Archistry

Survivability by Design™ since 2006

  • Home
  • About
    • Who Is Andrew?
    • C2T System™
    • The Agile Security System™
  • Contact
You are here: Home / Archistry Daily / Let there be Security Architecture!

February 1, 2020

Let there be Security Architecture!

Without a doubt, one of the biggest stumbling blocks for people attempting to create security architectures that align with the business, veritably scream the value they create and which underpin and drive the entirety of an effective security program that enables and protects the organization…

Is getting started.

Whatever your thoughts on religion might be, I’m guessing that you might be at least passingly familiar with the story of Genesis from the Bible. And, in this case, I’m talking about, like Genesis 1, page 1, story of creation type of stuff.

Now you might not remember it, but the story goes that God created the heavens and the earth, but the earth…well, let’s just say that the earth wasn’t yet exactly listed in Airbnb as the messy, politically charged place that’s teeming with life today. No, in the beginning, so the story goes…

It was formless. It was void. And it was full of darkness, so even if there were people wandering around, ready to argue until they passed out about one side of partisan politics or the other…they were kinda SOL, because they couldn’t see each other.

But there weren’t. Because it was void.

Empty.

A blank slate.

A ball of malleable clay…waiting for someone to unleash its potential.

Now, in the story, of course, that “someone” was God, and on the first day, apparently…

“And God said, ‘Let there be light,’ and there was light. And God saw that the light was good, and He separated the light from the darkness.” (from some Google indexed version of some edition the Bible)

Whether you believe the story or not, or what your religion (if any) might be, is actually irrelevant to the discussion, and frankly, I don’t care either way. It doesn’t matter to me in the slightest.

The thing is…while there are certainly some people I’ve met in my life that call themselves “architects” who do certainly have delusions of grander of God-like proportions…

There’s no practical way that any of us – and I don’t care how good you are – can just click your fingers, wave your hand, or simply conjure up by sheer force of will and mental energy…

…a fully-formed, business-driven, all-singing, all-dancing, party-animal of a security architecture—at any level.

It. Just. Doesn’t. Happen.

Sure, it’d be nice. But, if it were possible, you’d probably end up with some sandy-haired kid with dreadlocks trying to put it on the end of a stick or something like the classic “Captain Walker” scene in the original, Mel Gibson Mad Max, Beyond Thunderdome film…

“We kept it straight, right? Everything marked. Everything ‘membered”

Everyone wants to see “tomorrow-morrow land”…but nobody knows what it is…and very few know how to build it.

Because security architects, no matter how wide the definition you choose to follow, aren’t gods—as much as we’d sometimes like to be, because, well…it’d sure be a lot easier, right?

Unfortunately, any way you slice it, that blank slate…that formless ball of architecture clay that faces every security architect at some point in their career is up to you – and you alone – to lead its transformation.

Sure, there’s a load of frameworks out there you can use to guide the work you do…including SABSA, of course…

…but you still need to find your own way. You need to create a vision in your mind clear enough…consistent enough…to drive every decision that you make, every day, so that you don’t end up spinning your wheels, going in circles…

…and sitting in a pile of cracked and shattered pottery that had aspirations of someday becoming your organization’s business-enabling security architecture.

You certainly can do it yourself, from scratch. Lots of people do.

But, you don’t have to. If you want to stand on the shoulders of someone standing on the shoulders of giants, then maybe not starting from a blank slate or completely formless mass of clay and commanding it to become architecture isn’t really the right way…

For you.

Or maybe it is. I’ve no way of telling.

However, if you would like to learn a focused, coherent system, guided by 7 principles, with 14 practices I recommend you make automatic habits – and 3 Baseline Perspectives™, initial models of your organization, it’s services and how it interacts with the world…firmly sitting on the shoulders, methods, concepts and value of SABSA itself…

Then run, don’t walk, to this link:

https://archistry.com/besa

And register for the next cohort of Building Effective Security Architectures, Archistry’s 7-week, hands-on, security architecture skill development education program to make sure you’ve reserved your seat for February 24th.

It won’t make you a security architecture god by any means, but it just might help you get that business-enabling security architecture in place a whole lot faster and easier than you could knowing what you already know, right now, today.

Stay safe,

ast
—
Andrew S. Townley
Archistry Chief Executive

Article by Andrew Townley / Archistry Daily / Agile Security, BESA, SABSA, Security Architecture

  • Email
  • LinkedIn
  • Twitter
  • YouTube

EMAIL NEWSLETTER

Want to get DAILY email tips on how to build a more effective security program so you can prove your security investments deliver value to the business?

You can always unsubscribe at any time, and we won't sell your data to third parties.

About Us

Archistry works with you to ensure what you want to achieve actually gets done, linking strategy, risk, governance and compliance to enable sustained exceptional performance Read More…

Testimonials

Andrew is a highly skilled and experienced information systems architect and consultant, which in my view is a rare thing. He is innovative in his thinking and merits the title of 'thought leader' in his specialist domains of knowledge—in particular the management of risk. Andrew has embraced SABSA as a framework and, in doing so, has been a significant contributor to extending the SABSA body of knowledge."

— John Sherwood, Chief SABSA Architect

"Fabulous person to work with. Very engaging and insightful. Extremely good technical knowledge with ability to relate concepts together and overcome differing opinions. Makes things work."

— Kevin Howe-Patterson, Chief Architect, Nortel - Wireless Data Services

"Andrew was able to bring clarity and great depth of knowledge to the table. His breadth of thinking and understanding of the business and technical issues along with a clear and effective communication style were of great benefit in moving the process forward towards a successful conclusion."

— Doug Reynolds, Product Manager, MobileAware

"Andrew is a fabulous consultant and presenter that you simply enjoy listening to, as he manages to develop highly sophisticated subjects in very understandable way. His experience is actually surprising and his thoughts leave you without considerable arguments for any doubts in the subjects he covers."

— Biljana Cerin, Director, Information Security and Compliance

Recent Posts

  • If you want better security, you’d better have a better security architecture
  • The ultimate security song to keep you focused on what you’re doing
  • Security heroes
  • There’s always a people problem
  • Putting your data flow diagrams out to pasture…for good

Looking for something else?

  • Home
  • About
  • Contact

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Copyright © 2006-2025 Archistry Incorporated or its affiliates

"Archistry", the stained glass window logo, "Pragmantix" and the Pragmantix™ logo, "Archistry Execution Framework (AEF)", "Archistry Execution Framework, Cybersecurity Edition (ACS)", "The Agile Security System", "The Agile Business System", "Baseline Perspectives", "Architecture Wall", "Archistry Execution Engine", "Renegade Security", "Renegade Security System", "Security Value Delivery System (SVDS)" "Collapse-to-Traction", "Collapse-to-Traction System", "Adaptive Trust & Governance Model (ATGM)", and "Adaptive Trust & Governance Model for Organizations (ATGM4O)" are trademarks of Archistry Incorporated or its affiliates.