Identify Security Requirements
How a requirement becomes an architecture input
A stakeholder drops a 200-page standard on your desk and asks whether the new platform complies. Four questions settle that before a single control is chosen: who says this applies to us, does it reach this system, what exactly does it demand, and how would we prove it later. Governance, risk, and compliance (GRC) work at architect level begins with that discovery pass. The other page in this domain, Architecting for GRC, takes the finished requirement set as its input and designs the monitoring, reporting, auditability, and risk-treatment response; this page stops at knowing which obligations bind the architecture and how far they reach.
The four requirement families
Requirements on this objective arrive from four sources, and the rest of the page keeps these names:
- Standards and guidelines, running from cross-industry standards such as ISO/IEC 27001 and the NIST Cybersecurity Framework to industry-specific ones such as the payment card rules.
- Third-party and contractual obligations, covering supply chain, outsourcing, and partner agreements.
- Personal-data and privacy law, such as the General Data Protection Regulation (GDPR).
- Resilience requirements, the continuity and recovery duties the business imposes on itself.
One document can raise requirements in more than one family. A customer contract that also carries privacy terms is ordinary, so treat the families as a way of sorting requirements, not documents.
Assurance evidence, meaning the certificates, attestation reports, and product evaluations other parties hand you, is not a fifth family. It belongs to the evidence stage described below, and it gets its own section because reading its scope correctly is a distinct skill.
Binding authority comes first
A law, regulation, directive, or contract creates an obligation through the authority behind it, while a framework or guideline stays voluntary until an authority or an internal policy adopts it. That distinction is the most common failure point in requirement discovery. Teams cite a well-known framework as though publication made it mandatory, spend the budget on controls no assessor will ask about, and leave a genuine contractual duty unmet. The practical test is to ask who can penalize the organization for non-compliance, because the answer names the authority.
Internal policy sits on the mandatory side of that line. Applicable requirements include the organization's own policies and mission needs, so meeting an external minimum does not discharge a stricter internal baseline unless the authorized policy owner approves an exception or changes the policy.
From authority to evidence
Every family then runs the same five stages, which is why one model carries the whole page. The figure below traces them in order: name the binding authority, test whether it applies to this organization and this system, draw the scope boundary, allocate controls and owners, and retain the evidence that ties the result back to the source obligation.
One stage is explicitly not the architect's to perform. Security architects obtain authoritative readings of laws and regulatory conflicts from qualified legal and privacy stakeholders, then convert those readings into verifiable security and privacy requirements. Getting that division wrong produces an architecture defended by an engineer's opinion of a statute.
The takeaway holds for practice and for the exam: a requirement is usable only once you can state its authority, its applicability, its scope, its allocated controls, and its evidence. Anything missing one of the five is still an assumption.
Standards and guidelines: adopt, then tailor
This section covers the first family: the published standards, frameworks, and control catalogs an architect is expected to recognize, tell apart, and tailor.
Start with the distinction candidates lose most often. ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS), and it is the certifiable management-system standard. ISO/IEC 27002 is the companion guidance describing the controls themselves, and an organization does not certify against it. Both numbers look interchangeable on an exam screen and are not.
The NIST Cybersecurity Framework (CSF) 2.0 works differently again. It supplies a technology-neutral taxonomy of cybersecurity outcomes and points to informative references[1] for the practices and controls that achieve them, rather than prescribing an implementation. An architect tailors those outcomes to mission, sector, and risk appetite, so reading the CSF Core as a fixed control baseline misreads what the document is.
A control catalog is the third shape. NIST SP 800-53 provides a catalog of security and privacy controls that address requirements[2] derived from missions and business functions, laws, executive orders, directives, regulations, policies, standards, and guidelines. The catalog exists to be scoped, tailored, and allocated. Selecting all of it is not a risk-based architecture, it is an unfunded wish list, and it buries the controls that actually address the organization's risk.
| Publication | What it is | What the architect does with it |
|---|---|---|
| ISO/IEC 27001 | Requirements for an ISMS; the certifiable standard | Establish the management system and define its scope |
| ISO/IEC 27002 | Guidance describing information security controls | Use for control detail, never as the certification target |
| NIST CSF 2.0 | Technology-neutral cybersecurity outcomes | Tailor outcomes to mission, sector, and risk appetite |
| NIST SP 800-53 | Catalog of security and privacy controls | Scope, tailor, and allocate controls to the system |
Crosswalks indicate relationships, not equivalence
Mappings between standards give a general indication of coverage, and the relationships they assert may be subjective and are rarely one to one. A mapped control is a hypothesis about coverage, so compliance is validated against the source requirement and its scope rather than inferred from the crosswalk. This bites hardest where one control set is claimed to satisfy several regimes at once, because a single mapping error then propagates into every claim built on it.
The takeaway is to identify the shape of the document in front of you, whether management-system standard, outcome framework, or control catalog, and then tailor rather than adopt.
Industry standards: scope follows the protected data
Industry standards sit inside the standards and guidelines family, and they differ from the cross-industry ones mainly in how they bind: usually through contract rather than statute. Payment card rules are the example an ISSAP candidate is most likely to meet.
PCI DSS defines baseline technical and operational requirements designed to protect payment account data, which covers both cardholder data and sensitive authentication data. Its audience is every entity involved in payment card processing[3], including merchants, processors, acquirers, issuers, and service providers, rather than only the business that takes the card at checkout. An architect who assumes the standard is a merchant concern will under-scope a processing or service-provider design.
What lands inside the scope boundary
Scope covers the system components that store, process, or transmit account data, plus components that can affect the security of the cardholder data environment (CDE). The phrase that decides most real scoping arguments is the second one. A jump host, a directory service, a patch server, or a monitoring agent with reach into the CDE is in scope even though no card number is ever written to it, because compromising it would affect the security of the environment that does hold the data.
Segmentation narrows that boundary only when its effectiveness is established and maintained. A VLAN drawn on an architecture diagram is not segmentation for scoping purposes; a segmentation control whose effectiveness has been verified, and is re-verified as the environment changes, is. Excluding a connected dependency by assertion invalidates both the control design and the compliance evidence resting on it.
The generalizable rule is worth more than the payment specifics: for any industry standard, find the protected data, then follow every component that touches it or can affect its security.
Reading assurance evidence: certificates and evaluations
A supplier arrives at your design review carrying a certificate, an attestation report, and a datasheet quoting an assurance level, and asks you to accept all three as proof. Each is a bounded claim, and the boundary is the part that gets misread. This section covers how to read the kinds of assurance evidence an architect is handed, which is the evidence stage of the chain applied to somebody else's work rather than a requirement family of its own.
An ISO/IEC 27001 certificate provides independent confidence that the organization operates an ISMS conforming to the standard within the scope printed on the certificate. It is not a guarantee that every product, location, or information system is secure, and a certificate whose scope names one business unit says nothing about the rest.
A service provider assurance report carries the same lesson with more moving parts. Check the entity, the service, the location, the period covered, the exclusions, and the customer responsibilities the report assigns back to you. Current provider evidence never establishes that the customer's own configuration and retained controls are compliant, which is why an attestation is an input to your assessment rather than a substitute for it.
Common Criteria: what was evaluated, and how deeply
Under Common Criteria there are two documents worth separating. A Protection Profile (PP) states implementation-independent security requirements[4] for a class of products, so it is reusable and describes a need. A Security Target (ST) identifies one particular target of evaluation (TOE) along with the functional and assurance requirements that target is evaluated against, so it describes a specific claim about a specific product.
