Strategic Approaches to Digital Platform Security Assurance
Book information
Description
Nowadays it is impossible to imagine a business without technology as most industries are becoming \x22\x22smarter\x22\x22 and more tech\-driven, ranging from small individual tech initiatives to complete business models with intertwined supply chains and \x22\x22platform\x22\x22\-based business models. New ways of working, such as agile and DevOps, have been introduced, leading to new risks. These risks come in the form of new challenges for teams working together in a distributed manner, privacy concerns, human autonomy, and cybersecurity concerns. Technology is now integrated into the business discipline and is here to stay leading to the need for a thorough understanding of how to address these risks and all the potential problems that could arise. With the advent of organized crime, such as hacks and denial\-of\-service attacks, all kinds of malicious actors are infiltrating the digital society in new and unique ways. Systems with poor design, implementation, and configurations are easily taken advantage of. When it comes to integrating business and technology, there needs to be approaches for assuring security against risks that can threaten both businesses and their digital platforms. Strategic Approaches to Digital Platform Security Assurance offers comprehensive design science research approaches to extensively examine risks in digital platforms and offer pragmatic solutions to these concerns and challenges. This book addresses significant problems when transforming an organization embracing API\-based platform models, the use of DevOps teams, and issues in technological architectures. Each section will examine the status quo for business technologies, the current challenges, and core success factors and approaches that have been used. This book is ideal for security analysts, software engineers, computer engineers, executives, managers, IT consultants, business professionals, researchers, academicians, and students who want to gain insight and deeper knowledge of security in digital platforms and gain insight into the most important success factors and approaches utilized by businesses. Strategic Approaches to Digital Platform Security Assurance Table of Contents Preface REFERENCES Acknowledgment Introduction Digital Platforms and Frameworks From IT Security to Business Information Security to Digital Assurance REFERENCES ENDNOTE 1 Problems in the Area of Business Platform Models: How Are Governments Adapting the Platform Model to Improve Citizen Services 1 What Is “Government as A Platform”? 1.1 Introduction 1.2 Broad Definition of Business Platform Model 1.3 Evolution of Government Service Models Towards the Platform Model 1.4 What Should a Government Business Platform Enable? 1.5 Problem Statement 1.6 Research Questions 1.7 How Was Research Conducted? 1.7.1 Approach to Literature Research 1.7.1.1 Approach to Refining the Problem Statement 1.7.1.2 Approach to Answering the Research Questions 1.7.2 Approach to Getting Expert Opinions Through Interviews 1.7.3 Approach to Case Studies 2 Problems in government platform models 2.1 Introduction 2.2 Levels towards a citizen services oriented “Government as A Platform” 2.2.1 Level 1: Providing a Technology Platform 2.2.1.1 Definition 2.2.1.2 Platform Roles 2.2.1.3 Examples 2.2.1.4 Governance Basics 2.2.1.5 Relevance to this Research Project 2.2.2 Level 2: Opening Data 2.2.2.1 Definition 2.2.2.2 Platform Roles 2.2.2.3 Examples 2.2.2.4 Governance Basics 2.2.2.5 Relevance to this Research Project 2.2.3 Level 3: Opening Functionality 2.2.3.1 Definition 2.2.3.2 Platform Roles 2.2.3.3 Specific Examples: Smart City Platforms 2.2.3.4 Governance Basics 2.2.3.5 Relevance to this Research Project 2.2.4 Level 4: Opening Services 2.2.4.1 Definition 2.2.4.2 Platform Roles 2.2.4.3 Generic Examples 2.2.4.4 COVID-19 Examples in Flanders 2.2.4.5 Governance Basics 2.2.4.6 Relevance to this Research Project 2.3 Summary 3. STAKEHOLDER ANALYSIS: WHO IS WAITING FOR A GOVERNMENT PLATFORM MODEL IN FLANDERS? 