Question

Difficulty: MediumSecurity Governance Structures and Policy Frameworks

An information security officer at a biotechnology research institute is restructuring the organization's governance framework to align with updated compliance requirements. The officer must distinguish mandatory governance mandates from non-binding operational advice across the enterprise. Which of the following document types represent mandatory governance requirements that employees and systems must strictly follow? (Select TWO.)

  1. Enterprise Security Policy outlining executive direction, scope, and high-level security directives.Answer
  2. Technical Security Standard specifying mandatory baseline configurations and specific technology rules.Answer
  3. C
    Security Guideline offering recommended best practices and discretionary advice for secure remote working.
  4. D
    Corrective Control Baseline detailing post-incident recovery procedures to restore affected systems.
  5. E
    Authorization Policy defining dynamic permission assignment rules for verifying user identities.

Answer

The mandatory governance requirements are the Enterprise Security Policy and the Technical Security Standard.
Both policies and standards represent mandatory governance elements. An enterprise security policy provides top-down executive directives establishing mandatory compliance rules for the organization, while technical security standards set mandatory specific technical thresholds, hardware/software baselines, and configuration requirements.

Step-by-Step Solution

1
Analyze the security governance document hierarchy.
Governance documentation is categorized into mandatory directives (policies, standards, procedures) and non-binding advice (guidelines).
Understanding document authority determines compliance enforcement obligations.
2
Evaluate the role of an Enterprise Security Policy.
Policies are executive-level, overarching directives that mandate compliance across all organizational units.
It sets the mandatory foundational rules and goals.
3
Evaluate the role of a Technical Security Standard.
Standards mandate explicit technical configurations, protocols, and baselines that must be implemented without exception.
It translates high-level policy mandates into mandatory, measurable technical requirements.

Key Concept

Security Governance Hierarchy (Policy vs. Standard vs. Guideline)
Rate this question