Question

Difficulty: Very hardSecurity Governance Structures and Policy Frameworks

Following a third-party compliance audit that highlighted inconsistent multi-cloud storage configurations, an enterprise Chief Information Security Officer (CISO) publishes a high-level organizational mandate requiring all data at rest containing non-public personal information (NPI) to be protected with strong cryptographic controls. To translate this high-level directive into mandatory, non-negotiable operational requirements for deployment pipelines across all engineering units, the security governance committee drafts a document specifying exact encryption algorithms (AES-256), mandatory key rotation schedules (every 90 days), and rigid access control lists. Which document type in the security governance hierarchy is the committee publishing to establish these mandatory technical specifications?

  1. Security StandardAnswer
  2. B
    Security Guideline
  3. C
    Preventive Control Matrix
  4. D
    Authorization Framework

Answer

The security governance committee is publishing a Security Standard because standards provide mandatory, detailed technical requirements and specific operational configurations designed to enforce high-level policy directives.
In security governance, high-level policies state management intent, while Security Standards establish the mandatory, specific technical rules, algorithms, and configuration parameters required to achieve compliance across an enterprise. Specifying mandatory AES-256 encryption and rigid 90-day key rotation schedules directly aligns with the definition of a Security Standard.

Step-by-Step Solution

1
Analyze the organizational governance hierarchy levels present in the scenario.
Identified the CISO's overarching mandate as a Security Policy (high-level leadership directive).
Security policies define intent, scope, and objectives but omit low-level technical parameters.
2
Evaluate the nature of the requirement being drafted by the security steering committee.
The committee is establishing mandatory, specific technical parameters (AES-256, 90-day key rotation, ACL configurations).
The required document must be compulsory rather than advisory.
3
Map the technical parameters to the appropriate governance document layer.
Determined that mandatory technical criteria and compulsory minimum configurations define a Security Standard.
Standards bridge high-level policy directives with repeatable operational implementations.

Key Concept

Distinguishing Governance Document Hierarchy (Policy vs. Standard vs. Guideline vs. Procedure)
Estimated Time:1m 30s
Rate this question