Question

Difficulty: MediumSecurity Governance Structures and Policy Frameworks

An enterprise security operations team is establishing mandatory operational controls to ensure all newly deployed Linux virtual machines meet a uniform minimum level of system hardening before entering production. The documentation must specify exact mandatory technical configurations, such as disabled vulnerable protocols, default account lockouts, and required kernel parameters. Which type of security governance document should the team implement to fulfill this requirement?

  1. Security baselineAnswer
  2. B
    Security guideline
  3. C
    Acceptable use policy
  4. D
    Security procedure

Answer

The team should implement a security baseline, which specifies the mandatory minimum configuration settings and hardening thresholds required for a given platform.
A security baseline provides a mandatory, standardized set of minimum security settings and technical hardening requirements for specific systems or platforms (such as Linux virtual machines). It ensures that all instances deployed into production meet an acceptable baseline level of security configuration.

Step-by-Step Solution

1
Analyze the scenario requirements
The requirement calls for a mandatory document specifying minimum technical configuration settings (e.g., disabled protocols, account lockouts) for system hardening prior to production deployment.
Identifying whether requirements are high-level directives, technical specifications, operational steps, or optional recommendations dictates the correct governance tier.
2
Evaluate document types against governance definitions
A security baseline establishes mandatory minimum security configuration standards for specific operating systems or device types.
Baselines serve as the standardized technical benchmark against which system compliance and hardening are audited.

Key Concept

Security Baselines vs. Policies, Standards, Guidelines, and Procedures
Rate this question