The IBM Security Framework was developed to describe security in terms of the business resources that need to be protected, and looks at the different resource domains from a business point of view.
The IBM Security Blueprint expands on the business oriented view of the IBM Security Framework by mapping the domains into a core set of security capabilities and services. These capabilities and services serve as a starting point for design, development, integration, operation, and management of an enterprise IT environment that has security at its core. With the security domains, capabilities, and services as a backdrop, this guide covers two business scenarios, the first concerning password management related costs, and the second discussing PCI compliance to illustrate how the IBM Security Framework and IBM Security Blueprint can be best used.
This guide is a valuable resource for business leaders, security officers, consultants and architects who wish to understand and implement enterprise security following architectural guidelines.