Following an enterprise-wide audit, a Chief Information Security Officer (CISO) is restructuring the organizational governance framework to clear up employee confusion between mandatory directives and discretionary recommendations. Which of the following governance document types establish mandatory requirements that enforce compliance across the enterprise? (Select TWO).
- Security PoliciesAnswer
- Security StandardsAnswer
- CSecurity Guidelines
- DStandard Operating Procedures
- ECompensating Control Frameworks
Answer
Security Policies and Security Standards are mandatory elements of a governance framework.
In security governance, Security Policies serve as the overarching executive directives that define high-level mandatory rules, objectives, and responsibilities. Security Standards support policies by providing explicit, compulsory specifications, metrics, and technology baselines that all systems and staff must strictly adhere to.
Step-by-Step Solution
Key Concept
Security Governance Hierarchy (Mandatory Directives vs. Discretionary Guidance)