1 of 113

Marinus J. Kuivenhoven

Edzo A. Botjes

62nd ESReDA Seminar On

Managing the unexpected:

designing systems to embrace disorder

for increasing asset reliability

2023 04 12 @ UTwente

Embrace

Chaos &

Antifragility

Security

2 of 113

Security

2023-04� Embrace chaos & Antifragility

3 of 113

Who are we

Security

2023-04� Embrace chaos & Antifragility

4 of 113

GOAL

5 of 113

Content

  1. Security
  2. Chaos
  3. Variety and Security

  • Antifragility and Resilience
  • Research on Antifragility Attributes

  • Variety Engineering and Security

Appendix

Security

2023-04� Embrace chaos & Antifragility

6 of 113

SECURITY

7 of 113

A definition of security by Bruce Schneier

Reality

Feeling

Secure

in-Secure

Bruce Schneier: The security mirage - https://www.ted.com/talks/bruce_schneier_the_security_mirage

Security

2023-04� Embrace chaos & Antifragility

8 of 113

Flaws and bugs

“Bugs are simple mistakes in code leading to problems like buffer overflows;

flaws are mistakes in design. It turns out that a lot of software is flawed.

In fact, if you step back and look at a multitude of security problems over time, �you'll find that about 50% of them are due to bugs and 50% due to flaws.”

Functional

request

Technical

implementation

flaw

bug

security

Gary McGraw - https://linuxsecurity.com/features/an-interview-with-gary-mcgraw-co-author-of-exploiting-software-how-to-break-code

Security

2023-04� Embrace chaos & Antifragility

9 of 113

Perspective �and information

10 of 113

Perspective and information

https://twitter.com/DrNeenaJha/status/1338105837684977664

Security

2023-04� Embrace chaos & Antifragility

11 of 113

Perspective and information

https://twitter.com/TanMohammedMD/status/1337865483446587392

Security

2023-04� Embrace chaos & Antifragility

12 of 113

Perspective and information

https://en.wikipedia.org/wiki/Rabbit%E2%80%93duck_illusion�https://scitechconnect.elsevier.com/lessons-from-the-dress-the-fundamental-ambiguity-of-visual-perception

Security

2023-04� Embrace chaos & Antifragility

13 of 113

Perception �and information

14 of 113

Reflections and information

https://twitter.com/NicoleBeckwith/status/1277236284470280195/photo/1

Security

2023-04� Embrace chaos & Antifragility

15 of 113

Reflections and information

https://writing.exchange/@XanIndigo/109966588561594572

Security

2023-04� Embrace chaos & Antifragility

16 of 113

the colors in the rectangles are the same

https://writing.exchange/@XanIndigo/109966588561594572

Security

2023-04� Embrace chaos & Antifragility

17 of 113

Visualisation and information

https://twitter.com/jimhejl/status/1452814882701824001

https://twitter.com/AkiyoshiKitaoka/status/1568102162064113669

https://www.ritsumei.ac.jp/~akitaoka/index-e.html

Security

2023-04� Embrace chaos & Antifragility

18 of 113

https://www.ritsumei.ac.jp/~akitaoka/index-e.html

Rotating Snakes

19 of 113

https://www.linkedin.com/posts/rafaelgiraldotenorio_entarch-activity-6681201385402376192-4MNK

Security

2023-04� Embrace chaos & Antifragility

20 of 113

CONNECTIONS

21 of 113

Connections leads to chaos

1

2

Double Pendulum

https://en.wikipedia.org/wiki/Double_pendulum �Botjes, Edzo. (2020). Defining Antifragility and the application on Organisation Design (1.0) [Zenodo]. �https://doi.org/10.5281/zenodo.3719389

Security

2023-04� Embrace chaos & Antifragility

22 of 113

Innovation drives new connections

Huber, D., Kaufmann, H., and Steinmann, M. (2017). Innovation: An Abiding Enigma, pages 11–19. Springer International Publishing, Cham. https://books.google.nl/books?id=rzckDwAAQBAJ

Security

2023-04� Embrace chaos & Antifragility

23 of 113

Nonlinear dynamical systems

�https://www.linkedin.com/posts/complexity-academy_complexitytheory-activity-6625721108249354241-MsJi

Security

2023-04� Embrace chaos & Antifragility

24 of 113

https://commons.wikimedia.org/wiki/File:CMB_universe_expansion.png

25 of 113

CHAOS

26 of 113

The two faces of chaos

If a situation is chaotic depends on the perspective of the observer, �this is the subjective part of chaos.

