TOGAF's Approach in Developing an Enterprise Architecture for the Information Technology Security Industry

  • Rachmad Syarul Hidayat Information Technology, Pradita University, Indonesia
  • Richardus Eko Indrajit Information Technology, Pradita University, Indonesia
  • Erick Dazki Information Technology, Pradita University, Indonesia
Keywords: Enterprise Architecture, TOGAF, Information Security Industry, Risk Identification, Security Policy Development, Security Solution Implementation

Abstract

The information technology security industry, encompassing various activities such as risk identification and assessment, policy development, and solution implementation, plays a crucial role in maintaining the integrity and security of information systems. This study aims to develop and implement an efficient and effective enterprise architecture within the information security sector, focusing on three key core processes identified as the major revenue contributors: risk identification and assessment, security policy development, and security solution implementation. Utilizing the TOGAF-based Enterprise Architecture framework, this research identifies and designs architecture that integrates various systems, applications, and business processes, facilitating better alignment within the organization. The architecture design process involves a thorough analysis of operational needs and business strategies, leading to the development of a model that enhances efficiency and reduces the risk of failure in technology implementation. The outcomes of this study are intended to provide practical guidance for information security companies to optimize operations, simplify system complexities, and achieve strategic goals more effectively. It is anticipated that the application of the designed architecture will have a significant positive impact on the company's ability to address challenges and dynamic needs within the information security industry.

References

Ali, A. Q., Sultan, A. B. M., Abd Ghani, A. A., & Zulzalil, H. (2019). A systematic mapping study on the customization solutions of software as a service applications. IEEE Access, 7, 88196–88217.

Al-Turkistani, H. F., Aldobaian, S., & Latif, R. (2021, April). Enterprise architecture frameworks assessment: capabilities, cyber security and resiliency review. In 2021 1st International conference on artificial intelligence and data analytics (CAIDA) (pp. 79-84). IEEE. https://doi.org/10.1109/CAIDA51941.2021.9425343

Bernard, S. A. (2012). An introduction to enterprise architecture. AuthorHouse.

Coronado Mondragon, A. E., & Coronado Mondragon, C. E. (2018). Managing complex, modular products: how technological uncertainty affects the role of systems integrators in the automotive supply chain. International Journal of Production Research, 56(20), 6628–6643. https://doi.org/10.1080/00207543.2018.1424362

de Kinderen, S., Gaaloul, K., & Proper, H. A. (2014). Bridging value modelling to ArchiMate via transaction modelling. Software & Systems Modeling, 13(3), 1043–1057. https://doi.org/10.1007/s10270-012-0299-z

Dumitriu, D., & Popescu, M. A. M. (2020). Enterprise architecture framework design in IT management. Procedia Manufacturing, 46, 932-940. https://doi.org/10.1016/j.promfg.2020.05.011

Ellerm, A., & Morales-Trujillo, M. E. (2020). Modelling security aspects with archimate: a systematic mapping study. 2020 46th Euromicro Conference on Software Engineering and Advanced Applications (SEAA), 577–584. https://doi.org/10.1109/SEAA51224.2020.00094

Gao, R., Wang, Y., Feng, Y., Chen, Z., & Eric Wong, W. (2019). Successes, challenges, and rethinking–an industrial investigation on crowdsourced mobile application testing. Empirical Software Engineering, 24, 537–561. https://doi.org/10.1007/s10664-018-9618-5

Gong, Y., Yang, J., & Shi, X. (2020). Towards a comprehensive understanding of digital transformation in government: Analysis of flexibility and enterprise architecture. Government Information Quarterly, 37(3), 101487. https://doi.org/10.1016/j.giq.2020.101487

Gulledge, T. R. (2008). Architecture-driven enterprise integration. International Journal of Management and Enterprise Development, 5(3), 265-309. https://doi.org/10.1504/IJMED.2008.017433

Hacks, S., Höfert, H., Salentin, J., Yeong, Y. C., & Lichter, H. (2019). Towards the definition of enterprise architecture debts. 2019 IEEE 23rd International Enterprise Distributed Object Computing Workshop (EDOCW), 9–16. https://doi.org/10.1109/EDOCW.2019.00016

Haeckel, S. H. (1999). Adaptive enterprise: Creating and leading sense-and-respond organizations. Harvard business press.

Hanafi, B., & Purba, R. D. H. (2021). Perancangan Enterprise Architecture Dengan Modified Togaf Adm Pada PT Ilmu Komputercom Braindevs Sistema. JISICOM (Journal of Information System, Informatics and Computing), 5(2), 222–231. https://doi.org/10.52362/jisicom.v5i2.603

ISO/IEC. (2018). Information security management systems — Requirements. International Organization for Standardization. ISO/IEC 27001:2013.

