An enterprise executive committee issues a high-level mandate requiring all internal data transmissions containing sensitive customer information to be strongly encrypted. To implement this directive across the organization, the IT security team publishes a mandatory technical document establishing the exact approved cipher suites, minimum key lengths, and required protocol versions that all systems must comply with. Which of the following governance document types is represented by this mandatory technical document?
- Security StandardAnswer
- BSecurity Guideline
- CSecurity Policy
- DStandard Operating Procedure
Answer
The technical specification document is a Security Standard because it contains compulsory technical requirements and configurations that operationalize high-level policy mandates.
A Security Standard specifies compulsory, measurable technical criteria—such as explicit encryption algorithms, minimum key sizes, and approved protocols—that must be implemented to fulfill a broader policy objective.
Step-by-Step Solution
Key Concept
Information Security Governance Hierarchy (Policies, Standards, Baselines, Guidelines, Procedures)
Estimated Time:1m 15s