complex. By looking at security from multiple perspectives, including external access and physical security, network security, application and computer-specific security, you'll be looking from the outside in as well as from the inside out. These perspectives must also be balanced against other business requirements, financial and otherwise. Whatever model or security architecture you use, you are trying to ensure that your assets are available, reliable, and safe. Consider Figure 1.

The confidentiality perspective prevents your competition from siphoning off the cream of your company's products. The integrity perspective protects your information from unauthorized modification with verifiable, auditable access records. The availability perspective ensures that information within your business is accessible at all times. Your security architecture should focus on delivering these three attributes. Securing your information while keeping the click-and-mortar business open and vibrant is a very challenging task.

Dollars and Sense
When planning your security architecture, you are governed by overriding factors including time and money. In some cases, spending one makes more sense than the other. For example, a small company pushing their first product into the marketplace may require a security architecture overridden by cost above all (if the product doesn't make it to market, having a safe infrastructure doesn't matter). They may have to phase in security measures over time. At the other end, non-compliance with a regulatory security standard could cost a company a large account, or even threaten its ability to remain open for business. (See Figure 2)

It's also important to understand that the strategic view of your enterprise security architecture is a view of where you want to be. Few companies can afford to start from scratch with regard to implementing security. For example, your company may currently address physical access with Intrusion Detection Systems, gateways, and firewalls. These are integral elements of a good architecture, but alone they may not adequately address the risk to your company.

To create the appropriate architecture for your business, you need to strike a balance between the value of assets being protected and the cost of the protection. As a general guideline, protect the highest valued assets most stringently. This may be your source code and the servers it resides in, or perhaps the marketing info including the initial public offering data. Tape backup into an offsite location may provide adequate protection for some businesses (based on the cost/value analysis), while others may require biometric access to the clean rooms where prototyping is occurring. Secure higher-priority assets first, and keep moving forward with planned steps to reach a secure destination.

Create a Security Architecture That Fits the Business Framework
As we have seen, there are multiple perspectives in a security architecture. Many models exist that may match one, some, or all of the important perspectives. There are many framework examples, including the Lattice, the Federal Enterprise Architecture Framework, the Clark-Wilson or Biba models, and many other reference models (see the hyperlink section for reference links to these and other frameworks). In each case, the common goal is to create a balance between the business needs and the information systems that support them. Understanding what is important in relation to other things in your business helps you value both the assets and the corresponding protection you will afford them.

For example, Figure 3 is an X-Y graph that shows assets increasing in value (up the vertical axis), facing increasing risk over time (on the horizontal axis extending to the right).

This simplistic representation shows the most highly valued assets facing the least exposure to risk over time, descending in value to assets that can withstand increased exposure to risk over time. Whatever method you use, the value of assets in your enterprise needs to be determined. Revisit these models when you acquire additional assets so that their value is properly established and defended. In this way, there is an ongoing evaluation of what assets are present and their security needs within the business framework.

Network Security Architecture - It's Not Just Firewalls Anymore
As your customer community grows more sophisticated and begins to expect more protection from your products or services, the potential for accidental or intentional misuse or attack within your company grows as well. A majority of data loss in companies today occurs via credentialed accounts. Similarly, reliable and correct delivery of information on your LAN or WAN is no longer guaranteed via TCP/IP, with address spoofing and snooping available to anyone on your network, unless network security is active from the inside-out as well. Evaluate this short list of network security mechanisms as potential additions to your security plan:

About Richard Williams
Richard Williams is director of education for Symark Software in Agoura Hills, California. With over 20 years of experience in systems administration, architecture, and design, Richard oversees the development and delivery of Symark's University Training Program in providing customer support to global enterprise customers.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

How is article in anyway related to open source?

Information security is a top priority for many companies. Protecting information from external threats such as hackers, viruses, and spam, as well as governmental regulation requirements (SOX, HIPAA, NISPOM, etc.), are driving IT purchases beyond ROI as C-level executives seek to assure shareholders (and themselves) that assets are secure within the company complex. Viewed as today's growth market, many software/hardware/service companies are creating offerings to mitigate perceived risk or actual liability.

Designing and Implementing a Security Architecture. Information security is a top priority for many companies. Protecting information from external threats such as hackers, viruses, and spam, as well as governmental regulation requirements (SOX, HIPAA, NISPOM, etc.), are driving IT purchases beyond ROI as C-level executives seek to assure shareholders (and themselves) that assets are secure within the company complex. Viewed as today's growth market, many software/hardware/service companies are creating offerings to mitigate perceived risk or actual liability.

{{{governmental regulation requirements (SOX, HIPAA, NISPOM, etc.)}}}

Are there any good online resources on these, on SoX for examle?

}}} reliable and correct delivery of information on your LAN or WAN is no longer guaranteed via TCP/IP, with address spoofing and snooping available to anyone on your network {{{

How true. Sadly.


  Subscribe to our RSS feeds now and receive the next article instantly!
In It? Reprint It! Contact advertising(at)sys-con.com to order your reprints!
Subscribe to the World's Most Powerful Newsletters
Linux Links You Must Click On !

Lo Ultimo
Sony Europe ha anunciado hoy que su asociación con un joven equipo denominado Forest Guard ha alcanz...

KKBOX, el servicio de música por suscripción más grande de Taiwán, anunció hoy la e...

print24, la empresa de impresión online, está ofreciendo, con su estrategia BestBuy...

El Copenhagen Climate Council (CCC) ha anunciado hoy un memorable esfuerzo de once horas para la mov...
Covaca S.A, y el fabricante Voltz International han anunciado hoy la firma de un acuerdo para comerc...
ADS BY GOOGLE
Delegates will leave Virtualization Expo with a full understanding of the interaction between virtua...
OpenAir, Inc., a NetSuite Inc. company and a provider of cloud computing professional services autom...
“Our continued innovation in imaging software allows us to change the healthcare information distrib...
With their CRM and ERP data systems integrated, Tecan AG's staff and management will benefit from a ...
Until today, Monitis was providing monitoring only for Amazon’s EC2 and S3 services. With the releas...
Solaris 10 10/09 provides new features, fixes and hardware support in an easy-to-install manner, pre...
I've been at this 35 years and I've seen sea changes come and go. If you step back for a moment and ...
There are about 250,000 developers working with Flex and AIR. If you add an army of ActionScript dev...
Optibase announced a new release of its MGW FlashStreamer encoding and streaming platform, introduci...
Rackspace Hosting announced a new service to assist its e-commerce customers this holiday season. Th...
PrismTech is joining forces with Nextel Engineering Systems to deliver much-needed, highly-reliable ...
Microsoft Corp. and eBay Inc. today announced they are partnering to offer eBay Daily Deals through ...
What is a SatNav? I would define it as a small pocket sized computer, with a built-in GPS receiver, ...
Microsoft’s CFO Chris Liddell, 51, a New Zealand import, is bored and wants a better job. So he’s “l...
Cloud computing is a game changer. The cloud is disrupting traditional software and hardware busines...
The newest release of Open-Xchange builds on a consistent theme as its delivers more integration wit...
Recently I installed the Beta 2 version of "Geneva", or ADFS 2.0. All of my machines are now Windows...
Option, the wireless technology company, today announced that its GTM501 will be used in MOTO Develo...
SYS-CON Events (http://events.sys-con.com) announced today that the "show prospectus" for the 5th In...
In this fast pace life, it is quite impossible to survive without mobile phones. In short, mobile ph...