This is a sel -a chi ed e sion o an o iginal a icle. This e sion
may di e om he o iginal in pagina ion and ypog aphic de ails.
Au ho (s):
Ti le:
Yea :
Ve sion:
Copy igh :
Righ s:
Righ s u l:
Please ci e he o iginal e sion:
CC BY 4.0
h ps://c ea i ecommons.o g/licenses/by/4.0/
Me hod F amewo k o De eloping En e p ise A chi ec u e Secu i y P inciples
© 2019 Sa a La no e al
Published e sion
La no, Sa a; Seppänen, Ville; Nu mi, Ja kko
La no, S., Seppänen, V., & Nu mi, J. (2019). Me hod F amewo k o De eloping En e p ise
A chi ec u e Secu i y P inciples. Complex Sys ems In o ma ics and Modeling Qua e ly, 117(20),
57-71. h ps://doi.o g/10.7250/csimq.2019-20.03
2019
Complex Sys ems In o ma ics and Modeling Qua e ly (CSIMQ)
eISSN: 2255-9922
Published online by RTU P ess, h ps://csimq-jou nals. u.l
A icle 117, Issue 20, Sep embe /Oc obe 2019, Pages 57–71
h ps://doi.o g/10.7250/csimq.2019-20.03
Me hod F amewo k o De eloping En e p ise A chi ec u e
Secu i y P inciples
Sa a La no, Ville Seppänen
*
and Ja kko Nu mi
Facul y o In o ma ion Technology, Uni e si y o Jy askyla, Ma ilanniemi 2,
Jy äskylä, FI-40014, Finland
sa a.la [email protected], ille. .seppanen@jyu. i, ja samnu@s uden .jyu. i
Abs ac . O ganiza ions need o conside many ace s o in o ma ion secu i y in
hei daily ope a ions – among o he s, he apidly inc easing use o IT, eme ging
echnologies and digi aliza ion o o ganiza ions’ co e esou ces p o oke new
h ea s ha can be di icul o an icipa e. I has been a gued ha he secu i y and
p i acy conside a ions should be embedded in all he a eas o o ganiza ional
ac i i ies ins ead o only elying echnical secu i y mechanisms p o ided by he
unde lying sys ems and so wa e. En e p ise A chi ec u e Managemen (EAM)
o e s a holis ic app oach o managing di e en dimensions o an o ganiza ion,
and can be concei ed as a cohe en and consis en se o p inciples ha guide
how he en e p ise mus be designed. This a icle con ibu es wi h a me hod
amewo k o in eg a ing in o ma ion secu i y wi h EAM, aimed a p o iding
suppo o he decision-making ela ed o o mula ing con ex -awa e EA
secu i y p inciples. The p esen ed me hod amewo k is a esul o a
cons uc i e esea ch based on bo h he heo e ical body o knowledge and he
empi ical e idence, ob ained by in e iewing 35 Finnish EA and in o ma ion
secu i y p ac i ione s.
Keywo ds: En e p ise A chi ec u e Managemen , En e p ise A chi ec u e
P inciple, In o ma ion Secu i y, In o ma ion Secu i y Policy, Me hod
F amewo k, Cons uc i e Resea ch.
1 In oduc ion
O ganiza ions cons an ly ace new challenges in he a ea o in o ma ion secu i y. Digi al
ans o ma ion, ne wo ked business models, con inuously e ol ing o ganiza ions, eme ging
echnologies, inc easing complexi y o in o ma ion sys ems and echnology landscapes,
egula o y p essu es and changes in legisla ion, and se e al o he ac o s necessi a e ha
o ganiza ions mus cons an ly keep hei eye on he secu i y equi emen s and ede ine hem as
needed. As an example, since May 2018 he en e p ises ope a ing in Eu ope ha e been obliga ed
*
Co esponding au ho
© 2019 Sa a La no e al. This is an open access a icle licensed unde he C ea i e Commons A ibu ion License
(h p://c ea i ecommons.o g/licenses/by/4.0).
Re e ence: S. La no, V. Seppänen and J. Nu mi, “Me hod F amewo k o De eloping En e p ise A chi ec u e Secu i y
P inciples,” Complex Sys ems In o ma ics and Modeling Qua e ly, CSIMQ, no. 20, pp. 57–71, 2019. A ailable:
h ps://doi.o g/10.7250/csimq.2019-20.03
Addi ional in o ma ion. Au ho ’s ORCID iD: V. Seppänen – h ps://o cid.o g/0000-0003-3843-4843. PII S225599221900117X.
Recei ed: 30 May 2019. Accep ed: 23 Oc obe 2019. A ailable online: 31 Oc obe 2019.
58
o comply wi h he Gene al Da a P o ec ion Regula ion (GDPR); and ailing o gua an ee
o ganiza ional secu i y and p i acy o hei cus ome s’ pe sonal da a may lead o subs an ial
ines. I has been a gued ha nowadays he secu i y and p i acy conside a ions should be
embedded in all he a eas o o ganiza ional ac i i ies ins ead o only elying on echnical secu i y
mechanisms ha unde lying sys ems and so wa e p o ide [1], [2].
