Are there any best practices out there to connect #MITRE #ATT&CK and #D3FEND while doing a #Threatmodel in a #TOGAF #ADM security architecture?

How do I go from »There is an attack vector!« to »The developers closed their tickets which implement all relevant counter measures«?

Does #SABSA or #PASTA offer any insight here?

So I spent some time in #PlantUML trying to model #Risk #Trust #Attacks to tie #TOGAF #SABSA #Threatmodel and #PASTA #STRIDE together

As a Hacker, I don't need a fancy #diagram to visualise the attack vector and path I am already seeing. But as security architect/Team Blue I need to show it to others who don't see it.
And it has to be audit compliant.

The public repo with my PUMLs is here, feel free to reuse it
https://codeberg.org/0xKaishakunin/Architecture/src/branch/main/PlantUML-ModelingTrust

Architecture

Security Architecture Notes and Patterns

Codeberg.org

The security architecture patterns have been overhauled and revamped, after 15 years.

They are also now Open Source 😍

https://opensecurityarchitecture.org/

And PlantUML icons for architects are also available now, including black hats and white hats

https://github.com/Crashedmind/PlantUML-opensecurityarchitecture-icons

#architecture #security #floss #togaf #sabsa #uml #plantuml

Home | Open Security Architecture

Open Security Architecture - Free, open security patterns and NIST 800-53 control mappings for enterprise security architects.

Une approche « Model-Centric », combinée à un prompting avancé, permet d'automatiser des tâches fastidieuses de l’architecte d’entreprise, tout en garantissant traçabilité et continuité.

https://www.urbanisation-si.com/intelligence-artificielle-strategie-et-architecture-1

#togaf #archimate #architecture_entreprise

ArchiMate NEXT drops BAT. Now What?

A new version of ArchiMate is coming. Last summer a snapshot of “ArchiMate NEXT” was published. First of a few articles with my thoughts on the development. With a slight sprinkling of …

R&A IT Strategy & Architecture
On me dit trop by the book.
Mais tout ceux que j'entend me dire qu'il ne faut pas prendre la #méthode au pied de la lettre, et qu'il faut savoir s'adapter, (ce que je peux accepter si c'est par maitrise et expertise,) je les vois s'adapter par peur, par confort, par incompréhension et méconnaissance. #scrum #SAFe #Lean #XP #ITIL 4 #Togaf #PMP #PM2 #ADKAR

🏢 ArchiMate es el estándar para modelar arquitectura empresarial. Conecta negocio, apps y tecnología en un solo modelo visual. ¡Descúbrelo! 🔧

Lee más 👉 https://www.soloingenieria.org/ingenieria-en-sistemas/archimate/

#ArchiMate #ArquitecturaEmpresarial #IngenieriaEnSistemas #TOGAF #ModeladoEmpresarial

Sin un lenguaje común, la arquitectura empresarial es solo un conjunto de diagramas inconexos. ArchiMate unifica negocio, apps y tecnología en una sola visión. 🏢

#ArchiMate #ArquitecturaEmpresarial #IngenieriaEnSistemas #TOGAF #ModeladoEmpresarial

🏗️ TOGAF es el framework líder en arquitectura empresarial. Conecta TI con los objetivos del negocio y optimiza procesos. ¡Descubre sus fases y certificaciones! 💼

Lee más 👉 https://www.soloingenieria.org/ingenieria-en-sistemas/togaf/

#TOGAF #ArquitecturaEmpresarial #IngenieríaDeSistemas #FrameworkTI #CertificaciónTOGAF

Si quieres destacar en TI, aprende TOGAF. Empieza por entender sus cuatro dominios: Negocio, datos, aplicaciones y tecnología. Es la base de todo. 💡

#TOGAF #ArquitecturaEmpresarial #IngenieríaDeSistemas #FrameworkTI #CertificaciónTOGAF