CAS-002 · Question #188
A large financial company has a team of security-focused architects and designers that contribute into broader IT architecture and design solutions. Concerns have been raised due to the security…
The correct answer is C. Introduce an ESA framework. An Enterprise Security Architecture (ESA) framework provides the formalized methodology needed to incorporate business drivers, capabilities, baselines, and reusable patterns for consistent security design.
Question
A large financial company has a team of security-focused architects and designers that contribute into broader IT architecture and design solutions. Concerns have been raised due to the security contributions having varying levels of quality and consistency. It has been agreed that a more formalized methodology is needed that can take business drivers, capabilities, baselines, and re usable patterns into account. Which of the following would BEST help to achieve these objectives?
Options
- AConstruct a library of re-usable security patterns
- BConstruct a security control library
- CIntroduce an ESA framework
- DInclude SRTM in the SDLC
How the community answered
(22 responses)- A5% (1)
- B23% (5)
- C59% (13)
- D14% (3)
Why each option
An Enterprise Security Architecture (ESA) framework provides the formalized methodology needed to incorporate business drivers, capabilities, baselines, and reusable patterns for consistent security design.
A library of reusable security patterns covers only one component of the needed methodology and does not address business driver alignment, capability modeling, or baseline governance.
A security control library catalogs individual controls but does not provide the architectural methodology needed to translate business requirements into consistent, high-quality security designs.
An ESA framework establishes a structured, repeatable approach to security architecture that explicitly integrates business drivers, security capability models, configuration baselines, and reusable design patterns into a coherent reference architecture. This formalization ensures that security architects across the team work from the same methodology, directly addressing the quality and consistency gaps identified by the organization.
Including an SRTM (Security Requirements Traceability Matrix) in the SDLC improves requirements tracking within development projects but is not a broad architectural framework addressing the full scope of the problem described.
Concept tested: Enterprise Security Architecture framework for design consistency
Source: https://www.sabsa.org/the-sabsa-framework/
Topics
Community Discussion
No community discussion yet for this question.