Get fresh insights, pro tips, and thought starters–only the best of posts for you.
SABSA (Sherwood Applied Business Security Architecture) in cyber security is a risk-driven enterprise security architecture framework that helps organizations design, implement, manage, and continuously improve security based on business objectives. Rather than focusing only on technical controls, SABSA aligns cybersecurity with business requirements to ensure security investments support organizational goals.
Developed by John Sherwood, Andrew Clark, and David Lynas, SABSA provides a structured methodology for building security architectures across people, processes, technology, and information. It is widely used by enterprises to create scalable security programs, improve governance, and integrate security into business operations.
Because SABSA begins with business requirements instead of technology, it helps organizations build security architectures that are both effective and aligned with business priorities.
Organizations often implement security controls without fully understanding how they support business objectives. SABSA addresses this challenge by ensuring every security decision can be traced back to a business requirement.
SABSA helps organizations:
This business-first approach helps organizations prioritize security investments more effectively.
SABSA organizes enterprise security architecture into multiple layers that guide security from strategy to implementation and operations.
| Layer | Purpose |
|---|---|
| Contextual | Define business objectives, risks, and security requirements |
| Conceptual | Develop high-level security concepts and business architecture |
| Logical | Define logical security services and controls |
| Physical | Select technologies and implementation approaches |
| Component | Configure and deploy specific security products and systems |
| Operational | Manage, monitor, and continuously improve security operations |
Each layer builds on the previous one, ensuring technical controls remain aligned with business objectives.
Although both are enterprise architecture frameworks, they serve different purposes.
| SABSA | TOGAF |
|---|---|
| Focuses on enterprise security architecture | Focuses on enterprise architecture across the entire business |
| Uses a risk-driven approach | Uses a business architecture approach |
| Starts with business security requirements | Starts with enterprise architecture planning |
| Specializes in cybersecurity governance and design | Covers business, application, data, and technology architecture |
Many organizations use SABSA alongside TOGAF to integrate security into broader enterprise architecture initiatives.
Hexnode UEM helps organizations implement the endpoint security controls defined within enterprise security architectures by enforcing security policies, managing operating system updates, monitoring device compliance, deploying approved applications, and maintaining centralized device management across supported platforms.
Hexnode XDR complements enterprise security programs by providing endpoint telemetry, threat detection, incident visibility, and response capabilities for managed Windows endpoints. These capabilities support the operational layer of a SABSA-based security architecture by helping organizations continuously monitor, investigate, and improve their endpoint security posture.
SABSA is an enterprise security architecture framework. It focuses specifically on designing and managing security architectures that align with business objectives and risk management.
Yes. Organizations often use SABSA alongside frameworks such as NIST Cybersecurity Framework (CSF), ISO/IEC 27001, TOGAF, COBIT, and Zero Trust architectures to build comprehensive cybersecurity programs.