The en e p ise a chi ec u e (EA) managemen (EAM) has been seen as a iable app oach o
in eg a ing di e en laye s o in o ma ion secu i y and aligning hem wi h he con ex o
con inuously changing business equi emen s. (e.g. [3]). As s a ed by The Open G oup [4, p.1]
“ o oo long, in o ma ion secu i y has been conside ed a sepa a e discipline, isola ed om he
business p ocesses and En e p ise A chi ec u e”. Al hough some esea ch on secu i y and EA
exis ( o ins ance, en e p ise p i acy a chi ec u e (EPA), en e p ise secu i y a chi ec u e (ESA),
en e p ise in o ma ion secu i y a chi ec u e (EISA) and She wood Applied Business Secu i y
A chi ec u e (SABSA)), hese app oaches p opose addi ional a chi ec u es o ein o ce he
exis ing EA me hod [3]. As discussed la e in his a icle, he in o ma ion secu i y policy is
di ided in o h ee ca ego ies o abs ac ion encompassing he whole o ganiza ion [5], hus
necessi a ing he secu i y pe spec i es o be imme sed in o EA i sel , ins ead o being addi ional
a chi ec u al iewpoin s o ex ensions. As a gued in [25], he cu en app oaches o en ocus
solely on in o ma ion sys ems and echnology componen s o he a chi ec u e, and as such do no
o e a equisi e holis ic app oach o in eg a e he in o ma ion secu i y wi h he p ac ices o
EAM. Second, p io esea ch is ocused on discussing he isk managemen aspec s on
in o ma ion secu i y. While, o ins ance, En e p ise A chi ec u e-Based Risk and Secu i y
Modelling and Analysis (ERSM) sugges s secu i y p inciples, no guidance o he de elopmen
o he p inciples is gi en.
Acco ding o [6], he en i e EA can be concei ed as a cohe en and consis en se o p inciples
ha guide how he en e p ise mus be designed, making EA p inciples a iable ins umen o
achie ing o ganiza ional secu i y. The objec i e o his s udy is o de elop an abs ac design
knowledge a e ac in he o m o a me hod amewo k o in eg a ing in o ma ion secu i y
p inciple de elopmen wi h he EAM. As a p ac ical con ibu ion, he a icle p o ides suppo o
decision-making ela ed o o mula ing con ex -awa e EA secu i y p inciples, while a heo e ical
con ibu ion can be ound om he co e age o wo dis inc ye in e ela ed s eams o esea ch:
in o ma ion secu i y and EA. The p esen ed me hod amewo k is he esul o he cons uc i e
esea ch based on bo h he heo e ical body o knowledge and he empi ical e idence, which was
ob ained by in e iewing 35 Finnish EA and in o ma ion secu i y p ac i ione s.
The emainde o his a icle is o ganized as ollows. In he nex sec ion we ou line he
heo e ical ounda ion o his s udy by discussing i s co e concep s, i.e. he en e p ise
a chi ec u e p inciples and secu i y policies, and hei possible ela ion o each o he . The hi d
sec ion desc ibes ou cons uc i e esea ch p ocess phase by phase, and hen he ou h sec ion
p esen s he esul s o he cons uc i e wo k. The i h sec ion p o ides a discussion on he
esul s. Finally, he six h sec ion concludes he pape , add esses limi a ions o he s udy, and
sugges s opics o u he esea ch.
2 Theo e ical Backg ound
This sec ion discusses he key concep s o he esea ch domain and es ablishes he heo e ical
ounda ions o he cons uc i e pa o he s udy. The i s sec ion add esses he en e p ise
a chi ec u e and, mo e speci ically, he en e p ise a chi ec u e p inciples, and he second co e s
he concep o in o ma ion secu i y policy. While he clea dis inc ion be ween he e ms
p inciple and policy is no always d awn (c ., [7]), in he ollowing we cha ac e ize he o me as
a ule o be ollowed and he la e as collec ion o guidelines o be adop ed. By discussing hese
concep s, we aim o add ess he need o and he cu en lack o a holis ic app oach o
in eg a ing aspec s o in o ma ion secu i y in o he EAM.
59
2.1 En e p ise A chi ec u e P inciples
The EAM o e s a holis ic app oach o managing di e en dimensions o an o ganiza ion, such
as i s goals and objec i es, business ac i i ies, so wa e applica ions, da a and in o ma ion, and
echnology in as uc u es. I os e s he use o common language and suppo s he co-ope a ion
be ween s akeholde g oups [8]. EAM is widely used in s a egy o ma ion, planning, and
implemen a ion and in aligning business capabili ies wi h he suppo ing IT esou ces [9].