3.1. Introduction 3.2 Are Politicians Waiting for the Platform Model? 3.3 ARE CITIZENS WAITING FOR THE PLATFORM MODEL? (CONSUMERS) 3.4 Are Companies Waiting to Join the Ecosystem? (As Producers) 3.5 Some Critical Notes on Platform Models 3.6 Summary of Stakeholder Analysis 3.7 What About Citizen Collaboration Platforms? REFERENCES 2 Research Findings in the Domain of Business Platform Models: Defining the Practices to Design a Perfect Government Business Platform Model 1 DEFINITION OF PRACTICES FOR GOVERNMENT BUSINESS PLATFORM MODELS 1.1 Introduction 1.2 Requirements for defining practices 1.3 Approach used 1.4 CSFs for IT projects in general 1.5 CSFs for e-government projects 1.6 From CSFs to the right practices 1.6.1 Top Priority Practice: Getting the value right 1.6.1.1 Value from the Citizen Perspective 1.6.1.2 Value from the Government Perspective 1.6.1.3 Value from the Ecosystem Perspective 1.6.2 Top Priority Practice: Getting (Political) Leadership 1.6.3 Top Priority Practice: Establishing the Ecosystem 1.6.4 Platform Related Practices 1.6.4.1 Platform Design Principles 1.6.4.2 Platform (Technology) Architecture 1.6.4.3 Summary 1.6.5 Governance Related Practices 1.6.6 Data Related Practices 1.6.7 Challenges to overcome 1.7 Summary - list of practices 2 PLATFORM GOVERNANCE MECHANISMS 2.1 Introduction 2.2 Approach Used 2.3 Defining the Scope of the Organization to Design For 2.4 Governance Processes 2.4.1 Approach Used 2.4.2 Applying the COBIT2019 Design Toolkit 2.4.2.1 Design Factor 1: Enterprise Strategy 2.4.2.2 Design Factor 2: Enterprise Goals 2.4.2.3 Design Factor 3: Risk Profile 2.4.2.4 Design Factor 4: I&T Related Issues 2.4.2.5 Design Factor 5: Threat Landscape 2.4.2.6 Design Factor 6: Compliance 2.4.2.7 Design Factor 7: Role of IT 2.4.2.8 Design Factor 8: Sourcing Model for IT 2.4.2.9 Design Factor 9: Implementation Methods 2.4.2.10 Design Factor 10: Technology Adoption Strategy 2.4.2.11 Results from the Design Toolkit 2.4.3 Combining research and design toolkit results 2.4.4 Final list of processes for the defined practices 2.5 Organizational Structures 2.6 Relational Mechanisms 2.7 Summary – defined governance mechanisms 3 VALIDATION METHODS FOR PLATFORM ORGANIZATIONS 3.1 Introduction 3.2 Evaluation Methods 3.3 Method 1: Mapping the practices to an organizational Capability & Impact quadrant 3.3.1 Step 1: Definition of Indicators 3.3.2 Step 2: Definition of the Quadrant Map 3.3.3 Step 3: Mapping of the practices to the indicators 3.3.4 Step 4: Questions per Indicator 3.3.5 Step 5: Calculating the score of the indicators 3.3.6 Step 6: Mapping the scores on the quadrant model 3.4 Method 2: Governance Compliance Checklist 3.4.1 Process Checklist 3.4.2 Organizational Structures Checklist 3.4.3 Relational Mechanisms Checklist 3.5 Method 3: Introducing the Government Platform Maturity Model 3.6 Method 4: The Platform Balanced Score Card 4 EVALUATING GOVERNMENT PLATFORM ORGANIZATIONS 4.1 Introduction 4.2 Selecting the Right Case Organisations 4.3 Questions Addressed in Interview 4.4 Case Organization 1: VDAB - Matching Platform 4.4.1 