TOGAF Security and Risk Architecture Flashcards
6 cards from real TOGAF practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 TOGAF Security and Risk Architecture flashcards as text
How does TOGAF approach security architecture in the ADM?
Answer: Security concerns are integrated across all ADM phases as a pervasive concern affecting business, data, application, and technology domains
TOGAF treats security as a pervasive concern that must be addressed across all ADM phases and all four architecture domains (Business, Data, Application, Technology).
What is 'Risk Management' in the context of TOGAF Architecture Development?
Answer: Identifying, classifying, and mitigating risks to the successful development and implementation of the target architecture
Risk Management in TOGAF involves identifying, classifying, and developing mitigation strategies for risks that could affect the development or implementation of the target architecture.
In TOGAF, what is an 'Initial Risk Assessment' conducted during the ADM?
Answer: An assessment identifying risks to the architecture engagement conducted in Phase A before detailed architecture work begins
An Initial Risk Assessment in Phase A identifies risks to the architecture engagement, classifying them by impact and probability to determine mitigation approaches.
What are 'Architecture Principles' related to security, and where do they come from in TOGAF?
Answer: Enduring guidelines derived from business principles that guide security architecture decisions throughout the ADM
Security-related Architecture Principles are enduring guidelines derived from business and IT strategy that constrain and guide security architecture decisions across all ADM phases.
How does TOGAF recommend handling 'residual risk' after mitigation strategies are applied?
Answer: Residual risk is formally accepted and documented with approval from appropriate governance authorities
TOGAF recommends formally accepting residual risk (risk remaining after mitigation) with documented approval from appropriate governance authorities, creating an audit trail.
Which TOGAF concept describes the classification of information assets by sensitivity to support security architecture decisions?
Answer: Information Classification
Information Classification is a key input to security architecture in TOGAF, categorizing data by sensitivity level to drive appropriate security controls in the Data and Application architecture.