Archistry

Survivability by Design™ since 2006

  • Home
  • About
    • Who Is Andrew?
    • C2T System™
    • The Agile Security System™
  • Contact
You are here: Home / Archistry Daily / The rule of 3: brevity and rhythm

October 23, 2019

The rule of 3: brevity and rhythm

[Note that this is a slightly abbreviated version (yes, really…) of the original. The original only went to the subscribers to my daily email tips, but you can get all the goodies too if you type your email in that box. You’ll always be the first to know what’s going on, and sometimes, it might also help your bottom line. — Ed.]

Ok, so I’m hoping that I’ll at least get 50% with this email, because I have 3 announcements that I’d like to share with you.

The first one comes from feedback from people over the last 4 years as I’ve been zeroing in on what eventually became The Agile Security System™ in July. I’ve heard it from clients and customers, I’ve heard it from people at conferences and I’ve heard it from my wife:

“Why don’t you write a book?”

So…that’s what I’m going to finally do. Up to now, I’ve effectively written loads of books, but they just weren’t for general public consumption, nor were they the “right” book. That was because I hadn’t gelled it all together into something simple and accessible yet with all the power of SABSA.

And, as you’re part of the crew that gets my daily emails, you’re going to be the first to know about it—and you’ll also be the first to buy it at a pretty hefty discount. That’s mostly because I don’t want to write something I’m not sure people will actually buy. I mean, I know it’s all valid and useful, because it’s stuff I’ve now been doing for some time, but whether it’s really of interest to you or not is a whole different matter.

In fact, I’m going to be doing a lot of writing over the next few months, but the goal of this book is to provide the Definitive Guide to The Agile Security System for Security Leaders and Security Architects to integrate architecture into the way they deliver their security programs. It takes information from our newly updated flagship 7 week training course, Building Effective Security Architectures with The Agile Security System, some of the content from the newsletter and expands on some of the materials I’ve presented at COSAC over the last couple of years.

The short version of what’s in it is:

  • How to get started with The Agile Security System from an annual report, a project charter or your organization’s existing security policies
  • Exactly how to integrate architecture-driven security into Agile and DevOps delivery pipelines
  • Detailed descriptions of the Principles, Practices and the Baseline Perspectives
  • Building the right team to deliver Agile Security
  • The essentials of Requirements Engineering
  • The Agile Security Activity Triggers that will run your security program and architecture iterations
  • How to use the system to ensure effective information and cyber risk governance
  • The right way to conduct an architecture-based risk assessment
  • Basic security modeling with the Archistry Security Modeling Language™ (ASML)
  • And pages and pages of annotated and worked examples (by me) for each of the security architecture starting points mentioned above: the annual report, the project charter or the existing security policies

If this sounds like something that might help you, there is a catch or two:

First, I’m not sure I’m going to write it yet. To make it worthwhile, I need to get at least 10 people to pre-order the book before Halloween (31st of this month).

The second catch is that it’s a print, physical book—and it won’t be small.

The third catch is that it’s not going to be shipped until sometime in January to give me time to do this right.

The fourth catch is that it’s not going to be cheap.

If you want to make sure you’re going to get yours in the first print run, you can pre-order your copy for $247 here: https://archistry.com/go/dgpo/.

That’s basically a 50% discount, and the promise I’ll make to anyone who orders it is that they will get a copy of the book if we hit the target 10 orders, or I’ll give you your money back in November if we don’t.

There’s no sales page yet, so the link above takes you directly to the checkout page.

The Second Announcement
=====================

One of the things that’s become clear over the last several months is that there’s a desire for ad-hoc help that doesn’t quite fit any of the existing programs Archistry offers right now. So, what I’m going to do for people on this list – and ONLY for subscribers of this list – is that I’m going to start piloting a single, security problem solving offering.

[list-only content deleted. — Ed.]

 

The Third Announcement
===================

Unlike I usually do, I’m not going to promote the November issue of the Security Sanity™ newsletter for the rest of the month. It will be published, and it will go to anyone who signs up before the 31st of October, but I’m not going to talk much about it.

The November issue is all about Business Risk and using Business Risk to identify and predict the information and cybersecurity controls you will need in your environment.

As always, if you want it delivered to your door in November, then you can sign up here:

https://securitysanity.com

That’s all for now, so until next time:

Stay safe,

ast
—
Andrew S. Townley
Archistry Chief Executive

Article by Andrew Townley / Archistry Daily / Agile Security, Architecture Models, Book Launch, COSAC, Risk Assessment, SABSA, Security Architecture, TDG

  • Email
  • LinkedIn
  • Twitter
  • YouTube

EMAIL NEWSLETTER

Want to get DAILY email tips on how to build a more effective security program so you can prove your security investments deliver value to the business?

You can always unsubscribe at any time, and we won't sell your data to third parties.

About Us

Archistry works with you to ensure what you want to achieve actually gets done, linking strategy, risk, governance and compliance to enable sustained exceptional performance Read More…

Testimonials

Andrew is a highly skilled and experienced information systems architect and consultant, which in my view is a rare thing. He is innovative in his thinking and merits the title of 'thought leader' in his specialist domains of knowledge—in particular the management of risk. Andrew has embraced SABSA as a framework and, in doing so, has been a significant contributor to extending the SABSA body of knowledge."

— John Sherwood, Chief SABSA Architect

"Fabulous person to work with. Very engaging and insightful. Extremely good technical knowledge with ability to relate concepts together and overcome differing opinions. Makes things work."

— Kevin Howe-Patterson, Chief Architect, Nortel - Wireless Data Services

"Andrew was able to bring clarity and great depth of knowledge to the table. His breadth of thinking and understanding of the business and technical issues along with a clear and effective communication style were of great benefit in moving the process forward towards a successful conclusion."

— Doug Reynolds, Product Manager, MobileAware

"Andrew is a fabulous consultant and presenter that you simply enjoy listening to, as he manages to develop highly sophisticated subjects in very understandable way. His experience is actually surprising and his thoughts leave you without considerable arguments for any doubts in the subjects he covers."

— Biljana Cerin, Director, Information Security and Compliance

Recent Posts

  • If you want better security, you’d better have a better security architecture
  • The ultimate security song to keep you focused on what you’re doing
  • Security heroes
  • There’s always a people problem
  • Putting your data flow diagrams out to pasture…for good

Looking for something else?

  • Home
  • About
  • Contact

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Copyright © 2006-2025 Archistry Incorporated or its affiliates

"Archistry", the stained glass window logo, "Pragmantix" and the Pragmantix™ logo, "Archistry Execution Framework (AEF)", "Archistry Execution Framework, Cybersecurity Edition (ACS)", "The Agile Security System", "The Agile Business System", "Baseline Perspectives", "Architecture Wall", "Archistry Execution Engine", "Renegade Security", "Renegade Security System", "Security Value Delivery System (SVDS)" "Collapse-to-Traction", "Collapse-to-Traction System", "Adaptive Trust & Governance Model (ATGM)", and "Adaptive Trust & Governance Model for Organizations (ATGM4O)" are trademarks of Archistry Incorporated or its affiliates.