nerdexam
(ISC)2

CGRC · Question #349

What role ensures the selection of security controls is consistent with the enterprise architecture, including reference models and segment and solution architectures Response:

The correct answer is A. Information Security Architect. The Information Security Architect is responsible for ensuring the selection of security controls aligns with the organization's enterprise architecture, including reference models and segment architectures.

Selection and Approval of Framework, Security, and Privacy Controls

Question

What role ensures the selection of security controls is consistent with the enterprise architecture, including reference models and segment and solution architectures Response:

Options

  • AInformation Security Architect
  • BInformation System Owner
  • CAuthorizing Official
  • DChief Information Officer

How the community answered

(48 responses)
  • A
    96% (46)
  • C
    2% (1)
  • D
    2% (1)

Why each option

The Information Security Architect is responsible for ensuring the selection of security controls aligns with the organization's enterprise architecture, including reference models and segment architectures.

AInformation Security ArchitectCorrect

The Information Security Architect is tasked with designing and integrating security solutions into the enterprise architecture, making them responsible for ensuring that security control selections are consistent with established architectural models, standards, and overall enterprise design principles across the organization.

BInformation System Owner

The Information System Owner is primarily responsible for the overall procurement, development, integration, modification, operation, and maintenance of a specific information system, not enterprise-wide architectural consistency of control selection.

CAuthorizing Official

The Authorizing Official is a senior management official who accepts the risk of operating an information system, based on an assessment of its security posture, rather than ensuring architectural consistency of control selection.

DChief Information Officer

The Chief Information Officer (CIO) is responsible for the overall IT strategy and operations, but the detailed architectural consistency of security controls typically falls under the more specialized purview of a security architect.

Concept tested: Role of Information Security Architect

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf

Topics

#Information Security Architect#Security Control Selection#Enterprise Architecture#RMF Roles

Community Discussion

No community discussion yet for this question.

Full CGRC Practice