scieee Open visual document viewer

Method Framework for Developing Enterprise Architecture Security Principles

Larno, Sara,Seppänen, Ville,Nurmi, Jarkko

Full text

This is a sel -a chi ed e sion o an o iginal a icle. This e sion may di e om he o iginal in pagina ion and ypog aphic de ails. Au ho (s): Ti le: Yea : Ve sion: Copy igh : Righ s: Righ s u l: Please ci e he o iginal e sion: CC BY 4.0 h ps://c ea i ecommons.o g/licenses/by/4.0/ Me hod F amewo k o De eloping En e p ise A chi ec u e Secu i y P inciples © 2019 Sa a La no e al Published e sion La no, Sa a; Seppänen, Ville; Nu mi, Ja kko La no, S., Seppänen, V., & Nu mi, J. (2019). Me hod F amewo k o De eloping En e p ise A chi ec u e Secu i y P inciples. Complex Sys ems In o ma ics and Modeling Qua e ly, 117(20), 57-71. h ps://doi.o g/10.7250/csimq.2019-20.03 2019 Complex Sys ems In o ma ics and Modeling Qua e ly (CSIMQ) eISSN: 2255-9922 Published online by RTU P ess, h ps://csimq-jou nals. u.l A icle 117, Issue 20, Sep embe /Oc obe 2019, Pages 57–71 h ps://doi.o g/10.7250/csimq.2019-20.03 Me hod F amewo k o De eloping En e p ise A chi ec u e Secu i y P inciples Sa a La no, Ville Seppänen * and Ja kko Nu mi Facul y o In o ma ion Technology, Uni e si y o Jy askyla, Ma ilanniemi 2, Jy äskylä, FI-40014, Finland sa a.la [email protected], ille. .seppanen@jyu. i, ja samnu@s uden .jyu. i Abs ac . O ganiza ions need o conside many ace s o in o ma ion secu i y in hei daily ope a ions – among o he s, he apidly inc easing use o IT, eme ging echnologies and digi aliza ion o o ganiza ions’ co e esou ces p o oke new h ea s ha can be di icul o an icipa e. I has been a gued ha he secu i y and p i acy conside a ions should be embedded in all he a eas o o ganiza ional ac i i ies ins ead o only elying echnical secu i y mechanisms p o ided by he unde lying sys ems and so wa e. En e p ise A chi ec u e Managemen (EAM) o e s a holis ic app oach o managing di e en dimensions o an o ganiza ion, and can be concei ed as a cohe en and consis en se o p inciples ha guide how he en e p ise mus be designed. This a icle con ibu es wi h a me hod amewo k o in eg a ing in o ma ion secu i y wi h EAM, aimed a p o iding suppo o he decision-making ela ed o o mula ing con ex -awa e EA secu i y p inciples. The p esen ed me hod amewo k is a esul o a cons uc i e esea ch based on bo h he heo e ical body o knowledge and he empi ical e idence, ob ained by in e iewing 35 Finnish EA and in o ma ion secu i y p ac i ione s. Keywo ds: En e p ise A chi ec u e Managemen , En e p ise A chi ec u e P inciple, In o ma ion Secu i y, In o ma ion Secu i y Policy, Me hod F amewo k, Cons uc i e Resea ch. 1 In oduc ion O ganiza ions cons an ly ace new challenges in he a ea o in o ma ion secu i y. Digi al ans o ma ion, ne wo ked business models, con inuously e ol ing o ganiza ions, eme ging echnologies, inc easing complexi y o in o ma ion sys ems and echnology landscapes, egula o y p essu es and changes in legisla ion, and se e al o he ac o s necessi a e ha o ganiza ions mus cons an ly keep hei eye on he secu i y equi emen s and ede ine hem as needed. As an example, since May 2018 he en e p ises ope a ing in Eu ope ha e been obliga ed * Co esponding au ho © 2019 Sa a La no e al. This is an open access a icle licensed unde he C ea i e Commons A ibu ion License (h p://c ea i ecommons.o g/licenses/by/4.0). Re e ence: S. La no, V. Seppänen and J. Nu mi, “Me hod F amewo k o De eloping En e p ise A chi ec u e Secu i y P inciples,” Complex Sys ems In o ma ics and Modeling Qua e ly, CSIMQ, no. 20, pp. 57–71, 2019. A ailable: h ps://doi.o g/10.7250/csimq.2019-20.03 Addi ional in o ma ion. Au ho ’s ORCID iD: V. Seppänen – h ps://o cid.o g/0000-0003-3843-4843. PII S225599221900117X. Recei ed: 30 May 2019. Accep ed: 23 Oc obe 2019. A ailable online: 31 Oc obe 2019. 