In an enterprise information security program, governance documentation is structured into distinct tiers based on enforceability, scope, and technical specificity. Match each governance document type on the left with its corresponding operational characteristic on the right.
- Security PolicyHigh-level mandatory directive detailing executive management goals, principles, and overall governance objectives.
- Security StandardMandatory technical rule establishing compulsory, uniform controls across all enterprise systems to satisfy policy requirements.
- Security BaselineMandatory minimum security configuration state required for a specific system or platform prior to production deployment.
- Security GuidelineDiscretionary recommendation offering suggested operational methods and flexibility without strict compulsory enforcement.
Answer
Security Policy matches executive high-level mandatory directives; Security Standard matches mandatory uniform technical rules; Security Baseline matches mandatory minimum platform configuration states; Security Guideline matches discretionary non-mandatory recommendations.
Security Governance frameworks divide documentation into hierarchical tiers. Policies establish broad management intent and authority. Standards define compulsory technical rules. Baselines enforce the minimum required technical configurations for system operation. Guidelines offer non-binding advisory assistance.
Step-by-Step Solution
Key Concept
Security Governance Hierarchy and Policy Framework Document Types
Estimated Time:1m 30s