Enterprise Architecture Frameworks for IS Auditors
Explore enterprise architecture frameworks including TOGAF, Zachman, and SABSA, and their relevance to IS auditing and the CISA exam.
Enterprise architecture (EA) provides a structured approach to aligning an organization's IT infrastructure, applications, and processes with its business strategy. For CISA candidates, understanding EA frameworks helps in evaluating how well an organization's technology landscape supports its strategic objectives.
What Is Enterprise Architecture?
Enterprise architecture defines the structure and operation of an organization, with the goal of aligning IT and business strategy. It provides a blueprint that describes the current state of the enterprise, the desired future state, and the transition plan to get there. EA helps organizations make informed decisions about technology investments, reduce complexity, and improve agility.
Key Enterprise Architecture Frameworks
TOGAF (The Open Group Architecture Framework)
TOGAF is one of the most widely adopted EA frameworks. Its key components include:
- Architecture Development Method (ADM): A step-by-step approach to developing enterprise architecture through iterative phases including architecture vision, business architecture, information systems architecture, and technology architecture
- Enterprise Continuum: A repository of architecture assets, including reference models, patterns, and standards
- Architecture domains: Business, Data, Application, and Technology architectures
TOGAF's ADM provides a repeatable process that IS auditors can evaluate for completeness and consistency.
Zachman Framework
The Zachman Framework is a classification scheme for organizing architectural artifacts. It uses a two-dimensional matrix:
- Rows: Represent different stakeholder perspectives (Planner, Owner, Designer, Builder, Implementer, User)
- Columns: Represent different aspects of the architecture (What, How, Where, Who, When, Why)
The Zachman Framework does not prescribe a process for creating architecture; rather, it provides a taxonomy for organizing and understanding architectural artifacts.
SABSA (Sherwood Applied Business Security Architecture)
SABSA is a framework specifically designed for security architecture. It addresses security requirements at multiple layers:
- Contextual: Business requirements and risk context
- Conceptual: Security principles and fundamental concepts
- Logical: Information security services and policies
- Physical: Security mechanisms and technology solutions
- Component: Detailed security product specifications
SABSA is particularly relevant for IS auditors evaluating security architecture decisions.
Architecture Domains
Regardless of the framework used, enterprise architecture typically addresses four interrelated domains:
- Business architecture: Business strategy, governance, organization, and key business processes
- Data architecture: Structure of an organization's logical and physical data assets and data management resources
- Application architecture: Individual application systems, their interactions, and their relationships to core business processes
- Technology architecture: Hardware, software, and network infrastructure needed to support applications and data
The IS Auditor's Role in EA
IS auditors evaluate enterprise architecture by assessing:
- Whether the EA is aligned with the organization's business strategy
- Whether the EA is maintained and kept current
- Whether architectural standards and principles are followed in technology decisions
- Whether the EA governance process ensures compliance with architectural guidelines
- Whether the EA addresses security, risk, and compliance requirements
Benefits of Enterprise Architecture
- Improved strategic alignment between IT and business
- Reduced complexity and technology redundancy
- Better decision-making for technology investments
- Enhanced interoperability between systems
- Improved risk management through a holistic view of the IT landscape
CISA Exam Tips
Know the basic characteristics of TOGAF, Zachman, and SABSA. The exam may ask which framework is best suited for a particular purpose. Remember that Zachman is a taxonomy (classification), TOGAF provides a methodology (process), and SABSA focuses on security architecture. Questions may also ask about the four architecture domains and their relationships.