{"id":208,"date":"2017-09-06T08:41:12","date_gmt":"2017-09-06T06:41:12","guid":{"rendered":"http:\/\/www.scag.co.za\/wordpress\/?page_id=208"},"modified":"2017-09-13T09:08:21","modified_gmt":"2017-09-13T07:08:21","slug":"resources","status":"publish","type":"page","link":"https:\/\/www.scag.co.za\/wordpress\/resources\/","title":{"rendered":"Resources"},"content":{"rendered":"<p>*Work in progress*<br \/>\nThis page is a curated list of resources I have found useful as a security architect. I will be adding items to the list from time to time, so check back when you remember. There are more than enough &#8220;security lists&#8221; in the wild, but not many have a focus on security architecture.<\/p>\n<p>I consider these resources to be recommended for anyone interested in security architecture.<\/p>\n<p><strong>Frameworks<\/strong><br \/>\nFrameworks are great as a guideline, and some clients may insist you follow a particular framework. I find that having knowledge of a few complimentary frameworks provides the most well-rounded professional. Security oriented frameworks tend to be elusive, but they are out there. In order to fit in with the rest of the organisation, it is best to also be familiar with enterprise architecture frameworks.<\/p>\n<p><a href=\"http:\/\/www.sabsa.org\/node\/69\" target=\"_blank\" rel=\"noopener\">SABSA white paper<\/a>, SABSA Foundation<br \/>\n<a href=\"https:\/\/www.opengroup.org\/togaf\/\" target=\"_blank\" rel=\"noopener\">TOGAF<\/a>, The Open Group<br \/>\n<a href=\"http:\/\/www.opengroup.org\/subjectareas\/security\/architecture\" target=\"_blank\" rel=\"noopener\">O-ESA<\/a>, The Open Group<br \/>\n<a href=\"http:\/\/www.bredemeyer.com\/\" target=\"_blank\" rel=\"noopener\">Visual architecting<\/a>, Dana Bredemeyer and <a href=\"http:\/\/www.ruthmalan.com\/\" target=\"_blank\" rel=\"noopener\">Ruth Malan<\/a>. Bredemeyer consulting. Additional resource: <a href=\"http:\/\/traceinthesand.com\/blog\/\" target=\"_blank\" rel=\"noopener\">Trace in the sand<\/a><br \/>\n<a href=\"https:\/\/www.bsimm.com\/\" target=\"_blank\" rel=\"noopener\">BSIMM<\/a>, Building Security In<\/p>\n<p><strong>Books<\/strong><br \/>\n[<em>security engineering, design, coding<\/em>]<br \/>\n<a href=\"https:\/\/www.manning.com\/books\/secure-by-design\" target=\"_blank\" rel=\"noopener\">Secure by design<\/a> by\u00a0Dan Bergh Johnsson, Daniel Deogun, Daniel Sawano. Manning publications, 2017.<br \/>\n[<em>security engineering<\/em>]<br \/>\n<a href=\"http:\/\/www.cl.cam.ac.uk\/~rja14\/book.html\" target=\"_blank\" rel=\"noopener\">Security engineering<\/a>\u00a0by Ross Anderson. Wiley, 2008.<br \/>\n[<em>software engineering<\/em>]<br \/>\n<a href=\"https:\/\/www.amazon.com\/Phoenix-Project-DevOps-Helping-Business-ebook\/dp\/B00AZRBLHO\" target=\"_blank\" rel=\"noopener\">The Phoenix Project<\/a>\u00a0by Gene Kim, Kevin Behr, George Spafford.<br \/>\n[<em>enterprise architecture<\/em>]<br \/>\n<a href=\"https:\/\/www.amazon.com\/Enterprise-Architecture-Strategy-Foundation-Execution\/dp\/1591398398\" target=\"_blank\" rel=\"noopener\">Enterprise architecture as strategy<\/a>\u00a0by Jeanne Ross, Peter Weill, David Robertson. Harvard Business School Press, 2006.<br \/>\n<a href=\"http:\/\/www.dreamingincode.com\/\" target=\"_blank\" rel=\"noopener\">Dreaming in code<\/a> by Scott Rosenberg. Crown, 2007.