Enterprise Security Architecture: A Business-Driven Approach

Enterprise Security Architecture: A Business-Driven Approach by Andrew Clark, David Lynas and John Sherwood

Enterprise Security Architecture: A Business-Driven Approach

Binding:
Hardcover
Number of Pages:
608
ISBN:
157820318X
Product Group:
book
Publisher:
CMP
Publication Date:
Nov. 15, 2005
BooksForGeeks.com ID:
2661

Emphasizes the business approach and shows how security is important to be left in the hands of just one department or employee. This book shows that having a comprehensive plan requires more than the purchase of security software - it requires a framework for developing and maintaining a system that is proactive.

Reviews for Enterprise Security Architecture: A Business-Driven Approach

  1. THE authoritative treatise on enterprise security

    Rated 5 out of 5 stars, December 12th, 2008

    The SABSA method has been under development and in practical use for ten-fifteen years, mostly based on progressive conference presentations by the authors. The impression brought home from listening to the presentations was that this was something really great, breaking new ground and vastly more comprehensive than other enterprise security methods developed by the large consulting companies and a range of mostly American authors. If only it were possible to find all of it documented in one single place so that it could be understood holistically.

    This book does exactly that, and it does not disappoint. It is worth the ten-fifteen years wait and without any doubt the best work so far written about corporate security architectures. If government departments and their sub-contractors had followed this development process and implemented it rigorously we would not have seen the past few years' data loss scandals.

    The SABSA method should be used as the primary planning tool by all large organisations, not least governments. It makes it possible to introduce top level security without losing usability and flexibility - and without getting into the situation where a single rogue element in an organisation can cause huge havoc. It allows data to be valued correctly so that organisations avoid spending money on unnecessary security measures while providing appropriate information security throughout. The scope of the SABSA method, while primarily intended to provide an information security architecture, actually extends further and will help set up corporate management structures that can be used for other purposes as well.

    The book is written by three of the best experts of information security, globally. It should be studied by anybody involved with information security and corporate governance.
  2. Excellent and Complete!

    Rated 5 out of 5 stars, June 12st, 2006

    I cannot praise this book too highly. It covers the whole field of enterprise security architecture in great breadth and detail. Numerous useful models and patterns are included. Valuable (and sometimes amusing) case histories abound.

    The writing is particularly clear; difficult topics are explained in full and I gained new insights in many areas.
  3. Outstanding - the SABSA Business Approach documented at last

    Rated 5 out of 5 stars, November 12th, 2005

    I first saw a colleague's preview copy of this book in September and have just got a copy of the real thing. First things first, this book describes exactly what it says on the cover i.e. a Business Driven Approach to security. If you are used to technical security architectures being the start point for security implementations then think again. This book says you should start your work by talking with the "top of the shop" at any enterprise and make sure that your ESA is aligned with the real business drivers of the business. Although this sounds like common sense, in my opinion too many of us have got bogged down in the technologies of authentication, encryption etc. over the years and failed to recognise the real needs of the businesses in which we work.
    I particularly liked two things about this book:
    - the layout in two distinct parts, ths first covering the philosophy and approach of SABSA, followed by more of a reference type second section;
    - the "quick notes" in the left hand column of every page that let's you speed read each chapter.
    I think that this book will challenge a lot of conventional approaches - for example where else do you see a section on Measuring Return on Investment in Security?
    This book will not be a favourite of everyone that reads it - I did like it and am using it already in my work.

Our Network

BooksForGeeks.com is a participant in the Amazon Europe S.à r.l. Associates Programme, an affiliate advertising programme designed to provide a means for sites to earn advertising fees by advertising and linking to amazon.co.uk