0% found this document useful (0 votes)
57 views5 pages

Six Layers of SABSA Architecture

The document describes the six layers of the SABSA architecture model: Contextual Security Architecture, Conceptual Security Architecture, Logical Security Architecture, Physical Security Architecture, Component Security Architecture, and Operational Security Architecture. Each layer addresses security concerns at a different level of abstraction, from broad business goals in the Contextual layer to operational security controls in the Operational layer. The layers are designed to be addressed sequentially to develop a comprehensive security architecture for an organization from high-level concepts to detailed implementation and operation.

Uploaded by

api-480230170
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
57 views5 pages

Six Layers of SABSA Architecture

The document describes the six layers of the SABSA architecture model: Contextual Security Architecture, Conceptual Security Architecture, Logical Security Architecture, Physical Security Architecture, Component Security Architecture, and Operational Security Architecture. Each layer addresses security concerns at a different level of abstraction, from broad business goals in the Contextual layer to operational security controls in the Operational layer. The layers are designed to be addressed sequentially to develop a comprehensive security architecture for an organization from high-level concepts to detailed implementation and operation.

Uploaded by

api-480230170
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Running Header: Describing the Six Layers of SABSA Architecture 1

Micah Geertson
CSOL 520
05/25/2019

Describing the Six Layers of SABSA Architecture


Describing the Six Layers of SABSA Architecture 2

Table of Contents
The SABSA Model ...................................................................................................................................... 3
Contextual Security Architecture .............................................................................................................. 3
Conceptual Security Architecture ............................................................................................................. 3
Logical Security Architecture ................................................................................................................... 3
Physical Security Architecture .................................................................................................................. 4
Component Security Architecture ............................................................................................................. 4
Operational Security Architecture............................................................................................................. 4
Conclusion ................................................................................................................................................... 4
References .................................................................................................................................................... 5
Describing the Six Layers of SABSA Architecture 3

The SABSA Model


Architecture can have many meanings. It can be used to describe the design of a building or
it can be used to describe the layout of a digital data network used in the context of computers.
Whatever the application of the definition, the SABSA Model can be used to analyze the different
layers of the architecture view. From the broadest level to the most granular, these views are:
Contextual Security Architecture, Conceptual Security Architecture, Logical Security Architecture,
Physical Security Architecture, Component Security Architecture, and Operational Security
Architecture (the overlapping layer). Each of these layers can be described by asking six questions:
What? Why? How? Who? Where? And When?
Contextual Security Architecture
In this layer, the business is focused on defining the primary goals associated with the
development of a secure architecture. What type of security is needed? Why does the company need
security? Who will be using these security features? Where will these features be made available
and when will they be used? By answering these questions, the company will be better suited in the
Conceptual phase to design a secure architecture around things deemed important (such as
intellectual property, risk driven decisions, international partnerships, Etc.).
Conceptual Security Architecture
This layer is where imagination and ingenuity are allowed to take form. As mentioned by the
assigned text, “it defines principles and fundamental concepts that guides the selection and
organization of logical and physical elements” (Enterprise Security Architecture, pg. 37). By asking
the same questions in this layer, the business is able to define what must be protected and why, how
technical or administrative controls can provide this security, who will manage these technical or
administrative controls, where will these controls reside within the company and when it all must be
accomplished. Transitioning from this phase to the Logical phase will take design from conceptual
to reality.
Logical Security Architecture
The Logical layer is where the “designer has to interpret the architect’s conceptual vision and
turn it into a logical structure that can be engineered” (Enterprise Security Architecture, pg. 38). This
is most likely the most important phase of the SABSA model. It is easy to design the most secure
systems in the world but the question remains: Is it doable? If time, funding and understanding don’t
exist, then concept will never become reality. This phase asks what business information can be
represented as logical, why the logical representation must adhere to security policy standards, how
Describing the Six Layers of SABSA Architecture 4

logical security services will be modular and meet business requirements, who will be the users of
these systems and defining their roles, where each of the security domains (logical, physical, Etc.)
reside, and when does the security process cycle start? The technologies described in this phase are
fed into the Physical phase for product acquisition.
Physical Security Architecture
The purpose of this phase is to transform the Logical requirements into physical systems and
software logic that will be commissioned within the infrastructure to meet the defined security
requirements. This is possibly the most technical phase of the SABSA Model as it needs to define
how the systems operate. Some of the questions asked during this phase are what types of security
data structures will be used, the conditional and actions logic, how the defined security protocols will
be utilized (access control, software firewalls, Etc.), who will be dependent upon these security
protocols, where these systems and software will physically or virtually reside, and describing
security time dependencies for the question of When.
Component Security Architecture
This phase involves the assembly and integration of all the selected hardware and software
requirements of the Physical phase. It is the job of the Component layer to ensure that each specified
system can exist and operate in the designated environment. This layer asks what kinds of data
structures will be needed, how will the security standard be enforced with these systems, how the
standards will be enforced (through hardware and software), who will have access to these systems,
where these systems and processes will live, and how will security time dependencies be set up to
accomplish the aspect of When. This is the last architectural and construction phase of the SABSA
Model. It is now time to turn over to the operational aspects after the delivery of the defined security
architecture.
Operational Security Architecture
This final phase is after the final product has been delivered and it’s time to begin production.
The purpose of this layer is to focus on the operation of all the previously defined security features,
functions and systems during the lifetime of the system. Without continual assurances by
acknowledging what is being managed (information), how (security controls), and where (on all
information systems platforms), then there is no way to guarantee security within the company.
Conclusion
In conclusion, each SABSA Model layer (Contextual, , Logical Security Architecture,
Physical, Component, and Operational) has a role to play in the design, implementation and
management of the secured system to ensure effective operational and information security.
Describing the Six Layers of SABSA Architecture 5

References
John S., Andrew C., David L. (2005). Enterprise Security Architecture A Business-Driven
Approach. CRC Press, Taylor & Francis Group, LLC.

SABSA (2019). A Brief History of SABSA: Part 1 – 21 years old this year. Retrieved from
[Link]

SABSA (2019). A Brief History of SABSA: Part 2 – An Evolving Framework. Retrieved from
[Link]

You might also like