期刊论文详细信息
Technology Innovation Management Review
An Enterprise Security Program and Architecture to Support Business Drivers
关键词: cybersecurity;    cyberthreats;    information assurance;    information risk;    information security;    risk;    security architecture;   
DOI  :  
来源: DOAJ
【 摘 要 】

This article presents a business-focused approach to developing and delivering enterprise security architecture that is focused on enabling business objectives while providing a sensible and balanced approach to risk management. A balanced approach to enterprise security architecture can create the important linkages between the goals and objectives of a business, and it provides appropriate measures to protect the most critical assets within an organization while accepting risk where appropriate. Through a discussion of information assurance, this article makes a case for leveraging enterprise security architectures to meet an organizations' need for information assurance. The approach is derived from the Sherwood Applied Business Security Architecture (SABSA) methodology, as put into practice by Seccuris Inc., an information assurance integrator. An understanding of Seccuris’ approach will illustrate the importance of aligning security activities with high-level business objectives while creating increased awareness of the duality of risk. This business-driven approach to enterprise security architecture can help organizations change the perception of IT security, positioning it as a tool to enable and assure business success, rather than be perceived as an obstacle to be avoided.

【 授权许可】

Unknown   

  文献评价指标  
  下载次数:0次 浏览次数:1次