Information Technology Reference
In-Depth Information
Studying snapshots of A, B, C, D, and E over time provides a systemic picture of
their relationships and the eventual outcome of the system.
IA 2 provides a foundation with which to define and understand systems
dynamics models of risk. A generic representation of this type of model is the mis-
sion integrity boundary model in chapter 1. The quantification of IA operations
provides thresholds (upper and lower limits) that define mission integrity. IA sys-
tems dynamics models may show the effects of an evolving threat space, status of
IA services and mechanisms, and organizational risk posture on mission integrity.
The model will show effects over time with other aspects feeding a dynamic threat
space, including random factors and factors representing uncertainty (e.g., Bayes-
ian probability).
A practical theme is the need to align IA with business drivers. This alignment
needs to extend from operations to the core drivers of executive decision making,
which are the income statement and the balance sheet. The IA 2 Framework pro-
vides an IA 2 LoS that enables the aligning of IA operations to business line items
and shows direct relationships of IA to financial statements and financial ratios. It
is possible to extend this modeling concept to real-time, which shows the effects of
fluctuating risk levels on the financial posture of the organization.
The objectives of IA 2 are to provide a lexicon and a set of standards and frame-
works to identify, enumerate, articulate, and address business risk. This founda-
tion provides the ability to pursue many nuances of IA, including quantification
and business modeling. Future work on IA 2 includes quantification models for
situational awareness, financial models that align IA with income statement and
balance sheet, a maturity model to gauge the effectiveness of the organization's IA
posture, systems dynamics models of risk, and the Bayesian representation of risk
in terms of conditional probabilities and compound conditional probabilities. IA 2
provides an IA 2 Framework, IA 2 Process, and a useful set of frameworks to think
about IA in an enterprise context.
Norman Cousins states, “Wisdom is the anticipation of consequences.” Archi-
tecture is applied wisdom. IA architecture is wisdom applied to the security of
information and information technology to maintain mission integrity.
Search WWH ::




Custom Search