icode security architecture framework

12
Security Verified © 2012 iCode information security All rights reserved Security Architecture Framework ohamed Ridha Chebbi, CISSP Code InfoSec – CEO & Head of PS [email protected]

Upload: mohamed-ridha-chebbi-cissp

Post on 22-May-2015

1.127 views

Category:

Documents


13 download

DESCRIPTION

Information Security Architecture Framework by iCode

TRANSCRIPT

Page 1: iCode Security Architecture Framework

Security Verified

© 2012 iCode information security All rights reserved

Security Architecture Framework

Mohamed Ridha Chebbi, CISSPiCode InfoSec – CEO & Head of [email protected]

Page 2: iCode Security Architecture Framework

Security Verified

© 2012 iCode information security All rights reserved

Agenda

IntroductionApproach to Develop Security ArchitectureInformation Security ConceptsSecurity Architecture Levels & ViewpointsTechnical ViewpointInformation ViewpointBusiness ViewpointSecurity Architecture FrameworkiCode Professional Services

Page 3: iCode Security Architecture Framework

Security Verified

© 2012 iCode information security All rights reserved

Introduction

There are a Number of Approaches to Develop a Security Architecture Like :1. As a DOMAIN in the TECHNICAL ARCHITECTURE2. As TOTALLY SEPARATE Security Architecture ViewPoint

Security is Pervasive across all of Architecture impacting :- Business- Information - and Technology

Page 4: iCode Security Architecture Framework

Security Verified

© 2012 iCode information security All rights reserved

Approach to Develop Security Architecture

Information

Business

Technology

Solutions &Security

Architecture

Architecture

Architecture

Architecture

Security :. Data Security Requirements. Data Classification. Application Security Standard

Security :. Business Security Requirements. Security Organization. Security Policy Framework. Process Security

Security :. Technology Security Requirements. Security Principles. Security Patterns. Security Services. Security Bricks

Page 5: iCode Security Architecture Framework

Security Verified

© 2012 iCode information security All rights reserved

Information Security Concepts

InformationSystem

Confidentiality Integrity

AvailabilityCore Concept

Related Concept

Technique

only authorized disclosure

Data has not beenchanged

Data has not beenchanged

Isolation

Encryption

Data Validation

Data Hashing

Digital Signatures

Resilient Designs

Service LevelAgreements

AuthenticationVerifies

identities

UtilityUsefulness

of data

Page 6: iCode Security Architecture Framework

Security Verified

© 2012 iCode information security All rights reserved

iCode Security Architecture Framework

Vision

Security ServicesFramework

Design Principles

Requirement Templates

Conce

ptua

l

Leve

l

Logic

alLe

vel

Implem

entati

on

Leve

l

BusinessViewpoint

InformationViewpoint

TechnicalViewpoint

Page 7: iCode Security Architecture Framework

Security Verified

© 2012 iCode information security All rights reserved

Technical Viewpoint

Vision

Security ServicesFramework

Design Principles

Requirement Templates

.Trust Levels

.Conceptual Technology Models

.Logical Technology Models

.Trust Models

. Technical Reference Models.Security Infrastructure Architecture

.Security Services Architecture

.Application Security Architecture

Conce

ptua

l

Leve

l

Logic

alLe

vel

Implem

entati

on

Leve

l

TechnicalViewpoint

Page 8: iCode Security Architecture Framework

Security Verified

© 2012 iCode information security All rights reserved

Information Viewpoint

Vision

Security ServicesFramework

Design Principles

Requirement Templates

. PolicyFramework

. InformationClassificationFramework

. Security Information Flow Models

. Security Information Architecture

. SLA Model

. Information Classification Register

. SLA’s

Conce

ptua

l

Leve

l

Logic

alLe

vel

Implem

entati

on

Leve

l

InformationViewpoint

Page 9: iCode Security Architecture Framework

Security Verified

© 2012 iCode information security All rights reserved

Business Viewpoint

Vision

Security ServicesFramework

Design Principles

Requirement Templates

.ProcessModels

.Roles &Responsibi-

lities Models

.OrganizationModels

.OrganizationalArchitecture

Conce

ptua

l

Leve

l

Logic

alLe

vel

Implem

entati

on

Leve

l

BusinessViewpoint

Page 10: iCode Security Architecture Framework

Security Verified

© 2012 iCode information security All rights reserved

Global Security Architecture Framework

Vision

Security ServicesFramework

Design Principles

Requirement Templates

.Trust Levels

.Conceptual Technology Models

.Logical Technology Models

.Trust Models

. Technical Reference Models.Security Infrastructure Architecture

.Security Services Architecture

.Application Security Architecture

. PolicyFramework

. InformationClassificationFramework

. Security Information Flow Models

. Security Information Architecture

. SLA Model

. Information Classification Register

. SLA’s

.ProcessModels

.Roles &Responsibi-

lities Models

.OrganizationModels

.OrganizationalArchitecture

Conce

ptua

l

Leve

l

Logic

alLe

vel

Implem

entati

on

Leve

l

BusinessViewpoint

InformationViewpoint

TechnicalViewpoint

Page 11: iCode Security Architecture Framework

Security Verified

© 2012 iCode information security All rights reserved

iCode Professional Services for Tunisiana

Page 12: iCode Security Architecture Framework

Security Verified

© 2012 iCode information security All rights reserved

Thanks

Mohamed Ridha Chebbi, CISSPiCode InfoSec – CEO & Head of [email protected]