A financial technology company operating a cloud-native microservices platform requires all container host nodes processing sensitive transaction data to comply with a specific, mandatory set of minimum technical security settings, such as disabling root SSH logins and enabling kernel audit logging. Which of the following governance documents should the security architecture team publish to define these mandatory, platform-specific minimum configuration settings?
- Security baselineAnswer
- BSecurity guideline
- CAcceptable use policy
- DOrganizational security policy
Answer
The security baseline is the correct document type because it specifies mandatory minimum technical configuration standards for targeted platforms or operating systems.
A security baseline specifies mandatory minimum configuration settings tailored to a particular operating system, cloud platform, or device role. System-level hardening parameters like kernel audit configurations and SSH restrictions represent platform-specific baseline settings.
Step-by-Step Solution
Key Concept
Security Governance Hierarchy: Policies vs Standards vs Baselines vs Guidelines
Estimated Time:1m 0s