1

2

Double Pendulum

If a situation contains over a certain amount of connections, then it is impossible to predict the future, �this is the objective part of chaos.

https://en.wikipedia.org/wiki/Double_pendulum �https://en.wikipedia.org/wiki/Rabbit%E2%80%93duck_illusion

https://www.linkedin.com/posts/rafaelgiraldotenorio_entarch-activity-6681201385402376192-4MNK

https://www.linkedin.com/posts/complexity-academy_complexitytheory-activity-6625721108249354241-MsJi

Security

2023-04� Embrace chaos & Antifragility

27 of 113

The continuous security challenge

Reality

Feeling

Secure

in-Secure

Increasing subjective chaos

Increasing objective

chaos

MSc thesis: https://zenodo.org/record/3719389 // IEEE article: https://www.researchgate.net/publication/354321606 // Security: https://www.ted.com/talks/bruce_schneier_the_security_mirage

Security

2023-04� Embrace chaos & Antifragility

28 of 113

29 of 113

VARIETY �AND �SECURITY

30 of 113

Law of Requisite Variety

Variety is the number of possible states of whatever it is whose complexity we want measure - Beer, 1979

‘variety absorbs variety‘ - Beer, 1979

Attenuate Variety

Amplify Variety

‘variety can destroy variety‘ - Ashby, 1956

Ashby, W. R. (1958). Requisite variety and its implications for the control of complex systems. Cybernetica, 1(2):83–99.�Beer, S. (1979). The heart of enterprise: the managerial cybernetics of organization, volume 2 of Managerial cybernetics of organization. John Wiley & Sons, Chichester, West Sussex, UK

Increasing chaos equals increasing variety.

Dealing with chaos equals dealing with variety.

Security

2023-04� Embrace chaos & Antifragility

31 of 113

Security - The power of the many

also called ‘variety can destroy variety‘.

http://web.archive.org/web/20220226145643/http://ars.userfriendly.org/cartoons/?id=20021110

Security

2023-04� Embrace chaos & Antifragility

32 of 113

Security - The human variety

also called ‘variety can destroy variety‘.

https://twitter.com/TheRealSpaf/status/1401555550480080901/photo/1

https://cloudsecurityalliance.org/artifacts/state-of-cloud-security-risk-compliance

Security

2023-04� Embrace chaos & Antifragility

33 of 113

ANTIFRAGILITY �& RESILIENCE

34 of 113

Fragile has an mirror, anti-fragile

Taleb, N. N. (2012). Antifragile: Things that gain from disorder (Vol. 3). Random House Trade Paperbacks.

Security

2023-04� Embrace chaos & Antifragility

35 of 113

How to become antifragile?

Amplify Variety

202210 | © CC BY-SA 4.0�https://doi.org/10.5281/zenodo.3719388

also called ‘variety can destroy variety‘. �First resilience.

Ashby, W. R. (1958). Requisite variety and its implications for the control of complex systems. Cybernetica, 1(2):83–99.�Beer, S. (1979). The heart of enterprise: the managerial cybernetics of organization, volume 2 of Managerial cybernetics of organization. John Wiley & Sons, Chichester, West Sussex, UK

Security

2023-04� Embrace chaos & Antifragility

36 of 113

Resilience is about bouncing back

Security

2023-04� Embrace chaos & Antifragility

37 of 113

Three types of resilience

Martin-Breen, P. and Anderies, J. M. (2011). The bellagio initiative, background paper, resilience: A literature review. In Resilience: A Literature Review, Brighton:IDS. http://opendocs.ids.ac.uk/opendocs/handle/123456789/3692.

