This Guide examined the field of security architecture from the point of view of security governance. It explains how security architecture governance can be created as a sub-field of security governance and how the principles and structure of the same can be applied to security architecture governance to build an overarching security environment that is easy to understand, change, monitor and maintain. It has examined the security architecture governance from the point of view of business sponsors and other stakeholders. It has suggested security governance life cycle phases, sub-stages in each phase. For each sub-stage, it has described the list of activities, proposed required participants, stated expected outcomes and probable artifacts and identified building blocks of the area of concern. While describing the building blocks, the article has touched upon some of the fundamental concepts where required and explained it contextually to make the understanding clear. Its principle of arriving at inferences is primarily based on risk management. It proposes procedure, organisations, artifact, challenges and implementation hints that can be used to create a security architecture governance plan.

 The authors expect this article to be useful for organisations who are in the process of creating or improving their existing security development process. The article is created based on authors’ experience in building such a process for large enterprises in combination with the research of publicly available materials across internet and other forms of publications. It does not directly or indirectly attempts to depict any process of any particular organisation.


>> Click Here To Download Guide

This Guide Focuses On:

  • Developing A Customized Information Security Architecture Governance Framework
  • Applying The Framework In Organization Context To Create Implementation Roadmap
  • Developing A Measurement Program To Continuously Improve Security Architecture Governance


>> Click Here To Download Guide

About Authors

Arnab Chattopadhyay

Arnab is a passionate technologist and loves to design, build and protect large scale systems. Some of the key areas of his expertise includes telecom networks, large scale distributed software development, big data technologies, artificial intelligence and information security. He had spent significant number of years in security research, consulting and management of security functions that includes identity and access management, cryptography, security architecture, vulnerability management and security program development. He had worked across the globe with large corporations to secure their systems. An entrepreneur at heart, he was instrumental in creating one of the world’s first cloud-based penetration testing SaaS companies. 

Arnab has a Master’s of Science degree in Telecom Engineering with Distinction from the University College London. He held a patent in artificial intelligence.

>> Click Here To Download Guide

Nidhi Agarwal

Nidhi has been a Software Engineer for over 12 years. After years of working in the variety of areas of software development that includes web application development, database and developing algorithms, Nidhi moved into information security. She had lead development of information security governance program in software product companies. She had worked extensively in the areas of vulnerability management, identity and access management and security governance. She has special interest in security architecture.

Nidhi has Bachelor Degree in Computer Science and Engineering with Honors from National Institute of Technology, Allahabad.

8669811669?profile=original

Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion

CISO Platform

A global community of 5K+ Senior IT Security executives and 40K+ subscribers with the vision of meaningful collaboration, knowledge, and intelligence sharing to fight the growing cyber security threats.

Join CISO Community Share Your Knowledge (Post A Blog)
 

 

 

CISO Platform Talks : Security FireSide Chat With A Top CISO or equivalent (Monthly)

  • Description:

    CISO Platform Talks: Security Fireside Chat With a Top CISO

    Join us for the CISOPlatform Fireside Chat, a power-packed 30-minute virtual conversation where we bring together some of the brightest minds in cybersecurity to share strategic insights, real-world experiences, and emerging trends. This exclusive monthly session is designed for senior cybersecurity leaders looking to stay ahead in an ever-evolving landscape.

    We’ve had the privilege of…

  • Created by: Biswajit Banerjee
  • Tags: ciso, fireside chat

6 City Round Table On "New Guidelines & CISO Priorities for 2025" (Delhi, Mumbai, Bangalore, Pune, Chennai, Kolkata)

  • Description:

    We are pleased to invite you to an exclusive roundtable series hosted by CISO Platform in partnership with FireCompass. The roundtable will focus on "New Guidelines & CISO Priorities for 2025"

    Date: December 1st - December 31st 2025

    Venue: Delhi, Mumbai, Bangalore, Pune, Chennai, Kolkata

    >> Register Here

  • Created by: Biswajit Banerjee

Fireside Chat With Sandro Bucchianeri (Group Chief Security Officer at National Australia Bank Ltd.)

  • Description:

    We’re excited to bring you an insightful fireside chat with Sandro Bucchianeri (Group Chief Security Officer at National Australia Bank Ltd.) and Erik Laird (Vice President - North America, FireCompass). 

    About Sandro:

    Sandro Bucchianeri is an award-winning global cybersecurity leader with over 25…

  • Created by: Biswajit Banerjee
  • Tags: ciso, sandro bucchianeri, nab