Security Architecture Discussions

The day before yesterday I was lucky enough to be invited to a Security discussion with some very senior security people in the UK. I introduced myself as an architect which led to some fairly “interesting” views of the role of the architect. There was clearly a lot of feeling that people starting off with an “architecture” base were pretty valueless in real life and people starting with a set of technologies / issues and refactoring an architecture from them were doing something useful. I hope I am in the latter camp.

It was clear to me that we do however need some sort of security architecture which has to include both the technical sort of stuff I blogged about earlier and also less security technology focussed areas such as:

Present and projected threat analysis / risk mitigation.

Security and auditability.

Alerting and patching.

There were also some interesting specific areas of interest that came up the discussion too such as:

Anti Virus / Malware strategies.

Mobile strategy.

Spoofing / phishing / farming strategies.

This last one seemed to me to be the most immediately pressing area which needed some innovative thinking. An addin to the client which did host change detection and warning seemed like a simple and effective solution to this.