
Have you ever been developing or acquiring a system and said to yourself, I can't be the first architect to design this type of system. How can I tap into the architecture knowledge that already exists in this domain? If so, you might be looking for a reference architecture. A reference architecture describes a family of similar systems and standardizes nomenclature, defines key solution elements and relationships among them, collects relevant solution patterns, and provides...

The sixth practice described in the newly released edition of the Common Sense Guide to Mitigating Insider Threats is Practice 6: Consider threats from insiders and business partners in enterprise-wide risk assessments. In this post, I discuss the importance of developing a comprehensive, risk-based security strategy to prevent, detect, and respond to insider threats, including those caused by business partners that are given authorized access....

Longtime SATURN participant Eltjo Poort has posted a summary of SATURN 2017 on his blog. Eltjo was the winner of the inaugural Linda Northrop Software Architecture Award in 2016. "This was my fifth SATURN conference," writes Poort, "and just like the previous years I returned home full of new ideas and inspiration, and with many useful new contacts. I am already looking forward to the 2018 edition in Plano, TX." Read the whole thing....
CERT/CC
Timely insights about vulnerabilities, network situational awareness, and research in the security field offered by CERT Division researchers.