Assurance depth is the second axis. An evaluation determines whether the defined target satisfies specified security properties at a stated depth of assurance, expressed as an Evaluation Assurance Level (EAL). A higher EAL buys more rigorous evaluation of the claim, not freedom from all vulnerabilities and not suitability for every operating environment. Selecting a product because it carries the highest EAL, without reading what its Security Target actually claims, is the trap the exam builds around this topic.
| Evidence | What it establishes | What it does not establish |
|---|---|---|
| ISO/IEC 27001 certificate | An ISMS conforming to the standard within the certified scope | That any particular product or system is secure |
| Service provider attestation | Controls assessed for the named service, location, and period | That your configuration and retained controls comply |
| Protection Profile | Reusable requirements for a class of products | Any claim about a specific product |
| Security Target evaluation result | That the evaluated target met stated properties at a stated EAL | Absence of vulnerabilities, or fitness for every environment |
In every row the pattern repeats: read the scope statement before the conclusion.
Third-party and contractual obligations
Outsourcing moves the work and never the accountability. This section covers the second family, the obligations that arrive through suppliers and contracts. An acquiring organization remains responsible for managing the risks and obligations[5] attached to its own mission and information even when a supplier performs the activity, so the architecture allocates shared controls and evidence duties explicitly instead of assuming the provider's programme covers them.
Requirements flow down, notifications flow up
Controls implemented across the system life cycle frequently depend on prime suppliers (also called prime contractors) and their sub-tier suppliers. The contract therefore has to name which security, privacy, assurance, and reporting requirements pass down the supply chain. Without that flow-down, outsourcing depth quietly breaks the continuity of control, and the acquiring organization holds a prime supplier to a standard the prime supplier's own subcontractor never agreed to. The figure below shows the two directions that matter and who sits at each level.
Notification terms are the return path. An agreement states which incidents, vulnerabilities, component changes, or supply disruptions the supplier reports, to whom, and within what timeframe. Those terms are what make the acquiring organization's own response and regulatory reporting deadlines achievable. Without them, an acquiring organization with a 72-hour regulatory clock depends on a supplier who has agreed to no clock at all.
Assurance spans the relationship, not the purchase
Cybersecurity supply chain risk management (C-SCRM) applies risk-based due diligence and assessment before selection or acceptance, then continues with reviews and monitoring throughout performance. A one-time procurement questionnaire cannot address a later change of ownership, a new development location, a shift in subcontractors, or a vulnerability disclosed after award.
Provenance and component transparency
Provenance records track a component's origin, ownership, custody, and changes, which is what allows a component to be validated as genuine and unaltered. A software bill of materials (SBOM) adds visibility of software components for vulnerability and dependency analysis. Neither proves the components are secure. An SBOM is an inventory, and reading it as a product security certification is a distractor the exam uses more than once.
The takeaway is that every third-party requirement needs a named owner on both sides of the contract: what flows down, what reports back, and who holds the accountability that never moved.
Personal data across the processing lifecycle
Privacy obligations attach to data processing, and processing is a far longer list than storage. That single observation reorganizes most privacy architecture work.
Data processing covers collection, generation, transformation, use, disclosure, sharing, transmission, logging, retention, and disposal[6], among other actions performed on data. Protecting the production database therefore addresses a fraction of the duty, because derived records, log entries, analytics extracts, test data sets, and backups carry the same obligations as the source table. Privacy architecture follows the data and the records derived from it through every lifecycle action.
Minimization is a requirement, not a preference
NIST guidance recommends minimizing the use, collection, and retention of personally identifiable information (PII) to what is strictly necessary[7] for the mission or business purpose, and reviewing holdings periodically to confirm they are still needed. Encryption reduces the risk of disclosure but does not create a purpose, so encrypted data with no defined need is still data that should not have been retained.
Impact is contextual rather than a property of the field name. The confidentiality impact level of PII depends on identifiability, quantity, the sensitivity of individual data fields, context of use, obligations to protect, and access to and location of the data. The same element can be low impact in one system and high in another once it is combined with other fields or used for a more sensitive purpose.
Privacy risk is not a subset of security risk
Problems for individuals can arise from data processing that is entirely authorized and where confidentiality, integrity, and availability are intact. A security risk assessment focused on unauthorized access therefore cannot stand in for an analysis of purpose, predictability, autonomy, and the effects processing has on people. This is the distinction behind many privacy items: the scenario describes a system with no breach and a real privacy problem.
De-identification needs a re-identification analysis
Removing direct identifiers does not necessarily prevent records from being linked back to individuals through the remaining attributes or through external data sets. De-identification techniques and release controls[8] are selected against the intended use and a credible re-identification threat, so declaring a data set anonymous because the name column was dropped is an assertion, not an analysis.
The takeaway is to trace the data, not the datastore: every lifecycle action is a place where a privacy requirement applies.
Controller duties: lawful basis, rights, and breach notice
Under GDPR the controller determines the purposes and means of processing, and every duty in this section follows from holding that role. A controller here is an organization playing a legal role, not a security control, despite the shared word. The processor acts on the controller's documented instructions, which is why one event produces different obligations for each party.
GDPR's own reach is the applicability question that comes first. It can bind an organization that is not established in the EU where the processing relates to offering goods or services to people in the EU[9] or to monitoring their behavior there, so physical location is not the test. The duties below are GDPR's; other privacy regimes set their own thresholds and timeframes, and the applicability analysis is what decides which set binds a given system.
Select and document a lawful basis before processing
Processing is lawful only when an Article 6 basis supports the purpose[10]: consent, contract necessity, a legal obligation, vital interests, a public task, or a qualifying legitimate interest. The controller determines and documents that basis before processing begins and provides the required transparency to the data subject. A technical ability to use the data, or a business appetite for it, is not a lawful basis.
Consent is one of those six and not a universal prerequisite. Where it is the chosen basis it must be freely given, specific, informed, and unambiguous[11], the controller must retain evidence that it was obtained, and withdrawal must be as easy as giving it and must stop further consent-based processing. Designing a system that can record consent but cannot honor a withdrawal fails the requirement.
Build privacy into the design and the defaults
Privacy by design and by default[12] asks for appropriate technical and organizational safeguards to be integrated when the means of processing are determined and while processing runs. The default settings limit the amount of data collected, the extent of processing, the retention period, and accessibility to what each specified purpose requires, without depending on the individual to tighten a permissive default.
When a processor handles the data, the controller selects one providing sufficient guarantees and binds it with a written processing agreement[13] covering subject matter, duration, nature and purpose, data types, obligations and rights, security, assistance, return or deletion at the end, and processing only on documented instructions. Delegating execution never relieves the controller of accountability for demonstrating compliant processing.
Rights are an architectural requirement
The rights of the data subject[14] include information and access, rectification, erasure, restriction of processing, portability, objection, and safeguards concerning automated decision-making and profiling. Making them real means the architecture can locate data by subject, produce an intelligible copy, correct or delete records, restrict downstream use, export a portable form, propagate an objection to systems that already received the data, and govern automated decision workflows. Retrofitting this onto a design that cannot find one person's records across its stores is the expensive path, and it is the reason rights belong in requirement discovery rather than in a later compliance project.
Breach notification follows risk, recipient, and role
A processor notifies its controller without undue delay. A controller notifies the supervisory authority without undue delay[15] and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where a high risk to individuals is likely, the controller also communicates the breach to the affected data subjects[16] without undue delay, unless a stated exception applies, such as protection that renders the data unintelligible to anyone not authorized to access it. The figure below walks those branches in the order the decision is actually made.
The 72-hour clock is a frequent exam target, so note precisely what it qualifies: it bounds notification to the supervisory authority where feasible, not communication to individuals, which runs on the without-undue-delay standard and a high-risk trigger.
Resilience: from business impact to recovery objectives
Recovery numbers come from the business, and the architecture is what meets them. Reversing that order produces a design whose failover capability nobody asked for and whose data loss nobody accepted.
