Question

Difficulty: MediumSecurity Governance Structures and Policy Frameworks

An aerospace communications operator is updating its cybersecurity governance framework to ensure clear alignment across strategic leadership, system administrators, and third-party operational contractors. Match each governance document type on the left with its corresponding organizational scope and operational requirement on the right.

  • Acceptable Use Policy (AUP)A mandatory, executive-level document defining general rules, user responsibilities, and behavioral constraints for organizational resource usage.
  • Technical Security StandardA mandatory technical directive defining specific mandatory controls, cipher suites, and cryptographic key lengths required across system integrations.
  • Security BaselineA mandatory operational benchmark specifying the minimum required security configuration settings for all hardened server instances.
  • Security GuidelineA discretionary document offering recommended operational recommendations, best practices, and flexible guidance for non-critical systems.

Answer

Acceptable Use Policy matches the high-level mandatory executive policy governing user behavioral constraints. Technical Security Standard matches the mandatory technical directive specifying explicit controls like cipher suites. Security Baseline matches the mandatory minimum configuration benchmark for system hardening. Security Guideline matches the discretionary document offering best practices and recommendations.
Each governance document type fulfills a distinct level in the governance hierarchy: Policies set high-level executive rules and user boundaries (Acceptable Use Policy); Standards define mandatory technical and cryptographic requirements; Baselines define minimum secure build configurations for systems; and Guidelines provide optional, discretionary recommendations and best practices.

Step-by-Step Solution

1
Analyze the high-level management layer document (Acceptable Use Policy).
Identify that policies are high-level, mandatory executive statements governing organizational usage and user expectations.
Policies set overarching intent and legal/operational boundaries for personnel.
2
Differentiate between mandatory technical requirements and minimum hardening states.
Map Technical Security Standard to mandatory specific cryptographic/technical requirements, and Security Baseline to minimum system configuration benchmarks.
Standards dictate explicit mandatory implementations, whereas baselines establish the minimum hardening bar.
3
Evaluate discretionary documentation versus mandatory documentation.
Map Security Guideline to the discretionary document containing recommended best practices.
Guidelines are unique within policy governance as they are non-mandatory advice rather than enforced requirements.

Key Concept

Security Governance Policy Hierarchy and Document Categorization
Rate this question