Introduction to the Case Organization 4.4.2 Meeting Minutes of the Interviews 4.4.3 Evaluation of case versus defined practices 4.4.4 Evaluation of Governance Mechanisms 4.4.5 Mapping Onto Organizational Capability & Impact Quadrant 4.4.6 Mapping on Maturity Level 4.4.7 Summary of the VDAB Case 4.5 CASE ORGANIZATION 2: LB365 4.5.1 Introduction to the Case Organization 4.5.2 Meeting Minutes of the Interviews 4.5.3 Evaluation of Case Versus Defined Practices 4.5.4 Evaluation of Governance Mechanisms 4.5.4.1 Process Checklist 4.5.4.2 Organizational Structures Checklist 4.5.4.3 Relational Mechanisms Checklist 4.5.5 Mapping Onto Organizational Capability & Impact Quadrant 4.5.6 Mapping on Maturity Level 4.5.7 Summary of the LB365 Case 4.6 Case Organization 3: ACPAAS 4.6.1 Introduction to the Case Organization 4.6.2 Meeting Minutes of the Interviews 4.6.3 Evaluation of Case versus Defined Practices 4.6.4 Evaluation of Governance Mechanisms 4.6.5 Mapping Onto Organizational Capability and Impact Quadrant 4.6.6 Mapping on Maturity Level 4.6.7 Summary of the ACPAAS Case 4.7 OVERALL CASES COMPARED 4.8 SUMMARY OF THE CASE EVALUATION REFERENCES 3 Findings and Core Practices in the Domain of Business Platform Models: Overall Evaluation of the Practices 1 INTRODUCTION 2 USEFULNESS OF THE DEFINED ARTIFACTS 3 CONCLUSION 3.1 Contribution of this Research 1.3.2 Conclusions from literature research 3.3 Conclusions from Working with the Case Organizations 3.4 Conclusions on the Research Questions 3.4.1 Conclusion for research question 1 - practices 3.4.2 Conclusion on research question 2 – governance 3.5 CONCLUSION ON THE HYPOTHESIS 4 USING THE PRACTICES TO START A PLATFORM MODEL IN GOVERNMENT ORGANIZATIONS 5 Suggestions for extra research 5.1 Platform models as part of a government digital transformation agenda 5.2 Platform (Corporate) Governance 5.3 Impact of new or Emerging Technologies Like IoT 5.4 Security 6 FINAL NOTES REFERENCES 4 Problems in the Area of Agile Methodologies INTRODUCTION “Agile or Distributed Agile” is Always a Success: An Overhype or Reality! PROBLEM AREA RESEARCH QUESTION CONCEPTUAL MODEL Independent Variable: Distributed Agile Software Development AGILE SOFTWARE DEVELOPMENT Distributed Software Development Distributed Agile Software Development Dependent Variable: Team Performance Maturity Models Target Audience REFERENCES ENDNOTES 5 Research Findings in the Domain of Agile Methodologies INTRODUCTION Research Approach Literature Strategy Theoretical Model RESEARCH DESIGN Case Study Research EXPLORATORY RESEARCH Data Collection Interviews Documentation and Observation Scoring Data Analysis Descriptive Statistics Inferential Statistics RESEARCH FINDINGS Distributed Agile Software Development Challenges with Distributed Agile Software Development TEAM PERFORMANCE Team Performance Factors Team Performance Model Assessment of the Frameworks Team Performance vs Team Maturity MATURITY MODELS SQUAD HEALTH CHECK AGILE MATURITY CURVE Agile Fluency Model REFERENCES ENDNOTES 6 Findings and Core Practices in the Domain of Agile Methodologies INTRODUCTION CASE STUDY RESEARCH METHOD DATA PREPARATION Data Evaluation Parametric Statistical Hypothesis Test CONCLUSION Practices FURTHER RESEARCH REFERENCES ENDNOTES 7 Problems of CI/CD and DevOps on Security Compliance INTRODUCTION CONCEPTS OF CI/CD AND (SEC)DEVOPS KEY TERMS Problem Definition Scope Research Question RESEARCH APPROACH Research Methodology Theoretical Foundation REFERENCES ENDNOTE APPENDIX: Overview of Major Cybersecurity & Privacy-Related Frameworks 8 Research Findings in the Domain of