<br \/>\n[<em>Cybersecurity risk<\/em>]<br \/>\n<a href=\"http:\/\/www.howtomeasureanything.com\/cybersecurity\/\" target=\"_blank\">How to measure anything in Cybersecurity Risk<\/a> by Douglas W. Hubbard and Richard Seiersen. Wiley, 2016.<\/p>\n<p><strong>Certification<\/strong><br \/>\n<a href=\"http:\/\/www.sabsa.org\/\" target=\"_blank\">SABSA<\/a><br \/>\n<a href=\"https:\/\/www.axelos.com\/certifications\/itil-certifications\" target=\"_blank\">ITIL<\/a><br \/>\n<a href=\"https:\/\/cloudsecurityalliance.org\/\" target=\"_blank\">CCSK<\/a><\/p>\n<p><strong>Reference patterns\/designs<\/strong><br \/>\n<a href=\"http:\/\/www.opensecurityarchitecture.org\/cms\/library\/patternlandscape\" target=\"_blank\" rel=\"noopener\">Open Security Architecture patterns<\/a><br \/>\n<a href=\"http:\/\/aosabook.org\/en\/index.html\" target=\"_blank\" rel=\"noopener\">The Architecture of Open Source Applications<\/a><\/p>\n<p><strong>Web resources<\/strong><br \/>\n<a href=\"https:\/\/cto-security-checklist.sqreen.io\/\" target=\"_blank\" rel=\"noopener\">SaaS CTO checklist<\/a><br \/>\n<a href=\"https:\/\/fallible.co\/blog\/\/2016\/06\/22\/The-Security-Checklist\/\" target=\"_blank\" rel=\"noopener\">The Security Checklist: For developers<\/a><br \/>\n<a href=\"http:\/\/cloud-standards.org\/\" target=\"_blank\" rel=\"noopener\">Cloud-Standards.org<\/a><br \/>\n<a href=\"https:\/\/www.cutter.com\/\" target=\"_blank\" rel=\"noopener\">The Cutter Consortium<\/a><br \/>\n<a href=\"https:\/\/capec.mitre.org\/\" target=\"_blank\" rel=\"noopener\">CAPEC: Common Attack Pattern Enumeration and Classification<\/a><br \/>\n<a href=\"https:\/\/www.microsoft.com\/en-us\/sdl\/default.aspx\" target=\"_blank\" rel=\"noopener\">Microsoft Security Development Lifecycle<\/a><br \/>\n<a href=\"https:\/\/www.owasp.org\/index.php\/OWASP_Guide_Project\" target=\"_blank\" rel=\"noopener\">OWASP Development Guide Project<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>*Work in progress* This page is a curated list of resources I have found useful as a security architect. I will be adding items to the list from time to time, so check back when you remember. There are more than enough &#8220;security lists&#8221; in the wild, but not many have a focus on security &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.scag.co.za\/wordpress\/resources\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Resources&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-208","page","type-page","status-publish","hentry","entry"],"_links":{"self":[{"href":"https:\/\/www.scag.co.za\/wordpress\/wp-json\/wp\/v2\/pages\/208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.scag.co.za\/wordpress\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.scag.co.za\/wordpress\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.scag.co.za\/wordpress\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.scag.co.za\/wordpress\/wp-json\/wp\/v2\/comments?post=208"}],"version-history":[{"count":14,"href":"https:\/\/www.scag.co.za\/wordpress\/wp-json\/wp\/v2\/pages\/208\/revisions"}],"predecessor-version":[{"id":248,"href":"https:\/\/www.scag.co.za\/wordpress\/wp-json\/wp\/v2\/pages\/208\/revisions\/248"}],"wp:attachment":[{"href":"https:\/\/www.scag.co.za\/wordpress\/wp-json\/wp\/v2\/media?parent=208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}