Models and Resources

Practical models, frameworks, downloads, and presentations for security architecture work.

How To Use This Library

These resources were created for different goals: workshops, design reviews, architecture communication, risk conversations, and capability planning. Feel free to use them, reference the original author, and send feedback to esa@assuredcontrol.com so the material can keep improving.

Key Models

Architecture model diagram

Archi Model

An interactive architecture model with exported views for security operations, DevSecOps, protective monitoring, threat and vulnerability management, and role mapping.

Security Services Domain Model preview

Security Services Domain Model

A SABSA-aligned, relationship-first model connecting business drivers, risk, domain policy, security services, mechanisms, physical systems and products — with worked examples for IAM, payments, AI governance, and firewall and network security. Evolved from the original Security Services Ontology / ERD.

Security Domain Model preview showing Domains and Sub-domains

Security Domain Model

An interactive, structured view of security Domains and their supporting Sub-domains. It helps organisations understand the breadth of security, clarify the purpose and applicability of each area, identify gaps and establish a coherent foundation for policy, architecture and control design.

Security Controls Matrix preview

Security Controls Matrix

A cohesive taxonomy of security domains, controls, and business drivers. It helps identify gaps, align initiatives with strategic objectives, and drive risk-based security architecture.

Risk Domain Model preview

Risk Domain Model

A framework for understanding threats, hazards, vulnerabilities, controls, and treatment. It distinguishes business criticality from the attack value perceived by an event agent, linking both perspectives to risk decisions and measurement.

Privacy Domain Model preview

Privacy Domain Model

A connected model of natural persons, personal information, data classification, rights, regulation, privacy principles, controllers, processors, and privacy threats.

Operating Model preview

Operating Model

A connected model of vision, strategy, design principles, capabilities, value streams, the six design dimensions, governance, and the journey from current to target operating model.

CSDM 5 focused model preview

CSDM 5 Focused Model

An independent, relationship-first interpretation of the Common Service Data Model version 5, connecting strategy and design to deployed services, offerings, consumption, portfolio oversight, and foundational data.

Vulnerability Management Framework preview

Vulnerability Management Frameworks

Models for vulnerability detection, scoring, secure configuration, threat intelligence sharing, malware analysis, and secure development. Useful for architects designing resilient vulnerability management capabilities.

Threat Intelligence Framework preview

Threat Intelligence Service Framework

A model for threat intelligence, predictive analytics, threat modelling, risk prioritisation, threat hunting, adversary profiling, exploit intelligence, and threat sharing.

Presentations

What Good Looks Like metrics presentation preview

What Good Looks Like - Metrics

A practical guide to using KPIs, KCIs, and KRIs effectively for senior leaders, CISOs, and operational teams. It focuses on business outcomes, risk, control effectiveness, and operational performance.

Herding Cats DevSecOps presentation preview

Herding Cats In A DevSecOps World

An end-to-end view of how security integrates into modern software delivery pipelines, including feedback loops, SAST, DAST, SCA, RASP, dependency checking, and digital trust.

Business-Driven Cloud Architecture presentation preview

Business-Driven Cloud Architecture

A top-down approach to cloud architecture that starts with business motivations, capability development, and operating model outcomes rather than technology-first design.