To s uc u e and guide he EAM- ela ed ac i i ies, o ganiza ions use di e en me hodologies,
which ha e been de eloped bo h in he academia and indus y. The o igins o he mode n EA
can be aced o he Business Sys ems Planning me hodology in he 1960s [10]. Howe e , he
e m “en e p ise a chi ec u e” and he ela ed e minology we e coined la e in he ea ly
publica ions ega ding he PRISM a chi ec u e amewo k (c ., [11]) and he Zachman
F amewo k [12]. Cu en ly, The Open G oup A chi ec u e F amewo k (TOGAF®), in oduced
in 1995, is he mos widely adop ed EA me hodology in he indus y [13]. Howe e , mos o he
o ganiza ions ha e aken a “hyb id amewo k app oach”. [14] a gues ha no single
me hodology mee s all equi emen s o add esses all he needs o a pa icula o ganiza ion [13].
In a hyb id app oach, aspec s, ideas and app oach a e combined om a mul iple di e en
me hodologies and amewo ks.
The e a e some cha ac e is ics ha a e common o he majo i y o EAM me hodologies. These
include he sepa a ion o di e en iewpoin s (such as business- ela ed elemen s and echnology-
ela ed elemen s) when an o ganiza ion’s a chi ec u al s uc u es a e being designed o cons i u e
an aligned whole. Second, a chi ec u al planning and de elopmen is ad ised o conside he
cu en s a e o he a chi ec u al s uc u es in ela ion o he desi ed a ge s a e ha would be e
se e he implemen a ion o business objec i es. By analyzing gaps be ween he cu en and
desi ed s uc u es, i is possible o iden i y and p io i ize he ele an a eas o de elopmen .
Thi d, he EA amewo ks, which can be conside ed as a o m o en e p ise on ology (c ., [15],
[16], [17]), p o ide di e en iewpoin s and di e en le els o abs ac ion (such as con ex ual,
concep ual, logical and physical) o di e en s akeholde s and hei dis inc i e needs. Fo
ins ance, a CIO migh be in e es ed in inding ou da ed so wa e applica ions using he o e all
iew p o ided by he applica ion po olio model, while a so wa e de elope designing he bes -
i ed in eg a ion app oach migh be in e es ed in s udying he APIs suppo ed by he cu en
in o ma ion sys ems a chi ec u e. The design o ac ual implemen able a chi ec u al s uc u es is
guided by he s a egy-le el conside a ions. Fo ins ance, along wi h he business a chi ec u e,
in o ma ion sys ems a chi ec u e, and echnology a chi ec u e, he TOGAF® con en me amodel
sepa a es he a chi ec u e ision de i ed om he business and echnology s a egies, he
a chi ec u e equi emen s and cons ain s, and he a chi ec u e p inciples, which o mula e he
gene al unde lying ules and guidelines o he a chi ec u e de elopmen .
As he p inciples mani es gene al ules and guidelines o suppo an o ganiza ion ul illing i s
mission, de ining he a chi ec u e p inciples is ecommended as he ini ia ing ac i i y o EAM
[18]; whe eas p inciples cons i u e a ounda ion o hinking abou he sys ems design [19] and
he equi emen s, and, on he o he hand, s a e he unc ional and cons uc ional p ope ies o a
sys em o ha e [20]. The e o e, he p inciples can be seen as bounda y condi ions om which he
implemen able equi emen s a e de i ed.
The EA p inciples can ei he se e as he designing p inciples ha a e used o desc ibe he
design o ac ual sys em a e ac s o he egula i e p inciples o con ey a p esc ip i e no ion
limi ing he design op ions allowed in a sys em design [21]. [20] cha ac e izes he EA p inciples
being he la e . I is a gued ha he EA p inciples a e a speci ic o m no ma i e p inciples ha
“guide/di ec he en e p ise no ma i ely es ic ing design eedom” [20, p. 11]. No ma i e
p inciples a e based on a i ac s such as s a egy, he exis ing en i onmen , and ex e nal
de elopmen s [20]. The EA p inciples pu sue he o ganiza ion-wide consensus in he
de elopmen , main enance, and use o EA as well as in guiding i s implemen a ion as ope a ional
ac i i ies and suppo ing asse s. As such he p inciples b idge he s a egy and ope a ions. In
60
p ac ice, he EA p inciples a e widely o mula ed in o ganiza ions and used, o ins ance, o
e iewing de elopmen ini ia i es and p ojec s. The e o e, he documen a ion and
communica ion o EA p inciples is essen ial. The documen a ion should include, as a p o ound
elemen , a clea de ini ion o a p inciple’s s uc u e and he ela ions i has wi h i s en i onmen
[22]. Fu he mo e, he documen a ion should add ess he p inciple’s mo i a ing a ionale,
conc e e implica ions, and measu es wi h which i s ul illmen is e alua ed [23], [24].
