Preface
Twenty-five years ago, colleagues from the US traveled to the UK to help us develop a method and course to train a new cohort of security architects. Back then, most of the systems we dealt with were midrange or mainframes running a variant of Windows or Unix, and most of the networks were internal or private. The internet, cloud computing, containerized applications, Agile working, automation, and AI are examples of the tremendous change the world of information systems has gone through.
Hybrid Cloud for Simplicity
We will refer to hybrid cloud throughout for simplicity. Where you see “hybrid cloud,” also read that it could include multiple cloud services or be “multicloud.”
While many things have changed, the main security architecture concepts we created 25 years ago have remained constant. We started out with the following standard set of concepts:
-
Guiding principles (or security design objectives), based on protection from loss of confidentiality, integrity, and availability, set the stage for how to apply security controls.
-
A set of security domains, which we then called subsystems, to group the security controls.
-
Threat modeling examined data in transit and at rest to identify threats and countermeasures to protect the data. (Although we didn’t call it threat modeling in those days and used ideas from the Common Criteria to describe the technique.)
-
Network segmentation of a data center using zones and firewalls.
-
A controls framework based on the Common ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access