58 o comply wi h he Gene al Da a P o ec ion Regula ion (GDPR); and ailing o gua an ee o ganiza ional secu i y and p i acy o hei cus ome s’ pe sonal da a may lead o subs an ial ines. I has been a gued ha nowadays he secu i y and p i acy conside a ions should be embedded in all he a eas o o ganiza ional ac i i ies ins ead o only elying on echnical secu i y mechanisms ha unde lying sys ems and so wa e p o ide [1], [2]. The en e p ise a chi ec u e (EA) managemen (EAM) has been seen as a iable app oach o in eg a ing di e en laye s o in o ma ion secu i y and aligning hem wi h he con ex o con inuously changing business equi emen s. (e.g. [3]). As s a ed by The Open G oup [4, p.1] “ o oo long, in o ma ion secu i y has been conside ed a sepa a e discipline, isola ed om he business p ocesses and En e p ise A chi ec u e”. Al hough some esea ch on secu i y and EA exis ( o ins ance, en e p ise p i acy a chi ec u e (EPA), en e p ise secu i y a chi ec u e (ESA), en e p ise in o ma ion secu i y a chi ec u e (EISA) and She wood Applied Business Secu i y A chi ec u e (SABSA)), hese app oaches p opose addi ional a chi ec u es o ein o ce he exis ing EA me hod [3]. As discussed la e in his a icle, he in o ma ion secu i y policy is di ided in o h ee ca ego ies o abs ac ion encompassing he whole o ganiza ion [5], hus necessi a ing he secu i y pe spec i es o be imme sed in o EA i sel , ins ead o being addi ional a chi ec u al iewpoin s o ex ensions. As a gued in [25], he cu en app oaches o en ocus solely on in o ma ion sys ems and echnology componen s o he a chi ec u e, and as such do no o e a equisi e holis ic app oach o in eg a e he in o ma ion secu i y wi h he p ac ices o EAM. Second, p io esea ch is ocused on discussing he isk managemen aspec s on in o ma ion secu i y. While, o ins ance, En e p ise A chi ec u e-Based Risk and Secu i y Modelling and Analysis (ERSM) sugges s secu i y p inciples, no guidance o he de elopmen o he p inciples is gi en. Acco ding o [6], he en i e EA can be concei ed as a cohe en and consis en se o p inciples ha guide how he en e p ise mus be designed, making EA p inciples a iable ins umen o achie ing o ganiza ional secu i y. The objec i e o his s udy is o de elop an abs ac design knowledge a e ac in he o m o a me hod amewo k o in eg a ing in o ma ion secu i y p inciple de elopmen wi h he EAM. As a p ac ical con ibu ion, he a icle p o ides suppo o decision-making ela ed o o mula ing con ex -awa e EA secu i y p inciples, while a heo e ical con ibu ion can be ound om he co e age o wo dis inc ye in e ela ed s eams o esea ch: in o ma ion secu i y and EA. The p esen ed me hod amewo k is he esul o he cons uc i e esea ch based on bo h he heo e ical body o knowledge and he empi ical e idence, which was ob ained by in e iewing 35 Finnish EA and in o ma ion secu i y p ac i ione s. The emainde o his a icle is o ganized as ollows. In he nex sec ion we ou line he heo e ical ounda ion o his s udy by discussing i s co e concep s, i.e. he en e p ise a chi ec u e p inciples and secu i y policies, and hei possible ela ion o each o he . The hi d sec ion desc ibes ou cons uc i e esea ch p ocess phase by phase, and hen he ou h sec ion p esen s he esul s o he cons uc i e wo k. The i h sec ion p o ides a discussion on he esul s. Finally, he six h sec ion concludes he pape , add esses limi a ions o he s udy, and sugges s opics o u he esea ch. 2 Theo e ical Backg ound This sec ion discusses he key concep s o he esea ch domain and es ablishes he heo e ical ounda ions o he cons uc i e pa o he s udy. The i s sec ion add esses he en e p ise a chi ec u e and, mo e speci ically, he en e p ise a chi ec u e p inciples, and he second co e s he concep o in o ma ion secu i y policy. While he clea dis inc ion be ween he e ms p inciple and policy is no always d awn (c ., [7]), in he ollowing we cha ac e ize he o me as a ule o be ollowed and he la e as collec ion o guidelines o be adop ed. By discussing hese concep s, we aim o add ess he need o and he cu en lack o a holis ic app oach o in eg a ing aspec s o in o ma ion secu i y in o he EAM. 59 2.1 En e p ise A chi ec u e P inciples The EAM o e s a holis ic app oach o managing di e en dimensions o an o ganiza ion, such as i s goals and objec i es, business ac i i ies, so wa e applica ions, da a and in o ma ion, and echnology in as uc u es. I os e s he use o common language and suppo s he co-ope a ion be ween s akeholde g oups [8]. EAM is widely used in s a egy o ma ion, planning, and implemen a ion and in aligning business capabili ies wi h he suppo ing IT esou ces [9]. To s uc u e and guide he EAM- ela ed ac i i ies, o ganiza ions use di e en me hodologies, which ha e been de eloped bo h in he