
Introduces SABSA security architecture modeling in Archimate, outlining the security overlay, boundaryless information flow, and integration with TOGAF and Archimate layers for business-driven, modular security design.
Explore Archimate security perspective and SABSA benefits for practitioners through vendor-neutral modeling and the Archimate security overlay within TOGAF guidance.
Explore Archimate core elements and core relationships in the SABSA–Archimate context, across the three-layer metamodel of business, application, and technology, including active, passive, and behavior roles.
Discover Archimate 3.2 core relationships—structural, dependency, dynamic, specialization, and association—guided by the relationship table that defines valid connections and directionality.
Explore Archimate extension layers and elements, including the strategy layer, motivation aspects, and implementation and migration layer, plus composition elements like grouping and location for modeling capabilities and AI.
Explore the Archimate full framework, including code and extended layers, plus motivation, strategy, and migration. Compare Archimate with TOGAF ADM and Sabsa mappings and review learning resources and case studies.
Explore how sabsa aligns with archimate and archi to map five horizontal layers—from contextual to physical—across a security service management architecture, with togaf and itil mappings guiding the approach.
Explore how the motivation metamodel in Archimate maps meaning, value, stakeholder relationships, and the realization chain to model goals, outcomes, principles, and requirements.
this lecture recaps the basic elements and relationships for aligning sabsa with archimate, covering identifier, abstract flag, stereotype, and cardinality, including url and uri concepts.
Explore modeling security enhanced motivation with ArchiMate by mapping figure ten's motivation metamodel to ArchiMate notation, detailing value, loss, value chain, risk, assessment, goals, objectives, and principles.
For PlantUML tool usage, check my Udemy course "Learning and Practicing PlantUML (UML Modeling Language) with Live Demo" for detail
Learn to model the composition of the value chain in ArchiMate, connecting strategy layer value streams and business capabilities to processes and functions through hands-on diagramming.
Figure 16: Principles in the ArchiMate Motivation Hierarchy
Highlighting the Control Hierarchy Mismatch (i)
Highlighting the Control Hierarchy Mismatch (ii)
Figure 19: Achieving the Desired Hierarchy
Explore building figure 25 for a sabsa security model in archimate with archi, mapping goals to requirements and constraints across layers using control objectives and protections.
Learn to model business assets by linking the business service to service level agreements and the business interface in archimate. Explore sla metrics like availability, recovery time, and rpo.
Figure33: Avoid RACI Entanglement
a) A Pattern Repeated in Multiple Views
b) ... Caused Entanglement in the Underlying Model
Figure 34: Recommended RACI Patterns
a) Solved by a Tertiary Relationship
b) Solved by Specialization of an Abstract Base Role
Figure 35: Possibilities for Modeling Threat Actors
a) Something you are? (a throughly bad person)
b) Opportunist Exploit? (a trusted employee falls to temptation)
c) Something you do? (a wrong action)
Figure 36: Sensitivity in the Representation of Threats
a) Avoid unnecessary offence
b) Acknowledge the risk without personalizing it
c) Avoid assigning motive
Table 28: SABSA Contceptual Architecture, documented in Protege Ontology editing tool
Figure 37: Developing the SABSA Conceptual Security Architecture
Explore attribute profiling in SABSA security architecture in ArchiMate with Archi, identifying data minimization, accuracy, and up-to-date maintenance in figure 40.
Figure 42; Business Risk Analysis Process
Figure 43: Compliance Metamodel, built in Archi's sketch view
Figure 44: An Example Compliance Model
Figure 45: Control Consolidation
Figure 46: Possible Duplicate Objectives, Coupled Through Attribute Profile
Learn how to model conceptual security services in ArchiMate, comparing inline mediation, service inversion, and service isolation link, with authentication and access control across layers.
