The Open Group · TOGAF-RS
This credential validates an individual's understanding of essential security and risk concepts in relation to the TOGAF® Architecture Development Method (ADM), including Enterprise Risk Management (ERM), Information Security Management (ISM), and Enterprise Security Architecture (ESA). It demonstrates knowledge of how IT security and risk standards such as ISO/IEC 27000, ISO 31000, and COBIT relate to the TOGAF standard.
Practice Questions
600
≈ 10 practice exams
Duration
180 minutes
Passing Score
Pass/Fail
Difficulty
FoundationalLast Updated
Jun 2026
Use this TOGAF-RS practice exam to prepare for The Open Group Certified: Integrating Risk and Security within a TOGAF® Enterprise Architecture with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for The Open Group TOGAF-RS, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Security and Risk Concepts in TOGAF ADM, Enterprise Security Architecture (ESA), Enterprise Risk Management (ERM), Information Security Management (ISM), and IT Security and Risk Standards (ISO/IEC 27000, ISO 31000, COBIT). Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Open Group Certified: Integrating Risk and Security within a TOGAF® Enterprise Architecture is an awareness-level credential that validates foundational knowledge of how security and risk management integrate with the TOGAF® Architecture Development Method (ADM). It demonstrates that the holder understands the essential concepts of Enterprise Security Architecture (ESA), Enterprise Risk Management (ERM), and Information Security Management (ISM), and knows how these disciplines relate to each phase and artifact of the TOGAF ADM. The credential is part of the broader TOGAF Certification Portfolio built upon the TOGAF Standard, 10th Edition, and is designed to establish a common language between Security Architects and Enterprise Architects when developing risk-aware enterprise architectures.
The certification also covers how major IT security and risk standards — specifically the ISO/IEC 27000 family of standards, ISO 31000, and COBIT® — relate to and complement the TOGAF standard. Candidates learn why security and risk management must be treated as cross-cutting concerns that span the entire enterprise architecture lifecycle rather than being addressed in isolated phases. The credential is structured as a compact learning credential requiring approximately three hours of study, making it accessible as a standalone qualification or as a complement to broader TOGAF Enterprise Architecture certifications.
This credential is designed for professionals who need a structured, foundational understanding of security and risk concepts in the context of enterprise architecture. Primary audiences include Enterprise Architects who want to incorporate security and risk practices into their TOGAF ADM work, Security Architects seeking to align their practice with enterprise architecture frameworks, and IT risk and compliance professionals who collaborate with architecture teams. It is equally relevant for individuals working with governance frameworks such as COBIT or standards like ISO/IEC 27001 and ISO 31000 who need to understand how these standards interact with the TOGAF methodology.
Because the credential is at the awareness level with no prerequisites, it is well-suited to those who are early in their enterprise architecture or security architecture careers, as well as experienced practitioners expanding their knowledge into adjacent disciplines. Program managers, IT auditors, and CISOs who need to communicate with architecture teams or evaluate security architecture outputs will also find the credential valuable.
There are no formal prerequisites to sit for this credential. Candidates are not required to hold any prior TOGAF certification, though familiarity with the basic concepts of the TOGAF ADM — such as the architecture phases (Preliminary through Architecture Change Management) and core TOGAF terminology — will help candidates contextualize the security and risk content more effectively. No prior security certifications are required.
In practice, candidates will benefit from some exposure to enterprise IT environments and a general awareness of IT governance concepts. Those with experience in security operations, IT risk management, or enterprise architecture will find the material more immediately applicable. The Open Group offers a self-study option through its learning management system for candidates who wish to build prerequisite TOGAF knowledge before attempting this credential.
The assessment for this credential is delivered either through an Accredited Training Course (ATC) provider — in which case the assessment format is at the provider's discretion — or through The Open Group's own self-study online learning option, which includes a built-in assessment. The self-study path is available through The Open Group's online shop and learning management system. The credential requires a minimum of three hours of learning to be completed before the assessment is attempted. The Open Group awards a digital Open Badge via Credly and a certificate upon successful completion.
