SABSA CHARTERED FOUNDATION (SCF) CERTIFICATE VERIFIED EXAM
QUESTIONS AND ANSWERS - LATEST VERSION 2026/2027
Q: What does SABSA stand for? ANSWER Sherwood Applied Business Security
Architecture.
Q: Who is the creator of the SABSA framework? ANSWER John Sherwood.
Q: In what year was SABSA first developed? ANSWER 1995.
Q: What is the primary focus of the SABSA framework? ANSWER Aligning
security services with business needs to enable and support business
objectives.
Q: How does SABSA view security compared to traditional IT security?
ANSWER As a business enabler rather than a business inhibitor or pure
technical overhead.
Q: What is a "Business-driven" security architecture? ANSWER An architecture
where every security control can be traced back to a specific business
requirement or risk.
Q: What does "Risk-based" mean in the context of SABSA? ANSWER Security
investments and controls are prioritized and designed based on the level of risk
the business is willing to accept.
Q: What is "Traceability" in SABSA? ANSWER The unbroken chain of reasoning
and documentation from business requirements at the top down to
technology implementation at the bottom.
Q: Why is traceability important? ANSWER It justifies the cost of security,
ensures nothing is implemented without a business reason, and aids in
auditing.
Q: What is the SABSA Institute? ANSWER The global professional body that
governs the SABSA framework, certifications, and membership.
Q: What does SCF stand for? ANSWER SABSA Chartered Foundation.
,Q: Is SABSA a prescriptive or descriptive framework? ANSWER It is descriptive;
it describes what needs to be done and why, but does not dictate how to do it
(leaving room for vendor-neutral design).
Q: What is the core premise of SABSA regarding security architecture?
ANSWER Security architecture is a subset of enterprise architecture.
Q: How does SABSA define "Architecture"? ANSWER A set of descriptive
representations (models) that are relevant for describing an object such that it
can be built to satisfy requirements.
Q: What is the difference between a framework and a methodology? ANSWER
A framework provides the structure and categories (the "what"); a
methodology provides the step-by-step process (the "how"). SABSA provides
both.
Q: What are the SABSA "Directional Vectors"? ANSWER Different perspectives
or axes used to view the architecture (e.g., Top-Down, Bottom-Up, Horizontal).
Q: What does the "Top-Down" vector represent? ANSWER Driving architecture
from business requirements down to technology.
Q: What does the "Bottom-Up" vector represent? ANSWER Assessing existing
technology and infrastructure capabilities to see what can be leveraged.
Q: What does the "Horizontal" vector represent? ANSWER Looking across the
enterprise at a single layer (e.g., looking at all logical security functions across
departments).
Q: What does the "Future-State" vector represent? ANSWER Designing the
target architecture based on future business strategy.
Q: What is a "Security Domain" in SABSA? ANSWER A logical grouping of
assets, risks, and controls that share common characteristics or business
functions.
Q: What is the SABSA "Gold Standard"? ANSWER The principle that every
security requirement must be traceable to a business risk.
Q: Does SABSA mandate specific security products or vendors? ANSWER No, it
is entirely vendor-neutral.
, Q: What is the relationship between SABSA and Enterprise Architecture (EA)?
ANSWER SABSA integrates seamlessly with EA frameworks (like TOGAF) to
provide the security layer.
Q: What problem does SABSA primarily solve? ANSWER The disconnect
between business executives, IT management, and security technologists.
Q: How does SABSA handle change? ANSWER Through its lifecycle model,
ensuring architecture is continuously reviewed and updated as the business
changes.
Q: What is a "Stakeholder" in SABSA? ANSWER Anyone with an interest in the
security architecture (e.g., Board of Directors, CIO, end-users, auditors).
Q: Why must a SABSA architect identify all stakeholders? ANSWER To ensure
the architecture meets the specific concerns and views of every relevant party.
Q: What is "Defense in Depth" in SABSA terms? ANSWER Implementing
multiple layers of security controls across different SABSA layers to protect
against different types of risks.
Q: Does SABSA only apply to IT? ANSWER No, it applies to physical security,
personnel security, and operational security as well.
Q: What is an "Asset" in SABSA? ANSWER Anything of value to the business
(data, hardware, software, reputation, people).
Q: What is a "Threat Agent" in SABSA? ANSWER An entity that has the
potential to cause harm to an asset.
Q: What is a "Vulnerability" in SABSA? ANSWER A weakness in an asset or
control that could be exploited by a threat.
Q: What is "Impact" in SABSA? ANSWER The negative consequence to the
business if a threat exploits a vulnerability.
Q: What is "Risk" in SABSA? ANSWER The probability of a threat exploiting a
vulnerability, multiplied by the impact of that event.
Q: What is a "Security Control" (or Countermeasure)? ANSWER A measure
taken to reduce risk to an acceptable level.
Q: What is a "Security Service" in SABSA? ANSWER A logical or physical
function provided to mitigate a specific risk or meet a specific requirement.
