avatarAndrew Douma

Free AI web copilot to create summaries, insights and extended knowledge, download it at here

6526

Abstract

href="https://twitter.com/arcitura">modern training provider</a> has done a terrific job sharing their design patterns with the world, from the basics to the advanced.</p><figure id="4813"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/0*9Rke7xzqfnCTctl6.png"><figcaption>Arcitura Pattern for <a href="https://patterns.arcitura.com/cloud-computing-patterns/design_patterns/cloud_data_breach_protection">Cloud Data Breach Protection</a></figcaption></figure><p id="1f89">Currently, Arcitura covers Cloud Computing, Microservices and Containerization, Big Data, DevOps, and Blockchain — with plans to launch Machine Learning, Artificial Intelligence, and Internet of Things soon.</p><div id="f269" class="link-block"> <a href="https://patterns.arcitura.com/"> <div> <div> <h2>Arcitura Patterns</h2> <div><h3>Arcitura Education Inc. is a leading global provider of progressive, vendor-neutral training and certification…</h3></div> <div><p>patterns.arcitura.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*OBA8lk983f4aMr3T)"></div> </div> </div> </a> </div><ul><li><a href="https://patterns.arcitura.com/">https://patterns.arcitura.com/</a> (browse menu on left)</li><li><a href="https://patterns.arcitura.com/cloud-computing-patterns/design_patterns/cloud_data_breach_protection">Cloud Data Breach Protection</a></li><li><a href="https://patterns.arcitura.com/cloud-computing-patterns/design_patterns/automatically_defined_perimeter">Automatically Defined Perimeter</a></li></ul><figure id="ca6c"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/0*YJ0juPBKbXlE-9Rf.png"><figcaption></figcaption></figure><h2 id="1b79">IOA Knowledge Base</h2><p id="fbcf">I <a href="https://ioakb.com/register/">strongly recommend joining</a> this impressive open community of IT Architects championing the Interconnection Oriented Architecture framework.</p><figure id="063e"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/1*YD4XjU1TlBHXH1QlwZcjyA.png"><figcaption>IOKB Roadmap</figcaption></figure><p id="a920">IOA aims to enable you with blueprints, playbooks, and design patterns for a modern interconnected world. Their knowledge-base provides a wealth of information.</p><div id="5216" class="link-block"> <a href="https://ioakb.com/"> <div> <div> <h2>IOA Knowledge Base Homepage</h2> <div><h3>Access detailed blueprints, proven design patterns and a community of expertise focused on the interconnection-first…</h3></div> <div><p>ioakb.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*6JTksF-xbInchxLE)"></div> </div> </div> </a> </div><ul><li><a href="https://ioakb.com/register/">https://ioakb.com/register/</a></li></ul><p id="ce34">Currently, IOAKB covers Networking, Hybrid Multicloud, Security, Data, Applications, Internet of Things, Digital Payments, Analytics, CDN, Collaboration, and both Security and Distributed Security — in addition to many industry-specific designs.</p><p id="6759"><a href="https://ioakb.com/wiki/view/25/security-blueprint">IOA Security Blueprint</a></p><ul><li><a href="https://ioakb.com/wiki/view/47/design-pattern-boundary-control">Design Pattern: Boundary Control</a></li><li><a href="https://ioakb.com/wiki/view/48/design-pattern-inspection-zone">Design Pattern: Inspection Zone</a></li><li><a href="https://ioakb.com/wiki/view/49/design-pattern-policy-administration-enforcement">Design pattern: Policy Administration & Enforcement</a></li><li><a href="https://ioakb.com/wiki/view/50/design-pattern-locate-identity-and-key-management">Design Pattern: Locate Identity and Key Management</a></li><li><a href="https://ioakb.com/wiki/view/51/design-pattern-security-analytics-logging">Design Pattern: Security Analytics & Logging</a></li></ul><p id="4c0b"><a href="https://ioakb.com/wiki/view/499/distributed-security-blueprint">IOA Distributed Security Blueprint</a></p><ul><li><a href="https://ioakb.com/wiki/view/500/design-pattern-control-digital-communications">Design Pattern: Control Digital Communications</a></li><li><a href="https://ioakb.com/wiki/view/501/design-pattern-integrate-multicloud-and-data-controls">Design Pattern: Integrate Multicloud and Data Controls</a></li><li><a href="https://ioakb.com/wiki/view/502/design-pattern-security-as-a-digital-business-enabler">Design Pattern: Security as a Digital Business Enabler</a></li></ul><p id="4727">There is a wealth of information in each of the non-security designs as well.</p><figure id="b39f"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/1*9l9MEUtFpQHBxbODahTFfw.png"><figcaption></figcaption></figure><h2 id="a776">Azure Design Patterns</h2><p id="76e8">Microsoft is making headway now that more conglomerates are reluctant to fund what is often their direct competitor — Amazon.</p><figure id="fe53"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/0*biszLd_wQ4cKVKcp.png"><figcaption>Microsoft Azure <a href="https://docs.microsoft.com/en-us/azure/architecture/patterns/gatekeeper">Gatekeeper Pattern</a></figcaption></figure><p id="5bb7">Between their improved stance on Linux and <a href="https://azure.microsoft.com/en-us/solutions/confidential-compute/">the Azure confidential computing program</a>, I expect they will continue to attract customers from heavily regulated industries.</p><div id="b16c" class="link-block"> <a href="https://docs.microsoft.com/en-us/azure/architecture/patterns/"> <div> <div> <h2>Cloud Design Patterns — Azure Architecture Center</h2> <div><h3>These design patterns are useful for building reliable, scalable, secure applications in the cloud. Each pattern…</h3></div> <div><p>docs.microsoft.com</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*Zu9SU78nt0wd5tN1)"></div> </div> </div> </a> </div><figure id="12ef"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/1*K_mIBqecINBtKXAScdss7w.png"><

