CRISC - Information Technology and Security - Section 4.1

Apply enterprise architecture concepts to understand how technology decisions affect IT risk.

Apply enterprise architecture concepts - spanning the technology stack, data architecture, and system interconnections - to understand how technology decisions introduce or mitigate IT risk. Recognise that architecture risk arises when design choices create complexity, single points of failure, or shadow IT outside governance visibility.

Enterprise architectureTechnology stackData architectureArchitecture risk

Practice question for this objective

Free sampleInformation Technology and Securitymedium

A retail group is launching three new digital initiatives at once, and each delivery team has independently chosen its own programming language, hosting model and integration style. A risk practitioner wants to use the enterprise architecture function to reduce the IT risk this autonomy creates. Which use of enterprise architecture would most directly reduce that risk?

  • AAllow each team full freedom now and reconcile the differing technology choices into common patterns once all three initiatives have shipped
  • BRequire every team to adopt one identical technology stack regardless of whether it suits the specific problem each initiative solves
  • CPublish architecture principles and reference patterns that every initiative must justify any deviation against before build begins Correct
  • DRecord each team's chosen technologies in the configuration management database so the differences are at least visible to operations
Enterprise architecture reduces IT risk by guiding technology decisions through agreed principles and reference patterns before solutions are built. Enterprise architecture manages risk proactively by setting principles and reference patterns that shape design choices early, turning uncontrolled divergence into reviewed, justified exceptions rather than fragmentation that must be remediated after delivery.

Why A is wrong: Reconciling after delivery is tempting because it avoids slowing teams, but rework is far costlier later and the divergent choices have already created the integration and support risk by then.

Why B is wrong: Mandating a single stack looks like strong standardisation, but forcing an unsuitable choice creates its own risk and ignores the fit-for-purpose judgement that architecture governance is meant to apply.

Why C is correct: Shared principles and reference patterns constrain technology choices up front, so divergence becomes a deliberate, reviewed exception rather than an unmanaged source of fragmentation and risk.

Why D is wrong: Recording choices improves visibility, which is useful, but it documents the fragmentation after the fact rather than steering the decisions that create the risk in the first place.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Information Technology and Security objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.