SABSA

Glossary

SABSA

Definition: SABSA (Sherwood Applied Business Security Architecture) is a risk-driven framework for designing security architecture starting from business requirements and working downward, rather than starting from a checklist of controls and working upward.

Most security frameworks answer “which controls should we implement.” SABSA answers a different, earlier question: what is the business actually trying to achieve, and what does security architecture need to look like to enable that safely. That ordering matters most at the fintech/regulated-enterprise layer, where a control-first approach produces a compliant architecture that still doesn’t fit how the business actually operates. This is also the framework Dwight holds a certification in and applies directly in his day-job architecture reviews, not a framework covered secondhand from research.

Read the full case study on Substack: SABSA Isn’t a Framework. It’s a Business Conversation →

← Back to Glossary