Information Technology Reference
In-Depth Information
of product implementations. Vendor and product evaluations lead to the appro-
priate product selection.
he IA 2 implementation taxonomy provides an abbreviated line of sight from
business requirements to operations. The IA 2 LoS provides the IA architect with a
tool to capture more granular detail and rationale for the same line of sight from IA
business drivers through to IA operations.
2.12
Conclusion and Commentary
One of the claims that may be made with 100 percent certainty is that the informa-
tion assurance industry will continue to evolve. Traditional views of security were
in terms of standard business costs like door locks, or a nice to have if there is enough
budget , like video cameras. Only recently has security become a legislative mandate.
With the increase in attention to security, there is need to insert security planning,
budgets, operations, and justifications into the business processes in terms under-
stood by management and executives. Discussing IA operations in business terms
goes a long way in reaching common understanding that includes the knowledge
that while security cannot be ignored as a nice-to-have, security budgets are limited
and require justification and priorities. A security business case with its foundation
in return on investment (ROI) has more chance of success than one built on fear,
uncertainty, and doubt (FUD).
Aligning the IA 2 concepts to business drivers conveys IA to management and
executives in terms of business need, business fit, business justification, and business
risk. The more the IA material resonates with management, the greater the likeli-
hood of obtaining a sufficient IA budget and ultimately the greater likelihood of
producing an appropriately secure operating environment.
There is much to consider in achieving an assured enterprise architecture that
ultimately leads to assured operations. The structure of the IA 2 Framework lends
itself to large and small projects. The modularity of IA 2 provides the ability to use it
as a whole or to draw upon the parts as applicable to the IA situation at hand. The
next chapter presents a process for the application of the IA 2 Framework.
Search WWH ::




Custom Search