This document discusses concepts related to policy architecture in the SABSA framework. It introduces key ideas such as:
- Security domains that are subject to a common security policy set by a domain owner.
- Security policy defines the security services and requirements for a domain as well as its interactions with other domains.
- A layered policy architecture with each layer derived from the previous to ensure traceability from enterprise-wide to operational levels.
- Examples of how a backup policy can be expressed at different layers from the logical to operational.
- Inter-domain relationships where each domain authority is responsible for their risks but sets policy in the context of super domain authorities. Domains and policies can exist in multiple dimensions such as