The business impact analysis (BIA) determines process criticality and the impacts of an outage, identifies the resource requirements that support each process, and establishes recovery priorities[17]. A general risk assessment feeds the BIA without replacing it: vulnerability severity ranks weaknesses, while the BIA ranks what the organization cannot operate without. Setting recovery order from scan severity is a recognizable wrong answer.
Three numbers, three different losses
Maximum tolerable downtime (MTD) is the total length of time a mission or business process can be disrupted without unacceptable harm. The recovery time objective (RTO) states how quickly a system or process must be restored after disruption. The recovery point objective (RPO) states the acceptable age of the data once restored, which is what sets backup or replication frequency. The relationship between them is the testable part: the RTO plus the time needed to recover work lost since the last recovery point must fit inside the MTD. The figure below places all three on one timeline around the disruption.
RTO and RPO bound different losses, and swapping them is one of the most common distractors on this objective. Time to restore service is RTO. Age of the restored data is RPO.
An alternate capability has to fail differently
Relocating processing or storage adds resilience only when the alternate capability has suitable capacity, dependencies, accessibility, and separation from the threats affecting the primary environment. Redundancy that shares a power feed, a network path, a control plane, or a flood plain with the primary is nominal: one credible event still takes both. The question to ask of any alternate site or region is which specific failures it does not share.
Resilience also means more than staying up. A resilient architecture anticipates that some preventive controls will fail, preserves essential functions even in a degraded state, and enables rapid recovery. Boundary protection alone does not address attacks, environmental disruption, or human error that penetrates or bypasses it, which is why continuity requirements sit beside preventive ones rather than behind them.
Contingency plans: scope, phases, and validation
A regional data center goes dark overnight, and the on-call architect has five documents to choose between. Picking the wrong one wastes the first hour of an outage, and matching the situation to the right plan is a recurring exam item. This section covers which plan covers what, how execution is structured, and what actually counts as validation.
These are the plan types this objective expects you to tell apart, and NIST SP 800-34 distinguishes several more, including crisis communications and occupant emergency plans.
| Plan | What it sustains or restores |
|---|---|
| Business continuity plan (BCP) | Mission and business processes during and after a disruption |
| Continuity of operations (COOP) plan | An organization's mission-essential functions, typically at an alternate site |
| Cyber incident response plan | The response to malicious cyber events |
| Disaster recovery plan (DRP) | Information system operations relocated after a major facility disruption |
| Information system contingency plan (ISCP) | An individual system, at its current or an alternate location |
The scopes above come from NIST SP 800-34[17], and an ISCP can operate on its own or underneath the broader plans. The distinction that decides most questions is breadth: a BCP is about business processes, a DRP is about relocating system operations after a facility event, and an ISCP is about one system.
Execution runs in three phases
Activation and notification applies the outage criteria, declares the plan, assesses the disruption, and mobilizes the affected parties. Recovery restores the prioritized capabilities using the selected strategy. Reconstitution validates recovered data, functionality, and controls, resumes normal operations, and formally deactivates the plan. The figure below shows the three phases in the order they run and what each one delivers.
Reconstitution is where candidates slip. Recovery is not complete when the service answers a request; it is complete when the restored system has been validated and formally returned to normal operation, which is also when the temporary controls introduced during recovery are retired.
Testing, training, and exercises are not interchangeable
Testing validates recovery capabilities, training prepares personnel for their assigned duties, and exercises reveal coordination and planning gaps under a scenario. A tabletop discussion produces useful findings about decision-making, and it does not provide the assurance of executing technical recovery in an operationally representative environment. When a question offers a walkthrough as evidence that failover works, that is the distractor.
Plans track material change
Contingency plans are reviewed on an organization-defined schedule and whenever significant changes affect systems, interconnections, suppliers, facilities, personnel, responsibilities, or organizational requirements. A material change can force updates to the BIA, the recovery priorities, the procedures, the contact lists, the standby agreements, and every controlled copy of the plan. A plan that documents a supplier or a site the organization no longer uses is not a resilience control, it is a document.
Exam-pattern recognition
ISSAP items on this objective rarely ask you to recite a standard. They hand you a situation and ask what the architect does next, which means the winning skill is spotting which stage of the requirement chain the scenario is stuck at.
The framework-as-mandate stem. A scenario names a well-known framework and asks whether the organization must implement it. The correct answer establishes authority or applicability first. Distractors jump to implementing, certifying, or budgeting for the framework, which is exactly the behavior the binding-authority rule exists to prevent.
The accountability transfer. A service is outsourced, or a provider presents a certificate. Correct answers keep accountability with the organization, define the shared responsibility explicitly, and verify what the provider's evidence actually covers. Distractors treat the certificate or the contract as the end of the analysis.
The objectives swap. A stem gives a tolerable data loss and asks for the objective that expresses it, or gives a restoration deadline and asks the same. Match the number to the loss it bounds: RTO for time to restore service, RPO for the age of restored data, MTD for the ceiling both must fit inside.
The privacy scope trap. The scenario contains no unauthorized access, or mentions that the data is encrypted, and asks whether a privacy requirement is satisfied. Correct answers reach for purpose, minimization, lawful basis, and lifecycle coverage. Distractors equate privacy with confidentiality.
The scope-of-evidence item. An attestation, an ISO/IEC 27001 certificate, or a high EAL is offered as proof. Correct answers check scope, service, period, exclusions, and customer responsibilities before accepting the claim.
The legal-interpretation item. Two regulations appear to conflict, or a clause is ambiguous. The architect obtains the authoritative interpretation from legal counsel and then translates it into verifiable requirements, rather than resolving the law independently.
A reading strategy that works across all six: check which stage of the chain an option skips. Options that select a control before establishing authority, applicability, or scope are usually the distractors, and the answer that establishes the requirement before spending on a solution is usually the one the item wants.
How the four requirement families are established, scoped, and evidenced
| Question to answer | Standards and guidelines | Third-party and contractual obligations | Personal-data and privacy law | Resilience requirements |
|---|---|---|---|---|
| What makes it binding | An authority or internal policy adopts it; the standard alone is voluntary | A signed agreement, order, or flow-down clause | A statute whose reach test the organization meets | Business impact analysis findings accepted by process owners |
| What sets the scope | The systems and processes the adopting policy names | The services, sites, and sub-tier suppliers named in the agreement | The personal data and processing activities across their full lifecycle | The mission or business processes and the resources supporting them |
| What the architect produces | A tailored control set allocated to the system | Allocated shared controls, flow-down terms, and notification duties | Minimization, a documented lawful basis, and executable data-subject rights | Recovery objectives and a strategy that avoids common failures |
| What counts as evidence | Control implementation records traced to the source requirement | Contract terms, due-diligence records, and monitoring results | Processing records, lawful-basis documentation, and rights fulfillment records | Test, training, and exercise results plus the resulting plan updates |
| Where it commonly goes wrong | Adopting a catalog unchanged, or reading a crosswalk as equivalence | Assuming a supplier certificate transfers accountability | Limiting privacy analysis to unauthorized disclosure | Accepting a plan walkthrough as proof of technical failover |
Decision tree
Sharp facts the exam loves — give these one last read before exam day.
Cheat sheet
Sharp facts the exam loves — scan these before test day.
- Binding authority determines whether guidance is mandatory
A law, regulation, directive, or contract creates an obligation through its governing authority, while a framework or guideline is voluntary unless that authority incorporates it. The architect must establish applicability before treating published guidance as a compliance mandate.
Trap Treat every cited framework as independently mandatory
4 questions test this
- A private water utility's board reads that a federal agency has published cross-sector cybersecurity performance goals and asks whether the utility now has a compliance deadline for meeting them. How
- A federal civilian executive branch agency is told to remediate a named vulnerability class within a fixed deadline, and the instruction applies to it whether or not its own policy already required th
- A retailer's merchant agreement with its acquiring bank incorporates the acquirer's PCI compliance program. The project team nevertheless asserts that PCI DSS binds the company as national law. Which
- An insurer adopted a published cybersecurity framework as internal good practice, and its board now asks whether the firm is legally bound by every outcome that framework states. Which condition would
- ISO/IEC 27001 defines requirements for an information security management system
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an ISMS using a risk management process. It is the certifiable management-system standard, not merely a catalog of technical safeguards.
