CGEIT · Question #670
Which of the following is the FIRST consideration for a CISO when implementing Zero Trust architecture?
The correct answer is A. Refining relevant business goals. The initial consideration for a CISO implementing Zero Trust architecture should be refining relevant business goals to ensure security initiatives align with organizational objectives.
Question
Which of the following is the FIRST consideration for a CISO when implementing Zero Trust architecture?
Options
- ARefining relevant business goals.
- BLimiting the number of privileged accounts.
- CSelecting a security framework that is relevant to the business.
- DDefining security projects to address identified control gaps.
How the community answered
(50 responses)- A70% (35)
- B16% (8)
- C6% (3)
- D8% (4)
Why each option
The initial consideration for a CISO implementing Zero Trust architecture should be refining relevant business goals to ensure security initiatives align with organizational objectives.
Before implementing any security architecture like Zero Trust, a CISO must first understand and refine the relevant business goals, as security should always be an enabler of the business rather than a standalone technical exercise. Aligning Zero Trust principles with specific business outcomes ensures the architecture supports organizational objectives effectively.
Limiting privileged accounts is a key component of Zero Trust but is a specific implementation step, not the foundational first consideration before strategy alignment.
Selecting a security framework is important but comes after understanding the business context and goals, as the framework choice should support those objectives.
Defining security projects and addressing control gaps are tactical steps that flow from the overall strategy, which itself is driven by business goals.
Concept tested: Aligning Zero Trust with business goals
Source: https://learn.microsoft.com/en-us/security/zero-trust/zero-trust-overview
Topics
Community Discussion
No community discussion yet for this question.