Korhonen, J. J., & Halén, M. (2017). Enterprise architecture for digital transformation. 2017 IEEE 19th Conference on Business Informatics (CBI), 1, 349–358. https://doi.org/10.1109/CBI.2017.45

Kotusev, S. (2018). TOGAF-based enterprise architecture practice: An exploratory case study. Communications of the association for information systems, 43(1), 20. https://doi.org/10.17705/1CAIS.04320

Lankhorst, M. (2009). Enterprise architecture at work (Vol. 352). Springer.

Majstorović, M. N., & Terzić, R. М. (2018). Enterprise architecture as an approach to the development of information systems. Vojnotehnicki glasnik/Military Technical Courier, 66(2), 380-398. https://doi.org/10.5937/vojtehg66-15850

Martynov, V. V, Shavaleeva, D. N., & Salimova, A. I. (2018). Designing optimal enterprise architecture for digital industry: state and prospects. 2018 Global Smart Industry Conference (GloSIC), 1–7. https://doi.org/10.1109/GloSIC.2018.8570159

Mirsalari, S. R., & Ranjbarfard, M. (2020). A model for evaluation of enterprise architecture quality. Evaluation and Program Planning, 83, 101853. https://doi.org/10.1016/j.evalprogplan.2020.101853

Najib, W., Sumaryono, S., Nugroho, L. E., & Putra, G. D. (2018, July). Development of Enterprise Security Framework in SKK Migas Based on Integration of ISO 27000 and SABSA Model. In 2018 10th International Conference on Information Technology and Electrical Engineering (ICITEE) (pp. 382-387). IEEE. https://doi.org/10.1109/ICITEED.2018.8534747

Niemi, E., & Pekkola, S. (2020). The benefits of enterprise architecture in organizational transformation. Business & Information Systems Engineering, 62, 585–597. https://doi.org/10.1007/s12599-019-00605-3

Pourzolfaghar, Z., Bastidas, V., & Helfert, M. (2020). Standardisation of enterprise architecture development for smart cities. Journal of the Knowledge Economy, 11(4), 1336–1357. https://doi.org/10.1007/s13132-019-00601-8

Ross, J. W., Weill, P., & Robertson, D. (2006). Enterprise architecture as strategy: Creating a foundation for business execution. Harvard business press.

Sadovykh, A., Bagnato, A., Berre, A. J., & Walderhaug, S. (2020). Archimate as a specification language for big data applications-databio example. Software Engineering Aspects of Continuous Development and New Paradigms of Software Production and Deployment: Second International Workshop, DEVOPS 2019, Château de Villebrumier, France, May 6–8, 2019, Revised Selected Papers 2, 191–199. https://doi.org/10.1007/978-3-030-39306-9_14

Sales, T. P., Roelens, B., Poels, G., Guizzardi, G., Guarino, N., & Mylopoulos, J. (2019). A pattern language for value modeling in ArchiMate. Advanced Information Systems Engineering: 31st International Conference, CAiSE 2019, Rome, Italy, June 3–7, 2019, Proceedings 31, 230–245. https://doi.org/10.1007/978-3-030-21290-2_15

Shanks, G., Gloet, M., Someh, I. A., Frampton, K., & Tamm, T. (2018). Achieving benefits with enterprise architecture. The Journal of Strategic Information Systems, 27(2), 139–156. https://doi.org/10.1016/j.jsis.2018.03.001

Szczepaniuk, E. K., Szczepaniuk, H., Rokicki, T., & Klepacki, B. (2020). Information security assessment in public administration. Computers & Security, 90, 101709. https://doi.org/10.1016/j.cose.2019.101709

The Open Group. (2009). ArchiMate® 2.0 Specification. Opengrup.

The Open Group. (2018). Welcome to the TOGAF® Standard, Version 9.2, a standard of The Open Group. Opengrup.

The Open Group. (2023). The TOGAF® Standard, 10th Edition. The Open Group.

Varl, M., Duhovnik, J., & Tavčar, J. (2022). Customized product development supported by integrated information. Journal of Industrial Information Integration, 25, 100248. https://doi.org/10.1016/j.jii.2021.100248

Published
2024-10-01
How to Cite
Hidayat, R. S., Indrajit , R. E., & Dazki, E. (2024). TOGAF’s Approach in Developing an Enterprise Architecture for the Information Technology Security Industry. Journal La Multiapp, 5(5), 630-645. https://doi.org/10.37899/journallamultiapp.v5i5.1524