Taleb, N. N. (2012). Antifragile: Things that gain from disorder (Vol. 3). Random House Trade Paperbacks.

Botjes, Edzo. (2020). Defining Antifragility and the application on Organisation Design (1.0) [Zenodo]. https://doi.org/10.5281/zenodo.3719389

Security

2023-04� Embrace chaos & Antifragility

38 of 113

Three types of resilience

construction stays the same

�functionality stays the same

construction changes� �functionality stays the same

construction changes� �functionality changes

Martin-Breen and Anderies (2011), Taleb (2012), Botjes et al. (2021)

Security

2023-04� Embrace chaos & Antifragility

39 of 113

How does it fit?

Taleb, N. N. (2012). Antifragile: Things that gain from disorder (Vol. 3). Random House Trade Paperbacks.

Security

2023-04� Embrace chaos & Antifragility

40 of 113

How does it fit?

Martin-Breen and Anderies (2011),

Taleb (2012),

Botjes et al.(2021)

Security

2023-04� Embrace chaos & Antifragility

41 of 113

Resilience => Antifragility

Martin-Breen, P. and Anderies, J. M. (2011). The bellagio initiative, background paper, resilience: A literature review. In Resilience: A Literature Review, Brighton:IDS. http://opendocs.ids.ac.uk/opendocs/handle/123456789/3692.

Taleb, N. N. (2012). Antifragile: Things that gain from disorder (Vol. 3). Random House Trade Paperbacks.

Botjes, Edzo. (2020). Defining Antifragility and the application on Organisation Design (1.0) [Zenodo]. https://doi.org/10.5281/zenodo.3719389

Security

2023-04� Embrace chaos & Antifragility

42 of 113

Resilience => Antifragility

Impertinent

Recover

Adapt

Martin-Breen, P. and Anderies, J. M. (2011). The bellagio initiative, background paper, resilience: A literature review. In Resilience: A Literature Review, Brighton:IDS. http://opendocs.ids.ac.uk/opendocs/handle/123456789/3692.

Taleb, N. N. (2012). Antifragile: Things that gain from disorder (Vol. 3). Random House Trade Paperbacks.

Botjes, Edzo. (2020). Defining Antifragility and the application on Organisation Design (1.0) [Zenodo]. https://doi.org/10.5281/zenodo.3719389

Security

2023-04� Embrace chaos & Antifragility

43 of 113

EXTENDED ANTIFRAGILITY ATTRIBUTE �LIST

44 of 113

Resilient/ Antifragile organisation design

Learning �Organization

E. Botjes, M. van den Berg, B. van Gils and H. Mulder, "Attributes relevant to antifragile organizations," 2021 IEEE 23rd Conference on Business Informatics (CBI), Bolzano, Italy, 2021, pp. 62-71, �doi: 10.1109/CBI52690.2021.00017.

Attenuate Variety

Amplify Variety

Security

2023-04� Embrace chaos & Antifragility

45 of 113

Resilient/ Antifragile organisation design

Learning �Organization

Botjes, Edzo. (2020). Defining Antifragility and the application on Organisation Design (1.0) [Zenodo]. https://doi.org/10.5281/zenodo.3719389

Attenuate Variety

Amplify Variety

Top-down C&C

Micro-management

Redundancy

Modularity

Loosely coupled

Diversity

Non-monotonicity

Emergence

Self-organization

Insert low-level stress

Network-connections

Fail Fast

Resources to invest

Seneca’s barbell

Insert randomness

Reduce naive intervention

Skin in the game

Security

2023-04� Embrace chaos & Antifragility

46 of 113

Resilient/ Antifragile organisation design

Learning Organization

Personal mastery, Shared mental models, Building shared vision,

Team learning, Systems thinking.

