Question

Difficulty: MediumSecurity Governance Structures and Policy Frameworks

A newly appointed Chief Information Security Officer (CISO) at a global renewable energy management corporation is restructuring the organization's security documentation hierarchy. Match each security governance document type on the left with its corresponding operational characteristic on the right.

  • Security PolicyHigh-level mandatory directive approved by executive leadership defining overall security expectations and organizational scope.
  • Technical StandardMandatory specific operational or technical specification defining required technologies, protocols, or settings across the enterprise.
  • Security BaselineMandatory minimum security configuration state established as a reference benchmark for operating systems and network devices.
  • Security GuidelineDiscretionary recommendation providing flexible advice and industry best practices without enforcing strict compliance requirements.

Answer

Security Policy matches the high-level mandatory directive; Technical Standard matches mandatory specific technical specifications; Security Baseline matches the mandatory minimum configuration benchmark; Security Guideline matches discretionary recommendations.
In security governance, documents are categorized by authority and enforcement level. Policies provide high-level mandatory direction from leadership. Standards enforce specific required technologies or specifications. Baselines establish the minimum mandatory configuration build for hardware/software. Guidelines offer optional, flexible recommendations for best practices.

Step-by-Step Solution

1
Analyze the mandatory status and high-level nature of Security Policies.
Identify that a Security Policy represents executive-level directives providing overall organizational security goals and expectations.
Policies sit at the top of the governance hierarchy and apply broadly across the enterprise.
2
Differentiate mandatory technical specifications from minimum system configuration states.
Map Technical Standards to compulsory operational/technical specifications and Security Baselines to the minimum hardening build state required for individual assets.
Standards define mandatory technologies or behaviors, whereas baselines set the minimum threshold configuration.
3
Evaluate discretionary documentation versus mandatory compliance requirements.
Associate Security Guidelines with non-binding recommendations and operational best practices.
Guidelines provide flexibility and advice, unlike policies, standards, and baselines which are strictly mandatory.

Key Concept

Security Governance Policy Hierarchy and Document Roles
Rate this question