Application of a Government Data Center (GDC) Reference Model for Security Management Analysis
Wojciech Urbanczyk, Jan Werewka · 2021
The Government Data Center (GDC) differs from other data centers in functionality, service offer and the variety of solutions that are available. In order to facilitate the knowledge acquisition that is required to enable better management of GDCs, the development of an enterprise architecture reference model of these data centers is advisable. The proposed model would assist in data center management; improve communication related to the solutions used in the center; and would apply quality attributes to facilitate center management. The GDC reference model presented in this article consists of several layers and several dozen views. The model was built in ArchiMate, which is a language used mainly for enterprise architecture description. It was decided to adapt and extend this model to incorporate GDC security issues. Due to the variety of GDC software available, security solutions should be tailored to each heterogeneous situation. One of the basic demands of data centers is to meet recognized security standards. In particular, ISO / IEC 27000, a family of standards used to manage security for all types of organizational assets, was considered; the GDC reference model is a direct collection of such assets. A risk view meta model was used, which presents the basic dependencies between threats, risk and security, as related to a company's assets. The focus was on ISO 27001 control domains. Each one was assigned a practice (security implementation) that was used in the GDC. The next step was mapping control domains to GDC layers. This enabled conclusions to be drawn relating to coverage of security standards as well as supplementing the reference model with the missing security aspects.