2.2 In o ma ion Secu i y Policy
O ganiza ions need o conside many ace s o in o ma ion secu i y in hei daily ope a ions. The
apidly inc easing use o IT, eme ging echnologies and digi aliza ion o o ganiza ions’ co e
esou ces p o oke new h ea s ha can be di icul o an icipa e [25]. A acks ha damage o
modi y da a can a ec he c i ical in as uc u e wi hou any awa eness o i s owne . I is
no ewo hy ha a he same ime as new secu i y h ea s ha e appea ed alongside eme ging
echnologies, an inc easing numbe o h ea s a e loca ed inside he o ganiza ion. Many o hese
h ea s a e caused by unin en ional, ca eless o negligen beha io [26], [27], [28]. The e o e, a
majo i y o he li e a u e on in o ma ion secu i y ocuses on he use 's pe spec i e and how he
use s o in o ma ion and echnology esou ces can by hei ac ions p e en , de ec and espond o
secu i y h ea s [29].
In o ma ion secu i y also encompasses da a sou ces ha a e no in digi al o ma s. In o ma ion
ha is based on physical documen s o employees' knowledge can as well be a a ge o secu i y
h ea s [30]. Indi idual knowledge can be a key compe i i e ad an age o an o ganiza ion and
he e o e needs o be p o ec ed. In o ma ion secu i y ulne abili ies con ain a signi ican isk, no
only o he ope a ions o an o ganiza ion, bu also om he poin o iew o he o ganiza ion’s
epu a ion. To his end, se e al o ganiza ions ha e been inc easingly ocusing on de eloping
sa e y- ela ed policies and aligning hem wi h non-o ganiza ional egula ions.
The numbe o s udies on he implemen a ion and e iciency o in o ma ion secu i y has
signi ican ly inc eased in he 21s cen u y and he in o ma ion secu i y policy de elopmen is an
a ea o g owing schola ly in e es . Gene ally, he concep o he in o ma ion secu i y policy is
di ided in o he h ee ca ego ies o abs ac ion. A he lowes le el o abs ac ion, in o ma ion
secu i y is looked a om a echnical poin o iew [5]. A his le el, he key conce n is he
secu i y a chi ec u e o echnical sys ems, usually ocusing on s anda ds and p ocedu es o he
sys ems con igu a ion o main enance. A he nex le el o abs ac ion, in o ma ion secu i y is
iewed om he use 's poin o iew [5]. He e, ce ain a eas o echnology, such as he use o
in e ne se ices, a e add essed. These policies may include ins uc ions and p ocedu es ha
employees mus obse e in hei daily in e ac ions wi h he in o ma ion and echnology
esou ces. The majo i y o ex an esea ch li e a u e is examining he secu i y policies h ough an
indi idual and ope a ional abs ac ion le el [29]. A he highes le el o abs ac ion, he
in o ma ion secu i y is app oached om he senio managemen poin o iew [5]. A his le el,
ins ead o he ac ual ope a i e p inciples, he ocus is on he s a egic di ec ion o he
o ganiza ion and he ex en and na u e o secu i y objec i es. These guide he de elopmen ,
implemen a ion and managemen o he secu i y p og ams and assign esponsibili ies o he
a ious secu i y a eas a he mos abs ac , philosophical le el [29].
To gain a needed b oade pe spec i e on he p oblem a ea, he opic o secu i y has been
app oached om he pe spec i es o policy compliance and in o ma ion secu i y cul u e [29].
Howe e , [31] a gue ha he ex an li e a u e on in o ma ion secu i y policies ocuses on
desc ibing he s uc u es and con en , bu usually does no desc ibe a de ailed de elopmen
p ocess. The p o essionals in ol ed in he in o ma ion secu i y policy de elopmen a e p o ided
wi h li le knowledge abou he p ocesses hey should ollow. They o en need o ely on
guidelines which a e no speci ically designed o hei o ganiza ions and hus ail o ecognize
and answe o hei speci ic h ea s and equi emen s [5], [31].
61
Fo cons uc ing he in o ma ion secu i y policy, [5] a gues o h ee ma e s o be conside ed.
Fi s , an o ganiza ion mus be able o compile and upda e i s in o ma ion secu i y policy in an
agile manne . This is especially impo an when he o ganiza ion s i es o a change ha may
con lic wi h he exis ing in o ma ion secu i y policy. Howe e , his does no mean ha he
in o ma ion secu i y objec i es should be igno ed, bu he secu i y elemen s should, as quickly as
possible, be aligned wi h he changed equi emen s. The goal is ha he o ganiza ion is bo h
capable o e ec i ely seeking he change, bu also capable o achie ing an app op ia e le el o
in o ma ion secu i y. This kind o agile aspec is essen ial as o ganiza ional change can also help
o mee he in o ma ion secu i y equi emen s. The e o e, he p inciples o managing he
in o ma ion secu i y mus always be synch onized wi h he o ganiza ional p io i ies and he
p ocesses ha suppo hese goals.