academia and indus y. The o igins o he mode n EA can be aced o he Business Sys ems Planning me hodology in he 1960s [10]. Howe e , he e m “en e p ise a chi ec u e” and he ela ed e minology we e coined la e in he ea ly publica ions ega ding he PRISM a chi ec u e amewo k (c ., [11]) and he Zachman F amewo k [12]. Cu en ly, The Open G oup A chi ec u e F amewo k (TOGAF®), in oduced in 1995, is he mos widely adop ed EA me hodology in he indus y [13]. Howe e , mos o he o ganiza ions ha e aken a “hyb id amewo k app oach”. [14] a gues ha no single me hodology mee s all equi emen s o add esses all he needs o a pa icula o ganiza ion [13]. In a hyb id app oach, aspec s, ideas and app oach a e combined om a mul iple di e en me hodologies and amewo ks. The e a e some cha ac e is ics ha a e common o he majo i y o EAM me hodologies. These include he sepa a ion o di e en iewpoin s (such as business- ela ed elemen s and echnology- ela ed elemen s) when an o ganiza ion’s a chi ec u al s uc u es a e being designed o cons i u e an aligned whole. Second, a chi ec u al planning and de elopmen is ad ised o conside he cu en s a e o he a chi ec u al s uc u es in ela ion o he desi ed a ge s a e ha would be e se e he implemen a ion o business objec i es. By analyzing gaps be ween he cu en and desi ed s uc u es, i is possible o iden i y and p io i ize he ele an a eas o de elopmen . Thi d, he EA amewo ks, which can be conside ed as a o m o en e p ise on ology (c ., [15], [16], [17]), p o ide di e en iewpoin s and di e en le els o abs ac ion (such as con ex ual, concep ual, logical and physical) o di e en s akeholde s and hei dis inc i e needs. Fo ins ance, a CIO migh be in e es ed in inding ou da ed so wa e applica ions using he o e all iew p o ided by he applica ion po olio model, while a so wa e de elope designing he bes - i ed in eg a ion app oach migh be in e es ed in s udying he APIs suppo ed by he cu en in o ma ion sys ems a chi ec u e. The design o ac ual implemen able a chi ec u al s uc u es is guided by he s a egy-le el conside a ions. Fo ins ance, along wi h he business a chi ec u e, in o ma ion sys ems a chi ec u e, and echnology a chi ec u e, he TOGAF® con en me amodel sepa a es he a chi ec u e ision de i ed om he business and echnology s a egies, he a chi ec u e equi emen s and cons ain s, and he a chi ec u e p inciples, which o mula e he gene al unde lying ules and guidelines o he a chi ec u e de elopmen . As he p inciples mani es gene al ules and guidelines o suppo an o ganiza ion ul illing i s mission, de ining he a chi ec u e p inciples is ecommended as he ini ia ing ac i i y o EAM [18]; whe eas p inciples cons i u e a ounda ion o hinking abou he sys ems design [19] and he equi emen s, and, on he o he hand, s a e he unc ional and cons uc ional p ope ies o a sys em o ha e [20]. The e o e, he p inciples can be seen as bounda y condi ions om which he implemen able equi emen s a e de i ed. The EA p inciples can ei he se e as he designing p inciples ha a e used o desc ibe he design o ac ual sys em a e ac s o he egula i e p inciples o con ey a p esc ip i e no ion limi ing he design op ions allowed in a sys em design [21]. [20] cha ac e izes he EA p inciples being he la e . I is a gued ha he EA p inciples a e a speci ic o m no ma i e p inciples ha “guide/di ec he en e p ise no ma i ely es ic ing design eedom” [20, p. 11]. No ma i e p inciples a e based on a i ac s such as s a egy, he exis ing en i onmen , and ex e nal de elopmen s [20]. The EA p inciples pu sue he o ganiza ion-wide consensus in he de elopmen , main enance, and use o EA as well as in guiding i s implemen a ion as ope a ional ac i i ies and suppo ing asse s. As such he p inciples b idge he s a egy and ope a ions. In 60 p ac ice, he EA p inciples a e widely o mula ed in o ganiza ions and used, o ins ance, o e iewing de elopmen ini ia i es and p ojec s. The e o e, he documen a ion and communica ion o EA p inciples is essen ial. The documen a ion should include, as a p o ound elemen , a clea de ini ion o a p inciple’s s uc u e and he ela ions i has wi h i s en i onmen [22]. Fu he mo e, he documen a ion should add ess he p inciple’s mo i a ing a ionale, conc e e implica ions, and measu es wi h which i s ul illmen is e alua ed [23], [24]. 