Information Assurance: Managing Organizational IT Security Risks

Provide a definition of an organizational IA architecture that will include its objectives, necessity, and relationships to the organization's IA baseline and the other layers of the organization's Defense in Depth strategy
Provide a description of the basic components of a model of an organizational IA architecture
Provide a description of the process for designing an organizational IA architecture and the issues associated with this design
The description of the IA architecture should begin with an understanding of the term "architecture." An architecture could be defined as a means of providing the foundation for building or designing an entity (e.g., buildings, bridges, public telephone system, automated information system) while promoting a common structure and a set of standards. There are components that comprise an architecture, interrelationships between these components, and principles and guidelines governing the architecture's design and evolution over time.
The objectives of the IA architecture are to ensure that at least the minimum level of interoperability and services is available to authorized users to securely perform their assigned tasks, to securely coordinate activities with other users, and to securely exchange information within the physical and virtual boundaries of an organization's IA baseline (Chapter 3). The IA architecture can achieve these objectives by integrating three levels of security to control the execution of transactions that result in the flow of information (i.e., in hardcopy and logical states), people, and IT material (i.e., IT hardware equipment such as workstations, servers, routers, cables,...