CAS-002 · Question #196
An architect has been engaged to write the security viewpoint of a new initiative. Which of the following BEST describes a repeatable process that can be used for establishing the security…
The correct answer is C. Classify information types used within the system into levels of confidentiality, integrity, and. A repeatable security architecture process begins with classifying information by CIA categories, which systematically drives all downstream risk analysis and control selection.
Question
An architect has been engaged to write the security viewpoint of a new initiative. Which of the following BEST describes a repeatable process that can be used for establishing the security architecture?
Options
- AInspect a previous architectural document.
- BImplement controls based on the system needs. Perform a risk analysis of the system.
- CClassify information types used within the system into levels of confidentiality, integrity, and
- DPerform a risk analysis of the system.
How the community answered
(22 responses)- A9% (2)
- B5% (1)
- C82% (18)
- D5% (1)
Why each option
A repeatable security architecture process begins with classifying information by CIA categories, which systematically drives all downstream risk analysis and control selection.
Reviewing a previous architectural document is not a repeatable or generalizable process - it depends on the existence and relevance of prior documentation and may not apply to a new initiative.
Implementing controls before performing risk analysis reverses the correct order - controls must be selected based on identified risks, not the other way around.
Classifying information types into confidentiality, integrity, and availability levels (as described in NIST SP 800-60 and FIPS 199) is the foundational, repeatable first step in security architecture - it provides a consistent baseline that drives risk analysis and control selection for any system, making the entire process reproducible across different projects and initiatives.
Performing risk analysis without first classifying information types lacks the foundational impact-level data needed to assess risk meaningfully, making the process incomplete and less repeatable.
Concept tested: Information classification as foundation of repeatable security architecture
Source: https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.