Question

Difficulty: EasySecurity Governance Structures and Policy Frameworks

A healthcare organization is issuing new tablet devices to clinical staff. Before provisioning the devices, the information security team must define a mandatory document specifying the minimum security configuration requirements, such as enabling full-disk encryption, enforcing PIN complexity, and disabling unused radio interfaces. Which of the following governance document types should the security team publish to enforce these minimum requirements?

  1. Security baselineAnswer
  2. B
    Security guideline
  3. C
    Security policy
  4. D
    Standard operating procedure

Answer

The security team should publish a security baseline because it establishes the mandatory minimum technical configuration standards for specific systems and hardware devices.
A security baseline establishes mandatory minimum security controls and configuration settings that systems, applications, or devices must satisfy. In this scenario, establishing required settings like full-disk encryption and PIN requirements across all tablet devices represents creating a technical baseline.

Step-by-Step Solution

1
Analyze the operational requirements stated in the scenario.
The requirement specifies establishing mandatory minimum security configuration settings across all newly issued tablet devices.
Governance documents vary by enforceability and scope within the security documentation hierarchy.
2
Evaluate document types against enforceability and technical specificity.
Policies state high-level management goals; guidelines are discretionary recommendations; procedures detail step-by-step operational tasks; baselines define mandatory minimum technical settings.
Only a security baseline serves as the standardized technical benchmark for system hardening.

Key Concept

Security Baseline
Estimated Time:45s
Rate this question