Botjes, Edzo. (2020). Defining Antifragility and the application on Organisation Design (1.0) [Zenodo]. https://doi.org/10.5281/zenodo.3719389

Attenuate Variety

Amplify Variety

Top-down C&C

Micro-management

Redundancy

Modularity

Loosely coupled

Diversity

Non-monotonicity

Emergence

Self-organization

Insert low-level stress

Network-connections

Fail Fast

Resources to invest

Seneca’s barbell

Insert randomness

Reduce naive intervention

Skin in the game

Security

2023-04� Embrace chaos & Antifragility

47 of 113

https://pbs.twimg.com/media/C-QXz4BXsAAArh0?format=jpg&name=small

48 of 113

BREAK

49 of 113

UNKNOWN�UNKNOWN

&�MENTAL MODELS

50 of 113

Security

2023-04� Embrace chaos & Antifragility

51 of 113

Security

2023-04� Embrace chaos & Antifragility

52 of 113

What is security?

Reality

Feeling

Security

Security

2023-04� Embrace chaos & Antifragility

53 of 113

Security

2023-04� Embrace chaos & Antifragility

54 of 113

Security

2023-04� Embrace chaos & Antifragility

55 of 113

What causes uncertainty?

Design

Describe

Develop

Determine

Deploy

Do-it-again / Deprecate

Desire

Assumptions

Ambiguous

Resources

Unclear

Skills

Means

Risks

Feasible

Security

2023-04� Embrace chaos & Antifragility

56 of 113

Security

2023-04� Embrace chaos & Antifragility

57 of 113

Security

2023-04� Embrace chaos & Antifragility

58 of 113

Did the T-Rex walk over air? How could we fix this?

Security

2023-04� Embrace chaos & Antifragility

59 of 113

Security

2023-04� Embrace chaos & Antifragility

60 of 113

Secure Development Lifecycle

Requirements

Use Cases

Security Requirements

Abuse Cases

Architecture

Design

Threat Model

Flaw Analysis

Test plans

Plan Security Test

Code

Static Code Review

Test results

Clearance Advice

Application

Security Assessment

Feedback

Continuity Plan

Security

2023-04� Embrace chaos & Antifragility

61 of 113

Security

2023-04� Embrace chaos & Antifragility

62 of 113

Security

2023-04� Embrace chaos & Antifragility

63 of 113

Desire

  • Positive approach
      • Who may do what, from which location with which role, and therefore with which permissions, at what moment on which data, in which step of which process?
      • Persona -> Device -> Location -> Role -> Permissions -> Data -> Moment -> Process -> Step

  • Negative approach
      • Abuse Cases/stories
      • What shouldn’t happen
      • Unlimited
        • priority

Security

2023-04� Embrace chaos & Antifragility

64 of 113

Security

2023-04� Embrace chaos & Antifragility

65 of 113

The basics of Threat Modelling

Asset

Valuable resource

Vulnerability

Exploitable

weakness

Threat agent

Causes harm

Risk

Potential harm occurring

?

Countermeasure

Reduces risk

Security

2023-04� Embrace chaos & Antifragility

66 of 113

Security

2023-04� Embrace chaos & Antifragility

67 of 113

Security

2023-04� Embrace chaos & Antifragility

68 of 113

Security

2023-04� Embrace chaos & Antifragility

69 of 113

Security

2023-04� Embrace chaos & Antifragility

70 of 113

"If you think technology can solve your security problems, then you don't understand the problems and you don't understand the technology.”

