- Home
- All questions
- Question 21
CISM study material · question 21 of 1000
A design review proposes to complete the enterprise architecture and then add a separate information security architecture layer beside it. Why does SP 800-39 regard this as wrong?
Show the answer
Answer: B. The information security architecture is part of the enterprise architecture, not a layer alongside it
In SP 800-39 the information security architecture is a sub-architecture derived from and embedded within the enterprise architecture at Tier 2, developed as an integral part of it rather than defined separately.
Source: NIST SP 800-39 (NIST) — Sec. 2.2 Multitiered Risk Management