Question

Difficulty: HardSecurity Governance Structures and Policy Frameworks

A healthcare organization's high-level security policy mandates that all electronic protected health information (ePHI) must be encrypted both in transit and at rest. However, a internal audit reveals that different operational teams are deploying inconsistent encryption parameters, with some using outdated ciphers. To enforce compliance, security leadership must issue a document that mandates uniform technical rules and mandatory configurations—such as requiring minimum AES-256 for storage and TLS 1.3 for transmission—across all systems, without listing step-by-step administrative workflow actions. Which of the following governance document types should be published to meet this requirement?

  1. A
    Security guideline
  2. Security standardAnswer
  3. C
    Security policy
  4. D
    Security procedure

Answer

Security standard
A security standard provides mandatory, compulsory rules and technical specifications (such as explicit algorithm requirements like AES-256 or TLS 1.3) designed to support and enforce high-level security policies across an enterprise.

Step-by-Step Solution

1
Analyze the scenario requirement
The organization requires a mandatory document specifying technical configurations (AES-256, TLS 1.3) across all systems without step-by-step task steps.
Identifying the required level of enforceability and technical specificity points to the correct document tier.
2
Evaluate governance document definitions
Policies state high-level intent, standards define mandatory technical criteria, guidelines offer discretionary suggestions, and procedures give step-by-step instructions.
Enforcing compulsory cipher parameters enterprise-wide directly aligns with the definition of a security standard.
3
Select the governance document type
The security standard fulfills the requirement for mandatory, technology-specific compliance rules.
Standards bridge high-level policy intent with enforced baseline implementations.

Key Concept

Hierarchy of Security Governance Documents
Rate this question