On 2021-02-09
Cybersecurity

What is Architecture & System Design?

museum exhibition
Summary

We often hear news about critical and negative events in the life of a business.

In our society, tragic events and tales of failure are more appealing than successes and the news reflects that. How many people know the latest details about COVID-19 today and how many know about the ITER project and its tremendous stakes?

The world of cybersecurity is no different: we often hear about intrusions and data leaks but hear no news about organizations that excel at self-defense. In our opinion, self-defence is all about security by design: Compliance, Security risk assessment, Security in Architecture and System Design. The purpose of A&SD is simple: Technically design products and services that are resilient to malicious acts.

Who is involved?

Two professions are deeply involved in the development of an organisation’s self-defence:

  • Security Architects: are in charge of creating a comprehensive vision of security within a company, defining a defense-in-depth strategy and ensuring technical consistency in the security of products, services and the company itself.
  • System Designers: are in charge of designing and implementing security functions of the products and services offered by a company and of detailing security implementation, configuration and test plans.

According to us, these jobs are currently at the forefront of cybersecurity and of business projects and we believe that organizations that rely on a “Security by design” approach based on A&SD principles and Risk analysis methods are those who excel the most.

Which risk analysis methods can be used?

The arrival of new, more formal risk analysis methods such as EBIOS RM, the understanding of cyber-attacks mechanics as formalised in MITRE ATT&CK and the variety of research projects on modeling of security in systems engineering, show an improved understanding of the Architecture and System Design domain as well as its increasing maturity.

We can see the first effects of this increasing maturity as CIOs put these professions at the center of their priorities and strategic business decisions. It is after all, the deployment of adequate technical solutions to protect against malicious acts that keep their companies out of the news.

 

Want to learn the EBIOS RM method?

Check out our training catalogue!

EBIOS RISK MANAGER TRAINING CS2

Objectives:

• Acquire the knowledge and develop the skills necessary to master the
concepts and elements of risk management using the EBIOS Risk Manager
v1.5 method.

•  Acquire the vocabulary and knowledge required to become familiar
with the methodology and develop the necessary skills, with practical
exercises, simulations and tests.

Completion of the Airbus Protect Training Course CS2, registered
under n°EBIOS-002, for EBIOS Risk Manager skills certification
combined with the requested prerequisites, qualifies participants to
take the AFNOR Certification exam, endorsed by the EBIOS Club.

training catalogue cover
  • Share

More on Cybersecurity

Dead disk analysis with Velociraptor Cybersecurity

Performing Linux Dead Disk Forensic Analysis with Velociraptor

What is Velociraptor? Velociraptor is an open source digital forensic and incident response tool that supports several deployment models depending on the investigation scenario. While the most common approach is the client-server model, where agents are deployed on endpoints and communicate with a central server, Velociraptor can also operate through offline collectors or virtual clients [...]

Read more
it-sa 2026: Pragmatic OT Asset Management as the foundation for NIS 2 and ISO 27001 Cybersecurity

it-sa 2026: Pragmatic OT Asset Management as the foundation for NIS 2 and ISO 27001

The digitalisation of production continues to advance, but with increased connectivity comes a growing attack surface. At it-sa in Nuremberg on 28 October 2026, we will be demonstrating why a complete asset inventory is no longer just a 'nice-to-have' and how you can achieve visibility without putting your production at risk. Anyone who lacks detailed [...]

Read more
What the Shell? Accelerating Incident Response: Letting the Malware do the work for you Cybersecurity

What the Shell? Accelerating Incident Response: Letting the Malware do the work for you

Intrusion Context Last month, Airbus Protect’s CSIRT responded to an intrusion targeting a vulnerable, internet-facing Windows Server. What began as typical automated scanning quickly transitioned into a targeted attack utilising tools such as SQLMap and vulnerability scanners. By leveraging a flurry of SQL injection attacks, the threat actor successfully enabled xp_cmdshell which facilitated remote code [...]

Read more