Thanks to visit codestin.com
Credit goes to www.scribd.com

0% found this document useful (0 votes)
711 views1 page

Enterprise Security Framework

The document outlines the SABSA framework for architectural risk management. It describes six dimensions (What, Why, How, Who, Where, When) that define the context for business decisions and assets. Each dimension covers different aspects including goals, processes, roles, locations, and time dependencies that must be considered and addressed through the framework.

Uploaded by

Eli_Hux
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
711 views1 page

Enterprise Security Framework

The document outlines the SABSA framework for architectural risk management. It describes six dimensions (What, Why, How, Who, Where, When) that define the context for business decisions and assets. Each dimension covers different aspects including goals, processes, roles, locations, and time dependencies that must be considered and addressed through the framework.

Uploaded by

Eli_Hux
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 1

SABSA MATRIX ASSETS (What) Business Decisions CONTEXTUAL ARCHITECURE Taxonomy of Business Assets, including Goals & Objectives

Business Knowledge & Risk Strategy Business Attributes Profile Information Assets LOGICAL ARCHITECTURE Inventory of Information Assets Data Assets PHYSICAL ARCHITECTURE Data Dictionary & Data Inventory ICT Components COMPONENT ARCHITECTURE ICT Products, including Data Repositories and Processors Service Delivery Management Assurance of Operational Continuity & Excellence MOTIVATION (Why) Business Risk Opportunities & Threats Inventory Risk Management Objectives Enablement & Control Objectives; Policy Architecture Risk Management Policies PROCESS (How) Business Processes Inventory of Operational Processes Strategies for Process Assurance Process Mapping Framework; Architectural Strategies for ICT Process Maps & Services Information Flows; Functional Transformations; Service Oriented Architecture Process Mechanisms Applications; Middleware; Systems; Security Mechanisms Process Tools & Standards Tools and Protocols for Process Delivery Process Delivery Management Management & Support of Systems, Applications & Services PEOPLE (Who) Business Governance Organisational Structure & the Extended Enterprise Roles & Responsibilities Owners, Custodians and Users; Service Providers & Customers Entity & Trust Framework Entity Schema; Trust Models; Privilege Profiles Human Interface User Interface to ICT Systems; Access Control Systems Personnel Manment Tools & Standards Identities; Job Descriptions; Roles; Functions; Actions & Access Control Lists Personnel Management Account Provisioning; User Support Management LOCATION (Where) Business Geography Inventory of Buildings, Sites, Territories, Jurisdictions, etc. Domain Framework Security Domain Concepts & Framework Domain Maps Domain Definitions; Inter-domain associations & interactions ICT Infrastructure Host Platforms, Layout & Networks Locator Tools & Standards Nodes, Addresses and other Locators Management of Environment Management of Buildings, Sites, Platforms & Networks TIME (When) Business Time Dependence Time dependencies of business objectives Time Management Framework Through-Life Risk Management Framework Calendar & Timetable Start Times, Lifetimes & Deadlines Processing Schedule Timing & Sequencing of Processes and Sessions Step Timing & Sequencing Tools Time Schedules; Clocks, Timers & Interrupts Time & Performance Management Management of Calendar and Timetable

CONCEPTUAL ARCHITECTURE

Domain Policies

Risk Management Practices Risk Management Rules & Procedures Risk Management Tools & Standards Risk Analysis Tools; Risk Registers; Risk Monitoring and Reporting Tools Operational Risk Management Risk Assessment; Risk Monitoring & Reporting; Risk Treatment

SERVICE MANAGEMENT ARCHITECTURE

1995 2009 SABSA Limited | [email protected]

You might also like