2019UTUPub (University of Turku)Requires access

A Light Enterprise Information Security Architecture Model for Creating and Improving Security Architecture

Johannes Kossila

Open publisher page 0 citations

Abstract

For decades companies have utilized enterprise architecture for improving enterprise level IT management in order to achieve competitive advantage. For this purpose, several enterprise architecture frameworks have been created to describe business processes and IT systems, their interrelations, and connections to different parts of the company. To complement the general enterprise architecture frameworks companies can also utilize dedicated information security architecture frameworks to ensure that information security is addressed as part of enterprise architecture. However, these security frameworks are typically complex and require significant effort and resources for successful implementation. This makes companies often hesitant to actively develop their security architecture which results in insufficient security management practices making the organizations more prone to common security threats. \n \nThis thesis studies improving enterprise information security architecture by utilizing the best practices of common security architecture frameworks and combining them into a light enterprise information security architecture model. The model is flexible, easy to use and highly compatible with various enterprise architecture frameworks. This thesis contributes to the previous information security architecture research significantly as it provides a cost-effective model for creating and improving information security architecture without a need for changing the overall enterprise architecture framework. The model can also be used as basis for future information security architecture research and development. \n \nFirst, this thesis introduces the concepts of enterprise and information security architecture and presents some of the related frameworks. Then, it utilizes the best practices of these architecture frameworks to create a light enterprise information security architecture model. Finally, the proposed security architecture model is applied into an existing enterprise architecture environment and the results of implementation and the limitations of the model are discussed.

About this research paper

What this paper is about

For decades companies have utilized enterprise architecture for improving enterprise level IT management in order to achieve competitive advantage. For this purpose, several enterprise architecture frameworks have been created to describe business processes and IT systems, their interrelations, and connections to different parts of the company. To complement the general enterprise architecture frameworks companies can also utilize dedicated information security architecture frameworks to ensure that information security is addressed as part of enterprise architecture. However, these security frameworks are typically complex and require significant effort and resources for successful implementation. This makes companies often hesitant to actively develop their security architecture which results in insufficient security management practices making the organizations more prone to common security threats. \n \nThis thesis studies improving enterprise information security architecture by utilizing the best practices of common security architecture frameworks and combining them into a light enterprise information security architecture model. The model is flexible, easy to use and highly compatible with various enterprise architecture frameworks. This thesis contributes to the previous information security architecture research significantly as it provides a cost-effective model for creating and improving information security architecture without a need for changing the overall enterprise architecture framework. The model can also be used as basis for future information security architecture research and development. \n \nFirst, this thesis introduces the concepts of enterprise and information security architecture and presents some of the related frameworks. Then, it utilizes the best practices of these architecture frameworks to create a light enterprise information security architecture model. Finally, the proposed security architecture model is applied into an existing enterprise architecture environment and the results of implementation and the limitations of the model are discussed.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

For decades companies have utilized enterprise architecture for improving enterprise level IT management in order to achieve competitive advantage. For this purpose, several enterprise architecture frameworks have been created to describe business processes and IT systems, their interrelations, and connections to different parts of the company. To complement the general enterprise architecture frameworks companies can also utilize dedicated information security architecture frameworks to ensure that information security is addressed as part of enterprise architecture. However, these security frameworks are typically complex and require significant effort and resources for successful implementation. This makes companies often hesitant to actively develop their security architecture which results in insufficient security management practices making the organizations more prone to common security threats. \n \nThis thesis studies improving enterprise information security architecture by utilizing the best practices of common security architecture frameworks and combining them into a light enterprise information security architecture model. The model is flexible, easy to use and highly compatible with various enterprise architecture frameworks. This thesis contributes to the previous information security architecture research significantly as it provides a cost-effective model for creating and improving information security architecture without a need for changing the overall enterprise architecture framework. The model can also be used as basis for future information security architecture research and development. \n \nFirst, this thesis introduces the concepts of enterprise and information security architecture and presents some of the related frameworks. Then, it utilizes the best practices of these architecture frameworks to create a light enterprise information security architecture model. Finally, the proposed security architecture model is applied into an existing enterprise architecture environment and the results of implementation and the limitations of the model are discussed.

Key concepts: Enterprise information security architecture, Sherwood Applied Business Security Architecture, Architecture, Enterprise architecture, Enterprise architecture framework, Information security, Computer science, NIST Enterprise Architecture Model

Related papers

Back to paper searchBrowse research topicsOriginal source
A Light Enterprise Information Security Architecture Model for Creating and Improving Security Architecture — Research Paper | ScholarLens