Bruce Schneier, secrets and lies, 2007

Security

2023-04� Embrace chaos & Antifragility

71 of 113

THREAT MODELS

72 of 113

Threat Model Process

https://www.microsoft.com/en-us/securityengineering/sdl/threatmodeling

Security

2023-04� Embrace chaos & Antifragility

73 of 113

Threat Model Model

https://xebia.com/blog/threat-modeling-without-a-diagram/

Security

2023-04� Embrace chaos & Antifragility

74 of 113

Data Flow Diagram

https://learn.microsoft.com/en-us/windows-hardware/drivers/driversecurity/threat-modeling-for-drivers

Security

2023-04� Embrace chaos & Antifragility

75 of 113

STRIDE

https://developer.ibm.com/articles/threat-modeling-microservices-openshift-4/

Security

2023-04� Embrace chaos & Antifragility

76 of 113

USE CASE vs ABUSE CASE

Security

2023-04� Embrace chaos & Antifragility

77 of 113

LEARNING ORGANIZATION�AND �PERSONAL ACTION

78 of 113

Learning model of Senge and Hestenes

Mental Model

Building shared vision

Personal�Mastery

Team�Learning

Systems�Thinking

I

III

II

IV

V

Senge, P. M. (1990). The Fifth Discipline: The Art and Practice of the Learning organisation. A Currency book. Doubleday/Currency, New York, NY, USA. http://www.worldcat.org/oclc/815873729. ��Hestenes, D. (2010). Modeling theory for math and science education. In Modeling students’ mathematical modeling competencies, pages 13–41. Springer.

Security

2023-04� Embrace chaos & Antifragility

79 of 113

Learning model of Senge and Hennes

Mental Model

Building shared vision

Personal�Mastery

Team�Learning

Systems�Thinking

I

III

II

IV

V

Senge, P. M. (1990). The Fifth Discipline: The Art and Practice of the Learning organisation. A Currency book. Doubleday/Currency, New York, NY, USA.

Hestenes, D. (2010). Modeling theory for math and science education. In Modeling students’ mathematical modeling competencies, pages 13–41. Springer.

Security

2023-04� Embrace chaos & Antifragility

80 of 113

Systems Thinking

Mental Model

Building shared vision

Personal�Mastery

Team�Learning

Systems�Thinking

Behavior

Reality

I

III

II

IV

V

!

Senge, P. M. (1990). The Fifth Discipline: The Art and Practice of the Learning organisation. A Currency book. Doubleday/Currency, New York, NY, USA.

Hestenes, D. (2010). Modeling theory for math and science education. In Modeling students’ mathematical modeling competencies, pages 13–41. Springer.

Security

2023-04� Embrace chaos & Antifragility

81 of 113

Morphogenic social system model

Archer, M. S. (1995). Realist social theory: The morphogenetic approach. Cambridge university press.

Security

2023-04� Embrace chaos & Antifragility

82 of 113

On mental models, knowledge and action

Dietz, J., & Hoogervorst, J. (2017). Foundations of enterprise engineering. TEE-00 https://www.researchgate.net/publication/320353420_Foundations_of_Enterprise_Engineering

Hestenes, D. (2006). Notes for a modeling theory. In Proceedings of the 2006 GIREP conference: Modeling in physics and physics education, volume 31, page 27. University of Amsterdam Amsterdam�https://www.semanticscholar.org/paper/Notes-for-a-Modeling-Theory-of-Science%2C-Cognition-Hestenes/066bbeae4d25ade2d16055886e330159bf3a2312

Hestenes, D. (2010). Modeling theory for math and science education. In Modeling students’ mathematical modeling competencies, pages 13–41. Springer.

Mental �Models�(Subjective) personal knowledge

Conceptual Model�(Subjective) personal knowledge

Real things �& Process

Creating

Understanding

Perception

Action

Interpretation

Representation

Hestenes (2006), Hestenes (2010), Dietz and Hoogervorst (2017)

There is a difference between mental models used for action and mental models to understand.

Security

2023-04� Embrace chaos & Antifragility

83 of 113

Attributed based artifact design is fragile

FAjzen, I. (1991). The theory of planned behavior. Organizational behavior and human decision processes, 50(2), 179-211.

