Architecture Portal

Security approaches

Different contributions to the same design.

Adrian Sutherland · Version 1.0 · · © 2005–2026

Choosing an approach

The partner-sharing decision needs business risk assessment, a detailed access design and checks that continue through operation. Different sources help with different parts of that work.

NIST is the US National Institute of Standards and Technology.

Source or approach Useful contribution What to connect
A Simple Architectural Framework (ASAF) Gives Security its own aspect across the continuing process areas of Visioning, Transforming, Operating and Governing. Add the risk analysis, controls and assurance appropriate to the service.
TOGAF Integrates risk and security with enterprise architecture and its Architecture Development Method. Connect architecture decisions to the organisation’s risk and security management. Open Group guidance, 2022.
SABSA A business-driven security architecture framework, connecting business objectives and risk to services and management. Relate the business protection need to the controls and their continuing performance. SABSA overview.
NIST Cybersecurity Framework (CSF) 2.0 Organises cybersecurity outcomes through Govern, Identify, Protect, Detect, Respond and Recover. Use the outcomes to examine coverage and priorities. The functions can operate together. Framework, 2024.
OWASP Software Assurance Maturity Model (SAMM) Provides security practices across governance, design, implementation, verification and operations. Connect threat assessment and secure design to development, deployment and operational work. SAMM model.
Zero Trust Focuses access on the requesting identity, resource and policy rather than presumed trust from location. Connect access decisions to the wider treatment of threats, incidents and recovery. NIST SP 800-207, 2020.

The table selects contributions from public source material. Its rows cover different kinds of guidance: frameworks, outcomes, practices and a focused design approach. Compare what each contributes to the decision you face. The TOGAF row uses the official overview rather than a full review of the security guide.

Delivery methods

Security work can be organised within phased, iterative or continuous delivery. The chosen lifecycle still needs explicit security tasks, records and owners. NIST’s Secure Software Development Framework describes practices that can be integrated into an existing lifecycle. SSDF 1.1, 2022.

A design review may settle a shared access rule. Small releases can then repeat its checks, while a new partner or threat reopens the wider decision. Use the cycles to examine that arrangement in your own method.

Methodology configuration

Map the source practices into your design reviews, delivery checks and service reviews. Several practices may share one record or meeting. Use Methodology configuration to map terms, records and reviews to your own approach.

Use the security example, then adapt the risk and access records to connect a disclosure decision to its owner, safeguards and checks.

About this edition

Refreshed for the September 2026 website update. This edition develops the earlier Architecture Portal and ASAF material; the fictional worked example was added in 2026.

Scope, limitations and next checks

Status and accountability

Read this page with its boundaries visible

Status

In development

Last reviewed

Intended users

  • Architects comparing and adapting their existing approach

Non-goals

  • Prescribing a mandatory method or claiming measured benefits

Limitations

  • Guidance illustrated by a fictional example; proposed designs and checks have not been implemented or run.

Next evidence sought

  • Review the guidance and try its records with a practising architect.