Where scenario-based questions are used, as is common across the TOGAF Certification Portfolio, each question presents a real-world scenario with four possible answers ranked from best to worst. Under this model, the best answer earns 5 points, the second-best 3 points, the third-best 1 point, and the worst answer 0 points. Specific details such as the total number of questions and a published numeric passing score are not publicly disclosed by The Open Group for this credential; candidates should confirm the precise assessment parameters with their chosen training provider or The Open Group's official exam portal. The overall credential is classified as a pass/fail award.
Earning this credential signals to employers that an architect or security professional understands how to embed risk and security thinking into enterprise architecture work from the outset, rather than treating them as compliance afterthoughts. It is particularly valued in organizations that have adopted TOGAF as their architecture framework and are seeking to align security governance with frameworks like ISO/IEC 27001 or COBIT. Roles that benefit directly from this credential include Enterprise Architect, Security Architect, IT Risk Manager, IT Governance Analyst, and Information Security Manager. Because it is an awareness-level credential, it is often pursued alongside or as preparation for higher-level TOGAF certifications rather than as a standalone career milestone.
The credential carries one point in The Open Group's TOGAF Certification Portfolio, contributing to broader TOGAF professional recognition. While salary data specific to this credential is not published, professionals who combine TOGAF certification with security and risk specialization are well positioned for senior architecture and governance roles. Industry demand for architects who can speak fluently across security, risk, and enterprise architecture continues to grow, particularly in regulated sectors such as financial services, healthcare, and government, where risk-aware architecture is a compliance requirement.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 10 full-length practice exams.
Preview — answers shown1. During the kickoff of a major digital infrastructure program at Northwind Energy, the newly assigned security architect argues that security principles should be defined in Phase A (Architecture Vision) because that is when the high-level security vision and strategic direction for the program are established. The enterprise architect disagrees, stating that security principles belong in a different phase. According to G152, which phase is the correct location for establishing security principles? (Select one!)
Explanation
According to G152, security principles are established in the Preliminary Phase, not Phase A. The Preliminary Phase is where foundational governance elements are put in place before architecture development begins, including organizational context, architecture principles, and the conditions under which all subsequent architecture work will be conducted. Security principles are high-level statements composed of four components — Name, Statement, Rationale, and Implications — that guide all security decisions throughout every ADM phase from Phase A onward. Examples include principles such as Defense in Depth, Simplicity, Open Design, Complete Mediation, and Psychological Acceptability. Establishing security principles in the Preliminary Phase ensures they apply universally as enduring governance instruments rather than being reactive to a single initiative. Deferring security principles to Phase A would mean they are developed mid-stream for a specific program rather than serving as organization-wide guidance. Deferring them to Phase B or Phase E would allow early Phase A architectural decisions to be made without the benefit of guiding security principles.
2. A vendor management team at First Up Consultants is reviewing risk management credentials submitted by a potential supplier. The supplier's proposal prominently states that their organization holds an ISO 31000 certification as evidence of mature enterprise risk management practices. The enterprise architect advising the team must explain what this claim actually represents. Which response is most accurate? (Select one!)
Explanation
Unlike ISO 27001, which is a certifiable management system standard, ISO 31000 provides a framework and guidelines for risk management principles and processes and explicitly states that it is not intended for certification purposes. No accredited third-party organizational certification against ISO 31000 exists. A supplier claiming to hold an ISO 31000 organizational certification is making an inaccurate claim that warrants further investigation. Individual practitioners can obtain credentials related to ISO 31000 principles, such as the ISO 31000 Risk Manager or ISO 31000 CICRA qualifications offered by third-party training and certification bodies, but these are individual practitioner credentials rather than organizational management system certifications. Organizations seeking external validation of risk management maturity typically pursue standards that support formal certification, such as ISO 27001 for information security management. The vendor team should request clarification on what specific credential the supplier actually holds.
3. Proseware Energy's board publishes the following formal statement: 'We accept moderate cybersecurity risk in order to support our digital transformation agenda.' The CISO subsequently instructs the risk management team to define specific operational boundaries, including a maximum tolerable unplanned downtime of two hours per incident for SCADA control systems. A risk governance consultant is asked to explain how these two declarations relate to each other within a structured risk management programme. Which two statements correctly characterise the relationship between these two declarations? (Select two!)