Fishbein, M., & Ajzen, I. (2011). Predicting and changing behavior: The reasoned action approach. Taylor & Francis.

https://en.wikipedia.org/wiki/Reasoned_action_approach (image uploaded by Gjalt-Jorn Peters, feedback loop is new)

“Q: What is the difference between the theory of planned behavior (TPB) and the reasoned action approach (RAA)?

A: As its name implies, the reasoned action approach (RAA) is a general framework for predicting and explaining behavior in which it is assumed that much human behavior involves a measure of reasoning. The theory of planned behavior (TPB) is the best-known and most frequently applied theoretical model of this kind, but other models, such as Bandura's social cognitive theory and the health belief model, may also be viewed as taking a reasoned action approach. When reporting or discussing research findings, it is therefore not sufficient to reference the "reasoned action approach." Instead, you should refer to the particular model or theory within this general framework on which the research is based. “- https://people.umass.edu/aizen/faq.html

Statement: a design (group) activity is behaviour and is the result of knowledge (conceptual model) and action (RAA/ TPB) and therefore very limited in designing an artifact for the unknown where the variety of the EAAL designed artifacts meets the variety of the reality. Since thee RAA/TPB are dampening variety and the step from personal mental model to shared mental model is also dampening variety.

Security

2023-04� Embrace chaos & Antifragility

84 of 113

"If you think technology can solve your security problems, then you don't understand the problems and you don't understand the technology.”

Bruce Schneier, secrets and lies, 2007

Security

2023-04� Embrace chaos & Antifragility

85 of 113

ABOUT US …

86 of 113

Multiple whitepapers�Thesis with 1500+ reads�40+ Blogs�Quoted in Books and Theses.

Consultancy for �7 Sectors,

30 Clients,

40+ Assignments�Infra to business strategy

@Edzob

(.com, LinkedIn, Twitter)

2021- now Xebia

2006 - 2020 Sogeti

1992 - 2006 your IT guy

Research

ASc�Computer Science

2003

MSc�Enterprise�Architecture

2020

BSc�Business Information Systems

2006

PhD student�Information Security

2021-

Share

Apply

Edzo Botjes�Organisational Resilience Architect �Antifragility Architect

Trusted Advisor

https://www.edzob.com�ebotjes@xebia.com

Teaching Enterprise Architecture (MSc) at

Utrecht University

of Applied Sciences

2022 -

2023-04

Embrace chaos & Antifragility

87 of 113

Edzo Botjes�Organisational Resilience Architect �Antifragility Architect

Trusted Advisor

https://www.edzob.com�ebotjes@xebia.com

Consultant @ Xebia�2021-

Consultant @ Sogeti�2006 - 2020

Internships�2005-2006

2023-04

Embrace chaos & Antifragility

88 of 113

Edzo Botjes�Organisational Resilience Architect �Antifragility Architect

Trusted Advisor

https://www.edzob.com

ebotjes@xebia.com

Continuous Learning loop

Research

Share

Apply

2023-04

Embrace chaos & Antifragility

89 of 113

Marinus J. Kuivenhoven

Chief Technology Officer at Xebia Security

https://www.linkedin.com/in/marinuskuivenhoven/

2023-04

Embrace chaos & Antifragility

90 of 113

APPENDIX

91 of 113

List of handy Links

Appendix

Open

Description

Botjes, Edzo. (2020). �Defining Antifragility and the application on Organisation Design (1.0) [Zenodo]. https://doi.org/10.5281/zenodo.3719389

MSc Thesis on Antifragility

Bliekendaal, René. (2022). �Towards an Antifragile Public Sector �(1.0.1) [Zenodo]. https://doi.org/10.5281/zenodo.6862568

MSc Thesis on Antifragility

E. Botjes, M. van den Berg, B. van Gils and H. Mulder, "Attributes relevant to antifragile organizations," 2021 IEEE 23rd Conference on Business Informatics (CBI), Bolzano, Italy, 2021, pp. 62-71, doi: 10.1109/CBI52690.2021.00017. https://www.researchgate.net/publication/354321606_Attributes_relevant_to_antifragile_organizations

IEEE Paper on Antifragility

Curated list of books and videos on topics relevant to the domain of Enterprise Architecture.