Options

figcaption></figcaption></figure><h2 id="3c45">GCP Design Patterns</h2><p id="a324">Google Cloud Platform is the talk of the town these days.</p><p id="ded2">Google does an excellent job maintaining <a href="https://cloud.google.com/docs/">detailed product documentation,</a> including security best practices, and <a href="https://cloud.google.com/docs/enterprise/best-practices-for-enterprise-organizations">enterprise adoption checklists.</a></p><p id="f525">A few public solution patterns:</p><ul><li><a href="https://cloud.google.com/solutions/architecture-hipaa-aligned-project">HIPAA HITRUST</a></li><li><a href="https://cloud.google.com/solutions/hybrid-and-multi-cloud-architecture-patterns">Hybrid and Multi-Cloud</a></li><li><a href="https://cloud.google.com/solutions/patterns-for-authenticating-corporate-users-in-a-hybrid-environment">Identity & Federation</a></li><li><a href="https://cloud.google.com/solutions/deploy-fault-tolerant-active-directory-environment">Microsoft Active Directory</a></li><li><a href="https://cloud.google.com/solutions/pci-dss-compliance-in-gcp">PCI DSS</a></li><li><a href="https://cloud.google.com/solutions/best-practices-vpc-design">Virtual Private Cloud</a></li></ul><p id="c2c6">Most of their design patterns remain locked up till you participate in their (very affordable) <a href="https://cloud.google.com/certification/">Cloud Certification training</a> on <a href="https://www.coursera.org/googlecloud">Coursera.</a></p><figure id="c1f2"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/1*Ply2Y6GSCFU6vuIjlL7Ljg.png"><figcaption></figcaption></figure><h2 id="4243">AWS Design Patterns</h2><p id="fa64">Amazon AWS has a clear first-mover advantage and is by far the furthest along in their reference architectures and security guidance.</p><ul><li><a href="https://aws.amazon.com/architecture/well-architected/">https://aws.amazon.com/architecture/</a></li><li><a href="https://aws.amazon.com/blogs/security/">https://aws.amazon.com/blogs/security/</a></li></ul><p id="13ed">To get up to speed quickly with AWS Security, I can recommend <a href="https://acloud.guru/">this training provider.</a> But never discredit the value of reading vendor documentation.</p><figure id="1655"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/1*rnx8TJ-GSKFnVreywtwxxw.png"><figcaption></figcaption></figure><h1 id="9778">DISA Implementation Guides</h1><p id="e74c">Since 1998, DISA has played a critical role in enhancing the security posture of DoD’s security systems by providing the Security Technical Implementation Guides (STIGs).</p><p id="cce0">The STIGs contain technical guidance to “lockdown” information systems/software that might otherwise be vulnerable to a malicious computer attack.</p><div id="ed43" class="link-block"> <a href="https://public.cyber.mil/stigs/"> <div> <div> <h2>Security Technical Implementation Guides (STIGs)</h2> <div><h3>The Security Technical Implementation Guides (STIGs) are the configuration standards for DOD IA and IA-enabled…</h3></div> <div><p>public.cyber.mil</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/)"></div> </div> </div> </a> </div><p id="5ee1">Using a Java-based <a href="https://public.cyber.mil/stigs/srg-stig-tools/">STIG Viewing Tool</a> you can turn the files from the <a href="https://public.cyber.mil/stigs/downloads/">STIGs Document Library</a> into actionable check-lists.