it-governance11 min read

Enterprise Architecture Frameworks for IS Auditors

Explore enterprise architecture frameworks including TOGAF, Zachman, and SABSA, and their relevance to IS auditing and the CISA exam.

CISAPractice|

Enterprise architecture (EA) provides a structured approach to aligning an organization's IT infrastructure, applications, and processes with its business strategy. For CISA candidates, understanding EA frameworks helps in evaluating how well an organization's technology landscape supports its strategic objectives.

What Is Enterprise Architecture?

Enterprise architecture defines the structure and operation of an organization, with the goal of aligning IT and business strategy. It provides a blueprint that describes the current state of the enterprise, the desired future state, and the transition plan to get there. EA helps organizations make informed decisions about technology investments, reduce complexity, and improve agility.

Key Enterprise Architecture Frameworks

TOGAF (The Open Group Architecture Framework)

TOGAF is one of the most widely adopted EA frameworks. Its key components include:

  • Architecture Development Method (ADM): A step-by-step approach to developing enterprise architecture through iterative phases including architecture vision, business architecture, information systems architecture, and technology architecture
  • Enterprise Continuum: A repository of architecture assets, including reference models, patterns, and standards
  • Architecture domains: Business, Data, Application, and Technology architectures

TOGAF's ADM provides a repeatable process that IS auditors can evaluate for completeness and consistency.

Zachman Framework

The Zachman Framework is a classification scheme for organizing architectural artifacts. It uses a two-dimensional matrix:

  • Rows: Represent different stakeholder perspectives (Planner, Owner, Designer, Builder, Implementer, User)
  • Columns: Represent different aspects of the architecture (What, How, Where, Who, When, Why)

The Zachman Framework does not prescribe a process for creating architecture; rather, it provides a taxonomy for organizing and understanding architectural artifacts.

SABSA (Sherwood Applied Business Security Architecture)

SABSA is a framework specifically designed for security architecture. It addresses security requirements at multiple layers:

  • Contextual: Business requirements and risk context
  • Conceptual: Security principles and fundamental concepts
  • Logical: Information security services and policies
  • Physical: Security mechanisms and technology solutions
  • Component: Detailed security product specifications

SABSA is particularly relevant for IS auditors evaluating security architecture decisions.

Architecture Domains

Regardless of the framework used, enterprise architecture typically addresses four interrelated domains:

  • Business architecture: Business strategy, governance, organization, and key business processes
  • Data architecture: Structure of an organization's logical and physical data assets and data management resources
  • Application architecture: Individual application systems, their interactions, and their relationships to core business processes
  • Technology architecture: Hardware, software, and network infrastructure needed to support applications and data

The IS Auditor's Role in EA

IS auditors evaluate enterprise architecture by assessing:

  • Whether the EA is aligned with the organization's business strategy
  • Whether the EA is maintained and kept current
  • Whether architectural standards and principles are followed in technology decisions
  • Whether the EA governance process ensures compliance with architectural guidelines
  • Whether the EA addresses security, risk, and compliance requirements

Benefits of Enterprise Architecture

  • Improved strategic alignment between IT and business
  • Reduced complexity and technology redundancy
  • Better decision-making for technology investments
  • Enhanced interoperability between systems
  • Improved risk management through a holistic view of the IT landscape

CISA Exam Tips

Know the basic characteristics of TOGAF, Zachman, and SABSA. The exam may ask which framework is best suited for a particular purpose. Remember that Zachman is a taxonomy (classification), TOGAF provides a methodology (process), and SABSA focuses on security architecture. Questions may also ask about the four architecture domains and their relationships.

Related Tags

IT GovernanceEnterprise ArchitectureTOGAFZachmanFrameworks

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free