My Account Log in

1 option

Practical Cybersecurity Architecture : A Guide to Creating and Implementing Robust Designs for Cybersecurity Architects.

EBSCOhost Academic eBook Collection (North America) Available online

View online
Format:
Book
Author/Creator:
Kelley, Diana.
Contributor:
Moyle, Ed.
Language:
English
Subjects (All):
Computer security.
Architecture.
Physical Description:
1 online resource (388 pages)
Edition:
2nd ed.
Place of Publication:
Birmingham : Packt Publishing, Limited, 2023.
Summary:
Practical Cybersecurity Architecture serves as a comprehensive guide for cybersecurity architects seeking to design and implement robust security frameworks. Authored by Diana Kelley and Ed Moyle, the book delves into the essentials of cybersecurity architecture, emphasizing the importance of secure network and application design. It outlines methodologies for establishing architectural principles, creating blueprints, and integrating security strategies into business processes. The authors share insights from their extensive experience in the field, offering practical tools and case studies to aid in the development of effective cybersecurity solutions. This book is intended for cybersecurity professionals and architects aiming to enhance their understanding of security architecture in the context of evolving technological landscapes. Generated by AI.
Contents:
Cover
Title Page
Copyright &amp
Credits
Contributors
Table of Contents
Preface
Part 1: Security Architecture
What Is Cybersecurity Architecture?
Understanding the need for cybersecurity
What is cybersecurity architecture?
Network versus application security architecture
The role of the architect
Secure network architectures
Secure application architectures
Case study - the value of architecture
Architecture, security standards, and frameworks
Architecture frameworks
Security guidance and standards
Security architecture frameworks
Architecture roles and processes
Roles
Process overview
Key tasks and milestones
Summary
Architecture - The Core of Solution Building
Terminology
Understanding solution building
Establishing the context for designs
Understanding goals
Identifying business goals
Dimensions of success
Structures and documents
Policies, procedures, and standards
Applying to architectural frameworks
Additional frameworks
Risk management and compliance
Risk management and appetite
Compliance
Establishing a guiding process
Understanding the business' high-level goals
Understanding the technology goals
Drawing implied goals from existing documentation
Capturing (or defining) risk tolerances
Accounting for compliance requirements
Part 2: Building an Architecture
Building an Architecture - Scope and Requirements
Understanding scope
What's in this chapter?
Setting architectural scope
Enterprise security architecture
Application security architecture
Defining scope boundaries
Scope - enterprise security
Existing capability
Risk management
Strategic planning
Case study - enterprise scoping
Scope - application security
The development and release process.
Components, services, and design patterns
Team/organizational boundaries
Technology considerations
Case study - application scoping
The process for setting scope
Step 1 - consider high-level goals
Step 2 - review contextual or other constraints
Step 3 - set the initial scope
Step 4 - validate and refine initial scope
Building an Architecture - Your Toolbox
Introduction to the architect's toolbox
Planning tools
Analytical tools
Informational tools
Modeling and design tools
Case study - data gathering
Building blocks of secure design
Information security policies
Organization of information security
Human resources security
Asset management
Access control
Cryptography
Physical and environmental security
Operations security
Communications security
System acquisition, development, and maintenance
Supplier relationships
Information security incident management
Information security aspects of business continuity management
Building an Architecture - Developing Enterprise Blueprints
Requirements
Blueprints
Process
Why ADM?
The vision
Establishing architectural principles
Setting the scope
Getting the desired future (target) state
Case study - shared goals, vision, and engagement
Creating a program
Discovery, identification, and validation
Documenting your high-level approach
Creating the roadmap
Architecture definition
Accompanying documentation
Building an Architecture - Application Blueprints
Application design considerations
Life cycle models
Environment
Considerations for waterfall projects
Requirements phase
Design phase
Implementation phase
Verification phase
Maintenance phase
Case study - waterfall development.
Considerations for Agile projects
Conception phase
Inception phase
Construction phase
Release phase
Production phase
Retirement phase
Case study - Agile development
Considerations for DevOps projects
Develop
Build
Unit test
Deploy (integrate)
Quality assurance
Production
Validate
Case study - DevOps/DevSecOps development
Process for application security design
Systems security engineering
Architecture definition process
Documentation
Validation
Modifying the SDLC and development processes
Part 3: Execution
Execution -Applying Architecture Models
Process steps
Technical design
What specific provider do we use to do this?
Do we need additional infrastructure (VPN, access points, etc.)?
What client software do users require (if any)?
Creating technical implementation strategies
Assess constraints, synergies, and areas of opportunity
Validating against likely threat paths and creating a skeleton solution document
Validating implementation strategies
Finalizing the documentation
Operational integration
Changing context and evolution
Execution monitoring
Case study - Operational integration
Telemetry
Selecting strategic metrics
Selecting operational metrics
Execution - Future-Proofing
Overcoming obstacles in project execution
Scope and requirements
Support failure and organizational issues
Resource shortfalls
Communication failure
Technical and environmental issues
Future-proofing designs
Establishing a virtuous cycle
Monitoring our own environment for changes
Monitoring for external changes
Specifics for machine learning projects
Case study - future-proofing
Putting It All Together
Virtuous cycles.
Adapting architectural processes
Tips and tricks
Hone your ability to listen
Cultivate empathy
Have just enough process
When in doubt, over-communicate
Be ready to walk away
Gotchas
Be aware of (but don't play) politics
Don't shirk the preparation
Stay engaged until the end
Leave ego at the door
Use a multi-disciplinary approach
Case study: gotchas
Index
Other Books You May Enjoy.
Notes:
Description based on publisher supplied metadata and other sources.
Part of the metadata in this record was created by AI, based on the text of the resource.
ISBN:
9781837630288
1837630283
OCLC:
1409811211

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account