THE SECURITY BRUTALIST

Brutalist Security Architecture: Part 4 - Architecture Automation

(Part 4 of 4)

A high-level security brutalist approach to automating the initial security architecture review process. The goal is rapid, common-sense risk identification to filter out low-risk projects efficiently and flag high-risk ones for immediate architect attention. Again, this approach represents one possible implementation; there are many others. Finding what works for your specific organization is crucial.

Brutalist Automation Philosophy

Process Overview

  1. Project onboarding / initial information ingestion: A standardized, automated mechanism for project teams to provide essential information.
  2. Automated initial risk review: An automated script or tool analyzes the ingested data based on predefined, common-sense risk indicators.
  3. Initial report output: A concise report summarizing the ingested information and the automated risk categorization.

(Possible) Automation Steps

  1. Project Onboarding / Initial Information Ingestion:
  2. Automated Initial Risk Review:
  3. Initial Report Output for Architects:

Brutalist Benefits of this Automation

Important Considerations