Why is it important to include security and privacy in an EA program and the documentation of EA components?

The role of security and privacy within an EA program is best described as a comprehensive set of controls that pervade all architectural domains and are a key part of an organization’s risk management strategy. One can think of this as a vertical thread that weaves through all levels of the architecture. The thread metaphor is used (as opposed to a separate dedicated level) because security and privacy are most effective when they are integral to the enterprise’s strategic initiatives, business services, information flows, applications, and technology infrastructure.