</p><figure id="2db7"><img src="https://cdn-images-1.readmedium.com/v2/resize:fit:800/0*EcmdkCf6INTdO2iT.png"><figcaption></figcaption></figure><h1 id="a824">NIST Special Publications</h1><p id="832a">For 20 years, the Computer Security Resource Center (CSRC) has provided access to NIST’s <a href="https://csrc.nist.gov/Topics">cybersecurity-related projects</a> and <a href="https://csrc.nist.gov/Publications">special publications.</a></p><div id="d186" class="link-block"> <a href="https://csrc.nist.gov/"> <div> <div> <h2>Computer Security Resource Center</h2> <div><h3>For 20 years, the Computer Security Resource Center (CSRC) has provided access to NIST's cybersecurity- and information…</h3></div> <div><p>csrc.nist.gov</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*y-P8iQ68eHJEHsqw)"></div> </div> </div> </a> </div><p id="70e5">I recommend taking time to review the excellent publications on Digital Identity:</p><div id="be79" class="link-block"> <a href="https://pages.nist.gov/800-63-3/"> <div> <div> <h2>NIST SP 800–63 Digital Identity Guidelines</h2> <div><h3>June 22, 2017 The finalized four-volume SP 800–63 Digital Identity Guidelines document suite is now available, both in…</h3></div> <div><p>pages.nist.gov</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*zlZlcjQVMVkrNBpP)"></div> </div> </div> </a> </div><p id="933c">I am personally excited to dig into the draft on implementing a Zero Trust Architecture (ZTA) to improve an enterprise’ security posture!</p><div id="c015" class="link-block"> <a href="https://csrc.nist.gov/publications/detail/sp/800-207/draft"> <div> <div> <h2>NIST Special Publication (SP) 800–207 (Draft), Zero Trust Architecture</h2> <div><h3>Zero Trust is the term for an evolving set of network security paradigms that move network defenses from wide network…</h3></div> <div><p>csrc.nist.gov</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/)"></div> </div> </div> </a> </div><p id="e03a">Continue with part III ></p><h1 id="efc5">Do you have any advice? Corrections or additions?</h1><h1 id="98fb">Do not hesitate to reply. Feel free to share your experiences, advice, and questions in private or through the comments section.</h1></article></body>

Patterns of Secure Architecture & Security Engineering II

Organizations around the world are openly sharing their response to the cyber revolution: Patterns, Models & Frameworks are as helpful in Business as they can be for your Career.

  • Patterns provide a proven solution in a consistent format for each piece of the puzzle
  • Combining them allows you to work through complex problems and build your design or architecture
  • Solutions you can conjure up ultimately rely on technical mechanisms available to you

You will benefit from breaking things down into more straightforward to comprehend pieces when designing custom solutions for security problems.

Today we’ll cover modern defensive patterns, check out part I for the history of security patterns.

@securitystreak

About the Author

Andrew Douma is a vendor-neutral IT Security Professional. He performs professional audits, penetration tests, and risk assessments. He designs secure networks and engineers high-assurance systems in the Cloud.

