Choosing an approach
The partner-sharing decision needs business risk assessment, a detailed access design and checks that continue through operation. Different sources help with different parts of that work.
NIST is the US National Institute of Standards and Technology.
| Source or approach | Useful contribution | What to connect |
|---|---|---|
| A Simple Architectural Framework (ASAF) | Gives Security its own aspect across the continuing process areas of Visioning, Transforming, Operating and Governing. | Add the risk analysis, controls and assurance appropriate to the service. |
| TOGAF | Integrates risk and security with enterprise architecture and its Architecture Development Method. | Connect architecture decisions to the organisation’s risk and security management. Open Group guidance, 2022. |
| SABSA | A business-driven security architecture framework, connecting business objectives and risk to services and management. | Relate the business protection need to the controls and their continuing performance. SABSA overview. |
| NIST Cybersecurity Framework (CSF) 2.0 | Organises cybersecurity outcomes through Govern, Identify, Protect, Detect, Respond and Recover. | Use the outcomes to examine coverage and priorities. The functions can operate together. Framework, 2024. |
| OWASP Software Assurance Maturity Model (SAMM) | Provides security practices across governance, design, implementation, verification and operations. | Connect threat assessment and secure design to development, deployment and operational work. SAMM model. |
| Zero Trust | Focuses access on the requesting identity, resource and policy rather than presumed trust from location. | Connect access decisions to the wider treatment of threats, incidents and recovery. NIST SP 800-207, 2020. |
The table selects contributions from public source material. Its rows cover different kinds of guidance: frameworks, outcomes, practices and a focused design approach. Compare what each contributes to the decision you face. The TOGAF row uses the official overview rather than a full review of the security guide.
Delivery methods
Security work can be organised within phased, iterative or continuous delivery. The chosen lifecycle still needs explicit security tasks, records and owners. NIST’s Secure Software Development Framework describes practices that can be integrated into an existing lifecycle. SSDF 1.1, 2022.
A design review may settle a shared access rule. Small releases can then repeat its checks, while a new partner or threat reopens the wider decision. Use the cycles to examine that arrangement in your own method.
Methodology configuration
Map the source practices into your design reviews, delivery checks and service reviews. Several practices may share one record or meeting. Use Methodology configuration to map terms, records and reviews to your own approach.
Use the security example, then adapt the risk and access records to connect a disclosure decision to its owner, safeguards and checks.