A Light Enterprise Information Security Architecture Model for Creating and Improving Security Architecture
Johannes Kossila
Abstract
Johannes Kossila
Abstract
For decades companies have utilized enterprise architecture for improving enterprise level IT management in order to achieve competitive advantage. For this purpose, several enterprise architecture frameworks have been created to describe business processes and IT systems, their interrelations, and connections to different parts of the company. To complement the general enterprise architecture frameworks companies can also utilize dedicated information security architecture frameworks to ensure that information security is addressed as part of enterprise architecture. However, these security frameworks are typically complex and require significant effort and resources for successful implementation. This makes companies often hesitant to actively develop their security architecture which results in insufficient security management practices making the organizations more prone to common security threats. \n \nThis thesis studies improving enterprise information security architecture by utilizing the best practices of common security architecture frameworks and combining them into a light enterprise information security architecture model. The model is flexible, easy to use and highly compatible with various enterprise architecture frameworks. This thesis contributes to the previous information security architecture research significantly as it provides a cost-effective model for creating and improving information security architecture without a need for changing the overall enterprise architecture framework. The model can also be used as basis for future information security architecture research and development. \n \nFirst, this thesis introduces the concepts of enterprise and information security architecture and presents some of the related frameworks. Then, it utilizes the best practices of these architecture frameworks to create a light enterprise information security architecture model. Finally, the proposed security architecture model is applied into an existing enterprise architecture environment and the results of implementation and the limitations of the model are discussed.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
For decades companies have utilized enterprise architecture for improving enterprise level IT management in order to achieve competitive advantage. For this purpose, several enterprise architecture frameworks have been created to describe business processes and IT systems, their interrelations, and connections to different parts of the company. To complement the general enterprise architecture frameworks companies can also utilize dedicated information security architecture frameworks to ensure that information security is addressed as part of enterprise architecture. However, these security frameworks are typically complex and require significant effort and resources for successful implementation. This makes companies often hesitant to actively develop their security architecture which results in insufficient security management practices making the organizations more prone to common security threats. \n \nThis thesis studies improving enterprise information security architecture by utilizing the best practices of common security architecture frameworks and combining them into a light enterprise information security architecture model. The model is flexible, easy to use and highly compatible with various enterprise architecture frameworks. This thesis contributes to the previous information security architecture research significantly as it provides a cost-effective model for creating and improving information security architecture without a need for changing the overall enterprise architecture framework. The model can also be used as basis for future information security architecture research and development. \n \nFirst, this thesis introduces the concepts of enterprise and information security architecture and presents some of the related frameworks. Then, it utilizes the best practices of these architecture frameworks to create a light enterprise information security architecture model. Finally, the proposed security architecture model is applied into an existing enterprise architecture environment and the results of implementation and the limitations of the model are discussed.
Key concepts: Enterprise information security architecture, Sherwood Applied Business Security Architecture, Architecture, Enterprise architecture, Enterprise architecture framework, Information security, Computer science, NIST Enterprise Architecture Model