You can connect with him on GoodReads, LinkedIn, Medium, and Twitter.

More stories by Andrew

Buying a professional penetration testing laptop| Evaluating QubesOS as a Penetration Testing Platform | Finding the right exploit code | Antivirus in 2017: Why? Which? How? | Penetration Testers’ Guide to Windows 10 Privacy & Security | Full Disk Encryption with VeraCrypt | Hacker to Security Pro! On the Shoulders of #InfoSec Giants | Securing an Android Phone or Tablet (LineageOS) | Password (IN)SANITY: Intelligent Password Policy & Best Practices | Security Architecture Patterns I & Patterns II

ATT&CK Framework by The MITRE Corporation

Anti Patterns

I am reasonably confident that the security practice of Threat Modeling partly inspired the creation of MITRE’s ATT&CK Framework.

MITRE ATT&CK enables Information Security professionals to conduct structured adversary emulation exercises as well as model their security defenses against modern-day techniques.

Its adversarial tactics, techniques, and knowledge database are the most consulted anti-pattern for security architects. It spans attack preparation, cross-platform endpoint, and mobile device compromise.

Patterns by Arcitura Education

A vendor-neutral and modern training provider has done a terrific job sharing their design patterns with the world, from the basics to the advanced.

Arcitura Pattern for Cloud Data Breach Protection

Currently, Arcitura covers Cloud Computing, Microservices and Containerization, Big Data, DevOps, and Blockchain — with plans to launch Machine Learning, Artificial Intelligence, and Internet of Things soon.

IOA Knowledge Base

I strongly recommend joining this impressive open community of IT Architects championing the Interconnection Oriented Architecture framework.

IOKB Roadmap

IOA aims to enable you with blueprints, playbooks, and design patterns for a modern interconnected world. Their knowledge-base provides a wealth of information.

Currently, IOAKB covers Networking, Hybrid Multicloud, Security, Data, Applications, Internet of Things, Digital Payments, Analytics, CDN, Collaboration, and both Security and Distributed Security — in addition to many industry-specific designs.

IOA Security Blueprint

IOA Distributed Security Blueprint

There is a wealth of information in each of the non-security designs as well.

Azure Design Patterns

Microsoft is making headway now that more conglomerates are reluctant to fund what is often their direct competitor — Amazon.

Microsoft Azure Gatekeeper Pattern

Between their improved stance on Linux and the Azure confidential computing program, I expect they will continue to attract customers from heavily regulated industries.

GCP Design Patterns

Google Cloud Platform is the talk of the town these days.

Google does an excellent job maintaining detailed product documentation, including security best practices, and enterprise adoption checklists.

A few public solution patterns:

Most of their design patterns remain locked up till you participate in their (very affordable) Cloud Certification training on Coursera.

AWS Design Patterns

Amazon AWS has a clear first-mover advantage and is by far the furthest along in their reference architectures and security guidance.

To get up to speed quickly with AWS Security, I can recommend this training provider. But never discredit the value of reading vendor documentation.

DISA Implementation Guides

Since 1998, DISA has played a critical role in enhancing the security posture of DoD’s security systems by providing the Security Technical Implementation Guides (STIGs).

The STIGs contain technical guidance to “lockdown” information systems/software that might otherwise be vulnerable to a malicious computer attack.

Using a Java-based STIG Viewing Tool you can turn the files from the STIGs Document Library into actionable check-lists.

NIST Special Publications

For 20 years, the Computer Security Resource Center (CSRC) has provided access to NIST’s cybersecurity-related projects and special publications.

I recommend taking time to review the excellent publications on Digital Identity:

I am personally excited to dig into the draft on implementing a Zero Trust Architecture (ZTA) to improve an enterprise’ security posture!

Continue with part III >

Do you have any advice? Corrections or additions?

Do not hesitate to reply. Feel free to share your experiences, advice, and questions in private or through the comments section.

Mitre Attack
Nist Framework
Cybersecurity
Security Architecture
Information Security
Recommended from ReadMedium