A list of books relevant to the domain of DevSecOps.

Security

2023-04� Embrace chaos & Antifragility

92 of 113

To become more secure, make sense of your context and respond

Reality

Feeling

Secure

in-Secure

1

2

Double Pendulum

Probe - Sense - Respond

Act - Sense - Respond

Sense - Analyze - Respond

Sense - Categorize - Respond

Botjes, Edzo. (2020). Defining Antifragility and the application on Organisation Design (1.0) [Zenodo]. https://doi.org/10.5281/zenodo.3719389

https://www.ted.com/talks/bruce_schneier_the_security_mirage

https://en.wikipedia.org/wiki/Double_pendulum

Strategy in the context of uncertainty https://doi.org/10.1108/08944310510556955 �Complexity Theory: An Overview with Potential Applications for the Social Sciences https://www.researchgate.net/publication/330500755 �The new dynamics of strategy: Sense-making in a complex and complicated world https://ieeexplore.ieee.org/abstract/document/5386804https://thecynefin.co/library/cynefin-weaving-sense-making-into-the-fabric-of-our-worldhttps://www.systemswisdom.com/sites/default/files/Snowdon-and-Boone-A-Leader's-Framework-for-Decision-Making_0.pdf �Huber, D., Kaufmann, H., and Steinmann, M. (2017). Innovation: An Abiding Enigma, pages 11–19. Springer International Publishing, Cham. https://books.google.nl/books?id=rzckDwAAQBAJ

Appendix

Security

2023-04� Embrace chaos & Antifragility

93 of 113

The law of 3

Security

Business

Strategy

Information

Information Systems

Infrastructure

Service Management

Objective chaos, Subjective chaos and

The map is not the terrain

1

2

Double Pendulum

Situational awareness/ Cynefin,�Product development and�Maturity Models

Slice the cake,�optimize for luck and

Infinite layers

Virtual Machine

Network & Power

Storage

Database

Middleware

Application

Operating System

HyperVisor

Virtual Network

Compute/CPU

Application 3-Tier Layer

Virtual Machine Layer

Virtualization Layer

Hardware Layer

Configuration

Appendix

Security

2023-04� Embrace chaos & Antifragility

94 of 113

Toolkit

Mental Model

Building shared vision

Personal�Mastery

Team�Learning

Systems�Thinking

I

III

II

IV

V

Business

Strategy

Information

Information Systems

Infrastructure

Service Management

Security

What

How

Why

Appendix

Security

2023-04� Embrace chaos & Antifragility

95 of 113

The Agile Organization

“The agile organization is dawning as the new dominant organizational paradigm. (2017)”

Appendix

https://en.wikipedia.org/wiki/Antifragile_(book)

https://www.mckinsey.com/business-functions/organization/our-insights/the-five-trademarks-of-agile-organizations

Security

2023-04� Embrace chaos & Antifragility

96 of 113

Cynefin

Holistic

approach

Reductionistic

approach

Security

2023-04� Embrace chaos & Antifragility

97 of 113

Not all is chaos, Cynefin to make sense.

Reductionistic

approach

Holistic

approach

Probe - Sense - Respond

Act - Sense - Respond

Sense - Analyze - Respond

Sense - Categorize - Respond

Security

2023-04� Embrace chaos & Antifragility

98 of 113

Cynefin by Dave Snowden, another visualisation

Appendix

https://www.linq.it/complexity-is-killing-your-business/cynefinfrwk/

Security

2023-04� Embrace chaos & Antifragility

99 of 113

Cynefin by Dave Snowden

Appendix

https://www.cecan.ac.uk/events/cecan-webinar-cynefin-navigating-uncertainty/

Security

2023-04� Embrace chaos & Antifragility

100 of 113

Learning model of Senge and Hestenes

Mental Model

Building shared vision

Personal�Mastery

Team�Learning

Systems�Thinking

I

III

II

IV

V

Senge, P. M. (1990). The Fifth Discipline: The Art and Practice of the Learning organisation. A Currency book. Doubleday/Currency, New York, NY, USA. http://www.worldcat.org/oclc/815873729. ��Hestenes, D. (2010). Modeling theory for math and science education. In Modeling students’ mathematical modeling competencies, pages 13–41. Springer.

