Cyber Security Architecture serves as a foundational guide for designing, implementing, and monitoring secure, resilient digital infrastructures, focusing on aligning security with business goals. A cybersecurity architect is a bit like a building architect. When you think about how a building is designed, it starts with input from the stakeholders - the people who will use it and care about it. Then the architect steps in and designs something that works, not just aesthetically, but practically. And above all, it has to be safe. The building has to stand up to the weather, be structurally sound, and meet safety standards. Designing a secure IT system is remarkably similar. A cybersecurity architect listens to stakeholders, but in this case, the stakeholders are both the users and the business leaders. Then they design a system that won't fall apart when it's stressed, when someone tries to break into it, or when something unexpected happens. Just like in a building, where you want to prevent failures like a roof collapsing, in a digital system, you want to prevent security failures like data breaches or unauthorized access. That's where security principles come in, things like confidentiality, integrity, and availability. A cybersecurity architect doesn't just need to know one area. They need to be familiar with many different domains: identity and access management, which is all about making sure the right people get in and the wrong people don't; endpoint security, which protects devices like phones and laptops; network security, which is about securing the data that flows between systems; and application security, which ensures that the software itself is secure. They also work with data security making sure that sensitive information, like credit card numbers or medical records, stays protected. And they use tools like Splunk (for SIEM, or Security Information and Event Management) to monitor for potential security incidents in real time. A good cybersecurity architect doesn't just understand one aspect of security; they have to know a lot about different domains. There's identity and access management who gets in, and who stays out. Then there's endpoint security, which is about protecting devices like laptops or phones. You've got network security, making sure the data flows through the system safely. Then there's application security, which protects the actual software being used. There's also data security, making sure the information stays safe whether it's stored or in transit. And finally, there's SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response), which are about detecting and responding to threats in real time. Companion to Cyber Security Architecture discusses core practices and technologies that create a foundational defense against common cyber threats. Key elements include implementing fir
Dr. Alexander Thomson was a faculty member in the Electrical Engineering and Computer Systems Engineering Department's at the University of Arkansas. During this time, Dr. Thomson performed sponsored research on parallel and distributed embedded systems architectures, such as a SIMD array processor. From 2000 to 2008 Dr. Thomson was a faculty member at the University of Kansas and associated Information Technology and Telecommunications Center. While at Kansas, Dr. Thomson served as Principal and Co-Principal Investigator on several NSF sponsored research projects on modeling, run time systems, and architectures for embedded systems. Dr. Thomson research interests are primarily driven from a next generation cyber security perspective, looking at the definition, design, and interactions of programming languages, run time system software, and hardware components within a complete system architecture framework. Most recently he has focused on developing new computational models to support and enable the familiar thread programming model for hybrid systems. In 2008, Dr. Thomson joined the University of Arkansas as the Mullins Endowed Chair of Computer Engineering.
Preface
1. CYBER SECURITY FUNDAMENTALS
2. ATTACKER TECHNIQUES AND MOTIVATIONS
3. EXPLOITATION
4. MALICIOUS CODE
5. DEFENSE AND ANALYSIS TECHNIQUES
6. EXPLOITATION UNVEILED: NAVIGATING THE CYBER SECURITY OFFENSIVE
Bibliography
Index