CAS-002 · Question #548
A replacement CRM has had its business case approved. In preparation for a requirements workshop, an architect is working with a business analyst to ensure that appropriate security requirements…
The correct answer is A. Business requirements document. The Business Requirements Document is the correct artifact for capturing security requirements because it defines all functional and non-functional needs - including security constraints - that a solution must satisfy.
Question
A replacement CRM has had its business case approved. In preparation for a requirements workshop, an architect is working with a business analyst to ensure that appropriate security requirements have been captured. Which of the following documents BEST captures the security requirements?
Options
- ABusiness requirements document
- BRequirements traceability matrix document
- CUse case and viewpoints document
- DSolution overview document
How the community answered
(65 responses)- A85% (55)
- B5% (3)
- C2% (1)
- D9% (6)
Why each option
The Business Requirements Document is the correct artifact for capturing security requirements because it defines all functional and non-functional needs - including security constraints - that a solution must satisfy.
The Business Requirements Document formally captures what the business needs from a system, including non-functional requirements such as confidentiality, integrity, availability, and compliance obligations. In enterprise architecture practice, security requirements are embedded within the BRD so they are considered from the earliest stage of solution design rather than retrofitted later. This ensures security is addressed as a business need rather than a technical afterthought.
A Requirements Traceability Matrix tracks and links requirements to design and test artifacts but does not itself capture or define requirements.
Use case and viewpoints documents describe system interactions and perspectives but are not the primary vehicle for capturing security requirements.
A Solution Overview Document describes the proposed technical solution and architecture, not the business and security requirements the solution must meet.
Concept tested: Security requirements capture in enterprise architecture BRD
Source: https://pubs.opengroup.org/architecture/togaf9-doc/arch/chap08.html
Topics
Community Discussion
No community discussion yet for this question.