Figure 48: What the Security Overlay Would Like to Express
Figure 49: What the ArchiMate Specification Supports
Table 29: Elements used in Logical Access Management
Figure 50: Modeling Identity and Role Concepts
Figure 51: Common Examples of Signals Crossing Domain Boundaries
Figure 52: Simply Trust Relationships using Flow
Figure 53: Trust Attributes Associated with Inter-Domain Signals
Table 30: Elements and Relationships used in Trust Modeling
Figure 55: A better solution using Architectural Models to identify Critical Applications
Table 34: Application Component Properties
Table 35: Data Object Properties Schema, including «Defect», «Security Configuration», «Malware», and Data Object
Learn 8.2 risk modeling using an Open FAIR example scenario in ArchiMate, detailing a HR executive credential risk with two diagrams and mapping access, assets, and risk management strategies.
Translate the Open FAIR risk taxonomy into ArchiMate, employing aggregation and motivation elements to model loss event frequency, risk factors, and their influence on controls.
Explore application service modeling in ArchiMate within the SABSA security framework, detailing business processes, services, internal and external actors, data values, and SLA/RTO/RPO properties.
Table 36: Application Behavior Availability Properties
Figure 62: Modeling Authentication in the Primary Architecture
Figure 63: Example of Registration and Provisioning in Secondary Architecture
Table 37: Security Properties of Elements used in the Logical Layer
Explore modeling logical security architecture, focusing on 8.5 logical domains and 8.6 timing and events, and recap SABSA concepts, domain frameworks, and security event schemas in ArchiMate.
Figure 65: Stereotype of Artifact
Figure 66: Configuration Files
Explore Archimate 9.1 data and technology access modeling, focusing on node and device notations and security stereotypes such as HSM and VPN gateway, with practical property details.
Schema documented via JSON on:
Technology Service
Technology Process / Technology Function
System Software
Technology Interface
Schema documented via JSON on:
«Executable»
«Data»
«Defect»
Master sabsa security architecture in archimate with archi through recap, highlighting resources, mind maps, and four-layer contextual conceptual logical physical ontologies, plus access to the repository and udemy course.
SABSA® (Sherwood Applied Business Security Architecture) is a methodology for developing risk-driven enterprise information security and information assurance architectures and for delivering security infrastructure solutions that support critical business initiatives. It is an open standard, comprising a number of frameworks, models, methods and processes, free for use by all, with no licensing required for end-user organizations who make use of the standard in developing and implementing architectures and solutions. (Source: W100 - SABSA® White Paper)
Are you a security architect looking to make the SABSA framework more tangible? Or an enterprise architect needing to integrate a robust security overlay into your ArchiMate models? This course transforms the theoretical "Sherwood Applied Business Security Architecture" (SABSA) into a visual, actionable practice using the industry-standard ArchiMate language and the open-source Archi tool.
Why this course? SABSA is renowned for its business-driven logic, but creating its numerous artifacts at scale can be challenging. By leveraging ArchiMate’s extensibility, you will learn to build a "Security Overlay" that ensures traceability from business goals down to physical controls.
What You Will Learn:
The Rationale for Alignment: Why combining SABSA and ArchiMate is the "gold standard" for modern secure EA.
The Motivation Aspect: Modeling business drivers and security attributes using ArchiMate’s Motivation extension.
Layer-by-Layer Modeling: A step-by-step journey through Contextual, Conceptual, Logical, and Physical security architectures.
Tooling Excellence: How to use Archi (and advanced tools like jArchi scripts, PlantUML, and JSON) to automate and validate your models.
Practical Case Studies: Hands-on practice following patterns from the official "Guide to Modeling SABSA with the ArchiMate Specification."
Who is this for?
Security Architects wanting to move beyond spreadsheets and into model-based engineering.
Enterprise Architects (TOGAF/ArchiMate certified) looking to specialize in security.
Consultants who need to demonstrate compliance and risk management visually to stakeholders.
Through learning the Security Overlay modeling, you'll get chance to practice Archi, JSON, Protege, as well as FreePlane, enjoy!