Study. uk . com
  1. Home
  2. All questions
  3. Question 53

CISM study material · question 53 of 1000

An enterprise architect delivers a completed target architecture and then asks the security team to identify where controls should be added. Why is this sequence wrong under NIST guidance?

  1. Architecture must be formally approved before any control discussion can occur, so that controls are selected against a design that is stable
  2. Only the authorising official may add controls to an architecture
  3. Security should be built into all layers of the enterprise architecture rather than applied to finished designs
  4. The security team has no role in architecture under NIST guidance
Show the answer

Answer: C. Security should be built into all layers of the enterprise architecture rather than applied to finished designs

The chief enterprise architect is responsible for facilitating the integration of information security into all layers of the enterprise architecture, so that the organisation implements secure solutions by design.

Source: NIST SP 800-100 (NIST) — Sec. 2.2.3.4 Chief Enterprise Architect

Challenge yourself on this topic → Study as cards