首页> 外文期刊>Information security journal >Business Security Architecture: Weaving Information Security into Your Organization's Enterprise Architecture through SABSA®
【24h】

Business Security Architecture: Weaving Information Security into Your Organization's Enterprise Architecture through SABSA®

机译:业务安全体系结构:通过SABSA®将信息安全性纳入组织的企业体系结构中

获取原文
获取原文并翻译 | 示例
           

摘要

Information security is an imperative factor in organizational success, driven by the need to protect information assets. The continuous evolution of external and internal threats and the associated need to protect and secure information from exploitation of vulnerabilities has become a struggle for many organizations in both the public and private sectors. This struggle is the direct result of the narrow focus on operational security. Just as the lines between business and information technology have disappeared, so have the lines between business and information security. Some organizations simply "check the box" by performing the minimum actions required to pass or meet mandated compliance standards. Without practicing due diligence and by only meeting the minimum requirements, leads to the reactive response of exploited vulnerabilities in addition to the increase of after the fact incident investigations. Organizations need to take a proactive approach using established methodologies known to incorporate security into information technologies and systems. The Sherwood Applied Business Security Architecture (SABSA) is a solution oriented methodology for any business enterprise that seeks to enable its information infrastructure by applying security solutions within every layer of the organization. This article describes how SABSA can be integrated into organizations' existing architectures utilizing organizational business drivers.
机译:由于需要保护信息资产,因此信息安全是组织成功的必要因素。外部和内部威胁的不断发展以及保护和保护信息免遭漏洞利用的相关需求,已经成为公共部门和私营部门中许多组织的斗争。这场斗争是对运营安全的狭focus关注的直接结果。正如业务和信息技术之间的界限已经消失一样,业务和信息安全之间的界限也已经消失。一些组织只是通过执行通过或满足强制性合规性标准所需的最少操作来简单地“选中”复选框。在不进行尽职调查的情况下,仅通过满足最低要求,除了事后调查之后,还会导致对已利用漏洞的反应性响应。组织需要采用已知的将安全性整合到信息技术和系统中的既定方法,采取主动的方法。 Sherwood应用业务安全体系结构(SABSA)是一种面向解决方案的方法,适用于寻求通过在组织的每个层级中应用安全解决方案来启用其信息基础结构的任何企业。本文介绍如何使用组织业务驱动程序将SABSA集成到组织的现有体系结构中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号