The second ma e is poli ical simplici y. [5] no es ha in lexible policies induce sec e and
poo ly conside ed non-compliance. The e o e, he p ocess o policy cons uc ion mus be
anspa en , awa e o i s con ex , and in ol e he s akeholde s a he di e en le els o an
o ganiza ion. The policy- ela ed decisions need o be well- easoned and hei implica ions
explici . Thi dly, an in o ma ion secu i y policy mus implemen he exis ing c i e ia ha can be
ob ained, o ins ance, om legisla ion o o ganiza ion's own p io i ies. I should be no ed,
howe e , ha i hese c i e ia a e no de ailed, i is pe missible o policy make s o ha e a be e
chance o esponding lexibly in modi ying he o ganiza ion's in o ma ion secu i y policy so ha
he o ganiza ion can eac e icien ly in he o ganiza ional changes.
Cybe secu i y isks a e socio- echnical in na u e as hey include no only echnical
ulne abili ies bu o en also include ac o s ela ed o beha io o human ac o s [28].
Consequen ly, se e al esea che s ha e ph ased he po en ial o he EAM o se e as an
encompassing ins umen o app oaching in o ma ion secu i y ela ed ques ions. Fo ins ance,
[32] no es ha he EAM p o ides a mean o mi iga e he limi ing siloed hinking o adi ional
isk managemen p ocesses as i gi es a be e unde s anding on how an asse and i s alue can
be a ec by a mani es a ion o a isk. Simila ly, [2] a gues ha he EAM is a p omising app oach
o deal wi h he inc easing complexi y o o ganiza ions, echnologies and he ela ed secu i y
h ea s. Mos o he cu en e o s, howe e , ha e ocused only on indi idual a eas on he
domain o EAM, such as in o ma ion sys ems isk managemen (e.g. [2], [33], [34]). The e o e,
as a gued in [35], he holis ic app oach o he secu i y in EA is s ill lacking.
3 The Cons uc i e Resea ch App oach
As s a ed p e iously, he objec i e o his s udy is o de elop an abs ac design knowledge
a e ac . Design knowledge, p oduced by design esea ch, can be sepa a ed in o wo ou comes,
namely, abs ac and si ua ional design knowledge. Abs ac design knowledge comes om
me a-design, o ins ance, li e a u e e iew, modelling and engagemen schola ship [36] and
p oduces abs ac concep s, gene ic models, guidelines o design p ac ices and sys ems
abs ac ions wi h key p ope ies [36]. The me hod amewo k is c ea ed based on he li e a u e
om bo h esea ch ields: he EA and he in o ma ion secu i y. Engagemen schola ship was
execu ed h ough in e iews.
Bo h he me a-design and he design p ac ice ha e di e se ypes o e alua ion ha should be
conduc ed du ing he design and de elopmen phase. Design science e alua ion has wo o ms:
a i icial and na u alis ic e alua ion [46] o which a i icial e alua ion was used in his s udy. In
design science esea ch, he e a e wo e alua ion ela ed phases, e alua ion and demons a ion.
In his s udy, he demons a ion phase was conduc ed as a se ies o expe in e iews.
In e iewees we e asked o e alua e he sui abili y o he me hod amewo k, and he a e ac
was e alua ed based on he iews o he in e iewees. The me hod amewo k was modi ied he
i s ime a e ou in e iews, and he second ime a e all he nine in e iews we e conduc ed.
In he ield o me hod enginee ing, i is o en a gued ha no me hod is sui able as such and
some si ua ional adap a ion is always needed. The me hod adap a ion e e s o he ac i i ies o
62
enhancemen , ex ension o es ic ion o make a me hod sui able o a speci ic domain, an
o ganiza ion, o a p ojec [14], [37], [38]. Adap abili y o he EA me hods is pa icula ly
impo an due o he conside able he e ogenei y o o ganiza ions and hei business en i onmen s
[39], [40], [41], [42]. In compa ison o a me hod, a me hod amewo k is pu pose ully a mo e
abs ac me hodological elemen ha suppo s he de ini ion o me hods [43]. The me hod
amewo k can be conside ed as a gene aliza ion o a me hod, which is hen adjus ed and
speci ied o he con ex o a ce ain o ganiza ion.
This sec ion desc ibes s ep-by-s ep he cons uc i e esea ch p ocess ha adop s ideas om
se e al no able wo ks on he design science esea ch (e.g. [44], [45], [46], [47]). Also, he goals
and equi emen s ega ding he me hod amewo k’s con en and expedience a e p esen ed.
Figu e 1 summa izes he phases o he esea ch p ocess ha was ollowed while cons uc ing he
Me hod F amewo k o En e p ise A chi ec u e Secu i y P inciples (MF4EASP).