QUESTIONS AND ANSWERS - LATEST VERSION 2026/2027
Q: What does SABSA stand for? ANSWER Sherwood Applied Business Security
Architecture.
Q: Who is the creator of the SABSA framework? ANSWER John Sherwood.
Q: In what year was SABSA first developed? ANSWER 1995.
Q: What is the primary focus of the SABSA framework? ANSWER Aligning
security services with business needs to enable and support business
objectives.
Q: How does SABSA view security compared to traditional IT security?
ANSWER As a business enabler rather than a business inhibitor or pure
technical overhead.
Q: What is a "Business-driven" security architecture? ANSWER An architecture
where every security control can be traced back to a specific business
requirement or risk.
Q: What does "Risk-based" mean in the context of SABSA? ANSWER Security
investments and controls are prioritized and designed based on the level of risk
the business is willing to accept.
Q: What is "Traceability" in SABSA? ANSWER The unbroken chain of reasoning
and documentation from business requirements at the top down to
technology implementation at the bottom.
Q: Why is traceability important? ANSWER It justifies the cost of security,
ensures nothing is implemented without a business reason, and aids in
auditing.
Q: What is the SABSA Institute? ANSWER The global professional body that
governs the SABSA framework, certifications, and membership.
Q: What does SCF stand for? ANSWER SABSA Chartered Foundation.
,Q: Is SABSA a prescriptive or descriptive framework? ANSWER It is descriptive;
it describes what needs to be done and why, but does not dictate how to do it
(leaving room for vendor-neutral design).
Q: What is the core premise of SABSA regarding security architecture?
ANSWER Security architecture is a subset of enterprise architecture.
Q: How does SABSA define "Architecture"? ANSWER A set of descriptive
representations (models) that are relevant for describing an object such that it
can be built to satisfy requirements.
Q: What is the difference between a framework and a methodology? ANSWER
A framework provides the structure and categories (the "what"); a
methodology provides the step-by-step process (the "how"). SABSA provides
both.
Q: What are the SABSA "Directional Vectors"? ANSWER Different perspectives
or axes used to view the architecture (e.g., Top-Down, Bottom-Up, Horizontal).
Q: What does the "Top-Down" vector represent? ANSWER Driving architecture
from business requirements down to technology.
Q: What does the "Bottom-Up" vector represent? ANSWER Assessing existing
technology and infrastructure capabilities to see what can be leveraged.
Q: What does the "Horizontal" vector represent? ANSWER Looking across the
enterprise at a single layer (e.g., looking at all logical security functions across
departments).
Q: What does the "Future-State" vector represent? ANSWER Designing the
target architecture based on future business strategy.
Q: What is a "Security Domain" in SABSA? ANSWER A logical grouping of
assets, risks, and controls that share common characteristics or business
functions.
Q: What is the SABSA "Gold Standard"? ANSWER The principle that every
security requirement must be traceable to a business risk.
Q: Does SABSA mandate specific security products or vendors? ANSWER No, it
is entirely vendor-neutral.
, Q: What is the relationship between SABSA and Enterprise Architecture (EA)?
ANSWER SABSA integrates seamlessly with EA frameworks (like TOGAF) to
provide the security layer.
Q: What problem does SABSA primarily solve? ANSWER The disconnect
between business executives, IT management, and security technologists.
Q: How does SABSA handle change? ANSWER Through its lifecycle model,
ensuring architecture is continuously reviewed and updated as the business
changes.
Q: What is a "Stakeholder" in SABSA? ANSWER Anyone with an interest in the
security architecture (e.g., Board of Directors, CIO, end-users, auditors).
Q: Why must a SABSA architect identify all stakeholders? ANSWER To ensure
the architecture meets the specific concerns and views of every relevant party.
Q: What is "Defense in Depth" in SABSA terms? ANSWER Implementing
multiple layers of security controls across different SABSA layers to protect
against different types of risks.
Q: Does SABSA only apply to IT? ANSWER No, it applies to physical security,
personnel security, and operational security as well.
Q: What is an "Asset" in SABSA? ANSWER Anything of value to the business
(data, hardware, software, reputation, people).
Q: What is a "Threat Agent" in SABSA? ANSWER An entity that has the
potential to cause harm to an asset.
Q: What is a "Vulnerability" in SABSA? ANSWER A weakness in an asset or
control that could be exploited by a threat.
Q: What is "Impact" in SABSA? ANSWER The negative consequence to the
business if a threat exploits a vulnerability.
Q: What is "Risk" in SABSA? ANSWER The probability of a threat exploiting a
vulnerability, multiplied by the impact of that event.
Q: What is a "Security Control" (or Countermeasure)? ANSWER A measure
taken to reduce risk to an acceptable level.
Q: What is a "Security Service" in SABSA? ANSWER A logical or physical
function provided to mitigate a specific risk or meet a specific requirement.