Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IIBA-CCA Exam - Topic 6 Question 10 Discussion

Which of the following activities are part of the business analyst's role in ensuring compliance with security policies?
B) Ensuring that security policies are reflected in the solution requirements
A) Auditing enterprise security policies to ensure that they comply with regulations
C) Testing applications to identify potential security holes
D) Checking to ensure that business users follow the security requirements

IIBA-CCA Exam - Topic 6 Question 10 Discussion

Actual exam question for IIBA's IIBA-CCA exam
Question #: 10
Topic #: 6
[All IIBA-CCA Questions]

Which of the following activities are part of the business analyst's role in ensuring compliance with security policies?

Show Suggested Answer Hide Answer
Suggested Answer: B

Business analysts support cybersecurity compliance primarily by ensuring that security and privacy expectations are translated into clear, testable requirements that are built into the solution. This includes eliciting applicable organizational security policies, standards, and control objectives, then mapping them into functional and non-functional requirements such as authentication methods, role-based access, logging and audit trail needs, encryption requirements, session controls, data retention, and segregation of duties. When security policies are reflected in the solution requirements, they become part of the delivery lifecycle: they can be designed, implemented, validated in testing, and verified during acceptance. This creates traceability from policy to requirement to control implementation, which is essential for audits and for demonstrating due diligence.

Option A is typically the responsibility of governance, risk, and compliance functions or internal audit, not the BA. Option C is usually performed by security testing specialists, QA teams, or application security engineers using techniques like SAST, DAST, and penetration testing. Option D is largely an operational management and compliance enforcement function, supported by training, monitoring, and disciplinary processes. The BA's distinct contribution is ensuring policy-driven security controls are captured in requirements and embedded into the solution design and delivery artifacts.


Contribute your Thoughts:

0/2000 characters
Alyssa
4 days ago
Totally agree, A) and D) are crucial for compliance!
upvoted 0 times
...
Devorah
9 days ago
Wait, are we really expecting BAs to do all this? Sounds like a lot!
upvoted 0 times
...
Tatum
14 days ago
D) is super important, but it can be tricky to enforce.
upvoted 0 times
...
Fredric
19 days ago
I think C) is more of a developer's job, not a BA's.
upvoted 0 times
...
Audry
24 days ago
A) and B) are definitely part of the role!
upvoted 0 times
...
Ernest
29 days ago
I definitely remember discussing option D in class; it seems like a crucial part of ensuring compliance, but I'm unsure if it's solely the BA's job.
upvoted 0 times
...
Lynelle
1 month ago
I feel like option A could be part of the role too, but I can't recall if auditing is typically a BA responsibility.
upvoted 0 times
...
Bernardo
1 month ago
I'm not entirely sure about option C; I remember practicing a question where testing was more about functionality than security.
upvoted 0 times
...
Tommy
3 months ago
I think option B makes sense because the business analyst needs to ensure that security policies are integrated into the requirements.
upvoted 0 times
...

Save Cancel