[Paper Review] An Integrated Conceptual Model for Information System Security Risk Management and Enterprise Architecture Management based on TOGAF, ArchiMate, IAF and DoDAF
This paper proposes an integrated conceptual model that unifies Information System Security Risk Management (ISSRM) with Enterprise Architecture Management (EAM) by aligning key frameworks: TOGAF, ArchiMate, IAF, and DoDAF. It establishes alignment tables between ISSRM concepts and EA modeling constructs, enabling systematic integration of security risk management into enterprise architecture through standardized, interoperable modeling frameworks.
Risk management is today a major steering tool for any organization wanting to deal with Information System (IS) security. However, IS Security Risk Management (ISSRM) remains difficult to establish and maintain, mainly in a context of multi-regulations with complex and inter-connected IS. We claim that a connection with Enterprise Architecture Management (EAM) contributes to deal with these issues. A first step towards a better integration of both domains is to define an integrated EAM-ISSRM conceptual model. Among the steps of the research method followed to define such an integrated EAM-ISSRM conceptual, this technical report presents the whole outputs (through alignment tables) of the conceptual alignment between concepts used to model EA (based on ArchiMate, TOGAF, IAF and DoDAF) and concepts of the ISSRM domain model.
Motivation & Objective
- Address the challenge of integrating Information System Security Risk Management (ISSRM) into enterprise architecture in complex, multi-regulated environments.
- Overcome the fragmentation and lack of interoperability between ISSRM and EAM practices in large organizations.
- Develop a unified conceptual model that bridges the semantic and structural gaps between ISSRM and EA frameworks.
- Enable consistent, standardized, and traceable modeling of security risks within enterprise architecture using established modeling standards.
- Facilitate compliance and governance by aligning security risk management with enterprise architecture frameworks across diverse regulatory and technical contexts.
Proposed method
- Conduct a conceptual alignment between core concepts from the ISSRM domain model and modeling constructs from TOGAF, ArchiMate, IAF, and DoDAF.
- Use a systematic mapping approach to identify equivalent or complementary concepts across the four EA frameworks and the ISSRM model.
- Generate detailed alignment tables that map ISSRM elements (e.g., threats, vulnerabilities, risks) to corresponding EA artifacts (e.g., application components, data objects, views).
- Leverage the formalism of ArchiMate for semantic modeling of security risk components within the enterprise architecture context.
- Ensure consistency and reusability by grounding the integration in established, widely adopted enterprise architecture standards.
- Validate the alignment through iterative refinement and semantic coherence checks to ensure conceptual integrity across frameworks.
Experimental results
Research questions
- RQ1How can security risk management concepts be systematically aligned with enterprise architecture modeling constructs from TOGAF, ArchiMate, IAF, and DoDAF?
- RQ2What are the key semantic and structural mappings between ISSRM elements (e.g., threats, risks, controls) and EA artifacts (e.g., components, data, services)?
- RQ3To what extent can an integrated conceptual model improve traceability, compliance, and governance in multi-regulated IS environments?
- RQ4What are the practical implications of unifying ISSRM and EAM through standardized modeling frameworks?
- RQ5How can the integration of ISSRM into EAM enhance organizational resilience and risk visibility across complex information systems?
Key findings
- The study successfully establishes a comprehensive set of alignment tables mapping 23 core ISSRM concepts to corresponding artifacts in TOGAF, ArchiMate, IAF, and DoDAF.
- The integration enables traceability of security risks back to specific enterprise architecture components, such as applications, data objects, and services.
- The model supports multi-level risk analysis by linking high-level enterprise views (DoDAF) with detailed technical components (TOGAF/ArchiMate).
- The alignment enhances interoperability between security and architecture teams by providing a shared conceptual language grounded in standardized frameworks.
- The approach facilitates compliance with multiple regulations by enabling risk modeling that aligns with both architectural and security governance requirements.
- The conceptual model provides a foundation for tool-supported risk modeling and automated risk assessment within enterprise architecture environments.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.