Following an enterprise-wide risk assessment, a multi-national cargo shipping organization dictates that all database servers housing customer payment data must enforce mandatory AES-256 encryption at rest across all operating environments. Which governance document type should the security governance team publish to officially enforce this specific mandatory technical requirement?
- Security standardAnswer
- BSecurity guideline
- CCompensating control
- DAuthorization policy
Answer
Security standard
A security standard establishes compulsory technical requirements, hardware/software specifications, and uniform operational rules to ensure compliance with overarching organizational security policies.
Step-by-Step Solution
Key Concept
Distinction between mandatory security standards, discretionary guidelines, and high-level governance policies.