nerdexam
(ISC)2

CISSP · Question #1086

What is the correct order of execution for security architecture?

The correct answer is A. Governance, strategy and program management, project delivery, operations. Security architecture follows a defined hierarchical execution order where governance establishes the foundational rules before strategy, delivery, and operations can proceed.

Submitted by ashley.k· Mar 5, 2026Security Architecture and Engineering

Question

What is the correct order of execution for security architecture?

Options

  • AGovernance, strategy and program management, project delivery, operations
  • BStrategy and program management, governance, project delivery, operations
  • CGovernance, strategy and program management, operations, project delivery
  • DStrategy and program management, project delivery, governance, operations

How the community answered

(30 responses)
  • A
    93% (28)
  • B
    3% (1)
  • C
    3% (1)

Why each option

Security architecture follows a defined hierarchical execution order where governance establishes the foundational rules before strategy, delivery, and operations can proceed.

AGovernance, strategy and program management, project delivery, operationsCorrect

The correct order - Governance, Strategy and Program Management, Project Delivery, Operations - reflects the logical dependency chain in security architecture. Governance must be established first to define policies, risk tolerance, and authority structures; strategy and program management then translate governance directives into plans and programs; project delivery executes those plans; and operations sustains and monitors the implemented controls on an ongoing basis.

BStrategy and program management, governance, project delivery, operations

Strategy and program management cannot logically precede governance, as governance provides the foundational policies, mandates, and authority structures that strategy must align to and derive direction from.

CGovernance, strategy and program management, operations, project delivery

Placing operations before project delivery is incorrect because operations requires that security controls and systems have first been built and deployed through project delivery before they can be run and maintained.

DStrategy and program management, project delivery, governance, operations

This order places governance after project delivery, which is fundamentally incorrect since governance must define the rules, compliance requirements, and oversight structures that guide both strategy and project execution from the outset.

Concept tested: Security architecture execution order and lifecycle phases

Source: https://learn.microsoft.com/en-us/security/adoption/security-adoption-overview

Topics

#security architecture#governance#program management#project delivery

Community Discussion

No community discussion yet for this question.

Full CISSP Practice