← All TOGAF Flashcard Decks

TOGAF Security and Risk Architecture Flashcards

6 cards from real TOGAF practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 TOGAF Security and Risk Architecture flashcards as text
  1. What is 'Identity and Access Management (IAM)' in the context of TOGAF architecture?

    Answer: A key security capability that can be defined as an Architecture Building Block ensuring appropriate access controls across all architecture domains

    IAM is a cross-cutting security capability in TOGAF architectures, typically defined as an ABB and implemented as SBBs providing consistent access control across business, application, and technology layers.

  2. How does TOGAF's risk management approach categorize risks?

    Answer: By likelihood and impact, with classifications such as critical, significant, moderate, and low

    TOGAF's risk classification uses likelihood and impact dimensions to categorize risks as critical, significant, moderate, or low, determining the appropriate governance response.

  3. What is the role of 'Architecture Requirements' in driving security architecture in TOGAF?

    Answer: They are mandatory inputs that define the security capabilities the architecture must provide, driving design decisions in all phases

    Architecture Requirements — including security requirements — are mandatory inputs to the ADM phases that define what the architecture must deliver, directly driving security design decisions.

  4. What TOGAF mechanism helps prevent security architecture debt from accumulating over time?

    Answer: Architecture Compliance Reviews and Architecture Board governance ensuring ongoing conformance with security principles

    Architecture Compliance Reviews and Architecture Board oversight provide ongoing governance that catches and prevents non-conformance with security architecture principles before it accumulates.

  5. In TOGAF, what is the significance of 'Non-Repudiation' as an architecture requirement?

    Answer: It is a security requirement ensuring that parties cannot deny their actions, driving audit logging and digital signature capabilities in the architecture

    Non-repudiation is a security architecture requirement ensuring that actions cannot be denied, driving the design of audit logging, digital signatures, and authentication capabilities.

  6. How does TOGAF recommend documenting the security implications of 'Architecture Decisions' made during the ADM?

    Answer: Architecture Decision Records should capture the security trade-offs and implications of each significant architecture decision

    Architecture Decision Records in TOGAF should explicitly capture the security trade-offs, constraints, and implications of each significant decision made during the ADM.