Information security architecture
Jan H. P. Eloff, Mariki M. Eloff · Computer Fraud & Security · 2005
To work best information security must be holistic and fit into a company seamlessly. The practice should take account of personnel security, user access control, network security and regulatory aspects. Holistic security should integrate technology, people and processes. Information security architecture is a concept that specialists have come up with to achieve this. It is a management process intertwined into the day-to-day business operations of a company. The big problem is that no standardised architecture exists. Different researchers and groups have tried their hand at defining a framework that includes: BS 7799 ISO Part 2 Multi-planes model. PFIRES Meta Security Group ISA by Tudor Some focus on technical issues, while others focus on security policy. Some are merely methodologies that do not mention technological issues or the importance of a security culture. An information security architecture should make suggestions on how different controls can be synchronised… Implementing information security is a complex, time-consuming and costly process. Codes of practice for information security management indicate that information security is a multidisciplinary concept cutting horizontally across an. All aspects regarding information security must be addressed in a well-structured and holistic manner, failure of which may result in information infrastructures that are far less secure, with far more frequent and damaging security breaches. Information security experts have responded to this demand for a holistic approach towards the implementation of information security by introducing the concept of an information security architecture. The problem, however, is that no standardised, comprehensive information security architecture currently exists. This paper presents a state-of-the-art overview of distinguishable approaches, all attempting to define an information security architecture. This is followed by a proposition of requirements for an integrated Information Security Architecture (ISA).