Question

Difficulty: EasySecurity Governance Structures and Policy Frameworks

An organization is establishing a comprehensive security governance framework. The Chief Information Security Officer (CISO) needs to publish documents that define mandatory, high-level organizational security objectives as well as detailed step-by-step instructions for technical teams to execute. Which of the following governance document types fulfill these specific requirements? (Select TWO).

  1. PolicyAnswer
  2. ProcedureAnswer
  3. C
    Guideline
  4. D
    Standard
  5. E
    Deterrent control

Answer

The correct document types are Policy (which defines high-level mandatory objectives) and Procedure (which provides step-by-step instructions).
Policies establish high-level mandatory goals and organizational security intentions mandated by management. Procedures complement policies by defining exact, step-by-step instructions for technical personnel to execute operational tasks.

Step-by-Step Solution

1
Identify the high-level governance document that sets mandatory organizational goals.
A policy defines overarching mandatory rules and goals mandated by executive leadership.
Governance frameworks rely on policies to communicate high-level compliance and security expectations.
2
Identify the document type designed to give explicit, step-by-step task instructions.
A procedure outlines exact sequential actions for staff to follow.
Detailed step-by-step operational tasks are formally documented in procedures.

Key Concept

Security Governance Hierarchy
Rate this question