Context of Architecture Roles

Today I was triggered by some posts where there was some opinions on where the line between Architecture and Design is.

One discussion was around an interesting blog post from Mark Wilson: “Where’s the line between [IT] Architecture and Design“. From my point of view Chris Potts answered it in a great way:

No line. An architect designs. | RT @martinhowitt: The line between architecture & design? By @markwilsonit markwilson.co.uk/blog/2013/01/w… #entarch
— Chris Potts (@chrisdpotts) Januar 23, 2013

There was a second Twitter post which caught my attention:

Architecture stops when detailed design begins. #TOGAF #EntArch
— Glen McCallum (@mccallumg) Januar 23, 2013

For both ideas I have the tendency to answer them very similar to Chris Potts: The Architect Designs, as I have also put it in my blog post GLUE Roles and Responsibilities. The [Role] Architect does deliver the [GLUE Discipline] Design. Nevertheless there is an enormous amount of specialized Architecture Titles. And it is in the nature of the discussions between the people who own the title to create clearly defined empires, so that there is preferable no overlap. Reality (for real Enterprise Architecture) is that there is always overlaps. And the good news is that the tension and friction created due to the overlap have a good chance to enforce creation of new (hopefully great) ideas.
So, don’t think you are an [xxx] Architect, but know you are, then you do not have to seek for a perfect definition. (There might be no chance to find the perfect answer, but just a working one. One that works for you only). The key message though is, that it is not a title, but a role. A role which will be fulfilled in any given context, because [Enterprise] Architecture inevitable happens, no matter if the people who perform it are titled in the right way or not.

Categories Uncategorized

Wearables and Pervasive Computing: A 2013 Trend to Consider

It’s difficult as a CIO to gauge whether or not to add the latest technology to your portfolio. You don’t want to chase a fad without business value or get left behind. Balancing your technology portfolio is a delicate dance that involves making the right investments at the right times for the right reasons. Today, PwC released its list of 2013 Top 10 Technology Trends for Business. I suspect that many CIOs will see Pervasive […]

Managing Business Transformation

Just putting together the material for my new workshop next week.

This is the third day of my Business Architecture series. The first two days cover the six business architecture viewpoints. The idea is that people can tale these separately or together.

Day One – Modelling Business Operations 
Exploring process quality issues using the Activity Viewpoint, Knowledge (Information) Viewpoint and Motivation (Purpose) Viewpoint.

Day Two – Modelling Business Organization 
Exploring business relationships and strategy, using the Capability Viewpoint, Responsibility (Organizational) Viewpoint and Cybernetic Viewpoint.

Day Three – Managing Business Transformation 
Process guidelines and roadmap for business architects to analyse and manage structural change in large complex organizations.

Read more »

What is a value-proposition?

‘Value-proposition’ is a term much-bandied-about in business-models and the like. Yet what exactly is it? A tweet by Alex Osterwalder pointed me to an article by Steve Blank on ‘How to build a billion-dollar startup‘, which included this brief section on the role of

Metamodels

The Danish Agency for Digitisation has announced some coming updates of the national enterprise architecture framework and reference models. In a consultation draft about these, Et fælles overblik, the agency also introduces the OIO EA metamodel. The consultation also involves an update to STORM, the Service and Technology Reference Model. All documents are in Danish. Interested parties can submit comments to the agency until 14 …read more

Designing secure organizations. Risk management, Enterprise security management and ArchiMate.

