Enterprise Security Architecture
Stop bolting security on after the fact. Architect it into how the enterprise runs.
Tuition
$499
Advanced
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
10 hours
Estimated time
What you will be able to do
- You will be able to explain where security architecture sits in the enterprise and use a framework such as the Sherwood Applied Business Security Architecture (SABSA) to trace every control back to a business driver.
- You will be able to translate business risk appetite and compliance obligations into clear, testable security architecture requirements.
- You will be able to assess a current-state architecture against a target state and turn the gaps into prioritized work.
- You will be able to design reusable security patterns and reference architectures, including a zero trust model based on National Institute of Standards and Technology (NIST) guidance.
- You will be able to write security standards and baselines that engineering teams actually adopt, backed by a workable exception process.
- You will be able to stand up and run an architecture review board that guides design decisions without becoming a bottleneck.
- You will be able to run an architecture-level threat model and security design review, then capture the outcome in an architecture decision record.
- You will be able to build a sequenced, funded multi-year security roadmap and present the business case to executives.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Architecture Grounded in Business Risk
A security architect exists to turn business risk and compliance into designs the enterprise can build on, so the work starts with context, not tools. This module places security architecture inside the frameworks that govern it, the Sherwood Applied Business Security Architecture (SABSA) and The Open Group Architecture Framework (TOGAF), then teaches you to read the business drivers, risk appetite, and regulatory obligations every design must answer to. You will learn to map a current-state architecture against a target state and trace each requirement back to the business reason behind it.
2 lessons · 5 quiz questions
- 02
Security Patterns, Reference Architectures, and Standards
Enterprises do not scale security by reviewing every system from scratch; they scale it through reusable patterns and clear standards. This module teaches the anatomy of a security pattern and how to build reference architectures around principles like defense in depth, least privilege, and zero trust, drawing on National Institute of Standards and Technology (NIST) guidance. You will then learn to write the security standards, baselines, and paved roads that engineering teams actually adopt, including how to version them and handle exceptions without eroding trust.
2 lessons · 5 quiz questions · assignment
- 03
Architecture Review Boards and Design Governance
Patterns and standards only matter if real projects follow them, and that is the job of governance. This module shows you how to charter and run an architecture review board: who sits on it, how work reaches it, how decisions get made, and how risk is accepted or escalated. You will also run architecture-level threat models and security design reviews, then record each decision so it guides teams instead of gathering dust.
2 lessons · 5 quiz questions
- 04
Multi-Year Security Roadmaps and Executive Buy-In
A strong architecture is worth little if you cannot fund it and sequence it over time. In this final module you will turn current-to-target gaps into a multi-year security roadmap: prioritized, sequenced, and tied to a maturity model and a clear business case. You will also learn to win executive support, track a small set of architecture health metrics, and keep the roadmap alive as the business and its risks change.
2 lessons · 5 quiz questions · assignment