Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IIBA-CCA Exam - Topic 6 Question 10 Discussion

Which of the following activities are part of the business analyst's role in ensuring compliance with security policies?
B) Ensuring that security policies are reflected in the solution requirements
A) Auditing enterprise security policies to ensure that they comply with regulations
C) Testing applications to identify potential security holes
D) Checking to ensure that business users follow the security requirements

IIBA-CCA Exam - Topic 6 Question 10 Discussion

Actual exam question for IIBA's IIBA-CCA exam
Question #: 10
Topic #: 6
[All IIBA-CCA Questions]

Which of the following activities are part of the business analyst's role in ensuring compliance with security policies?

Show Suggested Answer Hide Answer
Suggested Answer: B

Business analysts support cybersecurity compliance primarily by ensuring that security and privacy expectations are translated into clear, testable requirements that are built into the solution. This includes eliciting applicable organizational security policies, standards, and control objectives, then mapping them into functional and non-functional requirements such as authentication methods, role-based access, logging and audit trail needs, encryption requirements, session controls, data retention, and segregation of duties. When security policies are reflected in the solution requirements, they become part of the delivery lifecycle: they can be designed, implemented, validated in testing, and verified during acceptance. This creates traceability from policy to requirement to control implementation, which is essential for audits and for demonstrating due diligence.

Option A is typically the responsibility of governance, risk, and compliance functions or internal audit, not the BA. Option C is usually performed by security testing specialists, QA teams, or application security engineers using techniques like SAST, DAST, and penetration testing. Option D is largely an operational management and compliance enforcement function, supported by training, monitoring, and disciplinary processes. The BA's distinct contribution is ensuring policy-driven security controls are captured in requirements and embedded into the solution design and delivery artifacts.


Contribute your Thoughts:

0/2000 characters
Delisa
2 days ago
D is key. Users must follow the rules to stay secure.
upvoted 0 times
...
Lai
7 days ago
C makes sense. We must find security holes before launch.
upvoted 0 times
...
Bronwyn
12 days ago
A is important too. Auditing keeps us compliant.
upvoted 0 times
...
Broderick
18 days ago
I think B is crucial. Policies need to be in the requirements.
upvoted 0 times
...
Paola
23 days ago
Wait, are we really expecting business users to follow all those rules?
upvoted 0 times
...
Kaitlyn
28 days ago
D) is crucial, but can be tricky to enforce.
upvoted 0 times
...
Reed
1 month ago
C) sounds right, but isn't that more for testers?
upvoted 0 times
...
Loren
1 month ago
I think B) is super important too.
upvoted 0 times
...
Aliza
1 month ago
A) is definitely part of the role!
upvoted 0 times
...
Alyssa
2 months ago
Totally agree, A) and D) are crucial for compliance!
upvoted 0 times
...
Devorah
2 months ago
Wait, are we really expecting BAs to do all this? Sounds like a lot!
upvoted 0 times
...
Tatum
2 months ago
D) is super important, but it can be tricky to enforce.
upvoted 0 times
...
Fredric
2 months ago
I think C) is more of a developer's job, not a BA's.
upvoted 0 times
...
Audry
2 months ago
A) and B) are definitely part of the role!
upvoted 0 times
...
Ernest
2 months ago
I definitely remember discussing option D in class; it seems like a crucial part of ensuring compliance, but I'm unsure if it's solely the BA's job.
upvoted 0 times
...
Lynelle
3 months ago
I feel like option A could be part of the role too, but I can't recall if auditing is typically a BA responsibility.
upvoted 0 times
...
Bernardo
3 months ago
I'm not entirely sure about option C; I remember practicing a question where testing was more about functionality than security.
upvoted 0 times
...
Tommy
4 months ago
I think option B makes sense because the business analyst needs to ensure that security policies are integrated into the requirements.
upvoted 0 times
...

Save Cancel