Domain 1. Security Frameworks
Security through obscurity - answer Relying upon the secrecy or complexity of an item
as its security, instead of practicing solid security practices
Not a recommended practice
Enterprise Architecture Development methodologies - answer Zachman Framework
TOGAF
DoDAF
MODAF
SABSA
Security Controls Developments – answer COBIT 5
NIST SP 800-53
COSO Internal Control - Integrated Framework
Process Management Developments – answer ITIL
Six Sigma
Capability Maturity Model Integration
ISO/IEC 27000 Series - answerThis standard provides guidance to organizations on
how to design, implement, and maintain policies, processes, and technologies to
manage risks to its sensitive information assets
architecture framework vs an actual architecture - answera framework is a guideline on
how to build an architecture to best fit your company's needs
an architecture is how the company actually implemented the architecture to fit their
needs
Framework - blueprint
Architecture - actual building taking into account landscape and other factors
NIST Enterprise Architecture Framework - answerNIST - National Institute of Standards
and Technology
Why do you need an enterprise architecture framework? - answerIn order to get
perspectives aligned between the business and technical side.
EXAMPLE:
, Business protocol - a set of approved processes that must be followed to accomplish a
task
Technical protocol - a standardized manner of communication between computers or
applications
Zachman Architectural Framework - answerA two-dimensional model that uses six
basic communication interrogatives (What, How, Where, Who, When, Why) intersecting
with different perspectives (Execs, Business Managers, System Architects, Engineers,
Technicians, and Enterprise-wide) to give a holistic understanding of the enterprise
TOGAF (The Open Group Architecture Framework) - answerTOGAF is a framework
that can be used to develop the following architecture types through the use of
Architecture Development Method (ADM)
ADM is an interactive and cyclic process that allows requirements to be continuously
reviewed and the individual architectures updated as needed. Helps a company to
understand the enterprise from four different views (business, data, application, and
technology)
DoDAF (The *D*epartment *o*f *D*efense *A*rchitecture *F*ramework) - answerThe
focus of this architecture framework is on command, control, communications,
computers, intelligence, surveillance, and reconnaissance systems and processes
When the U.S. DoD purchases technology products and weapon systems, enterprise
architecture documents must be created based upon DoDAF standards to illustrate how
they will properly integrate into the current infrastructures.
Ministry of Defence Architecture Framework (MODAF) - answerAn enterprise
architecture framework based upon the DoDAF. The crux of the framework is to be able
to get data in the right format to the right people as soon as possible
Fast and accurate decisions
Enterprise Security Architecture - answerAn enterprise security architecture is a subset
of an enterprise architecture and defines the information security strategy that consists
of layers of solutions, processes, and procedures and the way they are linked across an
enterprise strategically, tactically, and operationally. It is a comprehensive and rigorous
method for describing the structure and behavior of all the components that make up a
holistic ISMS
SABSA Framework - answerSherwood Applied Business Security Architecture
Is similar to the Zachman Framework. It is a layered framework, with its first layer
defining business requirements from a security perspective. Each layer of the
framework decreases in abstraction and increases in detail so it builds upon the others
Security through obscurity - answer Relying upon the secrecy or complexity of an item
as its security, instead of practicing solid security practices
Not a recommended practice
Enterprise Architecture Development methodologies - answer Zachman Framework
TOGAF
DoDAF
MODAF
SABSA
Security Controls Developments – answer COBIT 5
NIST SP 800-53
COSO Internal Control - Integrated Framework
Process Management Developments – answer ITIL
Six Sigma
Capability Maturity Model Integration
ISO/IEC 27000 Series - answerThis standard provides guidance to organizations on
how to design, implement, and maintain policies, processes, and technologies to
manage risks to its sensitive information assets
architecture framework vs an actual architecture - answera framework is a guideline on
how to build an architecture to best fit your company's needs
an architecture is how the company actually implemented the architecture to fit their
needs
Framework - blueprint
Architecture - actual building taking into account landscape and other factors
NIST Enterprise Architecture Framework - answerNIST - National Institute of Standards
and Technology
Why do you need an enterprise architecture framework? - answerIn order to get
perspectives aligned between the business and technical side.
EXAMPLE:
, Business protocol - a set of approved processes that must be followed to accomplish a
task
Technical protocol - a standardized manner of communication between computers or
applications
Zachman Architectural Framework - answerA two-dimensional model that uses six
basic communication interrogatives (What, How, Where, Who, When, Why) intersecting
with different perspectives (Execs, Business Managers, System Architects, Engineers,
Technicians, and Enterprise-wide) to give a holistic understanding of the enterprise
TOGAF (The Open Group Architecture Framework) - answerTOGAF is a framework
that can be used to develop the following architecture types through the use of
Architecture Development Method (ADM)
ADM is an interactive and cyclic process that allows requirements to be continuously
reviewed and the individual architectures updated as needed. Helps a company to
understand the enterprise from four different views (business, data, application, and
technology)
DoDAF (The *D*epartment *o*f *D*efense *A*rchitecture *F*ramework) - answerThe
focus of this architecture framework is on command, control, communications,
computers, intelligence, surveillance, and reconnaissance systems and processes
When the U.S. DoD purchases technology products and weapon systems, enterprise
architecture documents must be created based upon DoDAF standards to illustrate how
they will properly integrate into the current infrastructures.
Ministry of Defence Architecture Framework (MODAF) - answerAn enterprise
architecture framework based upon the DoDAF. The crux of the framework is to be able
to get data in the right format to the right people as soon as possible
Fast and accurate decisions
Enterprise Security Architecture - answerAn enterprise security architecture is a subset
of an enterprise architecture and defines the information security strategy that consists
of layers of solutions, processes, and procedures and the way they are linked across an
enterprise strategically, tactically, and operationally. It is a comprehensive and rigorous
method for describing the structure and behavior of all the components that make up a
holistic ISMS
SABSA Framework - answerSherwood Applied Business Security Architecture
Is similar to the Zachman Framework. It is a layered framework, with its first layer
defining business requirements from a security perspective. Each layer of the
framework decreases in abstraction and increases in detail so it builds upon the others