A1 Journal article (refereed)
Method Framework for Developing Enterprise Architecture Security Principles (2019)


Larno, S., Seppänen, V., & Nurmi, J. (2019). Method Framework for Developing Enterprise Architecture Security Principles. Complex Systems Informatics and Modeling Quarterly, 117(20), 57-71. https://doi.org/10.7250/csimq.2019-20.03


JYU authors or editors


Publication details

All authors or editorsLarno, Sara; Seppänen, Ville; Nurmi, Jarkko

Journal or seriesComplex Systems Informatics and Modeling Quarterly

eISSN2255-9922

Publication year2019

Volume117

Issue number20

Pages range57-71

PublisherRTU Press

Publication countryLatvia

Publication languageEnglish

DOIhttps://doi.org/10.7250/csimq.2019-20.03

Persistent website addresshttps://csimq-journals.rtu.lv/article/view/csimq.2019-20.03

Publication open accessOpenly available

Publication channel open accessOpen Access channel

Publication is parallel published (JYX)https://jyx.jyu.fi/handle/123456789/66269


Abstract

Organizations need to consider many facets of information security in their daily operations – among others, the rapidly increasing use of IT, emerging technologies and digitalization of organizations’ core resources provoke new threats that can be difficult to anticipate. It has been argued that the security and privacy considerations should be embedded in all the areas of organizational activities instead of only relying technical security mechanisms provided by the underlying systems and software. Enterprise Architecture Management (EAM) offers a holistic approach for managing different dimensions of an organization, and can be conceived as a coherent and consistent set of principles that guide how the enterprise must be designed. This article contributes with a method framework for integrating information security with EAM, aimed at providing support for the decision-making related to formulating context-aware EA security principles. The presented method framework is a result of a constructive research based on both the theoretical body of knowledge and the empirical evidence, obtained by interviewing 35 Finnish EA and information security practitioners.


Keywordsdata securitydata security policyenterprisesdata systemsenterprise architecture

Free keywordsenterprise architecture management; enterprise architecture principle; information security; information security policy; method framework; constructive research


Contributing organizations


Ministry reportingYes

Reporting Year2019

JUFO rating1


Last updated on 2024-08-01 at 21:14