THANK YOU FOR SUBSCRIBING
Network Infrastructure Magazine | Monday, January 31, 2022
Security must be built into the design of networks. A network security architecture serves as the foundation for an organization's cyber defenses and aids in protecting all of the organization's information technology assets.
FREMONT, CA: A well-designed cybersecurity architecture enables firms to remain resilient in the event of a cyberattack or a component of their infrastructure failing. The design should be optimized for daily use during routine business activities. It should equip the organization to withstand tolerable bursts, spikes, or surges in traffic and manage any cyber threats to the organization appropriately.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
For an organization's network and systems, security architects are responsible for discovering and preventing cyberattacks that could harm them. Network and security architects are responsible for constructing an architecture that allows them to see and control any cyber threats to an organization's systems. Strategic planning for installing security controls in the best possible place is an important part of this process.
The process of creating a network security architecture is divided into four distinct phases:
Assess: This process stage is for reviewing the business and architecture. This phase's critical steps include data collection, business modeling, and risk assessments.
This phase is for developing a response to the requirements and creating unique logical design blueprints and recommendations.
Implementation: This phase is for professional services, partners, and others to provide low-level design details and statement-of-works for real-world solutions.
Manage: This phase is devoted to constantly improving and enhancing the security posture.
Frameworks for Network Security Architecture
Network security architectures can be built using a variety of frameworks. Zero trust and the Sherwood Applied Business Security Architecture are two of the most extensively utilized models (SABSA).
Zero Trust
The zero-trust security model is intended to take the place of traditional perimeter-based security models that implicitly trust people, devices, and applications on the network. Zero trust eliminates the network perimeter by classifying all devices as possible threats regardless of their location.
All requests for access to company resources are reviewed on an individual basis in a zero-trust architecture. If the request is determined to be genuine based on role-based access controls (RBACs) and other contextual data, access is allowed for the length of the current session to the desired asset at the requested level.
A zero-trust security architecture enables comprehensive visibility and control of all activities occurring on the corporate network. This is accomplished by using a combination of robust authentication mechanisms, including multi-factor authentication (MFA) and granular access control via micro-segmentation.
Applied Business Security Architecture by Sherwood (SABSA)
SABSA is a framework for designing a security architecture that is risk- and business-aware. The methodology begins by identifying business security requirements and follows them throughout developing, deploying, and maintaining a security architecture.
SABSA contains a matrix for modeling security architecture. This encompasses various layers (contextual, conceptual, logical, physical, component, and operational) and related problems (what, why, how, who, where, and when). The model outlines the component of the security architecture that should address that question at each junction.
More in News