This course is presented as
Live Virtual Training.
Click for more details.
World's leading Security Architecture
SABSA® is the world’s leading open security architecture framework and methodology. SABSA is a top-to-bottom framework and methodology to conceive, conceptualise, design, implement and manage security in a business-driven model.
The term ‘business-driven’ is the key to SABSA’s power, and its acceptance. SABSA is all about empowering the organisation to do business as it needs and wants to do, while ensuring that it is secured and fully enabled. SABSA is an open and inclusive standard that readily integrates with other frameworks and tools such as ITIL, 17799/27000 series, COBIT and the like. It can be used as a compliance and governance framework for complex sets of standards.
SABSA is used commonly as the security parallel and tool set for organisations using the world’s leading IT Architecture Framework – Zachman.
Why is SABSA so successful
SABSA is governed by The SABSA Institute. In the United Kingdom an “Institute” is not an ordinary company: it has a protected and highly-regulated status that guarantees:
- SABSA intellectual property can never be sold
- SABSA will always remain vendor-neutral
- SABSA will be free-use in perpetuity
- SABSA will have ongoing development to meet the needs of business
SABSA’s community can obtain true competency-based professional certifications that provide trust and confidence to peers and employers of an architect’s capabilities.
SABSA Roadmap
The SABSA Certification Program is structured into three areas – Foundation (the mandatory base for all certification), Advanced Modules (counting towards Practitioner and Masters certification), and Topical Master Classes (two-day non- exam events covering specialty areas and offering credits towards certification).
There are five core career streams:
- Advanced Risk, Assurance & Governance
- Advanced Architectural Design
- Advanced Architecture Programme Management
- Advanced Incident, Monitoring & Investigations Architecture
- Advanced Business Continuity & Crisis Management
A Brief History of SABSA – 21 years old this year (2018)
Read this blog for a fascinating account of the birth and development of SABSA, direct from the pen of SABSA co-founder John Sherwood.
Learning outcomes
SABSA Foundation
Module F1 - Security Strategy and Planning
This module provides participants with a comprehensive understanding of how the SABSA framework delivers successful security strategy and architecture. Through a series of innovative presentations, case studies and workshops, you will develop the skills to use the most proven security architecture design and management processes and find out how to develop a comprehensive strategy for the creation of a security architecture that genuinely meets the needs of your organisation.
The top ten competencies developed on this course are:
- Define enterprise security architecture, its role, objectives and benefits
- Describe the SABSA model, architecture matrix, service management matrix and terminology
- Describe SABSA principles, framework, approach and lifecycle
- Use business goals and objectives to engineer information security requirements
- Create a business attributes taxonomy
- Apply key architectural defence-in-depth concepts
- Explain security engineering principles, methods and techniques
- Use an architected approach to design an integrated compliance framework
- Describe and design appropriate policy architecture
- Define security architecture value proposition, measures and metrics
Module F2 - Security Service Management and Design
This module leverages the strategy defined in Foundation Module One to create the roadmap to design, deliver and support a set of consistent and high-quality security services.
Covering the good practice lifecycle, participants will find out how to design, deliver and support a comprehensive security services architecture that integrates fully and seamlessly with their existing IT management and business infrastructure and practices.
The top ten competencies developed on this course are:
-
- Use SABSA to create an holistic framework to align and integrate standards
- Describe roles, responsibilities, decision-making and organisational structure
- Explain the integration of SABSA into a service management environment
- Define Security Services
- Describe the placement of security services within ICT Infrastructure
- Create a SABSA Trust Model
- Describe and model security associations intra-domain and inter-domain
- Explain temporal factors in security and sequence security services
- Determine an appropriate start-up approach for SABSA Architecture
- Apply SABSA Foundation level competencies to your own environment
Who should attend
- CIO / CISO / CRO / CIRO
- IT Strategists and Planners
- IT Architects
- IT Development Managers and Project Leaders
- Software Managers and Architects
- Computer / Information Security Managers, Advisors, Consultants & Practitioners
- IT Line Managers
- IT Service Delivery Managers
- Risk Managers
- Internal and External Auditors
SABSA Key Points
SABSA is used extensively by global business and governments around the world.
- SABSA provides a world-leading approach to the development and deployment of solutions to manage cyber risk, assurance and security in a globally accelerating digital business environment.
