Study. uk . com
  1. Home
  2. All questions
  3. Question 21

CISM study material · question 21 of 1000

A design review proposes to complete the enterprise architecture and then add a separate information security architecture layer beside it. Why does SP 800-39 regard this as wrong?

  1. Security architecture is optional once controls are selected
  2. The information security architecture is part of the enterprise architecture, not a layer alongside it
  3. Security architecture must be completed before enterprise architecture begins, so that the business design inherits its constraints
  4. Enterprise architecture is a Tier 3 system-level activity while security architecture belongs at Tier 1 with the risk executive
Show the answer

Answer: B. The information security architecture is part of the enterprise architecture, not a layer alongside it

In SP 800-39 the information security architecture is a sub-architecture derived from and embedded within the enterprise architecture at Tier 2, developed as an integral part of it rather than defined separately.

Source: NIST SP 800-39 (NIST) — Sec. 2.2 Multitiered Risk Management

Challenge yourself on this topic → Study as cards