21st National Information Systems Security Conference 1998 Conference paper submission
Jim Whitmore · 1998
Over the past few years it has become increasingly common for organizations, government agencies and businesses, i.e., enterprises, to position some or all of their information assets in close proximity to the Internet. Do enterprise architectures and designs apply to secure e-business computing? Issues of classification and management of data assets beyond the enterprise boundary, plus legal liabilities of electronically executed business transactions suggest that new approaches are needed. This paper analyzes the conceptual similarities and differences of the design intra-, and extraenterprise design environments in an effort to highlight some complexities of creating an ebusiness architecture. This paper concludes that the network/security architect cannot effect comprehensive e-business security for all aspects of an enterprise. The strategy and the solution needs to be addressed in a more fundamental way than firewalls, SSL or PKI.