2.2 In o ma ion Secu i y Policy O ganiza ions need o conside many ace s o in o ma ion secu i y in hei daily ope a ions. The apidly inc easing use o IT, eme ging echnologies and digi aliza ion o o ganiza ions’ co e esou ces p o oke new h ea s ha can be di icul o an icipa e [25]. A acks ha damage o modi y da a can a ec he c i ical in as uc u e wi hou any awa eness o i s owne . I is no ewo hy ha a he same ime as new secu i y h ea s ha e appea ed alongside eme ging echnologies, an inc easing numbe o h ea s a e loca ed inside he o ganiza ion. Many o hese h ea s a e caused by unin en ional, ca eless o negligen beha io [26], [27], [28]. The e o e, a majo i y o he li e a u e on in o ma ion secu i y ocuses on he use 's pe spec i e and how he use s o in o ma ion and echnology esou ces can by hei ac ions p e en , de ec and espond o secu i y h ea s [29]. In o ma ion secu i y also encompasses da a sou ces ha a e no in digi al o ma s. In o ma ion ha is based on physical documen s o employees' knowledge can as well be a a ge o secu i y h ea s [30]. Indi idual knowledge can be a key compe i i e ad an age o an o ganiza ion and he e o e needs o be p o ec ed. In o ma ion secu i y ulne abili ies con ain a signi ican isk, no only o he ope a ions o an o ganiza ion, bu also om he poin o iew o he o ganiza ion’s epu a ion. To his end, se e al o ganiza ions ha e been inc easingly ocusing on de eloping sa e y- ela ed policies and aligning hem wi h non-o ganiza ional egula ions. The numbe o s udies on he implemen a ion and e iciency o in o ma ion secu i y has signi ican ly inc eased in he 21s cen u y and he in o ma ion secu i y policy de elopmen is an a ea o g owing schola ly in e es . Gene ally, he concep o he in o ma ion secu i y policy is di ided in o he h ee ca ego ies o abs ac ion. A he lowes le el o abs ac ion, in o ma ion secu i y is looked a om a echnical poin o iew [5]. A his le el, he key conce n is he secu i y a chi ec u e o echnical sys ems, usually ocusing on s anda ds and p ocedu es o he sys ems con igu a ion o main enance. A he nex le el o abs ac ion, in o ma ion secu i y is iewed om he use 's poin o iew [5]. He e, ce ain a eas o echnology, such as he use o in e ne se ices, a e add essed. These policies may include ins uc ions and p ocedu es ha employees mus obse e in hei daily in e ac ions wi h he in o ma ion and echnology esou ces. The majo i y o ex an esea ch li e a u e is examining he secu i y policies h ough an indi idual and ope a ional abs ac ion le el [29]. A he highes le el o abs ac ion, he in o ma ion secu i y is app oached om he senio managemen poin o iew [5]. A his le el, ins ead o he ac ual ope a i e p inciples, he ocus is on he s a egic di ec ion o he o ganiza ion and he ex en and na u e o secu i y objec i es. These guide he de elopmen , implemen a ion and managemen o he secu i y p og ams and assign esponsibili ies o he a ious secu i y a eas a he mos abs ac , philosophical le el [29]. To gain a needed b oade pe spec i e on he p oblem a ea, he opic o secu i y has been app oached om he pe spec i es o policy compliance and in o ma ion secu i y cul u e [29]. Howe e , [31] a gue ha he ex an li e a u e on in o ma ion secu i y policies ocuses on desc ibing he s uc u es and con en , bu usually does no desc ibe a de ailed de elopmen p ocess. The p o essionals in ol ed in he in o ma ion secu i y policy de elopmen a e p o ided wi h li le knowledge abou he p ocesses hey should ollow. They o en need o ely on guidelines which a e no speci ically designed o hei o ganiza ions and hus ail o ecognize and answe o hei speci ic h ea s and equi emen s [5], [31]. 61 Fo cons uc ing he in o ma ion secu i y policy, [5] a gues o h ee ma e s o be conside ed. Fi s , an o ganiza ion mus be able o compile and upda e i s in o ma ion secu i y policy in an agile manne . This is especially impo an when he o ganiza ion s i es o a change ha may con lic wi h he exis ing in o ma ion secu i y policy. Howe e , his does no mean ha he in o ma ion secu i y objec i es should be igno ed, bu he secu i y elemen s should, as quickly as possible, be aligned wi h he changed equi emen s. The goal is ha he o ganiza ion is bo h capable o e ec i ely seeking he change, bu also capable o achie ing an app op ia e le el o in o ma ion secu i