Trap Use ISO/IEC 27002 as the certifiable requirements standard
4 questions test this
- Certification is offered to an organisation against the international code of practice for information security controls, with an accredited certificate promised on completion of a short audit. Which
- A supplier tells a bank that it applies the international code of practice for information security controls and that this makes its management system certifiable. Against which standard's requirement
- A software company plans to select its security controls by copying the control list a larger competitor publishes, and then to claim conformity with the certifiable information security management sy
- The certifiable management system standard requires an information security risk process but does not itself describe how to run one, and a separate international document exists to support exactly th
- The NIST Cybersecurity Framework states outcomes without prescribing implementations
CSF 2.0 supplies a technology-neutral taxonomy of cybersecurity outcomes and points to informative resources for practices and controls. An architect tailors those outcomes to mission, risk appetite, and sector rather than treating the Core as a fixed control baseline.
Trap Implement every CSF outcome through a prescribed NIST technology
4 questions test this
- The four Cybersecurity Framework 2.0 Tiers can be applied to an Organizational Profile, and a higher Tier is often assumed to bring a defined set of additional controls with it. Which characterisation
- An insurer's team proposes to decide which Cybersecurity Framework 2.0 outcomes to pursue first by ranking them on implementation cost alone. Which consideration does the framework name as the basis f
- A single Cybersecurity Framework Subcategory is mapped to one control from the NIST control catalogue, and the outcome is then recorded as fully achieved on the strength of that one mapping. What does
- A water utility runs plant control systems, industrial sensors, and cloud-hosted corporate applications, and its engineers argue that the Cybersecurity Framework Core was written for corporate IT only
- A control catalog must be tailored to the system's requirements and risk
NIST SP 800-53 provides flexible security and privacy controls that address requirements from missions, laws, policies, standards, and guidelines. Selecting the entire catalog without scoping, tailoring, and allocating controls does not produce a risk-based architecture.
Trap Adopt the complete control catalog unchanged
9 questions test this
- A utility is designing a smart meter that performs one narrowly defined function, and its engineers have derived a small, complete set of security requirements for it from the device's mission and gov
- A utility is designing a smart meter that performs one narrowly defined function, and its engineers have derived a small, complete set of security requirements for it from the device's mission and gov
- A utility is designing a smart meter that performs one narrowly defined function, and its engineers have derived a small, complete set of security requirements for it from the device's mission and gov
- A utility is designing a smart meter that performs one narrowly defined function, and its engineers have derived a small, complete set of security requirements for it from the device's mission and gov
- A utility is designing a smart meter that performs one narrowly defined function, and its engineers have derived a small, complete set of security requirements for it from the device's mission and gov
- NIST's control baseline guidance states that controls implementing legislative, regulatory, or policy requirements are not tailored out of a baseline, yet it also recognises one situation in which rem
- A defence contractor's field system operates disconnected for long periods over intermittent low-bandwidth links, and its programme office asks whether the federal baseline it selected can be reduced
- A hospital's design team plans to implement every audit and accountability control in its selected baseline on all clinical workstations, arguing that a wider footprint is always the safer choice. Whi
- Implementing the entire NIST control catalogue without omission is sometimes presented as the most defensible route to a risk-based architecture, but the baseline guidance states a different objective
- Framework crosswalks indicate relationships rather than control equivalence
Mappings between standards provide a general indication of coverage, but relationships may be subjective and are not necessarily one-to-one. Compliance must therefore be validated against the source requirement and its scope instead of inferred from a crosswalk alone.
Trap Accept a mapped control as conclusive proof of compliance
4 questions test this
- Two documents are compared during a mapping: one clause of a sector standard and one control of an adopted framework, where each of the two contains an obligation that the other leaves out. Which set
- Two suppliers each publish a mapping from their own controls to the same NIST publication, and both label their relationships 'supports', yet an architect finds that the two mappings cannot be read th
- In a mapping between a national regulation and an organisation's control framework, two texts share almost no wording, yet carrying out either one of them produces the same protective result. Which ra
- The absence of a row in a published crosswalk is sometimes read as proof that a regulatory requirement has no counterpart in the framework an organisation has adopted. Which property of published mapp
- Requirement applicability follows organizational and operating context
The architect identifies relevant laws, regulations, contractual duties, and internal policies by examining mission, sector, jurisdictions, stakeholders, data processing, and services. A control cannot be justified as compliant until the requirement's subject, scope, and triggering conditions apply.
5 questions test this
- A retailer's baseline includes a control implementing a statutory breach-notification duty that binds only firms operating in a jurisdiction the retailer has now exited. The architect must adjust the
- An organization holds employee, customer, and health-related personal data across two jurisdictions, and its data dictionary uses one internal definition of personal information for all of them. Which
- A federal agency will place regulated mission data with a commercial cloud provider. The agency's architect must ensure the provider is bound to the same protection obligations the agency carries. Whi
- A defense supplier processes controlled unclassified information for one program only. Its architect wants the CUI protection requirements to bind as few components as possible while still protecting
- An architect must show which parts of a sector regulation the organization's Cybersecurity Framework outcomes address, using material NIST publishes online. Which resource supplies those mappings betw
- Legal counsel interprets legal obligations while architects translate them into controls
Security architects should obtain authoritative interpretations of laws and regulatory conflicts from qualified legal and privacy stakeholders. Their architectural role is to convert those interpretations into verifiable security and privacy requirements, not to make unsupported legal determinations.
Trap Let the architect independently resolve ambiguous law
3 questions test this
- Counsel has issued a written interpretation of how a data-residency law applies to a planned platform. The architect must now express that interpretation in a form that engineers can build to and asse
- A new state statute may or may not cover the categories of personal information a company holds, and the wording is contested. The architect needs an authoritative determination before selecting contr
- An architect cannot tell whether a sector privacy rule's encryption clause extends to archived backups held by a processor. Before any control is chosen, which product of the organization's legal and
- Organizational policy may impose controls beyond external minimums
Applicable requirements include internal policies and mission needs as well as external mandates. Meeting a regulatory minimum does not satisfy a stricter organizational baseline unless the authorized policy owner approves an exception or changes the policy.
Trap Stop control selection at the least demanding regulation
4 questions test this
- Some organizations mandate controls beyond the standard baseline they start from, such as phishing-resistant multi-factor authentication for all remote administrative access to production systems. Whi
- A Cybersecurity Framework 2.0 Organizational Profile can include a component that specifies the desired outcomes an organization has selected and prioritized, and that expresses its expectations to su
- A control that an applicable regulation mandates cannot be implemented on a legacy platform, and an alternative safeguard is proposed in its place. Which condition must the alternative satisfy before
- A bank's approved cryptographic standard requires stronger protection for stored customer records than the applicable regulation's minimum. A project team proposes building only to the regulation. Whi
- Each compliance requirement needs traceability to controls and evidence
A defensible architecture maps each source obligation to implemented or inherited controls, responsible owners, assessment methods, and retained evidence. This traceability exposes coverage gaps and lets an assessor follow a requirement from authority to operating proof.
