Archistry

Survivability by Design™ since 2006

  • Home
  • About
    • Who Is Andrew?
    • C2T System™
    • The Agile Security System™
  • Contact
You are here: Home / Archistry Daily / “Just winging it” is for birds, not your security program

October 30, 2019

“Just winging it” is for birds, not your security program

How much of your security control environment has been driven by, basically, “it seemed like there was a gap” or, “it seemed like a good idea” instead of being traceably linked to real business requirements?

Now, how many of those controls are the same ones that the user community complains the most about?

Hmmm….any correlation?

One of the things I learned going to school at the University of Missouri-Rolla (now Missouri Science & Technology or whatever) was that the Show Me State isn’t just something that’s written on the license plates. It’s kinda built-in to the psyche of people who live there.

As a farm boy from East-central Illinois, this was kinda a new attitude for me, but now that I’m doing security and seeing all the issues caused by a massive disconnects between the business, IT, Risk and Security, I think maybe they were on to something.

For example: 

Want to spend $5M on that fancy, AI-based SIEM that will solve all our threat and incident monitoring problems?

Show me why it’s the right place to spend $5M.

The thing is, you can improve the control environment. You can improve the processes. You can improve the documentation templates, and you can improve the individual skill levels in your team…

…but if you want to really have a chance of improving the overall effectiveness of your security program, it starts with security architecture. Because that’s the only thing that allows you to play to the “Show Me” card, and demonstrate the value of what you’re doing.

In many cases, it’s common sense, but when, as humans, have we really ever let that get in the way of doing the wrong things, over and over again and then wondering to ourselves why things aren’t quite working out just the way we want…

Want to get better, more consistent results with your risk assessments?

Want to get better, faster response to business needs?

Want to get more security budget more quickly?

It’s all about telling the story. It’s all about being prepared for the ‘Show Me’ mindset, and having the language and the skills to communicate what you’re doing in the terms your customers care about. It’s about providing compelling evidence and traceability between the lofty aspirations of the organization to the depths of the security plumbing your team wrangles every day.

How do you build those skills?

You apply the principles and practices of The Agile Security System™ over and over again until the become habits, so that your way of thinking about any problem that comes across your desk is consistent. You immediately see the implications and the solutions in terms of attributes and domains, and that gives you the leverage to be faster, better and more effective than you’ve ever been.

To pre-order the big, fat, print book that tells you how to do just that for $247, go here before the 31st of October:

https://archistry.com/go/dgpo

You’ll get 50% off the price later, and you’ll be one of the first ones to get this tome of security architecture goodness—not to mention, ensuring it’s actually going to get written.

After the 31st (a mere 4 days from now), the pre-order price goes up by $100 until the middle of January when it’s targeted to ship.

Claim you can’t do proper architecture in the environment you have now?

Show me what’s stopping you.

Stay safe,

ast
—
Andrew S. Townley
Archistry Chief Executive

P.S. Are you stuck on some kind of security architecture, risk assessment or other issue that’s been driving you crazy? Do you want to get some quick advice that might help get things moving again? If you do, then I’d be happy to try and help. Book a one-off, problem solving session using this link: https://archistry.com/go/1pss.

P.P.S. And if you’re interested in subscribing to the monthly print Security Sanity™ newsletter where The Agile Security System™ first appeared, you can start with the next issue here: https://securitysanity.com

Article by Andrew Townley / Archistry Daily / Agile Security, Attributes, Credibility, Domains, SABSA, Security Architecture, TDG, Traceability

  • Email
  • LinkedIn
  • Twitter
  • YouTube

EMAIL NEWSLETTER

Want to get DAILY email tips on how to build a more effective security program so you can prove your security investments deliver value to the business?

You can always unsubscribe at any time, and we won't sell your data to third parties.

About Us

Archistry works with you to ensure what you want to achieve actually gets done, linking strategy, risk, governance and compliance to enable sustained exceptional performance Read More…

Testimonials

Andrew is a highly skilled and experienced information systems architect and consultant, which in my view is a rare thing. He is innovative in his thinking and merits the title of 'thought leader' in his specialist domains of knowledge—in particular the management of risk. Andrew has embraced SABSA as a framework and, in doing so, has been a significant contributor to extending the SABSA body of knowledge."

— John Sherwood, Chief SABSA Architect

"Fabulous person to work with. Very engaging and insightful. Extremely good technical knowledge with ability to relate concepts together and overcome differing opinions. Makes things work."

— Kevin Howe-Patterson, Chief Architect, Nortel - Wireless Data Services

"Andrew was able to bring clarity and great depth of knowledge to the table. His breadth of thinking and understanding of the business and technical issues along with a clear and effective communication style were of great benefit in moving the process forward towards a successful conclusion."

— Doug Reynolds, Product Manager, MobileAware

"Andrew is a fabulous consultant and presenter that you simply enjoy listening to, as he manages to develop highly sophisticated subjects in very understandable way. His experience is actually surprising and his thoughts leave you without considerable arguments for any doubts in the subjects he covers."

— Biljana Cerin, Director, Information Security and Compliance

Recent Posts

  • If you want better security, you’d better have a better security architecture
  • The ultimate security song to keep you focused on what you’re doing
  • Security heroes
  • There’s always a people problem
  • Putting your data flow diagrams out to pasture…for good

Looking for something else?

  • Home
  • About
  • Contact

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Copyright © 2006-2025 Archistry Incorporated or its affiliates

"Archistry", the stained glass window logo, "Pragmantix" and the Pragmantix™ logo, "Archistry Execution Framework (AEF)", "Archistry Execution Framework, Cybersecurity Edition (ACS)", "The Agile Security System", "The Agile Business System", "Baseline Perspectives", "Architecture Wall", "Archistry Execution Engine", "Renegade Security", "Renegade Security System", "Security Value Delivery System (SVDS)" "Collapse-to-Traction", "Collapse-to-Traction System", "Adaptive Trust & Governance Model (ATGM)", and "Adaptive Trust & Governance Model for Organizations (ATGM4O)" are trademarks of Archistry Incorporated or its affiliates.