y. This kind o agile aspec is essen ial as o ganiza ional change can also help o mee he in o ma ion secu i y equi emen s. The e o e, he p inciples o managing he in o ma ion secu i y mus always be synch onized wi h he o ganiza ional p io i ies and he p ocesses ha suppo hese goals. The second ma e is poli ical simplici y. [5] no es ha in lexible policies induce sec e and poo ly conside ed non-compliance. The e o e, he p ocess o policy cons uc ion mus be anspa en , awa e o i s con ex , and in ol e he s akeholde s a he di e en le els o an o ganiza ion. The policy- ela ed decisions need o be well- easoned and hei implica ions explici . Thi dly, an in o ma ion secu i y policy mus implemen he exis ing c i e ia ha can be ob ained, o ins ance, om legisla ion o o ganiza ion's own p io i ies. I should be no ed, howe e , ha i hese c i e ia a e no de ailed, i is pe missible o policy make s o ha e a be e chance o esponding lexibly in modi ying he o ganiza ion's in o ma ion secu i y policy so ha he o ganiza ion can eac e icien ly in he o ganiza ional changes. Cybe secu i y isks a e socio- echnical in na u e as hey include no only echnical ulne abili ies bu o en also include ac o s ela ed o beha io o human ac o s [28]. Consequen ly, se e al esea che s ha e ph ased he po en ial o he EAM o se e as an encompassing ins umen o app oaching in o ma ion secu i y ela ed ques ions. Fo ins ance, [32] no es ha he EAM p o ides a mean o mi iga e he limi ing siloed hinking o adi ional isk managemen p ocesses as i gi es a be e unde s anding on how an asse and i s alue can be a ec by a mani es a ion o a isk. Simila ly, [2] a gues ha he EAM is a p omising app oach o deal wi h he inc easing complexi y o o ganiza ions, echnologies and he ela ed secu i y h ea s. Mos o he cu en e o s, howe e , ha e ocused only on indi idual a eas on he domain o EAM, such as in o ma ion sys ems isk managemen (e.g. [2], [33], [34]). The e o e, as a gued in [35], he holis ic app oach o he secu i y in EA is s ill lacking. 3 The Cons uc i e Resea ch App oach As s a ed p e iously, he objec i e o his s udy is o de elop an abs ac design knowledge a e ac . Design knowledge, p oduced by design esea ch, can be sepa a ed in o wo ou comes, namely, abs ac and si ua ional design knowledge. Abs ac design knowledge comes om me a-design, o ins ance, li e a u e e iew, modelling and engagemen schola ship [36] and p oduces abs ac concep s, gene ic models, guidelines o design p ac ices and sys ems abs ac ions wi h key p ope ies [36]. The me hod amewo k is c ea ed based on he li e a u e om bo h esea ch ields: he EA and he in o ma ion secu i y. Engagemen schola ship was execu ed h ough in e iews. Bo h he me a-design and he design p ac ice ha e di e se ypes o e alua ion ha should be conduc ed du ing he design and de elopmen phase. Design science e alua ion has wo o ms: a i icial and na u alis ic e alua ion [46] o which a i icial e alua ion was used in his s udy. In design science esea ch, he e a e wo e alua ion ela ed phases, e alua ion and demons a ion. In his s udy, he demons a ion phase was conduc ed as a se ies o expe in e iews. In e iewees we e asked o e alua e he sui abili y o he me hod amewo k, and he a e ac was e alua ed based on he iews o he in e iewees. The me hod amewo k was modi ied he i s ime a e ou in e iews, and he second ime a e all he nine in e iews we e conduc ed. In he ield o me hod enginee ing, i is o en a gued ha no me hod is sui able as such and some si ua ional adap a ion is always needed. The me hod adap a ion e e s o he ac i i ies o 62 enhancemen , ex ension o es ic ion o make a me hod sui able o a speci ic domain, an o ganiza ion, o a p ojec [14], [37], [38]. Adap abili y o he EA me hods is pa icula ly impo an due o he conside able he e ogenei y o o ganiza ions and hei business en i onmen s [39], [40], [41], [42]. In compa ison o a me hod, a me hod amewo k is pu pose ully a mo e abs ac me hodological elemen ha suppo s he de ini ion o me hods [43]. The me hod amewo k can be conside ed as a gene aliza ion o a me hod, which is hen adjus ed and speci ied o he con ex o a ce ain o ganiza ion. This sec ion desc ibes s ep-by-s ep he cons uc i e esea ch p ocess ha adop s ideas om se e al no able wo ks on he design science esea ch (e.g. [44], [45], [46], [47]). Also, he goals and equi emen s ega ding he me hod amewo k’s con en and expedience a e p esen ed. Figu e 1 summa izes he phases o he esea ch p ocess ha was ollowed while cons uc ing he Me hod F amewo k o En e p ise A chi ec u e Secu i y P inciples (MF4EASP). Figu e 1. The phases o he esea ch p ocess and he accompanying sou ces o in o ma ion 3.1 P oblem Iden i ica ion and Mo i a ion The p oblem, i.e. he need o and he cu en lack o a holis ic app oach o in eg a ing aspec s o in o ma ion secu i y in o EAM, has been aised in ecen s udies. Fo ins ance, a s udy [35] a gues ha he in eg a ion o secu i y and isk ela ed conce ns in o he holis ic app oaches o EAM a e cu en ly a an inadequa e le el. Consequen ly, ecen e o s ha e ocused on in o ma ion sys ems isk managemen (e.g. [2], [7], [35], [48]). Howe e , in a e iew o 15 yea s o academic EA endea o s, a s udy [1] no es ha al hough some p og ess has been made, EA has no ye eached he s a e o being a iable ool o add essing eme ging secu i y challenges and new h ea s o o ganiza ions’ complex in o ma ion sys ems. Fo ins ance, al hough EAM is manda ed by legisla ion in he Finnish public sec o , he Na ional Audi O ice o Finland, in hei 2017 epo , disco e ed se e al p oblems in he a ea o in o ma ion secu i y. Thei epo s a es ha EA desc ip ions would se e as a aluable ool o e alua ing he c i icali y o elec onic se ices bu EAM is no p ope ly in eg a ed wi h he ope a ional equi emen s and p ac ices. I was also ound ha he c i icali y o he ICT sys ems is no egula ly checked, 63 al hough he equen changes occu ing in he ope a ing en i onmen would absolu ely need i . Finally, he epo s a es ha he in o ma ion secu i y is commonly ins i u ed as he esponsibili y o he IT uni s, e en hough hey may no be awa e o all he necessa y business- ela ed conce ns, and he eby he holis ic iew o he in o ma ion secu i y emains lacking. 3.2 Requi emen s and Objec i es We analyzed he ich quali a i e da a ob ained by in e iewing 26 seasoned expe s on EA, who con ibu ed o he p oblem iden i ica ion and o cap u ing he equi emen s and objec i es o he MF4EASP. These in o man s se e in di e en posi ions in bo h p i a e IT companies and public sec o and hei expe ience in EA- ela ed ac i i ies ange om 3 o 40 yea s wi h he a e age o 15 yea s. The in e iews add essed he in o man s’ iews o he pas , p esen and u u e p ac ices o EAM. The da a we e sc eened o he in o ma ion ele an o he objec i es o his s udy. The de ails o he da a collec ion can be ound in [48]. The iden i ied gene ic equi emen s o he MF4EASP a e p esen ed in Table 1. These a e accompanied wi h he ep esen a i e examples o ci a ions om he in e iew ansc ip s. The exce p s a e ansla ed om Finnish o English. Table 1. The guiding equi emen s o he de elopmen o MF4EASP Requi emen In o man s Example om an in e iew 1) In o ma ion secu i y should be included in e e y aspec o EAM. 1, 3, 5, 9, 10, 13, 14, 19, 22 “In o ma ion secu i y mus be aken in o accoun in all he a chi ec u al solu ions h ough all he [a chi ec u e] laye s.” 2) In o ma ion secu i y should be included in EA design p inciples. 1, 12 “Secu i y canno be jus a glued-on conce n. I mus be a design p inciple.” 3) Risk managemen should be an in eg al pa o EAM. 1, 2, 5, 20 “Yes, we ha e been ocusing ou a en ion o ha [ he EA me hod] could guide he in o ma ion secu i y and isk managemen .” 4) In o ma ion secu i y managemen p ac ices should be adap able o he pu pose o he o ganiza ion. 5, 8, 15, 23, 25 “[Planning o he in o ma ion secu i y] should be pu pose-d i en. I mean, wha a e he needs o he business and ope a ional unc ions. And wha a e he ela ed isks. Then you can conclude wha kind o in o ma ion p o ec ion o secu i y you eally need. Tha way, you don’ always ca ego ically need o ake he ha des oad.” 5) Silo-men ali y mus be disman led. 2, 6, 7, 19, 21 “I is also o en he case he e ha he e a e silos among expe s. The in e ac ion and co-ope a ion a e needed. And in a way, o cou se, he EAM is a p e y good ool o acili a ing ha con e sa ion.” 6) A means o deal wi h legisla i e demands and egula o y p essu es should be p o ided. 3, 5, 11,16, 17, 19, 26 “[Regula i e laws] a e e y ex ensi e [and] hey pose la ge and complex equi emen s. EAM is an app op ia e ool o dealing