ISSAP - Information Systems Security Architecture Professional Governance, Risk, and Compliance Questions and Answers — Questions and Answers
Question 1: A security architect is designing a system for a financial institution that must comply with the Sarbanes-Oxley Act (SOX). A primary objective is to align IT processes with business goals and ensure robust internal controls over financial reporting. Which of the following governance frameworks is MOST suitable for achieving this objective?
- ISO/IEC 27001
- NIST Cybersecurity Framework (CSF)
- ITIL (Information Technology Infrastructure Library)
- COBIT (Control Objectives for Information and Related Technologies) (Correct answer)
Correct answer: COBIT (Control Objectives for Information and Related Technologies)
COBIT is a comprehensive framework for the governance and management of enterprise IT. It is specifically designed to bridge the gap between technical issues, business risks, and control requirements, making it highly suitable for achieving compliance with regulations like SOX that require strong internal controls and alignment between IT and business objectives. While other frameworks are useful, COBIT's core focus is on governance and its link to business goals.
Question 2: As part of the NIST Risk Management Framework (RMF), a security architect is responsible for defining the initial set of security controls for a new information system. This selection is based on the system's security categorization. Which step of the RMF is being performed?
- Categorize System
- Select Controls (Correct answer)
- Assess Controls
- Authorize System
Correct answer: Select Controls
The 'Select Controls' step of the NIST RMF involves choosing an initial baseline of security controls for an information system based on its security categorization (determined in the 'Categorize System' step). The architect then tailors this baseline to align with the organization's specific risk tolerance and operational environment.
Question 3: A global e-commerce company is developing a comprehensive risk management strategy. They want to adopt a set of high-level principles to guide the integration of risk management into all organizational activities, ensuring it is dynamic, customized, and structured. Which international standard provides such principles for risk management?
- ISO 9001
- ISO/IEC 27005
- ISO 31000 (Correct answer)
- SABSA
Correct answer: ISO 31000
ISO 31000 is an international standard that provides principles, a framework, and a process for managing risk. It is not specific to any industry and focuses on integrating risk management throughout an organization's governance, strategy, and operations. Its core principles include integration, a structured approach, customization, and continual improvement.
Question 4: A security architect is embedding compliance requirements into the technology infrastructure from the initial design phase. This proactive approach ensures that controls for data protection, access management, and privacy are built-in rather than added later, significantly reducing the cost and effort of retrofitting. This practice is best described as which of the following?
- Compliance as Code
- Risk Transference
- Defense in Depth
- Security by Design (Correct answer)
Correct answer: Security by Design
Security by Design, also referred to as Secure by Design, is the principle of integrating security considerations and controls into the system development lifecycle from the very beginning. This approach ensures that compliance and security are fundamental components of the architecture, rather than afterthoughts that require costly retrofitting.
Question 5: Which of the following is a primary role of a security architect in the context of Governance, Risk, and Compliance (GRC)?
- Performing daily security operations and incident response.
- Configuring and managing firewall rules and intrusion detection systems.
- Designing and developing security solutions that align with business strategy, policies, and regulatory requirements. (Correct answer)
- Conducting forensic analysis of compromised systems after a security breach.
Correct answer: Designing and developing security solutions that align with business strategy, policies, and regulatory requirements.
A security architect's primary role within GRC is to design security solutions and architectures that are aligned with the organization's vision, mission, strategy, policies, and external factors like laws and regulations. They translate GRC objectives into technical and architectural requirements, ensuring that the security posture supports business goals while managing risk and maintaining compliance.
Question 6: A security architect at a multinational corporation is tasked with designing a security architecture that can adapt to a complex and constantly changing regulatory landscape. The architecture must provide a consistent set of reusable security services, such as identity management and network segmentation, across all business units. What is the main benefit of this architectural approach?
- It eliminates the need for all future security testing.
- It provides standardization that simplifies demonstrating compliance across multiple regulations. (Correct answer)
- It completely outsources all security risks to third-party vendors.
- It reduces the initial cost of security implementation to near zero.
Correct answer: It provides standardization that simplifies demonstrating compliance across multiple regulations.
A well-designed security architecture that uses consistent, standardized building blocks and common security services simplifies the process of meeting diverse regulatory obligations. This consistency makes it easier to audit, manage, and demonstrate compliance across the enterprise, even when regulations change or overlap.
A security architect is designing a system for a financial institution that must comply with the Sarbanes-Oxley Act (SOX).
A primary objective is to align IT processes with business goals and ensure robust internal controls over financial reporting.
Which of the following governance frameworks is MOST suitable for achieving this objective?