An e-commerce corporation is auditing its security program to ensure proper alignment between executive directives, technical requirements, and operational advice across software development teams. The Chief Information Security Officer (CISO) publishes an updated organizational framework document. Which of the following governance elements represent mandatory requirements that organizational members and technical systems must strictly comply with? (Select TWO.)
- Information Security Policies detailing high-level management goals, objectives, and organizational directives for asset protectionAnswer
- Security Standards specifying mandatory baseline technical configurations and specific operational rules, such as enforcing AES-256 encryption for sensitive customer databasesAnswer
- CSecurity Guidelines suggesting best practices for microservice code refactoring and optional performance optimizations
- DOperational Guidelines offering recommended methods for developers choosing local integrated development environment (IDE) extensions
- EAccess Control Guidelines suggesting advisory principles for defining role-based authorization rules during local testing
Answer
Information Security Policies and Security Standards are mandatory governance elements.
Information Security Policies and Security Standards are both mandatory governance components. Policies define high-level executive requirements and organizational goals, while standards define compulsory, measurable technical requirements and configuration baselines.
Step-by-Step Solution
Key Concept
Security Governance Hierarchy (Policies, Standards, Baselines, Guidelines, Procedures)