Figu e 1. The phases o he esea ch p ocess and he accompanying sou ces o in o ma ion
3.1 P oblem Iden i ica ion and Mo i a ion
The p oblem, i.e. he need o and he cu en lack o a holis ic app oach o in eg a ing aspec s
o in o ma ion secu i y in o EAM, has been aised in ecen s udies. Fo ins ance, a s udy [35]
a gues ha he in eg a ion o secu i y and isk ela ed conce ns in o he holis ic app oaches o
EAM a e cu en ly a an inadequa e le el. Consequen ly, ecen e o s ha e ocused on
in o ma ion sys ems isk managemen (e.g. [2], [7], [35], [48]). Howe e , in a e iew o 15 yea s
o academic EA endea o s, a s udy [1] no es ha al hough some p og ess has been made, EA has
no ye eached he s a e o being a iable ool o add essing eme ging secu i y challenges and
new h ea s o o ganiza ions’ complex in o ma ion sys ems. Fo ins ance, al hough EAM is
manda ed by legisla ion in he Finnish public sec o , he Na ional Audi O ice o Finland, in
hei 2017 epo , disco e ed se e al p oblems in he a ea o in o ma ion secu i y. Thei epo
s a es ha EA desc ip ions would se e as a aluable ool o e alua ing he c i icali y o
elec onic se ices bu EAM is no p ope ly in eg a ed wi h he ope a ional equi emen s and
p ac ices. I was also ound ha he c i icali y o he ICT sys ems is no egula ly checked,
63
al hough he equen changes occu ing in he ope a ing en i onmen would absolu ely need i .
Finally, he epo s a es ha he in o ma ion secu i y is commonly ins i u ed as he esponsibili y
o he IT uni s, e en hough hey may no be awa e o all he necessa y business- ela ed
conce ns, and he eby he holis ic iew o he in o ma ion secu i y emains lacking.
3.2 Requi emen s and Objec i es
We analyzed he ich quali a i e da a ob ained by in e iewing 26 seasoned expe s on EA, who
con ibu ed o he p oblem iden i ica ion and o cap u ing he equi emen s and objec i es o he
MF4EASP. These in o man s se e in di e en posi ions in bo h p i a e IT companies and
public sec o and hei expe ience in EA- ela ed ac i i ies ange om 3 o 40 yea s wi h he
a e age o 15 yea s. The in e iews add essed he in o man s’ iews o he pas , p esen and
u u e p ac ices o EAM. The da a we e sc eened o he in o ma ion ele an o he objec i es o
his s udy. The de ails o he da a collec ion can be ound in [48]. The iden i ied gene ic
equi emen s o he MF4EASP a e p esen ed in Table 1. These a e accompanied wi h he
ep esen a i e examples o ci a ions om he in e iew ansc ip s. The exce p s a e ansla ed
om Finnish o English.
Table 1. The guiding equi emen s o he de elopmen o MF4EASP
Requi emen
In o man s
Example om an in e iew
1) In o ma ion secu i y should be included
in e e y aspec o EAM.
1, 3, 5, 9, 10,
13, 14, 19, 22
“In o ma ion secu i y mus be aken in o
accoun in all he a chi ec u al solu ions
h ough all he [a chi ec u e] laye s.”
2) In o ma ion secu i y should be included
in EA design p inciples.
1, 12
“Secu i y canno be jus a glued-on
conce n. I mus be a design p inciple.”
3) Risk managemen should be an in eg al
pa o EAM.
1, 2, 5, 20
“Yes, we ha e been ocusing ou a en ion
o ha [ he EA me hod] could guide he
in o ma ion secu i y and isk
managemen .”
4) In o ma ion secu i y managemen
p ac ices should be adap able o he pu pose
o he o ganiza ion.
5, 8, 15, 23, 25
“[Planning o he in o ma ion secu i y]
should be pu pose-d i en. I mean, wha
a e he needs o he business and
ope a ional unc ions. And wha a e he
ela ed isks. Then you can conclude wha
kind o in o ma ion p o ec ion o secu i y
you eally need. Tha way, you don’
always ca ego ically need o ake he
ha des oad.”
5) Silo-men ali y mus be disman led.
2, 6, 7, 19, 21
“I is also o en he case he e ha he e
a e silos among expe s. The in e ac ion
and co-ope a ion a e needed. And in a
way, o cou se, he EAM is a p e y good
ool o acili a ing ha con e sa ion.”
6) A means o deal wi h legisla i e demands
and egula o y p essu es should be p o ided.
3, 5, 11,16, 17,
19, 26
“[Regula i e laws] a e e y ex ensi e
[and] hey pose la ge and complex
equi emen s. EAM is an app op ia e ool
o dealing wi h hem.”
8) In o ma ion secu i y p ac ices mus be
able o espond o changes aking place in
he ope a ing en i onmen s.
13, 17, 18, 20,
24, 26
“I hink ha he numbe o cloud-based
solu ions and hyb id solu ions, whe e
some o he in o ma ion is s o ed locally
and some o i in he cloud, [will con inue
o inc ease]. You need o be able o
con inuously change he way you do you
wo k.”
64
3.3 Design and De elopmen
The o e all s uc u e o he a e ac p esen ed in his pape d aws om he p e ious wo ks on
he design o EA p inciples and in o ma ion secu i y policies. A numbe o academic
con ibu ions on he EA p inciple de elopmen can also be ound (e.g. [6], [23], [24]), al hough
hei applicabili y is somewha limi ed due o hei gene ali y and pu pose ully wide scope.
