FREE STUDY NOTES · OGEA-102

Security as a concern that cuts across every domain

Why security architecture is not a separate domain, why every stakeholder has security concerns, and how security services differ from a control framework.

From Ultra Transcenders OGEA-102 by Tony Rough (publishing soon)

Security is called cross-cutting because security architecture is not a fifth domain with a phase of its own. It is a consistent collection of views, viewpoints and artifacts, covering security, privacy and operational risk perspectives, objectives and services, which shapes each of the four domains: Business, Data, Application and Technology.

Common trap: Building a stand-alone security architecture with its own stakeholders and roadmap - security artifacts must be developed alongside, and integrated with, the domain architectures in B, C and D.

No controls checklist

Integrating security does not mean ticking controls off a list. G152 bundles controls into security services, which behave like Architecture Building Blocks that steer the choice of Solution Building Blocks. Its examples include Identity and Access Management, Continuity Management, Security Intelligence, Digital Forensics, Security Analytics, Audit, Network Monitoring, Compliance Management, and Training and Awareness.

Item What it holds Role in the architecture
Control framework (such as ISO/IEC 27001/27002, COBIT, PCI-DSS) Requirements that controls must meet Listed in the Applicable Control Framework Register; a source of requirements
Security Services Catalog The building blocks that actually provide protection, with shared terminology Defined in Phase C (the SABSA logical layer); steers SBB selection later

Common trap: Treating a selected control framework as the security architecture - a framework lists requirements, whereas the Security Services Catalog describes the services that meet them, chosen through business-driven risk assessment.

Get the whole book

This note is one section of Ultra Transcenders OGEA-102: Enterprise Architecture Practitioner, an independent study guide that explains every learning unit the exam covers, topic by topic, with comparison tables, diagrams and the common traps, plus a glossary linked to the TOGAF Standard.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Publishing soon on Amazon in Kindle and paperback editions.

About the book · OGEA-102 terms in the glossary · All OGEA-102 study notes

More OGEA-102 study notes