wi h hem.” 8) In o ma ion secu i y p ac ices mus be able o espond o changes aking place in he ope a ing en i onmen s. 13, 17, 18, 20, 24, 26 “I hink ha he numbe o cloud-based solu ions and hyb id solu ions, whe e some o he in o ma ion is s o ed locally and some o i in he cloud, [will con inue o inc ease]. You need o be able o con inuously change he way you do you wo k.” 64 3.3 Design and De elopmen The o e all s uc u e o he a e ac p esen ed in his pape d aws om he p e ious wo ks on he design o EA p inciples and in o ma ion secu i y policies. A numbe o academic con ibu ions on he EA p inciple de elopmen can also be ound (e.g. [6], [23], [24]), al hough hei applicabili y is somewha limi ed due o hei gene ali y and pu pose ully wide scope. Based on he li e a u e e iew [49], he consolida ed me amodel o EA p inciples has been p esen ed [22]. By i emizing he elemen s o a p inciple, his me amodel di e en ia es he co e de ini ion o he EA p inciple, including i s s a emen , a ionale, implica ions, key ac ions, and ela ed measu es, and also p o ides an ex ended de ini ion ha conside s he p inciple’s impac on i s en i onmen . We used he wo k p esen ed in [22] o de ining he key componen s and he a eas o conce n o MF4EASP. Nex , o he s uc u e o EA secu i y p inciple de elopmen p ocess, we adap ed he p ocess o he policy de elopmen amewo k [31] and he ele an componen s p esen ed in he Comp ehensi e In o ma ion Secu i y Policy P ocess Model [50]. Finally, we s i ed o balance he equi emen s ound in ou empi ical da a wi h he equi emen s o suppleness, poli ical simplici y and c i e ion-o ien a ion as discussed in ela ion o in o ma ion secu i y me a-policy in [5]. The MF4EASP was cons uc ed using he A chiMa e® 3.0.1 speci ica ion. The A chiMa e® modeling language is an Open G oup s anda d, which p o ides a TOGAF® complian modeling no a ion ha co e s all he EA domains. I is widely used in bo h public and p i a e o ganiza ions a ound he wo ld and is suppo ed by he majo i y o EA modeling ools. As a semi- o mal modeling language, i p o ides a cohe en and isually uni o m ep esen a ion o EA a e ac s co e ing di e en componen s o an a chi ec u e and hei dependencies. As such i aims a enabling communica ion among s akeholde s, and guides complica ed change p ocesses on a chi ec u al s uc u es. 3.4 Demons a ion and E alua ion Nine expe p ac i ione s ook pa in e alua ing he en a i e e sions o MF4EASP. The e alua o s we e selec ed using he c i e ion sampling (c. ., [48]) so ha he in o man s could p o ide p o ound and well- easoned insigh s o suppo he u he de elopmen o he cons uc . Fou o he e alua o s ha e hei expe ise bo h in he ields o EA and in o ma ion secu i y, h ee in he in o ma ion secu i y, and wo in he EA. Thei occupa ional posi ions included Chie In o ma ion O ice , Chie Digi al O ice , En e p ise A chi ec , Specialis , Resea che , and di e en manage ial posi ions. The e alua o s’ p o essional expe ience in he ield o hei expe ise anged om 2 o 30 yea s wi h he a e age o 14 yea s. The e alua ion o he me hod amewo k was conduc ed by p esen ing he MF4EASP o he e alua o who was hen asked o gi e eedback, c i icism and cons uc i e ideas ega ding a ious aspec s. Each e alua o was me indi idually by he i s au ho , o ensu e ha hei iews and opinions would no a ec he o he e alua o s. The aspec s o e alua ion we e based in he me hod enginee ing knowledge and adhe ed o shell model p esen ed in [52]. Table 2 p esen s he hemes co e ed du ing he e alua ion and he ques ions hey we e add essed wi h. O e all, he e alua ion was a ge ed o he co ec ness, comple eness and applicabili y o he MF4EASP. The e alua ion was conduc ed o he wo e sions o MF4EASP in he wo ounds. Some changes we e implemen ed o he i s e sion o cons uc acco ding o he eedback gi en by he i s ou e alua o s. These included, o ins ance, a possibili y o bo h objec i es and cons ain s o de ine equi emen s o design p inciples, he acknowledgemen o possible s akeholde -induced isks, and ha he p ocess needs o, in addi ion o secu i y p inciple de elopmen , conside hei implemen a ion in an o ganiza ion. 71 [33] F. Inne ho e -Obe pe le and R. B eu, “Using an En e p ise A chi ec u e o IT Risk Managemen ,” P oc. o he ISSA 2006 om Insigh o Fo esigh Con e ence, 