Based on he li e a u e e iew [49], he consolida ed me amodel o EA p inciples has been
p esen ed [22]. By i emizing he elemen s o a p inciple, his me amodel di e en ia es he co e
de ini ion o he EA p inciple, including i s s a emen , a ionale, implica ions, key ac ions, and
ela ed measu es, and also p o ides an ex ended de ini ion ha conside s he p inciple’s impac
on i s en i onmen . We used he wo k p esen ed in [22] o de ining he key componen s and he
a eas o conce n o MF4EASP.
Nex , o he s uc u e o EA secu i y p inciple de elopmen p ocess, we adap ed he p ocess
o he policy de elopmen amewo k [31] and he ele an componen s p esen ed in he
Comp ehensi e In o ma ion Secu i y Policy P ocess Model [50]. Finally, we s i ed o balance
he equi emen s ound in ou empi ical da a wi h he equi emen s o suppleness, poli ical
simplici y and c i e ion-o ien a ion as discussed in ela ion o in o ma ion secu i y me a-policy in
[5].
The MF4EASP was cons uc ed using he A chiMa e® 3.0.1 speci ica ion. The A chiMa e®
modeling language is an Open G oup s anda d, which p o ides a TOGAF® complian modeling
no a ion ha co e s all he EA domains. I is widely used in bo h public and p i a e
o ganiza ions a ound he wo ld and is suppo ed by he majo i y o EA modeling ools. As a
semi- o mal modeling language, i p o ides a cohe en and isually uni o m ep esen a ion o
EA a e ac s co e ing di e en componen s o an a chi ec u e and hei dependencies. As such i
aims a enabling communica ion among s akeholde s, and guides complica ed change p ocesses
on a chi ec u al s uc u es.
3.4 Demons a ion and E alua ion
Nine expe p ac i ione s ook pa in e alua ing he en a i e e sions o MF4EASP. The
e alua o s we e selec ed using he c i e ion sampling (c. ., [48]) so ha he in o man s could
p o ide p o ound and well- easoned insigh s o suppo he u he de elopmen o he cons uc .
Fou o he e alua o s ha e hei expe ise bo h in he ields o EA and in o ma ion secu i y,
h ee in he in o ma ion secu i y, and wo in he EA. Thei occupa ional posi ions included Chie
In o ma ion O ice , Chie Digi al O ice , En e p ise A chi ec , Specialis , Resea che , and
di e en manage ial posi ions. The e alua o s’ p o essional expe ience in he ield o hei
expe ise anged om 2 o 30 yea s wi h he a e age o 14 yea s.
The e alua ion o he me hod amewo k was conduc ed by p esen ing he MF4EASP o he
e alua o who was hen asked o gi e eedback, c i icism and cons uc i e ideas ega ding
a ious aspec s. Each e alua o was me indi idually by he i s au ho , o ensu e ha hei
iews and opinions would no a ec he o he e alua o s. The aspec s o e alua ion we e based
in he me hod enginee ing knowledge and adhe ed o shell model p esen ed in [52]. Table 2
p esen s he hemes co e ed du ing he e alua ion and he ques ions hey we e add essed wi h.
O e all, he e alua ion was a ge ed o he co ec ness, comple eness and applicabili y o he
MF4EASP.
The e alua ion was conduc ed o he wo e sions o MF4EASP in he wo ounds. Some
changes we e implemen ed o he i s e sion o cons uc acco ding o he eedback gi en by
he i s ou e alua o s. These included, o ins ance, a possibili y o bo h objec i es and
cons ain s o de ine equi emen s o design p inciples, he acknowledgemen o possible
s akeholde -induced isks, and ha he p ocess needs o, in addi ion o secu i y p inciple
de elopmen , conside hei implemen a ion in an o ganiza ion.
71
[33] F. Inne ho e -Obe pe le and R. B eu, “Using an En e p ise A chi ec u e o IT Risk Managemen ,” P oc. o
he ISSA 2006 om Insigh o Fo esigh Con e ence, 2006.
[34] J. S. Bu ke , “Business Secu i y A chi ec u e: Wea ing In o ma ion Secu i y in o You O ganiza ion’s
En e p ise A chi ec u e h ough SABSA®,” In . Secu . J., ol. 21, no. 1, pp. 47–54, 2012. A ailable:
h ps://doi.o g/10.1080/19393555.2011.629341
[35] H. Jonke s and D. Qua el, “G aphical Models o Secu i y,” Thi d In e na ional Wo kshop, G aMSec 2016,
ol. 9987, pp. 94–101, 2016. A ailable: h ps://doi.o g/10.1007/978-3-319-46263-9_6
[36] Ł. Os owski, M. Hel e and F. Hossain, “A concep ual amewo k o design science esea ch,” P oc. o he
In e na ional Con e ence on Business In o ma ics Resea ch, Sp inge , LNBIP, ol. 90, pp. 345–354, 2011.
