nerdexam
(ISC)2

CSSLP · Question #259

You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You want to perform the following tasks: Develop a risk-driven enterprise information security architecture. Deliver security…

The correct answer is C. Sherwood Applied Business Security Architecture. This question asks for the specific methodology a CSO would use to develop a risk-driven enterprise information security architecture and deliver security solutions aligned with business initiatives.

Secure Software Architecture and Design

Question

You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You want to perform the following tasks: Develop a risk-driven enterprise information security architecture. Deliver security infrastructure solutions that support critical business initiatives. Which of the following methods will you use to accomplish these tasks?

Options

  • AService-oriented modeling and architecture
  • BService-oriented modeling framework
  • CSherwood Applied Business Security Architecture
  • DService-oriented architecture

How the community answered

(36 responses)
  • B
    3% (1)
  • C
    94% (34)
  • D
    3% (1)

Why each option

This question asks for the specific methodology a CSO would use to develop a risk-driven enterprise information security architecture and deliver security solutions aligned with business initiatives.

AService-oriented modeling and architecture

Service-oriented modeling and architecture (SOMA) focuses on defining services within a Service-Oriented Architecture (SOA), not specifically on security architecture.

BService-oriented modeling framework

Service-oriented modeling framework (SOMF) is a general framework for service-oriented modeling, broader than just security architecture.

CSherwood Applied Business Security ArchitectureCorrect

Sherwood Applied Business Security Architecture (SABSA) is a methodology for developing risk-driven enterprise information security and information assurance architectures. It directly addresses the need to align security with business objectives and provides a framework for designing and delivering security infrastructure solutions that support critical business initiatives.

DService-oriented architecture

Service-oriented architecture (SOA) is an architectural style for building business applications as loosely coupled services, not a specific methodology for enterprise security architecture.

Concept tested: SABSA security architecture framework

Source: https://sabsa.org/

Topics

#Enterprise Security Architecture#SABSA#Security Frameworks#Risk-driven Architecture

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice