SABSA Flashcards
SABSA means
The Sherwood Applied Business Security Architecture (SABSA) is a framework
and methodology for enterprise security architecture and service management.
SABSA is based on what matrix
6 x 6 matrix. According to the SABSA approach, security architecture is the process of populating the 36 cells in the SABSA matrix.
The below questions represents what?
1. What? – What type of system is it? What will it be used for? What assets
will it be protecting?
2. Why? – Why will it be used? Why are you applying security?
3. How? – How will it be used? How will security be preserved?
4. Who? – Who will use it? Who will be affected?
5. Where? – Where will it be used? Are there location dependencies?
6. When? – When will it be used? Are there temporal dependencies?
The six questions for each of the six layers
in the matrix
SABSA Cycle
Strategy & Concept
Design
Implementation
Manage & Measure
SABSA Business Attributes is organised under which group headings
User attributes Management attributes Operational attributes Risk Management attributes Legal/Regulatory attributes Technical Strategy attributes Business Strategy attributes