Enterprise Architecture and Information Technology
This chapter marks the beginning of Domain 4: Information Technology and Security for CRISC. This domain represents 22 percent (approximately 33 questions) of the revised CRISC exam. These topics build the foundation of an organization and information technology and are essential to learn and understand not only for the exam but also for building a career in the information security domain. In addition, we will be talking about information technology, information security principles, and data privacy in the following chapters.
The aim of this chapter is to introduce the concept of Enterprise Architecture (EA), the Capability Maturity Model (CMM), and IT operations such as network and technology concepts. Without a thorough understanding of the following topics, it is difficult to rationalize the security controls that should be implemented to secure IT assets including networks, networking devices, firewalls, and cloud resources...