nerdexam
CompTIA

CAS-001 · Question #179

A large financial company has a team of security-focused architects and designers that contribute into broader IT architecture and design solutions. Concerns have been raised due to the security…

The correct answer is C. Introduce an ESA framework. An Enterprise Security Architecture (ESA) framework provides a structured, repeatable methodology for designing security solutions that align with business drivers, incorporate capability models, establish security baselines, and promote reusable design patterns. It addresses…

Enterprise Security

Question

A large financial company has a team of security-focused architects and designers that contribute into broader IT architecture and design solutions. Concerns have been raised due to the security contributions having varying levels of quality and consistency. It has been agreed that a more formalized methodology is needed that can take business drivers, capabilities, baselines, and re- usable patterns into account. Which of the following would BEST help to achieve these objectives?

Options

  • AConstruct a library of re-usable security patterns
  • BConstruct a security control library
  • CIntroduce an ESA framework
  • DInclude SRTM in the SDLC

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    10% (4)
  • C
    80% (33)
  • D
    7% (3)

Explanation

An Enterprise Security Architecture (ESA) framework provides a structured, repeatable methodology for designing security solutions that align with business drivers, incorporate capability models, establish security baselines, and promote reusable design patterns. It addresses exactly the problem described: inconsistent quality and lack of formalized process across a team of security architects. Frameworks like SABSA or TOGAF with security extensions are examples of ESA frameworks. Option A (library of reusable security patterns) is a component that might exist within an ESA framework but alone does not provide the full methodology for incorporating business drivers and capability baselines. Option B (security control library) addresses control selection but not the broader architectural methodology. Option D (SRTM - Security Requirements Traceability Matrix - in the SDLC) is a tool for tracking requirements in development projects, not a comprehensive architectural framework for a security team.

Topics

#enterprise security architecture#ESA framework#security patterns#SDLC

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice