TOGAF TOGAF Security and Risk Architecture 1 — Questions and Answers
Question 1: How does TOGAF approach security architecture in the ADM?
- Security is addressed only in Phase D (Technology Architecture)
- Security concerns are integrated across all ADM phases as a pervasive concern affecting business, data, application, and technology domains (Correct answer)
- Security is handled separately outside the ADM
- Security is only relevant in Phase G (Implementation Governance)
Correct answer: Security concerns are integrated across all ADM phases as a pervasive concern affecting business, data, application, and technology domains
TOGAF treats security as a pervasive concern that must be addressed across all ADM phases and all four architecture domains (Business, Data, Application, Technology).
Question 2: What is 'Risk Management' in the context of TOGAF Architecture Development?
- Managing the financial risk of the architecture project budget
- Identifying, classifying, and mitigating risks to the successful development and implementation of the target architecture (Correct answer)
- Managing vendor contract risks
- Assessing the risk of technology obsolescence only
Correct answer: Identifying, classifying, and mitigating risks to the successful development and implementation of the target architecture
Risk Management in TOGAF involves identifying, classifying, and developing mitigation strategies for risks that could affect the development or implementation of the target architecture.
Question 3: In TOGAF, what is an 'Initial Risk Assessment' conducted during the ADM?
- A security penetration test
- An assessment identifying risks to the architecture engagement conducted in Phase A before detailed architecture work begins (Correct answer)
- A financial risk assessment for the project
- A vendor risk assessment
Correct answer: An assessment identifying risks to the architecture engagement conducted in Phase A before detailed architecture work begins
An Initial Risk Assessment in Phase A identifies risks to the architecture engagement, classifying them by impact and probability to determine mitigation approaches.
Question 4: What are 'Architecture Principles' related to security, and where do they come from in TOGAF?
- Rules created ad hoc by the security team for each project
- Enduring guidelines derived from business principles that guide security architecture decisions throughout the ADM (Correct answer)
- Hardware security specifications
- Vendor security product recommendations
Correct answer: Enduring guidelines derived from business principles that guide security architecture decisions throughout the ADM
Security-related Architecture Principles are enduring guidelines derived from business and IT strategy that constrain and guide security architecture decisions across all ADM phases.
Question 5: How does TOGAF recommend handling 'residual risk' after mitigation strategies are applied?
- Residual risk is always eliminated through further mitigation
- Residual risk is formally accepted and documented with approval from appropriate governance authorities (Correct answer)
- Residual risk is ignored if below a certain threshold
- Residual risk is transferred to the vendor
Correct answer: Residual risk is formally accepted and documented with approval from appropriate governance authorities
TOGAF recommends formally accepting residual risk (risk remaining after mitigation) with documented approval from appropriate governance authorities, creating an audit trail.
Question 6: Which TOGAF concept describes the classification of information assets by sensitivity to support security architecture decisions?
- Architecture Principles
- Information Classification (Correct answer)
- Architecture Compliance
- Security Baseline
Correct answer: Information Classification
Information Classification is a key input to security architecture in TOGAF, categorizing data by sensitivity level to drive appropriate security controls in the Data and Application architecture.
How does TOGAF approach security architecture in the ADM?