2006. [34] J. S. Bu ke , “Business Secu i y A chi ec u e: Wea ing In o ma ion Secu i y in o You O ganiza ion’s En e p ise A chi ec u e h ough SABSA®,” In . Secu . J., ol. 21, no. 1, pp. 47–54, 2012. A ailable: h ps://doi.o g/10.1080/19393555.2011.629341 [35] H. Jonke s and D. Qua el, “G aphical Models o Secu i y,” Thi d In e na ional Wo kshop, G aMSec 2016, ol. 9987, pp. 94–101, 2016. A ailable: h ps://doi.o g/10.1007/978-3-319-46263-9_6 [36] Ł. Os owski, M. Hel e and F. Hossain, “A concep ual amewo k o design science esea ch,” P oc. o he In e na ional Con e ence on Business In o ma ics Resea ch, Sp inge , LNBIP, ol. 90, pp. 345–354, 2011. A ailable: h ps://doi.o g/10.1007/978-3-642-24511-4_27 [37] J. Raly e e al., “Towa ds a Gene ic Model o Si ua ional Me hod Enginee ing To ci e his e sion : Towa ds a Gene ic Model o Si ua ional Me hod,” P oc. o he In . Con . Ad . In . Sys . Eng., Sp inge , LNCS, ol. 2681, pp. 95–110, 2012. A ailable: h ps://doi.o g/10.1007/3-540-45017-3_9 [38] M. Leppänen, An On ological F amewo k and a Me hodical Skele on o Me hod Enginee ing: A Con ex ual App oach. Jy äskylä S udies in Compu ing 52, 2005. [39] M. Leppänen, K. Val onen, and M. Pulkkinen, “Towa ds a Con ingency F amewo k o Enginee ing an En e p ise A chi ec u e Planning Me hod,” P oc. o 30 h In o ma ion Sys ems Resea ch Semina in Scandina ia, 2007. [40] C. Riege and S. Aie , “A Con ingency App oach o En e p ise A chi ec u e Me hod Enginee ing,” In e na ional Con e ence on Se ice-O ien ed Compu ing, Sp inge , LNCS, ol. 5472, pp. 388–399, 2008. A ailable: h ps://doi.o g/10.1007/978-3-642-01247-1_39 [41] K. Val onen, V. Seppänen, and M. Leppänen, “Go e nmen en e p ise a chi ec u e g id adap a ion in Finland,” P oc. o he 42nd Annual Hawaii In e na ional Con e ence on Sys em Sciences, HICSS, 2009. A ailable: h ps://doi.o g/10.1109/hicss.2009.232 [42] S. Buckl, “De eloping o ganiza ion-speci ic en e p ise a chi ec u e managemen unc ions using a me hod base,” Ph.D. disse a ion, Technische Uni e si ä München, Leh s uhl ü In o ma ik XIX, 2011. [43] C. Sal iano, A. Zoucas, J. Sil a, Â. Al es, C. G. on Wangeheim, and M. Thi y, “A Me hod F amewo k o Enginee ing P ocess Capabili y Models,” 16 h Eu . Sys . So w. P ocess Imp o . Inno . Ind. Eu oSPI 2009., ol. 1, pp. 25–36, 2009. [44] S. T. Ma ch and G. F. Smi h, “Design and na u al science esea ch on in o ma ion echnology,” Decis. Suppo Sys ., ol. 15, no. 4, pp. 251–266, 1995. A ailable: h ps://doi.o g/10.1016/0167-9236(94)00041-2 [45] A. R. He ne , S. T.Ma ch, J. Pa k, and S. Ram, “Design Science in In o ma ion Sys ems Resea ch,” MIS Q., ol. 28, no. 1, pp. 75–105, 2004. A ailable: h ps://doi.o g/10.2307/25148625 [46] J. Venable, “The ole o heo y and heo ising in Design Science esea ch,” P oc. DESRIST, pp. 24–35, 2006. [47] K. Pe e s, T. Tuunanen, M. A. Ro henbe ge , and S. Cha e jee, “A Design Science Resea ch Me hodology o In o ma ion Sys ems Resea ch,” J. Manag. In . Sys ., ol. 24, no. 3, pp. 45–77, 2007. A ailable: h ps://doi.o g/10.2753/MIS0742-1222240302 [48] M. Q. Pa on, Quali a i e e alua ion and esea ch me hods. Thousand Oaks, CA, US: Sage Publica ions, Inc., 1990. [49] K. Pen inen, “The Long and Winding Road o En e p ise A chi ec u e Implemen a ion in he Finnish Public Sec o ,” Ph.D. disse a ion, Facul y o In o ma ion Technology, Uni e si y o Jy äskylä, Finland, 2018. [50] D. S elze , “En e p ise a chi ec u e p inciples: Li e a u e e iew and esea ch di ec ions,” Se ice-O ien ed Compu ing. ICSOC/Se iceWa e 2009 Wo kshops, Sp inge , LNCS, ol. 6275, pp. 12–21, 2010. A ailable: h ps://doi.o g/10.1007/978-3-642-16132-2_2 [51] K. J. Knapp, R. F. Mo is, T. E. Ma shall, and T. A. By d, “In o ma ion secu i y policy: An o ganiza ional- le el p ocess model,” Compu . & Secu ., ol. 28, no. 7, pp. 493–508, 2009. A ailable: h ps://doi.o g/10.1016/j.cose.2009.07.001 [52] J.-P. Tol anen, “Inc emen al Me hod Enginee ing wi h Modeling Tools: Theo e ical P inciples and Empi ical E idence,” Ph.D. disse a ion, Uni e si y o Jy äskylä, Finland, 1998. [53] C. Magnusson and S. C. Chou, “Risk and compliance managemen amewo k o ou sou ced global so wa e de elopmen ,” P oc. o he 5 h In . Con . Glob. So w. Eng. ICGSE 2010, pp. 228–233, 2010. A ailable: h ps://doi.o g/10.1109/ICGSE.2010.34