<p><span style=”color: #505050; font-size: 11px; line-height: 19px;”>No one is allowed to enter the building without proper authorization; all incoming e-mail messages are filtered; personal computers that are used to store sensitive data do not have a direct connection to the internet, and therefore cannot be accessed remotely. With these </span><strong style=”color: #505050; font-size: 11px; line-height: 19px;”>enterprise security</strong><span style=”color: #505050; font-size: 11px; line-height: 19px;”> rules, we have ensured that our private information is safe, right? Wrong! </span></p><p>Cyber-attacks are getting increasingly sophisticated, using a combination of digital, physical and social engineering techniques. A typical example is the so-called “road apple attack”. A would-be intruder “accidentally” leaves a USB flash drive – with company logo – in a public spot such as the company car park. An employee picks it up, and chances are that he will not be able to suppress his curiosity and plug it into his PC. Surprise: the drive is infected with malware which, unless proper measures have been taken, will infect the PC and send sensitive information to the intruder.</p><p><img class=”left” src=”http://www.bizzdesign.com/assets/BlogDocuments-2/_resampled/resizedimage600395-Risk-Management.png” width=”600″ height=”395″ alt=”” title=””/></p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p>Of course, there are several ways to prevent this from happening. The system administrator may decide to completely disable the use of USB drives, but perhaps this is too restrictive, causing employees to find ways to circumvent this. Or perhaps a policy against the use of unverified storage devices suffices, if people are disciplined enough to comply with it… There is no easy way to determine how much security is enough, and how much is too much. In other words, how do we find the optimal position on the trade-off between security, usability and costs?</p><p>Most of the present-day security and <strong><a title=”risk management, secuirity measures” href=”http://www.bizzdesign.com/consultancy/governance-risk-and-compliance/”>risk management </a></strong>approaches are based on checklists, heuristics and best practices. Security measures are applied in a bottom-up way, often neglecting the social aspects. This may lead to an overkill of preventive security measures, also in cases where cheaper (and less intrusive) curative measures may suffice. On the other hand, less obvious threats or vulnerabilities in the organization may easily be overlooked.</p><p> </p><div class=”captionImage left” style=”width: 424px;”><img class=”left” src=”http://www.bizzdesign.com/assets/BlogDocuments-2/Enterprise-security-management-ArchiMate.png” alt=”Enterprise Secuirity Management” title=”enterprise security management, model-based approach ” width=”424″ height=”458″/><p class=”caption”>enterprise security management, Archimate core</p></div><p><span style=”font-size: 11px; line-height: 19px;”>To avoid this, we advocate a model-based approach to </span><strong style=”font-size: 11px; line-height: 19px;”>enterprise security management</strong><span style=”font-size: 11px; line-height: 19px;”>, in which security aspects are fully integrated in the design chain: from strategy and business model, through enterprise architecture, to the design and implementation of the organization and IT support. For this purpose, risk-related concepts are included in existing architecture and design languages. At the </span><strong style=”font-size: 11px; line-height: 19px;”><a title=”enterprise architecture, Archimate” href=”http://www.bizzdesign.com/consultancy/enterprise-architecture-management/”>enterprise architecture</a></strong><span style=”font-size: 11px; line-height: 19px;”> level, </span><strong style=”font-size: 11px; line-height: 19px;”><a title=”ArchiMate open standard” href=”http://www.bizzdesign.com/consultancy/enterprise-architecture-management/archimate/”>ArchiMate</a></strong><span style=”font-size: 11px; line-height: 19px;”>, as a broadly accepted open standard (with available tool support) that is suitable to describe business and IT aspects in an integrated way, is an obvious choice. Architectures described in </span><strong style=”font-size: 11px; line-height: 19px;”><a title=”ArchiMate goals, principles and requirements” href=”http://www.bizzdesign.com/consultancy/enterprise-architecture-management/archimate/”>ArchiMate</a></strong><span style=”font-size: 11px; line-height: 19px;”> can be linked to goals, principles and requirements, and to detailed design models expressed in languages such as BPMN or UML. The resulting models provide the input for risk and vulnerability analysis, highlighting the areas in the architecture that are most susceptible to attack. In addition, they will guide the design of effective and efficient security measures.</span></p><p>With this approach, <strong><a title=”Bizzdesign the Netherlands Contact” href=”http://www.bizzdesign.com/contact/netherlands/”>BiZZdesign</a></strong> can help you to design a secure organization – without unduly restricting your people in their daily work. </p>

Categories Uncategorized

On the use of the word ‘delivery’

Enterprise architects and consultants often enjoy building specific languages. This is both good and bad. Good jargon allows one to be very specific and concisely articulate observations about a particular specialised field of interest — for instance a domain architecture or a very specific business process, which only few people understand or carry out. Bad …read more