Domain 2 of 4 · Chapter 1 of 2

Select a security architecture approach

Unlock the complete study guide + 1,500 practice questions across 12 full exams.

Bundled into the existing Information Systems Security Architecture Professional premium course — no separate purchase.

14-day money-back guarantee — no questions asked.

Included in this chapter:

  • What selecting a security architecture approach means
  • Setting the scope of the architecture
  • Naming the architecture type
  • The TOGAF Architecture Development Method
  • SABSA: business-driven security architecture
  • Reusing published reference content
  • Enumerating threats with STRIDE
  • Scoring severity with CVSS
  • Prioritizing coverage with MITRE ATT&CK
  • Reading the stem: which choice is being tested

The fifth choice: what each threat-modeling framework answers

Aspect of the choiceSTRIDECVSSMITRE ATT&CK
Question it answersWhat can go wrong with this design?How severe is this vulnerability?Which adversary behaviors should we cover?
What it takes as inputA model of elements and data flowsOne identified vulnerabilityThreat intelligence about observed activity
What it producesThreats per element, by categoryA severity score plus its vectorTechniques mapped to tactics
Unit of analysisModeled element or data flowVulnerabilityAdversary technique
Ordering of its partsCategories are applied, not sequencedMetric groups refine one scoreTactics are unordered goals
What it does not tell youHow severe or how likely any threat isYour organizational riskWhether your controls actually work

Decision tree

Which of the five choices is open? Choice 3: which method Choice 4: what to reuse Choice 5: which analysis Must controls trace to measured business outcomes? Yes No SABSA Business Attribute Profiles TOGAF ADM, tailored security endorsed in Phase A Does a published reference architecture cover this pattern? Yes No Tailor the reference architecture or blueprint Design the specific architecture from principles Which threat question is open? What can go wrong? How severe is this flaw? Which adversary behavior? STRIDE per element and data flow CVSS Base then Threat and Environmental MITRE ATT&CK threat-informed coverage Always first: choice 1 scope, then choice 2 type

Cheat sheet

  • Security architecture shows how the design enforces security policy
  • Architecture scope and detail must fit the decision and stakeholder concern
  • Enterprise security architecture must align security structure to mission
  • Architecture detail should decompose without losing requirement traceability
  • A viewpoint defines how a stakeholder concern will be represented
  • NIST security engineering iterates among problem, solution, and trustworthiness contexts
  • Trustworthy design balances preemptive protection with reactive recovery
  • Cloud scope is defined by the cloud model rather than remote hosting alone
  • IaaS leaves the guest software stack under consumer control
  • Cloud service models shift the consumer-provider control boundary
  • Cloud reference architecture separates five actor roles
  • Cloud deployment and service models answer different architecture questions
  • Cloud architecture includes management and orchestration as well as service delivery
  • Network security architecture must model trust transitions, not only topology
  • SOA composes business capability from loosely coupled services
  • Semantic interoperability gives SOA services a common meaning for exchanged information
  • SOA governance keeps reusable services aligned with enterprise policy
  • Zero trust shifts protection from network location to individual resources
  • Zero trust access decisions must remain responsive to changing context
  • SOA does not require every service interaction to traverse an enterprise service bus
  • TOGAF ADM is an iterative method that must be tailored to the enterprise
  • TOGAF separates business, data, application, and technology concerns
  • TOGAF Phase A establishes security endorsement and sign-off
  • Requirements management remains central throughout the TOGAF ADM
  • TOGAF architecture detail follows the level of architecture
  • TOGAF security architecture addresses failure modes early
  • TOGAF separates migration planning from implementation conformance governance
  • SABSA derives security architecture from business outcomes
  • SABSA Business Attribute Profiles turn business expectations into measurable requirements
  • SABSA preserves two-way traceability from business mandate to security service
  • SABSA layers move from business context toward implementation detail
  • SABSA Manage and Measure feeds operational performance back into architecture
  • SABSA can supply business-risk depth inside TOGAF
  • SABSA prioritizes proportional responses to business risk and opportunity
  • A reference architecture establishes a reusable common model
  • Specific architecture views map activities to functional components
  • Security patterns are governed security knowledge assets
  • Reference content accelerates design but does not replace tailoring
  • Reference-architecture conformance does not prove control effectiveness
  • A reusable blueprint must state its assumptions and boundaries
  • Threat modeling is a scoped form of risk assessment
  • The four-question threat-modeling cycle is iterative
  • STRIDE systematically applies threat categories to modeled elements and flows
  • Spoofing, tampering, and repudiation target distinct security properties
  • Disclosure, denial of service, and elevation of privilege separate confidentiality, availability, and authorization threats
  • CVSS Base measures intrinsic vulnerability severity, not organizational risk
  • CVSS Threat and Environmental metrics contextualize Base severity
  • A CVSS score should be communicated with its vector and metric nomenclature
  • MITRE ATT&CK structures threat intelligence around observed adversary behavior
  • ATT&CK coverage should be prioritized to relevant threats rather than maximized indiscriminately
  • ATT&CK tactics are unordered while Cyber Kill Chain phases are ordered
  • Map relevant ATT&CK techniques to both prevention and detection coverage
  • CVSS Base combines exploitability with impacts to affected systems

Unlock with Premium — includes all practice exams and the complete study guide.

Also tested in

References

  1. The TOGAF Standard
  2. SABSA Executive Summary
  3. NIST SP 800-160 Vol. 1 Rev. 1: Engineering Trustworthy Secure Systems Whitepaper
  4. NIST SP 800-145: The NIST Definition of Cloud Computing Whitepaper
  5. NIST SP 500-292: NIST Cloud Computing Reference Architecture Whitepaper
  6. NIST SP 800-207: Zero Trust Architecture Whitepaper
  7. OWASP Threat Modeling Cheat Sheet
  8. OWASP Threat Modeling
  9. CVSS v4.0 Specification Document
  10. MITRE ATT&CK
  11. MITRE ATT&CK Enterprise Tactics