6 questions test this
- An assessor asks the architect for the single document that gives an overview of a system's security requirements and describes the controls in place or planned to meet them, together with the system
- A traceability record states how each requirement's control will be verified, and each verification names an assessment method. One method obtains evidence by reviewing, inspecting, observing, or anal
- Two teams each assume the other maintains a control that satisfies a contractual obligation, and the control lapsed for a quarter without anyone noticing. Which element of the traceability record woul
- An architect must show which parts of a sector regulation the organization's Cybersecurity Framework outcomes address, using material NIST publishes online. Which resource supplies those mappings betw
- One assessment artifact states the objectives for a control assessment, the specific procedures to be executed against each control, and the roles and responsibilities for carrying them out, and it is
- An external auditor accepts that a contractual obligation is mapped to a named control with an owner, but asks the architect to demonstrate that the control actually operated last quarter. Which eleme
- Compliance scope boundaries must include dependencies that affect protected processing
The architecture defines systems, data flows, facilities, people, external services, and interconnections that can affect the regulated service or information. Arbitrarily excluding a connected dependency can invalidate both control design and compliance evidence.
Trap Limit scope to hosts that directly store regulated records
5 questions test this
- Federal risk management guidance warns that an authorization boundary drawn too narrowly, leaving out elements that support the same mission and carry comparable protection needs, imposes a specific p
- A payment gateway routes card data through an internal message broker that writes nothing to disk and holds each message in memory for a few seconds. The broker team argues that the component keeps no
- Scoping guidance for a regulated payment environment tells an assessed entity what starting position to take each year, before any component is excluded and the resulting scope is documented for the a
- A build pipeline rebuilds and redeploys a regulated trading platform automatically from a separate cloud account, and it holds no regulated data of its own. The compliance boundary currently lists onl
- A manufacturer's regulated payment environment is administered day to day by an outside support firm, and the compliance lead wants the assessment limited to the servers that store payment records. Wh
- GDPR reach can extend beyond an organization's location
An organization need not be established in the EU for GDPR obligations to apply when its processing relates to offering goods or services to people in the EU or monitoring their behavior in the EU. Physical establishment alone is therefore not a sufficient test of applicability.
3 questions test this
- An analytics vendor incorporated outside the Union places tags on European publishers' sites and profiles individual readers located there to predict their interests. It bills only the publishers. Whi
- A company with a sales and marketing branch in Dublin runs every customer system in a data centre outside the Union, and its counsel argues that the Regulation cannot reach processing performed abroad
- A foundation established outside the Union runs a free mobile application aimed at residents of several member states and receives no payment from any user. Which characteristic of that offering decid
- Outsourcing a service does not outsource the acquirer's accountability
An organization remains responsible for managing risks and obligations attached to its mission and information when a supplier performs the work. The architecture must allocate shared controls and evidence duties explicitly rather than assuming the provider's program satisfies the acquirer automatically.
Trap Treat supplier certification as a transfer of accountability
2 questions test this
- Explicit statements of a service provider's specific responsibilities, together with the expectations the customer may hold, belong in one named agreement document rather than being inferred from the
- Outsourcing systems and services reduces an enterprise's visibility into and control over the functions a provider performs, while the resulting risk to enterprise systems and data stays with the ente
- Supply chain requirements must flow down to relevant subcontractors
Controls implemented across the system life cycle often depend on prime contractors and their sub-tier suppliers. Contracts must identify which security, privacy, assurance, and reporting requirements flow down so that outsourcing depth does not break the control chain.
6 questions test this
- A system integrator's proposal includes several layers of suppliers and teaming arrangements the acquirer did not select. The acquirer has strong visibility into the integrator relationship and wants
- A telecommunications operator's shortlisted supplier will deliver a platform that depends on several fourth- and fifth-party providers. The operator must decide how far down the chain its security req
- A European retailer's payment processor engages an offshore analytics firm to handle part of the processing. The analytics firm then fails its data protection obligations. Under the processor provisio
- Delivery of a critical managed service depends on several of the supplier's own upstream providers, and an incident at any of them should reach the acquiring enterprise. Which requirement should the s
- The processor provisions of the General Data Protection Regulation restrict how far processing may be delegated when a controller has granted no standing approval for additional processors. What must
- A prime contractor will build an enterprise identity platform using three lower-tier development houses that the acquirer never contracts with directly. The acquirer needs its security requirements en
- Supplier assurance begins before selection and continues through the relationship
C-SCRM uses risk-based due diligence and assessment before selection or acceptance, followed by reviews and monitoring during performance. A one-time procurement questionnaire cannot address later ownership, development, vulnerability, or service changes.
Trap Perform supplier assessment only after contract award
6 questions test this
- A programme proposes to collect signed software bills of materials from every supplier and, on the strength of that transparency, to stop performing vendor risk assessments. An architect reviews the p
- A programme proposes to collect signed software bills of materials from every supplier and, on the strength of that transparency, to stop performing vendor risk assessments. An architect reviews the p
- Assessing every supplier on an identical annual cycle starves the most important relationships of attention while burdening marginal ones with the same paperwork. Which basis does cyber supply chain g
- A programme proposes to collect signed software bills of materials from every supplier and, on the strength of that transparency, to stop performing vendor risk assessments. An architect reviews the p
- Critical hardware components are examined for evidence of tampering when they arrive and are then placed into service for years. The assurance obtained at delivery decays while those components remain
- Cybersecurity supply chain evaluation of bidders and their proposed products has to produce a result usable as a weighted factor in a competitive enterprise platform buy, not a record filed afterwards
- Third-party agreements must define security notification duties
Notification agreements establish which incidents, vulnerabilities, component changes, or supply disruptions a supplier reports, to whom, and within what required timeframe. Without these terms, the customer cannot reliably meet its own response and reporting obligations.
5 questions test this
- A cloud payroll provider processes employee records solely on the documented instructions of a European client and discovers a personal data breach inside its own platform. Which notification duty doe
- A payment firm outsources card settlement to a managed provider, and the agreement leaves the timing of any incident report to the provider's judgement. The firm's regulator measures the firm's own fi
- A sole-source supplier manufactures a signalling controller that a rail operator cannot substitute at short notice. The operator's continuity plan depends on learning early when the supplier will be u
- Long-lived industrial control assets routinely outlive the support cycles of the firmware they run. Which supplier notification obligation gives the acquiring organisation time to plan a replacement b
- Supply chain guidance treats early warning of events that may have affected an acquirer's systems as essential, yet many supplier agreements oblige a report only once the supplier's own investigation
- Provenance and component transparency support supply chain trust decisions
Provenance records help track origin, ownership, custody, and changes so components can be validated as genuine and unaltered. An SBOM adds software-component visibility for vulnerability and dependency analysis, but does not by itself prove that those components are secure.
Trap Treat an SBOM as a product security certification
6 questions test this
- An architect must decide what evidence would justify trusting the internal composition of a mission-critical microelectronics part, including the origin of the materials and code within it. Which supp
- An enterprise standard requires a component record for every software item in a regulated platform. One widely used open source library that the platform depends on publishes no such record of its own
- A supplier offers its component record as proof that a delivered application contains no exploitable vulnerabilities, and asks the acquirer to waive further security assurance on the strength of it. W
- A component record delivered once at contract award describes a build that later supplier releases have changed, so the acquirer's dependency queries no longer describe the running software. Which agr
- Component records that arrive as free-text spreadsheets and portable documents with differing field names cannot be correlated across suppliers at the moment a widely used library flaw is announced. W
- A utility receives a component record with every software release from all of its suppliers and files each one in a document repository that nobody opens. Which addition converts that transparency int
- Privacy requirements apply across the complete data-processing lifecycle
Data processing includes collection, generation, use, transformation, logging, retention, disclosure, sharing, transmission, and disposal. Privacy architecture must therefore follow data and derived records through every lifecycle action rather than protect only stored databases.
