1
1

00:00:00,750  -->  00:00:03,330
<v Instructor>Enterprise security architecture.</v>
2

2

00:00:03,330  -->  00:00:05,910
In this lesson, we are going to talk about the importance
3

3

00:00:05,910  -->  00:00:08,340
of enterprise security architecture.
4

4

00:00:08,340  -->  00:00:10,860
Now, the concept of enterprise security architecture
5

5

00:00:10,860  -->  00:00:14,520
goes back to IT governance and IT service management.
6

6

00:00:14,520  -->  00:00:16,470
When we talk about IT service management,
7

7

00:00:16,470  -->  00:00:18,780
or information technology service management,
8

8

00:00:18,780  -->  00:00:21,390
we're really focused on the idea of stakeholders
9

9

00:00:21,390  -->  00:00:23,370
picking out the right technologies,
10

10

00:00:23,370  -->  00:00:24,630
deploying those technologies,
11

11

00:00:24,630  -->  00:00:26,280
and operating those technologies
12

12

00:00:26,280  -->  00:00:29,280
for the best benefit of the organization.
13

13

00:00:29,280  -->  00:00:31,710
Now, to successfully do IT service management,
14

14

00:00:31,710  -->  00:00:34,170
we use framework-based governance.
15

15

00:00:34,170  -->  00:00:36,540
Framework-based governance is going to seek to mitigate
16

16

00:00:36,540  -->  00:00:39,960
the risks that are associated with IT service delivery.
17

17

00:00:39,960  -->  00:00:41,520
Now, when we talk about all of this
18

18

00:00:41,520  -->  00:00:44,460
we're really talking about enterprise security architecture
19

19

00:00:44,460  -->  00:00:46,920
as I mentioned in the beginning of this lesson.
20

20

00:00:46,920  -->  00:00:49,290
Enterprise security architecture, or ESA,
21

21

00:00:49,290  -->  00:00:52,440
is a framework for defining the baseline, the goals,
22

22

00:00:52,440  -->  00:00:54,990
and the methods that are used to secure the business
23

23

00:00:54,990  -->  00:00:56,790
from all those different risks
24

24

00:00:56,790  -->  00:00:59,130
that could go against your organization.
25

25

00:00:59,130  -->  00:01:00,300
Now, these different frameworks
26

26

00:01:00,300  -->  00:01:02,430
that we can put in place under ESA
27

27

00:01:02,430  -->  00:01:04,770
can provide us with a lot of different things.
28

28

00:01:04,770  -->  00:01:08,070
For example, they can provide us with a list of policies
29

29

00:01:08,070  -->  00:01:10,380
and provide us with checklists of procedures.
30

30

00:01:10,380  -->  00:01:11,940
They can provide us with activities,
31

31

00:01:11,940  -->  00:01:13,860
and they can even tell us what technologies
32

32

00:01:13,860  -->  00:01:16,110
we should be using as part of the framework
33

33

00:01:16,110  -->  00:01:18,360
and the overall architecture.
34

34

00:01:18,360  -->  00:01:19,740
Now, when we deal with frameworks,
35

35

00:01:19,740  -->  00:01:21,720
these frameworks are there to help provide
36

36

00:01:21,720  -->  00:01:25,860
an externally verifiable statement of regulatory compliance.
37

37

00:01:25,860  -->  00:01:28,770
This is really important, especially in some industries
38

38

00:01:28,770  -->  00:01:31,350
where regulatory compliance is essential.
39

39

00:01:31,350  -->  00:01:33,420
For example, if you take credit cards,
40

40

00:01:33,420  -->  00:01:36,900
you need to make sure your in compliance with PCI DSS.
41

41

00:01:36,900  -->  00:01:38,400
If you're a healthcare provider,
42

42

00:01:38,400  -->  00:01:40,530
you need to make sure you're following HIPAA.
43

43

00:01:40,530  -->  00:01:43,500
If you're a financial company or a publicly traded company,
44

44

00:01:43,500  -->  00:01:46,080
you might be affected by Sarbanes-Oxley.
45

45

00:01:46,080  -->  00:01:47,580
These are things you have to think about
46

46

00:01:47,580  -->  00:01:49,200
as you start thinking about the frameworks,
47

47

00:01:49,200  -->  00:01:51,630
because these frameworks are going to help us achieve
48

48

00:01:51,630  -->  00:01:53,730
that regulatory compliance to make sure
49

49

00:01:53,730  -->  00:01:55,200
we are meeting all the requirements
50

50

00:01:55,200  -->  00:01:57,330
that lawmakers have put on us.
51

51

00:01:57,330  -->  00:01:58,860
Now, there are lots of different frameworks
52

52

00:01:58,860  -->  00:02:00,660
that are used in the industry.
53

53

00:02:00,660  -->  00:02:02,610
Now, you can choose any of them that you want
54

54

00:02:02,610  -->  00:02:04,050
for your organization.
55

55

00:02:04,050  -->  00:02:06,030
This really does depend on your organization
56

56

00:02:06,030  -->  00:02:08,130
and its IT governance structure.
57

57

00:02:08,130  -->  00:02:11,297
This can include things like ITIL, COBIT,
58

58

00:02:11,297  -->  00:02:13,890
TOGAF, and ISO 20000.
59

59

00:02:13,890  -->  00:02:15,480
All of these are different frameworks
60

60

00:02:15,480  -->  00:02:19,140
that fit into this idea of enterprise service architecture.
61

61

00:02:19,140  -->  00:02:21,510
Personally, I'm a big fan of the ITIL framework
62

62

00:02:21,510  -->  00:02:24,180
and I teach a lot of courses on the ITIL framework,
63

63

00:02:24,180  -->  00:02:26,940
but all of these are valid choices to consider.
64

64

00:02:26,940  -->  00:02:29,220
Now for the exam, you don't have to memorize
65

65

00:02:29,220  -->  00:02:32,130
all the details of each of these different frameworks,
66

66

00:02:32,130  -->  00:02:34,710
but learning a well-known framework like ITIL
67

67

00:02:34,710  -->  00:02:36,960
can provide you with more career opportunities
68

68

00:02:36,960  -->  00:02:39,240
as you go into management and executive levels
69

69

00:02:39,240  -->  00:02:40,533
within your organization.
