Cybersecurity 101back-iconWhat is SABSA in Cyber Security?

What is SABSA in Cyber Security?

SABSA (Sherwood Applied Business Security Architecture) in cyber security is a risk-driven enterprise security architecture framework that helps organizations design, implement, manage, and continuously improve security based on business objectives. Rather than focusing only on technical controls, SABSA aligns cybersecurity with business requirements to ensure security investments support organizational goals.

Developed by John Sherwood, Andrew Clark, and David Lynas, SABSA provides a structured methodology for building security architectures across people, processes, technology, and information. It is widely used by enterprises to create scalable security programs, improve governance, and integrate security into business operations.

Because SABSA begins with business requirements instead of technology, it helps organizations build security architectures that are both effective and aligned with business priorities.

Why SABSA matters

Organizations often implement security controls without fully understanding how they support business objectives. SABSA addresses this challenge by ensuring every security decision can be traced back to a business requirement.

SABSA helps organizations:

  • Align cybersecurity with business goals.
  • Build risk-driven security architectures.
  • Improve security governance.
  • Support regulatory and compliance requirements.
  • Strengthen enterprise-wide risk management.
  • Create measurable security programs.

This business-first approach helps organizations prioritize security investments more effectively.

SABSA layers

SABSA organizes enterprise security architecture into multiple layers that guide security from strategy to implementation and operations.

Layer Purpose
Contextual Define business objectives, risks, and security requirements
Conceptual Develop high-level security concepts and business architecture
Logical Define logical security services and controls
Physical Select technologies and implementation approaches
Component Configure and deploy specific security products and systems
Operational Manage, monitor, and continuously improve security operations

Each layer builds on the previous one, ensuring technical controls remain aligned with business objectives.

SABSA vs TOGAF

Although both are enterprise architecture frameworks, they serve different purposes.

SABSA TOGAF
Focuses on enterprise security architecture Focuses on enterprise architecture across the entire business
Uses a risk-driven approach Uses a business architecture approach
Starts with business security requirements Starts with enterprise architecture planning
Specializes in cybersecurity governance and design Covers business, application, data, and technology architecture

Many organizations use SABSA alongside TOGAF to integrate security into broader enterprise architecture initiatives.

How Hexnode supports SABSA initiatives

Hexnode UEM helps organizations implement the endpoint security controls defined within enterprise security architectures by enforcing security policies, managing operating system updates, monitoring device compliance, deploying approved applications, and maintaining centralized device management across supported platforms.

Hexnode XDR complements enterprise security programs by providing endpoint telemetry, threat detection, incident visibility, and response capabilities for managed Windows endpoints. These capabilities support the operational layer of a SABSA-based security architecture by helping organizations continuously monitor, investigate, and improve their endpoint security posture.

FAQs

SABSA is an enterprise security architecture framework. It focuses specifically on designing and managing security architectures that align with business objectives and risk management.

Yes. Organizations often use SABSA alongside frameworks such as NIST Cybersecurity Framework (CSF), ISO/IEC 27001, TOGAF, COBIT, and Zero Trust architectures to build comprehensive cybersecurity programs.