4 questions test this
- A retailer's privacy assessment documents how customer records are collected, stored, and deleted. Its recommendation engine then creates new propensity scores about each customer that no customer eve
- An architect finds that customer records protected in the production database also appear in nightly backups, diagnostic files, and a reporting warehouse. Which activity gives the privacy program a co
- Which term names the collective set of life cycle operations that a system performs on data, spanning collection, generation, logging, transformation, use, disclosure, sharing, transmission, and dispo
- Which data action is being performed when an application writes complete transaction detail, including cardholder names and addresses, into diagnostic files, so that the resulting records fall inside
- Personal data collection and retention must be limited to a defined purpose
NIST guidance recommends minimizing the use, collection, and retention of PII to what is necessary for mission or business purpose and periodically reviewing holdings. Encryption reduces disclosure risk but does not justify collecting unnecessary personal data.
Trap Retain all encrypted PII for possible future use
6 questions test this
- An architect designs a customer platform whose records are copied into a reporting warehouse and an archive tier. Deletion must occur once each record's business purpose ends. Which design element mak
- An architect designs a customer platform whose records are copied into a reporting warehouse and an archive tier. Deletion must occur once each record's business purpose ends. Which design element mak
- An architect designs a customer platform whose records are copied into a reporting warehouse and an archive tier. Deletion must occur once each record's business purpose ends. Which design element mak
- A marketing team asks to keep every archived customer record indefinitely, arguing that the archive is encrypted and that a future analytics project may eventually need the data. Which practice should
- An application must confirm that a user is at least eighteen years old. The product owner proposes collecting each user's full date of birth, while the architect proposes storing only an age-threshold
- A health insurer collected claims data to administer member benefits. A new analytics team wants to reuse those records to train a marketing propensity model unrelated to the benefits administration t
- PII confidentiality impact depends on context, not merely field names
Protection level considers identifiability, quantity, field sensitivity, context of use, obligations, access, and location. The same data element may create different harm when combined with other fields or used in a more sensitive context.
4 questions test this
- Which factor, under NIST's guidance on protecting PII, accounts for two directories that hold the same fields of name, address, and telephone number being assigned different confidentiality impact lev
- Which factor should raise the assessed confidentiality impact level of a research extract that carries no names and no account numbers, yet keeps a five-digit postal code, a date of birth, and a sex c
- Which factor justifies raising the confidentiality impact level of a customer record when a release adds place of birth and a parent's middle name, values many services accept for password recovery, t
- A state agency holds a small taxpayer dataset that only two analysts ever open, and it proposes a low confidentiality impact level on that basis. Which factor must be settled with legal counsel before
- Authorized data processing can still create privacy risk
Privacy risk includes problems individuals may experience from data processing even when confidentiality, integrity, and availability are not breached. A security risk assessment alone therefore cannot replace analysis of purpose, predictability, autonomy, and potential effects on individuals.
Trap Limit privacy analysis to unauthorized disclosure scenarios
3 questions test this
- Which activity evaluates the problems individuals could experience from a workforce analytics platform's authorized processing, and therefore remains necessary even after security testing of that plat
- A transit authority wants trip records processed for network planning without tying them to identifiable riders beyond what operations require. The processing is lawful and the records are retained fo
- Which privacy engineering objective is failing when the users of a fitness service repeatedly find their activity data used in ways they did not anticipate, although every one of those uses is authori
- De-identification requires analysis of residual re-identification risk
Removing direct identifiers does not necessarily prevent records from being linked back to individuals through remaining attributes or external data. The architect selects de-identification techniques and release controls according to the intended use and credible re-identification threat.
Trap Declare data anonymous after masking names alone
2 questions test this
- Which model bounds mathematically what an analyst can learn about any single individual from published statistical tables, without depending on assumptions about the outside data an adversary may hold
- Which category of attributes must be addressed before releasing a hospital research extract whose patient names and medical record numbers have been deleted, but whose every row still carries an admis
- Select and document a lawful basis before processing personal data
GDPR processing is lawful only when an applicable Article 6 basis supports the purpose, such as consent, contract necessity, legal obligation, vital interests, public task, or a qualifying legitimate interest. The controller should determine and document that basis before processing and provide the required transparency to the data subject; a technical ability or business desire to use the data is not a lawful basis.
- Embed privacy in processing design and default settings
Privacy by design integrates appropriate technical and organizational safeguards when processing means are chosen and while processing occurs. Privacy by default limits the amount collected, extent of processing, retention, and accessibility to what each specified purpose requires without relying on the individual to tighten permissive settings.
2 questions test this
- A hospital's new records system grants every clinician access to every patient record, and leadership plans to let departments request narrower profiles after go-live. Which default should the archite
- A retailer's loyalty programme switches every optional profiling model on for each member account at enrolment, and a member may turn those models off afterwards. Which element of the GDPR's data prot
- Consent must be specific, provable, and withdrawable
When consent is the selected GDPR basis, it must be freely given, specific, informed, and unambiguous, and the controller must retain evidence that it was obtained. Withdrawal must be as easy as giving consent and must stop future consent-based processing; consent is one possible lawful basis, not a universal prerequisite or permanent permission.
3 questions test this
- The GDPR requires a controller relying on consent to be able to show, for a named individual and a specific purpose, that valid consent was obtained before the processing began. Which platform capabil
- A fitness service captures marketing consent through a single in-app toggle, but a user who wants to stop that processing must post a signed form to a service address. Which consent condition does the
- A subscription platform presents one tick box that covers product analytics, partner marketing, and profile enrichment together. The wording is plain, the box starts empty, and users who decline all t
- Controller accountability continues when processors handle personal data
The controller determines the purposes and means of processing and must select processors that provide sufficient compliance guarantees. A written, binding processing agreement defines scope, duration, data, responsibilities, security, assistance, return or deletion, and documented instructions; delegating execution to the processor does not remove the controller's accountability to demonstrate compliant processing.
8 questions test this
- Before a controller engages a processor to handle customer personal data, the Regulation requires it to use only processors that can show they will implement appropriate technical and organisational m
- Before a controller engages a processor to handle customer personal data, the Regulation requires it to use only processors that can show they will implement appropriate technical and organisational m
- Before a controller engages a processor to handle customer personal data, the Regulation requires it to use only processors that can show they will implement appropriate technical and organisational m
- Before a controller engages a processor to handle customer personal data, the Regulation requires it to use only processors that can show they will implement appropriate technical and organisational m
- Before a controller engages a processor to handle customer personal data, the Regulation requires it to use only processors that can show they will implement appropriate technical and organisational m
- A payroll platform provider processes employee records for its client and now proposes adding a model it designed itself, scoring attrition risk to shape its own product roadmap. The client remains th
- A controller receives an access request covering records that live only inside its processor's platform, and the processor answers that its contract does not oblige it to help. Which contractual term
- Before a controller engages a processor to handle customer personal data, the Regulation requires it to use only processors that can show they will implement appropriate technical and organisational m
- Systems must make applicable data-subject rights executable
GDPR rights include information and access, rectification, erasure, restriction, portability, objection, and safeguards concerning automated decisions and profiling. The architecture must therefore support finding data by subject, supplying intelligible copies, correcting or deleting records, restricting downstream use, exporting portable data, propagating objections, and governing automated-decision workflows.
4 questions test this
- A retailer keeps customer personal data in an order platform, a support tool, and a reporting warehouse, and no shared subject identifier links them. The privacy team must answer access and erasure re
- The right to data portability lets a data subject receive the personal data she provided in a form another controller can ingest without manual re-entry, and have it transmitted directly where that is
- A controller receives an access request covering records that live only inside its processor's platform, and the processor answers that its contract does not oblige it to help. Which contractual term
- A retailer keeps customer personal data in an order platform, a support tool, and a reporting warehouse, and no shared subject identifier links them. The privacy team must answer access and erasure re
- Privacy breach notification follows risk, recipient, and role
Under GDPR, a processor notifies its controller without undue delay, and the controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours unless the breach is unlikely to risk people's rights and freedoms. When high risk is likely, the controller also communicates with affected data subjects without undue delay unless a specified exception, such as effective protection that renders the data unintelligible, applies.
