Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« The Security Market is No Place for Irony | Main | Controlling Messaging Services - Delivery and Support »

Controlling Messaging Services - Acquistions and Implementation

When it comes to governing messaging services, the acquitision and implementation phases come after the planning and organizing. The control objective at this point is ensuring an appropriate solution is selected, that is one that meets the functional requirements and at the same time fits into the existing technology infrastrucutre. This isn't always as easy as it sounds.

For starters, you will need a set of requirments for what is expected of a messaging system. How many users will be supported? What volume of traffic is expected? What are the availability requirments? How averse to risk is management? How will it work with existing access control/identity management systems? What other security requiements exist? Are crypto services required? Will it integarate with a PKI? How will digital signatures be managed? And on and on and on ...

The next step is map the requirements into a design specification and implement the solution in a test environment. This may seem the obvious next step from the perspective of a seasoned developer or system admin, but concepts like code promotion through distinct development, test and production envioronments and formal release management procedures are suprisingly new to some organizations.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/82

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net