Following a series of regulatory audits, an enterprise Chief Information Security Officer (CISO) publishes an executive document mandating that all sensitive customer data must be protected against unauthorized disclosure across all environments to set management's strategic intent. Shortly thereafter, the security engineering team publishes a separate compulsory document specifying that all cloud databases must utilize AES-256 GCM encryption with key rotation enforced every 90 days. Which of the following correctly classifies these two documents within the organizational security governance hierarchy?
- The CISO's document is a Policy, while the security engineering team's document is a Standard.Answer
- BThe CISO's document is a Guideline, while the security engineering team's document is a Baseline.
- CThe CISO's document is a Standard, while the security engineering team's document is a Technical Control Category.
- DThe CISO's document is a Procedure, while the security engineering team's document is an Authorization Framework.
Answer
The CISO's high-level document is classified as a Policy, while the engineering team's mandatory technical specification is classified as a Standard.
In security governance, a Policy is a high-level, mandatory executive directive that establishes management's goals and strategic intent (such as protecting customer data). A Standard is a compulsory specification that defines specific technologies, configurations, or hardware/software parameters (such as AES-256 GCM and 90-day rotation) required to achieve policy compliance across the organization.
Step-by-Step Solution
Key Concept
Security Policy vs Security Standard Hierarchy