Control Architecture: How does the enterprise model information-related controls?


A control architecture should be in place to include, without limit, protection objectives, access control, original identification, authentication, access facilitation, trust, and change management.


Enterprises use implicit or explicit models as the basis for decision-making with regard to information protection and to structure the way they think about the issues.