- Since the launch of the SABSA certification program in 2007, InfoSec professionals in 43 countries have obtained SABSA Certification
- Top-tier banks around the globe have adopted SABSA for their security architecture framework
- Major Government departments - particularly those concerned with defence, security and law enforcement - have adopted SABSA
- The SABSA Institute and The Open Group have announced collaboration in the development of the next generation TOGAF. This joint development puts SABSA Business Attributes Profiling (BAP) at the heart of the TOGAF Architecture Development Method (ADM) for requirements management – not just for security, but also for all aspects of business requirements definition.
Course contents
This 5-day Foundation Certificate program has been designed to provide participants with a thorough coverage of the knowledge required for the SABSA Foundation Level Certificate. It is structured in two modules:
- Module F1: Security Strategy & Planning
- Module F2: Security Service Management
Module F1: Security Strategy & Planning
This module provides participants with a comprehensive understanding of how the SABSA framework delivers successful security strategy and architecture. Through a series of innovative presentations, case studies and workshops, you will develop the skills to use the most proven security architecture design and management processes and find out how to develop a comprehensive strategy for the creation of a security architecture that genuinely meets the needs of your organisation:
THE SABSA FRAMEWORK
1. Information Security Strategy, Benefits and Objectives
- Security: A Cultural Legacy as a Business Constraint
- Technical Legacy of Tactical Point Solutions
- Security Strategy, Tactics and Operations
- Critical Success Factors for Business, IT and Security
- Measuring and Prioritising Business Risk
- Enabling Business and Empowering Customers
- Adding Value to the Core Product
- Protecting Relationships and Leveraging Trust
2. Introduction to SABSA Best Practice
- Information Security and its Role in the Modern Enterprise
- Enterprise Security Architecture: Definition and Principles
- The History of SABSA Development
- Introduction to the SABSA Model
- The Business View of Security: Contextual Architecture
- The Architect’s View of Security: Conceptual Architecture
- The Designer’s View of Security: Logical Architecture
- The Builder’s View of Security: Physical Architecture
- The Tradesman’s View of Security: Component Architecture
- The Service Manager’s View of Security: Operational Architecture
- Traceability from Business Requirements to Deployed Solutions
- The SABSA Matrix and Service Management Matrix
INFORMATION SECURITY STRATEGY
3. Business Requirements & How To Define Them
- Business Goals, Success Factors and Operational Risks
- Business Processes and the Need for Security
- Location Dependence of Enterprise Security Needs
- Organisation and Relationships Affecting Enterprise Security
- Time Dependency of Enterprise Security
- Collecting Enterprise Requirements for Security
- Creating a Business Attributes Profile
- Defining Control Objectives
4. Strategic Concepts & How To Apply Them
- Managing Complexity
- Systems Engineering for Security
- Architectural Layering
- End-to-End Security
- Defence-in-Depth Models
- Security Domains
- Security Associations
- Trust Modelling
- Organisation & Workflow
- Infrastructure Strategy
- Management Strategy
SABSA PRACTITIONER GUIDE
5. The Strategy Programme & Architecture Delivery
- The SABSA Development Process
- The SABSA Lifecycle
- Strategy and Concept Phase Processes and Sub-processes
- Design Phase Processes and Sub-processes
- Implement Phase Processes and Sub-processes
- Manage and Measure Phase Processes and Sub-processes
- Top-down Decomposition of the SABSA Model
- Scope, Deliverables and Project Sequencing
6. Managing The Strategic Programme
- Introduction to Return on Investment & Return of Value
- Defining the Benefits and Value Propositions
- Selling the Benefits
- Getting Sponsorship and Budget
- Building the Team
- Team Competency Assessment & Development
- Programme Planning and Management
- ‘Fast Track’ Start-up Programmes
- Collecting the Information You Need
- Gaining Consensus on the Conceptual Architecture
- Strategic Architecture Governance, Compliance and Maintenance
- Identifying Quick Wins and Gaining Long Term Confidence
Module F2: Security Service Management
This module leverages the strategy defined in Foundation Module One to create the roadmap to design, deliver and support a set of consistent and high-quality security services. Covering the good practice lifecycle, participants will find out how to design, deliver and support a comprehensive security services architecture that integrates fully and seamlessly with their existing IT management and business infrastructure and practices:
THE SABSA SECURITY MANAGEMENT FRAMEWORK
