An enterprise healthcare provider establishes an executive directive mandating that all sensitive patient data must be encrypted both in transit and at rest across all internal systems. To operationalize this executive mandate, the IT security team creates a mandatory compliance document that details the specific required cryptographic algorithms, minimum key lengths, and approved cipher suites that system administrators must configure on all database nodes without exception. Which component of the security governance hierarchy does this technical configuration document represent?
- Security StandardAnswer
- BSecurity Guideline
- CSecurity Policy
- DCompensating Control
Answer
The cryptographic configuration document represents a Security Standard because it provides mandatory, specific technical requirements designed to support high-level policy objectives.
The correct option is Security Standard. Security standards are compulsory governance documents that define specific technical requirements, hardware/software configurations, or operational rules (such as approved cipher suites and key lengths) necessary to support high-level policies.
Step-by-Step Solution
Key Concept
Security Policy and Standard Hierarchy
Estimated Time:1m 30s