3 questions test this
- A hosting provider that processes personal data on behalf of a client discovers that a customer database was copied without authorisation. The provider is not the controller for that data. Which actio
- An attacker exfiltrated an archive of customer records that was encrypted with keys held only in a separate hardware module the attacker never reached. The controller has already notified the supervis
- Hours after confirming a breach of a customer database, a controller's forensic team still cannot say how many records were taken, and the legal lead wants to hold everything back until the final repo
- A business impact analysis drives recovery requirements and priorities
The BIA determines process criticality and outage impacts, identifies supporting resource requirements, and establishes recovery priorities. A general risk assessment informs the BIA but does not replace its continuity-focused deliverables.
Trap Use vulnerability scan severity to set recovery order
7 questions test this
- The total amount of time a system owner will accept for a mission or business process outage is recorded during contingency planning as one figure. It includes all impact considerations and bounds the
- Continuity planning requires one determination before any decision about which services must keep running through a disruption and which may be suspended. Cyber resiliency guidance calls identifying t
- An investment case for a second processing facility must show what an extended interruption would cost before funds are committed. One output of the business impact analysis expresses that cost in ope
- A print server holds almost no data and is inexpensive to replace, yet the contingency plan restores it ahead of several costly database platforms. An auditor challenges that ordering as inconsistent
- A financial services firm must decide the order in which forty systems are restored after a regional outage. The architect will accept only a documented statement of how badly each supported business
- Criticality rankings and a restoration sequence for a payroll process are available from a completed impact study. The study as delivered still does not state what must be present at the alternate cap
- A hospital's enterprise risk register is complete and current, and leadership asks whether anything further is required before contingency strategies for its clinical systems are selected. The archite
- RTO limits service interruption while RPO limits tolerable data loss
The recovery time objective expresses how quickly a system or process must be restored after disruption. The recovery point objective expresses the acceptable age of restored data and therefore drives backup or replication frequency.
Trap Use RTO to specify the acceptable backup age
7 questions test this
- A distributor can tolerate a one-day interruption of its warehouse system. Its budget rules out maintaining a duplicate facility that is fully configured and staffed, but the recovery window is far to
- The total amount of time a system owner will accept for a mission or business process outage is recorded during contingency planning as one figure. It includes all impact considerations and bounds the
- A requirement states that after any failover, no more than the last fifteen minutes of committed transactions may be missing from the restored database. The figure will drive how often transaction dat
- A rule requires an insurer to keep closed claim records retrievable for seven years, long after the systems that created them are replaced. Contingency documentation must record that seven-year obliga
- A records system may lose at most one day of data after a disruption, and it must be back in service within two hours of one. Each of the two figures governs a different parameter of the recovery desi
- Backup media for a hospital's clinical system are held in a commercial vault three hundred kilometres away, staffed only during weekday business hours. The system's recovery objective assumes the medi
- A claims platform may be unavailable for at most four hours before the insurer suffers unacceptable harm to its operations. Within that ceiling the architect sets a two-hour target for returning the p
- Alternate capabilities must avoid the primary environment's credible common failures
Relocating processing or storage adds resilience only when the alternate capability has suitable capacity, dependencies, accessibility, and separation from threats affecting the primary site. Nominal redundancy inside one shared failure domain can still leave a single point of failure.
6 questions test this
- A distributor can tolerate a one-day interruption of its warehouse system. Its budget rules out maintaining a duplicate facility that is fully configured and staffed, but the recovery window is far to
- A regional bank's continuity team proposes an alternate processing site four kilometres from the primary data centre. The proposed site sits inside the same river flood plain and draws its power from
- Backup media for a hospital's clinical system are held in a commercial vault three hundred kilometres away, staffed only during weekday business hours. The system's recovery objective assumes the medi
- A data centre buys two circuits from different carriers to reach its alternate site. Both carriers hand their circuits to the building through one street conduit, and both lease capacity on the same r
- Criticality rankings and a restoration sequence for a payroll process are available from a completed impact study. The study as delivered still does not state what must be present at the alternate cap
- A logistics firm keeps its only backup copies on a storage array standing in the same computer room as the production servers those copies protect. The architect must correct the arrangement before th
- Resilience includes operating under adversity and recovering essential functions
A resilient architecture anticipates that some preventive controls will fail and preserves essential operations, possibly in a degraded state, while enabling rapid recovery. Boundary protection alone is insufficient for attacks, environmental disruptions, and human errors that penetrate or bypass it.
5 questions test this
- Continuity planning requires one determination before any decision about which services must keep running through a disruption and which may be suspended. Cyber resiliency guidance calls identifying t
- A design assumes preventive controls will sometimes be defeated. It must let defenders change course while an intrusion unfolds, rerouting traffic, suspending non-essential services or isolating a zon
- A water utility's treatment control system must not stop when it encounters conditions it cannot process correctly. The architect specifies that on those conditions the system continues only a restric
- A design keeps a system's essential business functions running while an intrusion is under way. It accepts that the intrusion may go undetected, or be misread as user error, and that compromised compo
- A cyber resiliency technique defines and separates system elements by criticality and trust, so that a compromise originating in a low-trust environment such as corporate email cannot propagate into t
- Testing, training, and exercises validate different aspects of contingency readiness
Testing validates recovery capabilities, training prepares personnel for their assigned duties, and exercises reveal coordination and planning gaps under scenarios. A tabletop discussion cannot provide the same assurance as executing technical recovery in an operationally representative environment.
Trap Treat a plan walkthrough as proof of technical failover
3 questions test this
- A hospital revised its information system contingency plan after consolidating two data centres, and the recovery procedures now name different facilities and teams. Test, training and exercise (TT&E)
- Recovery team members at a water utility have never been told which duties the information system contingency plan assigns to them. The programme coordinator is sequencing the coming year's test, trai
- A test, training and exercise programme separates tests from exercises. A test evaluates whether a system or one of its components actually operates the way the plan requires. Which characteristic of
- Maximum tolerable downtime bounds recovery objectives
Maximum tolerable downtime is the total duration a mission or business process can be disrupted without significant harm. The system RTO plus the time needed to recover lost work must not exceed that limit.
5 questions test this
- A settlement system's recovery target is set at the maximum tolerable downtime of the process it supports. Contingency planning guidance states that the target must normally be shorter than that limit
- A reporting system supports a mission essential function whose maximum tolerable downtime is fixed by a federal continuity directive. The system's own owner proposes a longer downtime limit, arguing t
- Recovery procedures for a wide area network with many interdependent components are written as a stepwise sequence in which the order of restoration steps must reflect the system's maximum tolerable d
- A contingency planning team has completed its impact estimates, but the system owner has never stated how long the supported mission or business process may be disrupted before significant harm occurs
- A trading process may be interrupted for at most six hours. The proposed design returns the platform to service five hours after a disruption, and re-entering the queued trades then takes a further ni
- Resilience plans must be selected and coordinated by scope
A BCP sustains mission or business processes during and after disruption, while a COOP plan sustains an organization's mission-essential functions, typically at an alternate site. A cyber incident response plan addresses malicious cyber events, whereas a disaster recovery plan relocates information-system operations after a major facility disruption. An ISCP restores an individual system at its current or an alternate location and may operate alone or under the broader plans.
4 questions test this
- A federal agency must be able to perform its mission essential functions from an alternate site for up to thirty days after a disruption makes its headquarters unusable, and then return to normal oper
- During a regional outage, an insurer must ensure that only designated officials answer questions from the public and the press, and that consistent status reports reach its own staff. Which plan in th
- Two planning disciplines are commonly confused. One concerns the ability to continue critical functions and processes during and after an emergency event. The other provides the steps needed to recove
- Contingency planning guidance requires an organisation's business continuity plan, disaster recovery plan and individual system contingency plans to be coordinated during development and whenever they
- Contingency plans must track material change
Contingency plans should be reviewed on an organization-defined schedule and whenever significant changes affect systems, interconnections, suppliers, facilities, personnel, responsibilities, or organizational requirements. Material changes may require updating the BIA, recovery priorities, procedures, contacts, agreements, and controlled plan copies so the documented strategy remains viable.
