没有合适的资源?快使用搜索试试~ 我知道了~
首页TOGAF and SABSA Integration
How SABSA and TOGAF complement each other to create better architectures. This White Paper documents an approach to enhance the TOGAF enterprise architecture methodology with the SABSA security architecture approach and thus create one holistic architecture methodology.
资源详情
资源评论
资源推荐

TOGAF
®
and SABSA
®
Integration
How SABSA and TOGAF complement each
other to create better architectures
A White Paper by:
The Open Group TOGAF-SABSA Integration Working Group,
comprising leading representatives from the SABSA Institute and
members of The Open Group Architecture and Security Forums
October 2011

TOGAF
®
and SABSA
®
Integration
www.opengroup.org
A Whi te P aper P ublished by The Open Grou p
2
Copyright © 2011 The Open Group and The SABSA Institute
The Open Group hereby authorizes you to use this document for any purpose, PROVIDED THAT any copy
of this document which you make shall retain all copyright and other proprietary notices contained herein.
This document may contain other proprietary notices and copyright information.
Nothing contained herein shall be construed as conferring by implication, estoppel, or otherwise any license
or right under any patent or trademark of The Open Group or any third party. Except as expressly provided
above, nothing contained herein shall be construed as conferring any license or right under any copyright of
The Open Group.
Note that any product, process, or technology in this document may be the subject of other intellectual
property rights reserved by The Open Group, and may not be licensed hereunder.
This document is provided "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR
IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. Some
jurisdictions do not allow the exclusion of implied warranties, so the above exclusion may not apply to you.
Any publication of The Open Group may include technical inaccuracies or typographical errors. Changes
may be periodically made to these publications; these changes will be incorporated in new editions of these
publications. The Open Group may make improvements and/or changes in the products and/or the programs
described in these publications at any time without notice.
Should any viewer of this document respond with information including feedback data, such as questions,
comments, suggestions, or the like regarding the content of this document, such information shall be deemed
to be non-confidential and The Open Group shall have no obligation of any kind with respect to such
information and shall be free to reproduce, use, disclose and distribute the information to others without
limitation. Further, The Open Group shall be free to use any ideas, concepts, know-how, or techniques
contained in such information for any purpose whatsoever including but not limited to developing,
manufacturing, and marketing products incorporating such information.
Boundaryless Information Flow
™
is a trademark and ArchiMate
®
, Jericho Forum
®
, Making Standards Work
®
,
Motif
®
, OSF/1
®
, The Open Group
®
, TOGAF
®
, UNIX
®
, and the ``X'' device are registered trademarks of The
Open Group in the United States and other countries.
COBIT
®
is a registered trademark of the Information Systems Audit and Control Association and the IT
Governance Institute.
ITIL
®
and M_o_R
®
are registered trademarks of the Office of Government Commerce in the United
Kingdom and other countries.
SABSA
®
is a registered trademark of the SABSA Institute.
All other brand, company, and product names are used for identification purposes only and may be
trademarks that are the sole property of their respective owners.
TOGAF
®
and SABSA
®
Integration
Document No.: W117
Published by The Open Group and the SABSA Institute, October 2011.
Any comments relating to the material contained in this document may be submitted to:
The Open Group, 44 Montgomery St. #960, San Francisco, CA 94104
(ogspecs@opengroup.org)
or to:
The SABSA Institute, 17 Ensign House, Admirals Way, Canary Wharf, London E14 9XQ, UK
(info@sabsa.org)

TOGAF
®
and SABSA
®
Integration
www.opengroup.org
A Whi te P aper P ublished by The Open Grou p
3
Table of Contents
Executive Summary
4
Introduction
6
Overview of TOGAF-SABSA Integration
7
Operational Risk and its Relevance to Enterprise Architecture
17
A Central Role for Requirements Management
21
Creating an Enterprise Architecture with Integrated Security
29
Appendix A: Glossary
48
Appendix B: TOGAF Benefits for SABSA Practitioners
51
References
56
About The Open Group
57
About the SABSA Institute
57
About the SABSA-TOGAF Integration Working Group
58

TOGAF
®
and SABSA
®
Integration
www.opengroup.org
A Whi te P aper P ublished by The Open Grou p
4
Boundaryless Information Flow
achieved through global interoperability
in a secure, reliable, and timely manner
Executive Summary
This White Paper documents an approach to enhance the TOGAF enterprise architecture methodology with
the SABSA security architecture approach and thus create one holistic architecture methodology. The
following aspects are highlighted:
•
Overview of TOGAF and SABSA integration – why bolster TOGAF with security architecture and why
use SABSA?
•
Operational risk and its relevance to enterprise architecture – why incorporating the concept of
operational risk is essential to modern enterprise architecture design.
•
A central role for requirements management – how to perform requirements management using SABSA
Business Attribute Profiling.
•
Creating an enterprise architecture with integrated security – how to align SABSA concepts to the
TOGAF ADM.
•
TOGAF benefits for SABSA practitioners – how to enhance SABSA-based projects by introducing
TOGAF concepts.
This White Paper is intended to guide enterprise and security architects in fully integrating security and risk
management into enterprise-level architectures, to stimulate review comments and inform the global
architecture community of proposed new content from the SABSA perspective for a future edition of the
TOGAF standard.
In December 2005, The Open Group Security Forum submitted a White Paper (W055: Guide to Security
Architecture in TOGAF) to the Architecture Forum expressing similar intent regarding integrating security
and risk management into TOGAF. This was included in TOGAF 9 but not in the integrated manner that the
Security Forum had intended. The Security Forum is revising W055 to submit as complementary to this
TOGAF and SABSA Integration White Paper.
Integrating security and risk management in enterprise architecture strongly supports The Open Group vision
of Boundaryless Information Flow, by informing well justified design decisions which maximize business
opportunity whilst minimizing business risk.

TOGAF
®
and SABSA
®
Integration
www.opengroup.org
A Whi te P aper P ublished by The Open Grou p
5
Where appropriate, this White Paper includes excerpts from the SABSA Blue Book and SABSA White Paper
update, with the full approval and permission of the SABSA Institute.
剩余57页未读,继续阅读


















安全验证
文档复制为VIP权益,开通VIP直接复制

评论1