SABSA Module f2 Questions with Correct
Answers
1. Authenticates identity
2. Checks authorisation
Which 2 actions does the Relying Party perform in the trust broker model?
1. Claims identity
2. Claims authority
Which two (2) actions does the Claimant perform in the trust brokering model
Component Layer, People (Who) Column
Where in the SABSA Architecture Matrix is Personnel Management Tools & Standards
located?
Conceptual layer, Motivation (Why) column
Where in the SABSA Architecture Matrix are Risk Management Objectives and enablement
and control objectives located?
Trust is a Relational business attribute not a technical one.
What type of attribute is Trust?
Risk Management Policies;
Domain Policies
What objectives/outcomes exist at the Logical Architecture layer in the Motivation (Why)
column of the SABSA Matrix?
Domain Maps
Domain Definitions; Inter-domain associations & interactions
,What objectives/outcomes exist at the Logical Architecture layer in the Location (Where)
column of the SABSA Matrix?
Business Risk - Opportunities & Threats Inventory
What objectives/outcomes exist at the Contextual Architecture layer in the Motivation (Why)
column of the SABSA Matrix?
Risk Management Objectives;
Enablement & Control Objectives
Policy Architecture
What objectives/outcomes exist at the Conceptual Architecture layer in the Motivation (Why)
column of the SABSA Matrix?
Business Attributes Profile
What objectives/outcomes exist at the Conceptual Architecture layer in the Assets (What)
column of the SABSA Matrix?
The Owner role is primarily ACCOUNTABLE for the performance of assets
(attributes) within a specific domain.
The Trustee role is RESPONSIBLE for the performance of assets (attributes) within a
specific domain. Trustee is a delegated authority role. Consults domain owner on risk
appetite.
What is the main difference between the Owner role and Trustee role in the SABSA
Governance model?
It is the heart of the SABSA methodology. The Business Attributes Profile is the
'requirements engineering' technique that makes SABSA truly unique and provides
linkage between business requirements and technology / process design.
, Describe the concept of the SABSA Business Attributes Profile
1. Executive Interview Approach
2. Analysis followed by validation
3. SABSA Fast-Track
4. Blended Approach
What are the four (4) SABSA start-up approaches?
1. Enterprise Policy
2. Domain Policy
List the two high-level categories of the SABSA Policy Framework
False. Each domain should enforce its own security policy, independently of other
domains. Trust between domains will have different registration authorities.
TRUE or FALSE: Trust between domains is also constant
A security domain is a set of elements subject to a common security policy defined and
owned by a single policy authority.
What is the definition of a Security Domain according to SABSA?
security services
Relating to Infrastructure Layer Domains, _____________ _______________ are deployed
in each technical domain to meet the policy, control & enablement objectives of that domain
Designer's view of ICT Systems
Concerned with information security & systems functionality
Elements exist in logical domains not tied to specific physical locations
Describe the Design Phase Logical Layer
Answers
1. Authenticates identity
2. Checks authorisation
Which 2 actions does the Relying Party perform in the trust broker model?
1. Claims identity
2. Claims authority
Which two (2) actions does the Claimant perform in the trust brokering model
Component Layer, People (Who) Column
Where in the SABSA Architecture Matrix is Personnel Management Tools & Standards
located?
Conceptual layer, Motivation (Why) column
Where in the SABSA Architecture Matrix are Risk Management Objectives and enablement
and control objectives located?
Trust is a Relational business attribute not a technical one.
What type of attribute is Trust?
Risk Management Policies;
Domain Policies
What objectives/outcomes exist at the Logical Architecture layer in the Motivation (Why)
column of the SABSA Matrix?
Domain Maps
Domain Definitions; Inter-domain associations & interactions
,What objectives/outcomes exist at the Logical Architecture layer in the Location (Where)
column of the SABSA Matrix?
Business Risk - Opportunities & Threats Inventory
What objectives/outcomes exist at the Contextual Architecture layer in the Motivation (Why)
column of the SABSA Matrix?
Risk Management Objectives;
Enablement & Control Objectives
Policy Architecture
What objectives/outcomes exist at the Conceptual Architecture layer in the Motivation (Why)
column of the SABSA Matrix?
Business Attributes Profile
What objectives/outcomes exist at the Conceptual Architecture layer in the Assets (What)
column of the SABSA Matrix?
The Owner role is primarily ACCOUNTABLE for the performance of assets
(attributes) within a specific domain.
The Trustee role is RESPONSIBLE for the performance of assets (attributes) within a
specific domain. Trustee is a delegated authority role. Consults domain owner on risk
appetite.
What is the main difference between the Owner role and Trustee role in the SABSA
Governance model?
It is the heart of the SABSA methodology. The Business Attributes Profile is the
'requirements engineering' technique that makes SABSA truly unique and provides
linkage between business requirements and technology / process design.
, Describe the concept of the SABSA Business Attributes Profile
1. Executive Interview Approach
2. Analysis followed by validation
3. SABSA Fast-Track
4. Blended Approach
What are the four (4) SABSA start-up approaches?
1. Enterprise Policy
2. Domain Policy
List the two high-level categories of the SABSA Policy Framework
False. Each domain should enforce its own security policy, independently of other
domains. Trust between domains will have different registration authorities.
TRUE or FALSE: Trust between domains is also constant
A security domain is a set of elements subject to a common security policy defined and
owned by a single policy authority.
What is the definition of a Security Domain according to SABSA?
security services
Relating to Infrastructure Layer Domains, _____________ _______________ are deployed
in each technical domain to meet the policy, control & enablement objectives of that domain
Designer's view of ICT Systems
Concerned with information security & systems functionality
Elements exist in logical domains not tied to specific physical locations
Describe the Design Phase Logical Layer