Appendix

Security

2023-04� Embrace chaos & Antifragility

101 of 113

Appendix

Security

2023-04� Embrace chaos & Antifragility

102 of 113

Product development stages

Appendix

Meige, 2016 Three Factors Driving the Uberization of Talents, https://open-organisation.com/en/2016/01/29/three-factors-driving-the-uberization-of-talents

Botjes, 2018 - Three Steps to Successful Innovation, https://labs.sogeti.com/three-steps-to-successful-innovation

Kim, 2005 - Blue Ocean Strategy, https://www.goodreads.com/book/show/4898

Knapp et al, 2016 - Sprint, https://www.goodreads.com/book/show/25814544

Ries, 2011 - The Lean Startup, https://www.goodreads.com/book/show/10127019

Security

2023-04� Embrace chaos & Antifragility

103 of 113

Product development stages

Appendix

Gartner, 2017 Enterprise Architecture and Technology Innovation Leadership Vision for 2017, https://www.gartner.com/binaries/content/assets/events/keywords/enterprise-architecture/epaeu17/enterprise_architecture_and__tech-innovation.pdf

Security

2023-04� Embrace chaos & Antifragility

104 of 113

Godfather of devops infinity loop

You will find many iterations and variations on this loop

Appendix

https://awkwardgen.com/devops-infinity-loop-for-beginners/​

Security

2023-04� Embrace chaos & Antifragility

105 of 113

Levels of Automating “product” creation by DoD

https://dodcio.defense.gov/Portals/0/Documents/Library/DevSecOpsFundamentalsPlaybook.pdf

https://dodcio.defense.gov/Portals/0/Documents/DoD%20Enterprise%20DevSecOps%20Reference%20Design%20v1.0_Public%20Release.pdf

Appendix

Security

2023-04� Embrace chaos & Antifragility

106 of 113

… as a Service

Appendix

Security

2023-04� Embrace chaos & Antifragility

107 of 113

The Cloud

�https://commons.wikimedia.org/wiki/File:CMB_universe_expansion.png �https://www.researchgate.net/publication/327700356

Appendix

Security

2023-04� Embrace chaos & Antifragility

108 of 113

OSI Cloud Stack (adaption)

Appendix

Integrity

Access (Identify & keys)

Virtual Machine

Network & Power

Storage

Database

Middleware

Application

Operating System

HyperVisor

Virtual Network

Compute/CPU

Application 3-Tier Layer

Virtual Machine Layer

Virtualization Layer

Hardware Layer

Configuration

Tools/ Services

Data / Interfaces

(DevOps) LifeCycle Management

Dev & Ops Environment

Security

2023-04� Embrace chaos & Antifragility

109 of 113

Cyber Defense Matrix

Appendix

https://cyberdefensematrix.com

Security

2023-04� Embrace chaos & Antifragility

110 of 113

Stafford Beer - Viable Systems Model

https://www.wikiwand.com/en/Viable_system_model

https://en.wikipedia.org/wiki/Stafford_Beer

Appendix

Security

2023-04� Embrace chaos & Antifragility

111 of 113

TRANSACTION AS FABRIC OF OUR REALITY

https://www.pronto-lectures.org/docs/glossary/

https://www.researchgate.net/publication/351461134_The_Evolution_of_DEMO

Appendix

Security

2023-04� Embrace chaos & Antifragility

112 of 113

Law of Requisite Variety

https://www.flickr.com/photos/davegray/6463738151 .

1

2

Double Pendulum

Appendix

Security

2023-04� Embrace chaos & Antifragility

113 of 113