Multiple correct answersExplanation
Risk appetite and risk tolerance are related but distinct concepts operating at different levels of a risk governance hierarchy. Risk appetite is a strategic, board-level declaration expressing the aggregate amount and type of risk an organisation is prepared to accept in pursuit of its objectives. It is typically expressed qualitatively and applies organisation-wide, as illustrated by the board's statement regarding moderate cybersecurity risk. Risk tolerance, by contrast, represents measurable, granular boundaries applied to individual risks at an operational level, specifying the maximum acceptable deviation before escalation or treatment is required. The two-hour SCADA downtime limit is a classic expression of risk tolerance: it translates the board's strategic appetite into a concrete, actionable metric for a specific system and process. Risk appetite and risk tolerance are not interchangeable, and operational risk tolerance does not override board-level risk appetite statements.
4. A security architect at Litware Manufacturing is developing an enterprise security architecture using the SABSA framework. During a requirements workshop, the architect must identify which SABSA matrix dimensions should address two specific concerns: first, identifying who within the organization is accountable for protecting critical manufacturing data; and second, defining the temporal constraints that govern when automated production systems must be available for secure operation. Which two SABSA matrix column dimensions directly address these concerns? (Select two!)
Multiple correct answersExplanation
The SABSA matrix consists of six layers and six column dimensions applied at each layer. The Who (People) dimension addresses organization, accountability, and responsibility for security at each architectural layer — directly applicable to identifying which roles and individuals are accountable for protecting manufacturing data. The When (Time) dimension addresses timing, scheduling, and temporal constraints governing when processes and systems must operate securely — directly applicable to defining availability windows and timing requirements for production systems. The What (Assets) dimension covers business data and information assets in terms of what needs to be protected. The Why (Motivation) dimension addresses business risks, goals, and motivations that drive security requirements. The Where (Location) dimension covers business locations, network domains, and geographic deployment constraints. SABSA's analytical power comes from examining all six dimensions consistently across all six layers from Contextual through Operational.
5. The CISO at Bellows College presents a security investment proposal to the board following a successful audit cycle that achieved full compliance with FERPA, PCI-DSS, and institutional accreditation requirements. A board member challenges the proposal, arguing that since all external compliance obligations have been satisfied, additional security spending is redundant and unjustifiable. The CISO must explain why compliance achievement alone does not make the proposed investment unnecessary. Which statement most accurately describes the relationship between compliance and security risk management according to G152 principles? (Select one!)
Explanation
G152 emphasizes that compliance and security risk management are distinct but complementary disciplines, and neither alone is sufficient. Compliance is rules-based and externally motivated, establishing the minimum requirements that satisfy regulatory, legal, or contractual obligations as defined by external bodies. Security risk management is threat-driven and internally motivated, proactively identifying and treating the actual risks facing the organization, which may demand controls well beyond what any compliance framework mandates. A fully compliant organization may still carry significant unmitigated risk if actual threats exceed what regulations address. Conversely, a highly secure organization may still fail a compliance audit due to documentation or procedural gaps. Treating compliance achievement as equivalent to security adequacy is a misconception that G152 explicitly cautions against. Both programs must operate in parallel, with risk management ensuring that security controls exceed compliance minimums wherever the actual threat landscape warrants.
TOGAF® Enterprise Architecture Leader
TOGAF EA Leader · 598 questions
TOGAF® Enterprise Architecture Part 2 Exam (OGEA-102)
OGEA-102 · 600 questions
TOGAF® Framework Digital Specialist
OG0-DS1 · 598 questions
The Open Group Certified: TOGAF® Framework Agile Specialist
TOGAF-Agile-Specialist · 589 questions
TOGAF® Business Architecture Foundation (OGBA-101)
OGBA-101 · 600 questions
TOGAF® Enterprise Architecture Foundation (OGEA-101)
OGEA-101 · 600 questions
$17.99
One-time access to this exam