Newsletters Welcome, Guest Log In | Register

Join the Community

Exchange

Get full access to our community's expertise and resources.

Register Now >

Security Architect Skills

31 Replies Last post: Oct 10, 2009 4:57 PM by JasonT.Zane   1 2 3 Previous Next
Ralph DeFrangesco   52 posts since
Oct 3, 2008
Reply

Sep 24, 2009 11:44 AM

Security Architect Skills

"What business and soft skills would be beneficial for a security architect to have, and why?"

MarcZurcher   12 posts since
Sep 25, 2009
1. Sep 25, 2009 7:17 PM in response to: Ralph DeFrangesco
Re: Security Architect Skills

After listening to what you talked about last class i have to say that i think having basic communication and people skills goes a long way. the basic ability to talk to coworkers in a plain and simple manner makes it much easier to discuss different topics with a wide variety of people including upper management. I also think that having some business courses such as economics, under your belt would aid in being able to more easily understand business decisions and how they differ from IT decisions.

RobDeStasio   14 posts since
Sep 27, 2009
2. Sep 27, 2009 6:42 PM in response to: Ralph DeFrangesco
Re: Security Architect Skills

A Security Architect should possess confidence in his work, and needs to know his or her job better than anyone else. As we discussed in class a security architect will need to state their case for the equipment they feel the company will need. We talked about how companies tend to dislike spending a lot of money, and how we halt business in their eyes. Security Architechs need to be smooth, convincing talkers.  The Architects need to be able to explain the risk and certain vulnerabilities in which the company they work for should be aware and prepared for.

RobDeStasio   14 posts since
Sep 27, 2009
3. Sep 27, 2009 6:49 PM in response to: MarcZurcher
Re: Security Architect Skills

I agree, a better understanding of how the business is thinking will help build a stronger bridge between everyone. This would make it easier for a security architect to get a little more out of their company.

JeVoneSmith   21 posts since
Sep 27, 2009
4. Sep 27, 2009 8:42 PM in response to: Ralph DeFrangesco
Re: Security Architect Skills

I think a person who will carry the title as "Security Architect" will have a well verse backgroud in all aspects of security. This includes digital, physical, personnel and other security areas. They should be network, equipment (physical and virtual) savvy and very well spoken. Be familiar with different network security tools and architecture in order to accomodate business goals. Furthermore, a security architect will have to be persuasive in selling there facts and how the impact of not having the security mechanisms in place could be very detrimental to a company or business.

JeVoneSmith   21 posts since
Sep 27, 2009
5. Sep 27, 2009 8:47 PM in response to: MarcZurcher
Re: Security Architect Skills

Good point Marc. Being able to communicate with co workers upper management and deck plate personnel is always a good trait. An just to add my two cents in is they must be able to sell security to those same people even though it will probably put many restrictions in them getting there work done, and no tangible return on investment. Upper management especially the bean counters never understand why we can not afford to skimp on funds when it comes to security. They only worry about how much revenue it's going to produce for them. Well the revenue is produce when the security incidents and intrusion do not happen.

 

JeVone

JeVoneSmith   21 posts since
Sep 27, 2009
6. Sep 27, 2009 8:51 PM in response to: RobDeStasio
Re: Security Architect Skills

Your absolutely right. Security Architects should use fact sheets of security infractions, intrusions, etc that have happened to other companies to help get their points across and drive home the fact that security is paramount. They need to see what the consequences have been for other companies and compare that to what could happen to them.

BryanMareletto   14 posts since
Sep 28, 2009
8. Sep 28, 2009 3:01 PM in response to: Ralph DeFrangesco
Re: Security Architect Skills

A security architect should possess necessary skills to effectively communicate his or her plans, emphasizing what's best for the company. If the company's mission or business plan does not mesh well with the security architect's plans, then there is a good chance it's not going to go through. It's part of a security architect's necessary skillset to be able to convince the senior management that these plans are good for the company and will bring a return on investment.

BryanMareletto   14 posts since
Sep 28, 2009
9. Sep 28, 2009 3:04 PM in response to: RobDeStasio
Re: Security Architect Skills

I agree with Rob, confidence is an important trait to have as a security architect. It helps convince senior management that your ideas are in the company's best interest.

MattHemeleski   8 posts since
Sep 25, 2009
11. Sep 29, 2009 4:08 AM in response to: Ralph DeFrangesco
Re: Security Architect Skills

While I will agree that communicatin is a big part of Security Architecture, I would argue it is at the tail-end of things. You could be a great communicator, but still communicate the absolute wrong thing. Having a crisp idea of what the actual needs of the company are, as well as accounting for expansion and worst-case-scenarios. This requires a good deal of big-picture thinking that is a bit more nuanced than simply piling up the sexiest hardware and measures.

 

The job of the architect isto give the business the measures and defenses that they need. And, as was mentioned in class this last week, most business people don't really know what that is. To a degree, you're doing the thinking for them. This requires the flexibility to bring yourself out of the IT world and think in terms of feasablility and the effect that any new network and its appropriate security will have on all phases and departments of a given company.

MattHemeleski   8 posts since
Sep 25, 2009
12. Sep 29, 2009 4:17 AM in response to: JeVoneSmith
Re: Security Architect Skills

JeVone:

 

I would agree. But such comparisons could only be made in an apples to apples sense. For example, my current company is an internet-based phone company with a little over four hundred clients and about one hundred employees. The stability of our server and network is absolutely vital to the business itself. However, while that is the case, I would not guage that we at the same security risk as, lets say, Google. We don't have that much exposure and rarely anyone outside of our clients, and local competitors, is even aware of our existance. I do agree that making comparisons out of case studies is important for communicating the needs of the network to the business, but it should be done in a measured and well thought ot manner.

JackieClayton   14 posts since
Sep 28, 2009
14. Sep 29, 2009 2:40 PM in response to: Ralph DeFrangesco
Re: Security Architect Skills

A security architect should have an indepth buisiness skill's foundation in information security and the soft skills to encourage innovation.  A strong foundation in information security will allow the security architect the ability to support the business goals by designing and appling the required governance to current system operations with little impact on daily operations.  Additionally, encouraging innovation within the company will allow all staff members the opportunity to provide quality feedback during each layer of security application.  A security architect must be able to communicate the big picture to management and each tenant of the business to be effective.

Security Architect Skills

Go to original post 1 2 3 Previous Next

ITIL V3 Foundation - Complete Certification Kit

Enhance your IT career by getting your ITIL Foundation Certificate. It's fast and easy with this complete resource. The 186-page eBook and companion online training course is guaranteed to help you pass the ITIL exam.

Learn more >

The Complete IT Policy Kit

Download a comprehensive bundle containing over 40 IT policy templates. Each can be modified to align with your specific business requirements. Complete instructions are included.

Learn more >

Data Deduplication

Data manipulation strategies that make data stores more manageable and reduce the need for storage capacity and its associated costs.

Service Oriented Architecture (SOA)

Service-Oriented Architecture is the catalyst that allows today’s companies to respond to business demands faster and more effectively than ever.

Data Management Solutions

Data management and storage solutions, tips and best practices to improve the scalability, reliability, and accessability of your data.

Data Loss Protection

Data-loss prevention tactics, technologies and best practices to protect your sensitive and valuable company data.

Software Forum: Information On Demand Virtual Experience

This interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Performance Under Pressure: The State of Enterprise Web Application Quality and Availability

This research study finds that Web application issues are an all-too-common problem and examines these Web-based enterprise application issues from two perspectives: that of an online customer and that of a site manager.