- Contingency execution separates activation, recovery, and reconstitution
Activation and notification applies outage criteria, declares the plan, assesses the disruption, and mobilizes affected parties; recovery restores prioritized capabilities using the selected strategy. Reconstitution validates recovered data, functionality, and controls before resuming normal operations and formally deactivating the plan.
- Industry-standard scope follows the protected data and systems that can affect it
For standards such as PCI DSS, scope includes the protected data environment and system components that store, process, transmit, or can affect the security of that data. Segmentation can reduce scope only when its effectiveness is established and maintained.
6 questions test this
- Under PCI DSS scoping guidance, which condition must be satisfied before an existing subnet boundary between the payment systems and the rest of an internal network counts as segmentation that reduces
- A retailer's directory, patching and log servers sit outside the cardholder data environment, yet they authenticate to and push updates into the payment servers that store account data. The architect
- Under the PCI Data Security Standard, which of the following sets of components falls inside the assessment boundary of an organisation whose payment systems share one flat internal network with no co
- A retailer is rebuilding its payment platform on cloud microservices that are created and destroyed continuously. The architect must keep the PCI DSS boundary accurate across those ephemeral workloads
- Before each annual assessment a merchant must identify every location and flow of cardholder data, together with every system that could impact the cardholder data environment if it were compromised.
- Which property determines whether employee laptops on a corporate network, which can reach the shared-services jump server that administrators use to sign in to the cardholder data environment, must t
- Service-provider assurance evidence covers only its stated services and responsibilities
An attestation or assessment report must be checked for entity, service, location, period, exclusions, and customer responsibilities. The existence of current provider evidence does not establish that the customer's configuration and retained controls are compliant.
Trap Accept a provider attestation without reviewing its scope
6 questions test this
- A shortlisted cloud service appears in a public assurance registry solely on the strength of a questionnaire the provider completed about its own controls. The architect requires assurance validated b
- When a retailer outsources hosting of its payment application to a service provider that holds current independent compliance evidence for that hosting service, what is the effect on the retailer's ow
- A managed hosting provider's assurance report excludes the data-centre operator it depends on, presenting those controls as another organisation's responsibility. The architect must still cover the de
- A merchant and its hosting provider disagree over which of them patches the payment servers. The architect wants one artefact that records, requirement by requirement, which party performs each contro
- In a service provider's assurance report, what is the name for the controls that the report assumes each customer will implement in its own environment, and on which the auditor's conclusions about th
- A payment gateway offers its current Attestation of Compliance as evidence for a merchant's own assessment. The gateway sells several distinct services, of which the merchant uses two. What must the m
- ISO/IEC 27001 certification is bounded by the certified ISMS scope
Certification provides independent confidence that the organization operates an ISMS conforming to the standard within the certificate's defined scope. It is not a blanket guarantee that every product, location, or information system is secure.
6 questions test this
- A cloud service the architect intends to use is delivered from a region and a business unit that the supplier's ISO/IEC 27001 certificate may not cover. The supplier repeats that the company is certif
- What does a valid ISO/IEC 27001 certificate, issued to a supplier by a certification body that is itself nationally accredited, establish on its own about that supplier at the level of assurance the s
- A group holding company is certified to ISO/IEC 27001, and the architect's data will be handled at a subsidiary site acquired after the last certification audit. The board treats the group certificate
- Which evidence should an enterprise architect request in order to confirm that two shortlisted suppliers, each certified to ISO/IEC 27001, encrypt the backups holding the organisation's data, a specif
- A vendor answers a request to evidence a security appliance's own protection functions by supplying its corporate ISO/IEC 27001 certificate. The architect needs independent evaluation of the appliance
- Which body issues an organisation's ISO/IEC 27001 certificate after auditing its information security management system, given that the standard itself is published jointly by two international standa
- A Protection Profile states reusable needs while a Security Target describes a specific evaluation target
Under Common Criteria, a Protection Profile expresses implementation-independent security requirements for a class of products. A Security Target identifies the particular target of evaluation and the functional and assurance requirements against which that target is evaluated.
Trap Use a Protection Profile as the evaluated product's specific claim
5 questions test this
- Common Criteria defines one document that states implementation-independent security needs for a type of product, and another that states the security requirements one identified product is evaluated
- A utility has commissioned an independent Common Criteria evaluation of a substation gateway from an accredited laboratory. The project board asks the architect what the laboratory will measure the ga
- A supplier is asked to evidence what its firewall appliance was evaluated to do under Common Criteria. It replies with the Protection Profile that its entire product family claims conformance to. The
- An architect is drafting the security section of a competitive tender for hardware security modules. The organisation wants suppliers with quite different internal designs to be able to bid, and wants
- An internal auditor treats the Common Criteria Protection Profile published for a technology class as the record of what the organisation's installed product actually does. The architect must explain
- Evaluation assurance measures confidence in evaluated claims rather than absolute security
A Common Criteria evaluation determines whether a defined target satisfies specified security properties at a stated assurance depth. A higher assurance package increases evaluation rigor but does not prove freedom from all vulnerabilities or suitability for every operating environment.
Trap Select the highest EAL as proof of universal product security
4 questions test this
- A vulnerability is publicly disclosed in a product holding a current Common Criteria certificate, and it concerns functionality that sat inside the evaluated boundary. A risk committee asks whether th
- An architect compares two evaluated storage encryptors, one of which carries a higher Common Criteria assurance package than the other. The board asks what that higher package, taken on its own, tells
- A programme team proposes requiring the highest available Common Criteria assurance package for every component of a new payments platform, including low-risk ancillary components. The architect must
- An architect requires independent confirmation that the mathematical properties of a product's cryptographic algorithms are sound. The product already holds a current Common Criteria certificate issue
- PCI DSS establishes a payment-account protection baseline
PCI DSS defines baseline technical and operational requirements designed to protect payment account data, including cardholder data and sensitive authentication data. Its intended audience spans entities involved in payment-card processing, including merchants, processors, acquirers, issuers, and service providers, rather than only the organization that accepts the card at checkout.
Also tested in
- CCSP Certified Cloud Security Professional
- CISSP Certified Information Systems Security Professional
- CISSP Certified Information Systems Security Professional
- CISSP Certified Information Systems Security Professional
- CISSP Certified Information Systems Security Professional
- CISSP Certified Information Systems Security Professional
- CISSP Certified Information Systems Security Professional
References
- The NIST Cybersecurity Framework (CSF) 2.0 Whitepaper
- NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations Whitepaper
- PCI DSS: Payment Card Industry Data Security Standard
- Common Criteria for Information Technology Security Evaluation (CC:2022)
- NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices Whitepaper
- NIST Privacy Framework 1.0 Whitepaper
- NIST SP 800-122, Guide to Protecting the Confidentiality of PII Whitepaper
- NIST SP 800-188, De-Identifying Government Data Sets Whitepaper
- GDPR Article 3: Territorial scope Whitepaper
- GDPR Article 6: Lawfulness of processing Whitepaper
- GDPR Article 7: Conditions for consent Whitepaper
- GDPR Article 25: Data protection by design and by default Whitepaper
- GDPR Article 28: Processor Whitepaper
- GDPR Chapter 3: Rights of the data subject Whitepaper
- GDPR Article 33: Notification of a personal data breach to the supervisory authority Whitepaper
- GDPR Article 34: Communication of a personal data breach to the data subject Whitepaper
- NIST SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems Whitepaper