Courseiva

CISM Information Security Programme Practice Question

Which role is primarily responsible for developing and maintaining the organization's security architecture?

⚠ Common exam trap

CISM often tests role clarity — candidates confuse the Security Architect (design) with the Security Analyst (operations) or GRC Analyst (compliance), so the trap is picking an operational or governance role for an architecture question.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Architect

The Security Architect is the role explicitly chartered with designing, building, and maintaining the organization's security architecture — defining frameworks, controls, and reference designs that align with business and compliance requirements. This is a design-and-strategy role, distinct from operational or assessment roles. The other options focus on monitoring, governance, or testing rather than architecture ownership.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security Analyst

    Why it's wrong here

    A Security Analyst monitors alerts, triages incidents and operates existing controls; the role does not own architecture design or maintenance. It is tempting because analysts work closely with the architecture and feed findings back, so this would be correct when the task is day-to-day detection and response rather than defining security architecture.

  • ✗

    GRC Analyst

    Why it's wrong here

    A GRC Analyst handles policy, risk registers, compliance mapping and audit evidence; architecture design and maintenance sit outside that remit. It is tempting because governance artefacts shape architectural standards, so GRC would be the right choice when the requirement is regulatory alignment, risk reporting or control documentation rather than technical architecture ownership.

  • ✓

    Security Architect

    Why this is correct

    The security architect develops and maintains security architecture, defining structural controls and standards across the organisation. This satisfies the stem's development-and-maintenance responsibility, separating strategic architecture ownership from the security operations staff who administer deployed controls day to day.

  • ✗

    Penetration Tester

    Why it's wrong here

    Penetration testing validates controls by exploiting vulnerabilities under scope; it neither designs nor maintains the target architecture. It is tempting because testers assess security architecture effectiveness, so penetration testing would be the right choice when the requirement is to verify implemented controls through simulated attack, not to own architectural design.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.