Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Cybersecurity Architect's Handbook

You're reading from  Cybersecurity Architect's Handbook

Product type Book
Published in Mar 2024
Publisher Packt
ISBN-13 9781803235844
Pages 494 pages
Edition 1st Edition
Languages
Author (1):
Lester Nichols Lester Nichols
Profile icon Lester Nichols

Table of Contents (20) Chapters

Preface 1. Part 1:Foundations
2. Chapter 1: Introduction to Cybersecurity 3. Chapter 2: Cybersecurity Foundation 4. Chapter 3: What Is a Cybersecurity Architect and What Are Their Responsibilities? 5. Part 2: Pathways
6. Chapter 4: Cybersecurity Architecture Principles, Design, and Analysis 7. Chapter 5: Threat, Risk, and Governance Considerations as an Architect 8. Chapter 6: Documentation as a Cybersecurity Architect – Valuable Resources and Guidance for a Cybersecurity Architect Role 9. Chapter 7: Entry-Level- to-Architect Roadmap 10. Chapter 8: The Certification Dilemma 11. Part 3: Advancements
12. Chapter 9: Decluttering the Toolset – Part 1 13. Chapter 10: Decluttering the Toolset – Part 2 14. Chapter 11: Best Practices 15. Chapter 12: Being Adaptable as a Cybersecurity Architect 16. Chapter 13: Architecture Considerations – Design, Development, and Other Security Strategies – Part 1 17. Chapter 14: Architecture Considerations – Design, Development, and Other Security Strategies – Part 2 18. Index 19. Other Books You May Enjoy

Decluttering the Toolset – Part 2

“Water shapes its course according to the nature of the ground over which it flows; the soldier works out his victory in relation to the foe whom he is facing.”

– Sun Tzu

“By method and discipline are to be understood the marshaling of the army in its proper subdivisions, the graduations of rank among the officers, the maintenance of roads by which supplies may reach the army, and the control of military expenditure.”

– Sun Tzu

“Hence the skillful fighter puts himself into a position which makes defeat impossible, and does not miss the moment for defeating the enemy.”

– Sun Tzu

“Thus it is that in war the victorious strategist only seeks battle after the victory has been won, whereas he who is destined to defeat first fights and afterwards looks for victory.”

– Sun Tzu

In the previous chapter, we discussed how to make sense of the certification...

What tool to use?

Selecting the optimal set of cybersecurity tools from the multitude of options available can seem daunting. Just look at the previous section to see that only the surface was scratched regarding the potential tools. However, by methodically aligning tools to organizational needs and infrastructure, architects can assemble the ideal toolkit. Cybersecurity tool selection is a critical strategic decision that impacts the overall security posture of an organization. To navigate the complex landscape of available options, a structured approach aligning tools with the organization’s unique requirements and risk profile is essential. This section delves into the methodology for selecting the optimal set of tools. Here are some key considerations when deciding which tools to implement.

Clearly define requirements

Start by identifying your specific use cases and requirements. Determine where you have gaps in visibility, protection, or response capabilities. Define...

Business considerations

In the realm of cybersecurity, aligning technical decisions with business considerations is paramount. The optimal toolset must not only safeguard the organization’s assets but also support its strategic objectives and operational efficiencies. This section examines the business realities that cybersecurity architects must balance during the tool selection process.

Total cost of ownership (TCO)

Look beyond upfront software/hardware costs to account for ongoing maintenance, training, integration expenses, and staffing requirements. Cloud services can reduce capital outlay but have subscription fees. Evaluating the TCO is vital in understanding the long-term financial impact of cybersecurity tools:

  • Factor in not only initial acquisition costs but also recurring costs such as maintenance fees, subscription models for cloud-based services, and potential scaling expenses
  • Assess the need for ongoing training and the potential for these costs...

Summary

In closing, this chapter emphasized the importance of thoughtfully curating a cybersecurity toolkit tailored to an organization’s unique risk profile, infrastructure, and strategic drivers. Rather than getting overwhelmed by the endless tool options and feature hype cycles, architects must take a methodical approach rooted in clearly defining security requirements and gaps. Tight alignment with security frameworks, layered defenses, future-proofing, and business considerations are all critical factors during selection as well.

The key takeaways include the following:

  • Clearly identify your specific use cases, vulnerabilities, requirements, and infrastructure first before assessing tools
  • Map tools to core security framework functions such as NIST CSF to ensure comprehensive coverage
  • Implement complementary preventive, detective, and corrective controls for defense in depth
  • Evaluate total cost, business alignment, usability, and other practical factors...
lock icon The rest of the chapter is locked
You have been reading a chapter from
Cybersecurity Architect's Handbook
Published in: Mar 2024 Publisher: Packt ISBN-13: 9781803235844
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime}