Aljosa Pasic
 |
| Head of AIM department, Atos Research & Innovation |
|
|
The "security-aware" era, in which the belief that security must be a forethought and "built-in" component has gained popularity over the last few years. Although this belief acknowledges the need for integrating security into the early design and development phases of information systems, in practice, this integration has not yet been achieved. In current system development processes, security requirements are identified independently for each system component, such as network layer, server storage and computing resources, processing of sensitive data etc without explicitly considering the interdependences between them. In addition, these requirements are often limited just for a single context (user, environment, community etc), which for the future service oriented world seems inappropriate. NESSI working group on Trust, Security and Dependability (TSD) we have witnessed a growing interest in security information governance in service oriented systems. We envisage that securing the architecture will therefore be a part of global information governance process (as is the case of a proper security strategy) that needs to encompass requirements from various types of architecture properties and different stakeholders.
|