Enterprise Asset Management: The Most Boring Thing You Absolutely Need
Let’s get something out of the way upfront.
Read article: Enterprise Asset Management: The Most Boring Thing You Absolutely Need12 articles tagged Security Architecture.
Let’s get something out of the way upfront.
Read article: Enterprise Asset Management: The Most Boring Thing You Absolutely NeedI’ve talked about network segmentation in many blog posts, but I’ve never had a blog post dedicated specifically to that topic. So, here we go.
Read article: Network Segmentation: Macro, Micro, and the Building Blocks“Defense in Depth” is the idea that no single security control is trusted to stop an attack. Instead, you stack multiple, independent layers so that if one fails, others still stand in the way.
Read article: Defense In DepthZero Trust Architecture (ZT or ZTA) is a security model / framework based on one simple idea: Never trust, always verify. From NIST, we have, the “… ZT approach is primarily focused on data and service protection but can and should be expanded to include all enterprise assets (devices,…
Read article: Zero Trust ArchitectureA long time ago, I was doing integration architecture work in the land of Enterprise Service Buses (ESBs) and API Gateways. Think IBM WebSphere DataPower and Apigee — I like to remember Apigee the way it was before it was integrated into GCP. After we had designed and built the ESB, we moved on to…
Read article: A Vendor DMZ PatternRegardless of your application architecture or front-end type, there are a variety of common attack types that the application security architecture’s capabilities must protect against. I’ve talked about these topics briefly before here, here, and here.
Read article: Prevent XSS and Other Common Attacks on Your AppI like to start system design (at the application level) with the security model that will be used to protect the system. Application security models have several attributes that need to be addressed at each layer of the application.
Read article: Application Security ModelsIn the last post, we looked at the steps involved in generating a digital signature using the XML Digital Signature spec. The algorithm to produce a signature and validate it were explored but no examples were given. In this post, we’ll look at an example that is given in the XML Digital Signature…
Read article: XML Digital Signature (an Example)I have been in several different shops that are either deploying DataPower or are a few years after deploying DataPower. I’ve also had opportunities to talk to numerous different DataPower technical resources about how they have utilized DataPower. In the post, I want to describe what I’ve seen as…
Read article: Three Internal Architectures—Designs for DataPower DeploymentsFollowing up on the recommended reading lists I’ve posted recently, this post contains a list of the books and specifications that I direct people to about SOA.
Read article: Recommended Reading Material for SOA