1. The SABSA Security Management Framework
- SABSA in the I.T. Lifecycle
- Using SABSA To Integrate Other Methods, Models & Standards
- SABSA and the ITIL Framework
- SABSA and CobIT
- SABSA and Project Management Standards
- SABSA and ISO Security Standards
- SABSA and IT Architecture
THE SABSA SECURITY POLICY AND RISK MANAGEMENT FRAMEWORK
2. Security Policy Management
- Policy Principles
- Policy Content, Hierarchy & Architecture
- Security Policy Making
- Information & Systems Classification
- Third Party & Outsourcing Strategy & Policy Management
3. Operational Risk Management
- The Meaning of Risk
- Risk Philosophy & Methodology
- Corporate Governance & Enterprise Risk Management
- Risk Measurement and Risk Assessment
- Risk Mitigation
- Risk Appetite
- Risk Management Tools
- Measuring Success of Risk Management
THE SABSA INTEGRATED ASSURANCE MANAGEMENT FRAMEWORK
4. Security Organisation & Responsibilities
- Security Governance
- Security Culture Development, Training & Awareness
- Ownership & Custody
- Service Provider & Customer Roles in Security Management
- Enterprise Audit & Review Framework
5. Assurance of Operational Continuity
- Business Continuity Planning
- Contingency Planning
- Crisis Management
- Business Recovery Planning
6. Systems Assurance
- Technical Assurance of Security Correctness & Completeness
- Managing the Assurance Process for Systems & Software Development
- Assuring Integrity and Acceptable Use of Systems & Software
- Principles of Multi-phased Testing
SECURITY SERVICES DESIGN
7. Security Services Architecture
- Information as the Logical Representation of Business
- Logical Entities & Their Relationships
- Using Trust Models to Define Security Services
- Security Domains, Domain Definitions & Associations
- Security Processing Cycle
8. Security Infrastructure Services
- Security Rules, Practices & Procedures
- Security Mechanisms
- User Security
- Platform & Network Security
- Infrastructure for Service Delivery
- Technical Standards & Components
SECURITY SERVICES DELIVERY & SUPPORT
9. Operational Security Services
- Incident Management
- Incident Response
- Problem Management
- Change Management
- Continuity, Crisis & Recovery Management
10. Security Administration & Management
- Security Service Management
- Security Mechanism Management
- Security Component Management
- System Management & Administration
- User Management & Administration
- Security Audit Management
- Security Operations
- Product Evaluation & Selection
SECURITY SERVICES PERFORMANCE MEASUREMENT
11. Return on Investment & Return of Value
- Return on Investment
- Net Present Value
- Internal Rate of Return
- Defining Value Metrics
- Business Attributes & Return of Value
12. Security Measures & Metrics
- Why Do We Need Measures & Metrics
- Measurement Approaches
- Defining Metrics
- Benchmarking Security
- Remedial Project Planning
- Maturity Models Applied to Security
Course fees
Prerequisites:
The SABSA Foundation Level certification neither requires nor assumes any experience in any branch of security.
Examination:
Live Virtual Training – For students who attend a virtual SABSA course with ALC – you will be invited to sit an online exam held at a set date & time the week following the course. The exams are web-based and run via Synap & ProctorExam. Exact details on the exam date & time are provided at the time of booking.
Face-to-Face Training – Participants will be provided with a paper-based exam which is completed whilst at the course in the same venue of the course itself.
Each exam is of one-hour duration and contains 48 multiple choice questions. The SABSA Foundation Certificate is issued to candidates who pass both Foundation Level exams.
The SABSA Foundation exams:
Each of the two Foundation modules F1 and F2 consists of 48 multiple choice questions and candidates must score 75% or greater in each module to gain a Pass.
Each test module is of 60 minutes duration but candidates for whom English is not a first language may apply for an additional 15 minutes per module.
SABSA receives Open Group 2018 Award
Acknowledged as global thought leader in cyber security architecture
SABSA co-founder John Sherwood (middle) at Open Group Awards, London 17 April 2018.
The SABSA Institute received the 'Partnership Award’ for its outstanding partnership on several projects to develop both the TOGAF® Standard and Security ecosystem at The Open Group.
Full Open Group Awards List
New Security Architecture Practitioner’s Initiative
The Security Architecture Practitioner’s Initiative is a joint effort of The Open Group Security Forum (a global thought leader in Enterprise Architecture) and The SABSA Institute (a global thought leader in Security Architecture) to articulate in a clear, approachable way the characteristics of a highly-qualified Security Architect. Read more...
SABSA White Papers
The SABSA Institute has an interesting selection of White Papers.