TOGAF Security and Risk Architecture Flashcards
6 cards from real TOGAF practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 TOGAF Security and Risk Architecture flashcards as text
What is a 'Risk Register' in the context of TOGAF architecture governance?
Answer: A document capturing identified risks, their classification, mitigation strategies, and ownership throughout the architecture lifecycle
The Risk Register is a governance artifact capturing all identified risks to the architecture, with their classification, probability, impact, mitigation approaches, and responsible owners.
In TOGAF, how does security architecture relate to the concept of 'Architecture Building Blocks'?
Answer: Security capabilities can be defined as Architecture Building Blocks (ABBs) and implemented as Solution Building Blocks (SBBs) for reuse
Security capabilities (e.g., identity management, encryption services) can be defined as ABBs specifying the required capability and then implemented as SBBs representing specific products.
What is the purpose of a 'Security Architecture View' in TOGAF?
Answer: To communicate the security architecture to security-focused stakeholders by addressing their specific security concerns
A Security Architecture View addresses the concerns of security-focused stakeholders, showing how security requirements and controls are incorporated across the architecture domains.
How does TOGAF recommend integrating compliance requirements (e.g., regulatory, legal) into the architecture?
Answer: Compliance requirements should be captured as architecture requirements and constraints early in the ADM, influencing architecture decisions
TOGAF recommends treating regulatory and compliance requirements as architecture constraints captured early in the ADM (Phase A/B) so they influence all subsequent architecture decisions.
What does the TOGAF concept of 'Security Zoning' contribute to Technology Architecture design?
Answer: Segmenting the technology environment into zones with different trust levels and controlling inter-zone traffic
Security Zoning divides the technology architecture into trust zones (e.g., DMZ, internal, restricted) with defined controls on traffic between zones, a key element of Technology Architecture.
In TOGAF, what is the relationship between 'Architecture Principles' and security constraints during Phase B (Business Architecture)?
Answer: Security-related Architecture Principles constrain what business processes and capabilities can be designed in Phase B
Security-related Architecture Principles apply from Phase B onwards, constraining business process design to ensure inherent security is considered in business architecture decisions.