CI/CD and DevOps on Security Compliance LITERATURE REVIEW DEFINING THE ARTIFACT ISO/IEC 27001 and NIST SP 800-53 Relevant Control Objectives and Controls (Sec)DevOps Capability Artifact EVALUATING ARTIFACT Introduction Subject Matter Expert Interviews Result comparison with DoD Enterprise DevSecOps Reference Design Report REFERENCES 9 Findings and Core Practices in the Domain of CI/CD and DevOps on Security Compliance FINDINGS LIMITATIONS OVERVIEW PRACTICES FOR CI/CD AND DEVOPS SECURITY COMPLIANCE FUTURE RESEARCH 10 Challenges and Opportunities for Security Assurance in DevOps INTRODUCTION Background PROBLEM STATEMENT OBJECTIVE OF THIS RESEARCH REFERENCES 11 Research Findings in the Domain of Security Assurance in DevOps RESEARCH APPROACH AND DELIVERABLES Selection of Research Methods Design Problems and Knowledge Questions Research Approach Research Deliverables ACADEMIC LITERATURE REVIEW Searching the Knowledge Base Analysis of the Dataset Interim Conclusion VALIDATION AND PRIORITISATION OF THE RESEARCH FINDINGS Preparation Prioritisation by Expert Panel Interim Conclusion DETAILED OVERVIEW OF THE SECURITY ACTIVITIES IDENTIFIED DURING THE RESEARCH PROJECT Collaboration Provide Security Training Establish Security Satellites Practice Incident Response Establish a Security Mindset Across the Organisation USE OF NON-AUTOMATED ACTIVITIES Performing Security Requirements Analysis Performing Threat Modelling Performing Risk Analysis Establishing Security SLA’s for Cloud Providers Performing Continuous Assurance Performing Manual Security Testing Performing Manual Penetration Testing Performing Manual Security Review Secure the CI/CD Pipeline USE OF AUTOMATED ACTIVITIES Performing Automated Security Testing Performing Automated Run-Time Testing Performing Automated Static Testing Integrate Security Tests in Unit Testing Performing Continuous Monitoring Performing Continuous Monitoring of Security SLAs Performing Continuous Monitoring of Security Metrics Throughout the SDLC Using CI/CD Tooling Performing Continuous Monitoring of System Metrics Using Automated Tools Performing Continuous Monitoring of Security Controls Performing Continuous Monitoring of Application Behavior Provide Self-Service Monitoring Capabilities to dev and ops Implement Centralized Dashboards Implement Automated Remediation Performing Security Configuration Automation Manage Digital Supply Chain Establish Artefact and Source Code Registries Which are Automatically Scanned for Vulnerabilities Implement Automated Container Security Scanning Performing Automated Software Composition Analysis REFERENCES APPENDIX 12 Findings and Core Practices in the Domain of Security Assurance in DevOps SUMMARY OF THE RESEARCH RESULTS CONCLUSION Collaboration Use of Non-Automated Activities Use of Automated Activities General Findings CORE PRACTICES IN DEVSECOPS Maintain a Business Perspective Business Context Implement Mechanisms for Security Trade-Offs Establish a Common Shared Security Perspective Empower Teams Ensure Security Scalability Establish a Security Culture by Promoting Communication and Collaboration Leverage and Secure the Pipelines Establish Security Observability Practice Incident Response Perform Continuous Assurance RESEARCH LIMITATIONS FUTURE RESEARCH REFERENCES ENDNOTES About the Contributors Index
Similar books
Transformer ageing : monitoring and estimation techniques
2018 · PDF
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF
Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.
2022 · PDF
The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians
1809 · PDF