QuestionQ29

The TOGAF Standard, Version 9.2

During the Preliminary Phase, you need to define appropriate policies and ensure that the company has the necessary capability to address the Corporate Board’s concerns.

Based on TOGAF 9, which of the following is the best answer?

  • A You start by clarifying the intent that the Board has for raising these concerns. This enables you to understand the implications of the concern in terms of regulatory requirements and the potential impact on current business goals and objectives. You propose that a security architect or security architecture team be allocated to develop a comprehensive security architecture and that this be considered an additional domain architecture.
  • B You evaluate the implications of the Board's concerns by examining the security and regulatory impacts on business goals, business drivers and objectives. Based on your understanding, you then update the current security policy to include an emphasis on the concerns. You define architecture principles to form constraints on the architecture work to be undertaken in the project. You then allocate a security architect to ensure that security considerations are included in the architecture planning for all domains.
  • C You identify and document the security and regulatory requirements for the application and the data being collected. You ensure that written policies are put in place to address the requirements, and that they are communicated across the organization, together with appropriate training for key employees. You identify constraints on the architecture and communicate those to the architecture team. You establish an agreement with the security architects defining their role within the ongoing architecture project.
  • D You evaluate the implications of the concerns raised by the Corporate Board in terms of regulatory requirements and their impact on business goals and objectives. Based on this understanding, you then issue a Request for Architecture Work to commence an architecture development project to develop a solution that will address the concerns. You allocate a security architect to oversee the implementation of the new application that is being developed.
Explanation

The Preliminary Phase establishes the enterprise architecture capability, including governance, policies, and architecture principles. Security and regulatory concerns must be reflected in security policy and in principles that constrain subsequent architecture work. Because security is a cross-cutting concern, a security architect should participate in planning across all architecture domains, not be limited to a separate domain or only implementation oversight.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!