A ailable: h ps://doi.o g/10.1007/978-3-642-24511-4_27
[37] J. Raly e e al., “Towa ds a Gene ic Model o Si ua ional Me hod Enginee ing To ci e his e sion : Towa ds a
Gene ic Model o Si ua ional Me hod,” P oc. o he In . Con . Ad . In . Sys . Eng., Sp inge , LNCS, ol. 2681,
pp. 95–110, 2012. A ailable: h ps://doi.o g/10.1007/3-540-45017-3_9
[38] M. Leppänen, An On ological F amewo k and a Me hodical Skele on o Me hod Enginee ing: A Con ex ual
App oach. Jy äskylä S udies in Compu ing 52, 2005.
[39] M. Leppänen, K. Val onen, and M. Pulkkinen, “Towa ds a Con ingency F amewo k o Enginee ing an
En e p ise A chi ec u e Planning Me hod,” P oc. o 30 h In o ma ion Sys ems Resea ch Semina in
Scandina ia, 2007.
[40] C. Riege and S. Aie , “A Con ingency App oach o En e p ise A chi ec u e Me hod Enginee ing,”
In e na ional Con e ence on Se ice-O ien ed Compu ing, Sp inge , LNCS, ol. 5472, pp. 388–399, 2008.
A ailable: h ps://doi.o g/10.1007/978-3-642-01247-1_39
[41] K. Val onen, V. Seppänen, and M. Leppänen, “Go e nmen en e p ise a chi ec u e g id adap a ion in Finland,”
P oc. o he 42nd Annual Hawaii In e na ional Con e ence on Sys em Sciences, HICSS, 2009. A ailable:
h ps://doi.o g/10.1109/hicss.2009.232
[42] S. Buckl, “De eloping o ganiza ion-speci ic en e p ise a chi ec u e managemen unc ions using a me hod
base,” Ph.D. disse a ion, Technische Uni e si ä München, Leh s uhl ü In o ma ik XIX, 2011.
[43] C. Sal iano, A. Zoucas, J. Sil a, Â. Al es, C. G. on Wangeheim, and M. Thi y, “A Me hod F amewo k o
Enginee ing P ocess Capabili y Models,” 16 h Eu . Sys . So w. P ocess Imp o . Inno . Ind. Eu oSPI 2009.,
ol. 1, pp. 25–36, 2009.
[44] S. T. Ma ch and G. F. Smi h, “Design and na u al science esea ch on in o ma ion echnology,” Decis. Suppo
Sys ., ol. 15, no. 4, pp. 251–266, 1995. A ailable: h ps://doi.o g/10.1016/0167-9236(94)00041-2
[45] A. R. He ne , S. T.Ma ch, J. Pa k, and S. Ram, “Design Science in In o ma ion Sys ems Resea ch,” MIS Q.,
ol. 28, no. 1, pp. 75–105, 2004. A ailable: h ps://doi.o g/10.2307/25148625
[46] J. Venable, “The ole o heo y and heo ising in Design Science esea ch,” P oc. DESRIST, pp. 24–35, 2006.
[47] K. Pe e s, T. Tuunanen, M. A. Ro henbe ge , and S. Cha e jee, “A Design Science Resea ch Me hodology
o In o ma ion Sys ems Resea ch,” J. Manag. In . Sys ., ol. 24, no. 3, pp. 45–77, 2007. A ailable:
h ps://doi.o g/10.2753/MIS0742-1222240302
[48] M. Q. Pa on, Quali a i e e alua ion and esea ch me hods. Thousand Oaks, CA, US: Sage Publica ions, Inc.,
1990.
[49] K. Pen inen, “The Long and Winding Road o En e p ise A chi ec u e Implemen a ion in he Finnish Public
Sec o ,” Ph.D. disse a ion, Facul y o In o ma ion Technology, Uni e si y o Jy äskylä, Finland, 2018.
[50] D. S elze , “En e p ise a chi ec u e p inciples: Li e a u e e iew and esea ch di ec ions,” Se ice-O ien ed
Compu ing. ICSOC/Se iceWa e 2009 Wo kshops, Sp inge , LNCS, ol. 6275, pp. 12–21, 2010. A ailable:
h ps://doi.o g/10.1007/978-3-642-16132-2_2
[51] K. J. Knapp, R. F. Mo is, T. E. Ma shall, and T. A. By d, “In o ma ion secu i y policy: An o ganiza ional-
le el p ocess model,” Compu . & Secu ., ol. 28, no. 7, pp. 493–508, 2009. A ailable:
h ps://doi.o g/10.1016/j.cose.2009.07.001
[52] J.-P. Tol anen, “Inc emen al Me hod Enginee ing wi h Modeling Tools: Theo e ical P inciples and Empi ical
E idence,” Ph.D. disse a ion, Uni e si y o Jy äskylä, Finland, 1998.
[53] C. Magnusson and S. C. Chou, “Risk and compliance managemen amewo k o ou sou ced global so wa e
de elopmen ,” P oc. o he 5 h In . Con . Glob. So w. Eng. ICGSE 2010, pp. 228–233, 2010. A ailable:
h ps://doi.o g/10.1109/ICGSE.2010.34