nerdexam
Isaca

CRISC · Question #367

Which of the following is the PRIMARY benefit of integrating risk and security requirements in an organization's enterprise architecture (EA)?

The correct answer is D. Consistent management of information assets. The primary benefit of integrating risk and security requirements into an organization's enterprise architecture (EA) is the consistent management of information assets.

Submitted by wei.xz· Apr 18, 2026Governance

Question

Which of the following is the PRIMARY benefit of integrating risk and security requirements in an organization's enterprise architecture (EA)?

Options

  • AAdherence to legal and compliance requirements
  • BReduction in the number of test cases in the acceptance phase
  • CEstablishment of digital forensic architectures
  • DConsistent management of information assets

How the community answered

(64 responses)
  • A
    2% (1)
  • B
    11% (7)
  • C
    5% (3)
  • D
    83% (53)

Why each option

The primary benefit of integrating risk and security requirements into an organization's enterprise architecture (EA) is the consistent management of information assets.

AAdherence to legal and compliance requirements

While adherence to legal and compliance requirements is a benefit, consistent management of information assets is a broader and more fundamental outcome that enables compliance.

BReduction in the number of test cases in the acceptance phase

Reduction in test cases is a potential operational benefit, but not the primary or most strategic benefit of integrating risk/security into EA.

CEstablishment of digital forensic architectures

Establishment of digital forensic architectures is a specific security capability, but not the overall primary benefit of integrating risk and security into EA, which is about broader asset protection.

DConsistent management of information assetsCorrect

By embedding risk and security requirements directly into the enterprise architecture, an organization establishes a standardized and holistic approach to protecting all information assets. This integration leads to consistent application of security principles, controls, and risk management strategies across various systems and domains, preventing fragmented security postures and improving overall asset management.

Concept tested: Benefits of integrating security into enterprise architecture

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v1.pdf

Topics

#Enterprise Architecture#Risk Integration#Security Requirements#Information Asset Management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice