Enterprise Security Architecture (ESA) extends traditional Enterprise Architecture (EA) by adding explicit, risk-driven perspectives that EA historically lacked. Security must address risks, threats, and vulnerabilities without obstructing business objectives, and it operates under a “weakest link” dynamic: defenders must protect many interdependent components while attackers may succeed by compromising only one or a few. As a result, ESA must exist in parallel with EA across all architecture layers and integrate with governance, risk management, and audit needs rather than functioning as disconnected technical diagrams.
Industry alignment between EA and ESA is relatively new, and most enterprises still lack a unified ESA, instead maintaining fragmented artifacts that describe isolated protections. ESA provides a unifying, multi-layer framework—contextual, conceptual, logical, and physical/component/solution—that can incorporate existing materials (e.g., board-level security presentations, CIO/CTO logical models, network diagrams), rationalize overlaps, replace gaps, and align security decisions with business priorities.
The Open Group’s TOGAF community has chosen to improve EA–security alignment by referencing established ESA work rather than rebuilding security discipline inside TOGAF, notably leveraging SABSA. ESA can be lightweight for smaller organizations and expand for complex environments. It should align with existing EA practices, control frameworks, and risk programs to optimize security investments, reduce cost and complexity, and maximize control effectiveness—while avoiding excessive additional processes beyond those already required for audit, compliance, and EA.
Two practical adoption paths emerge: use NIST Cybersecurity Framework (CSF) for control prioritization and roadmapping, or adopt/distill SABSA concepts to build a more comprehensive, business-driven, risk-aligned ESA integrated with TOGAF processes.
See All Locations
See All Locations