CGRC · Question #349
What role ensures the selection of security controls is consistent with the enterprise architecture, including reference models and segment and solution architectures Response:
The correct answer is A. Information Security Architect. The Information Security Architect is responsible for ensuring the selection of security controls aligns with the organization's enterprise architecture, including reference models and segment architectures.
Question
What role ensures the selection of security controls is consistent with the enterprise architecture, including reference models and segment and solution architectures Response:
Options
- AInformation Security Architect
- BInformation System Owner
- CAuthorizing Official
- DChief Information Officer
How the community answered
(48 responses)- A96% (46)
- C2% (1)
- D2% (1)
Why each option
The Information Security Architect is responsible for ensuring the selection of security controls aligns with the organization's enterprise architecture, including reference models and segment architectures.
The Information Security Architect is tasked with designing and integrating security solutions into the enterprise architecture, making them responsible for ensuring that security control selections are consistent with established architectural models, standards, and overall enterprise design principles across the organization.
The Information System Owner is primarily responsible for the overall procurement, development, integration, modification, operation, and maintenance of a specific information system, not enterprise-wide architectural consistency of control selection.
The Authorizing Official is a senior management official who accepts the risk of operating an information system, based on an assessment of its security posture, rather than ensuring architectural consistency of control selection.
The Chief Information Officer (CIO) is responsible for the overall IT strategy and operations, but the detailed architectural consistency of security controls typically falls under the more specialized purview of a security architect.
Concept tested: Role of Information Security Architect
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf
Topics
Community Discussion
No community discussion yet for this question.