Question

Difficulty: EasySecurity Governance Structures and Policy Frameworks

Match each security governance document type to its corresponding operational characteristic within an enterprise governance framework.

  • Security PolicyHigh-level organizational directive that defines mandatory security objectives and administrative authority.
  • Security StandardMandatory course of action or technical requirement that enforces specific compliance rules across the organization.
  • Security GuidelineDiscretionary recommendation or best practice that offers operational advice without strict compliance enforcement.
  • Security BaselineMandatory minimum security configuration threshold applied to specific systems or operational environments.

Answer

Security Policy matches the high-level directive statement; Security Standard matches the mandatory compliance requirement; Security Guideline matches the discretionary advice; Security Baseline matches the minimum configuration threshold.
In security governance, documents follow a formal hierarchy: Policies provide top-down executive leadership direction; Standards define mandatory procedural and technical requirements; Guidelines offer non-binding best practice advice; and Baselines establish minimum security build configurations for IT assets.

Step-by-Step Solution

1
Identify mandatory versus non-mandatory governance documents.
Guidelines are non-mandatory (discretionary), while policies, standards, and baselines are mandatory.
Governance frameworks explicitly distinguish between mandatory directives and discretionary recommendations.
2
Differentiate high-level strategic directives from implementation-level controls.
Policies reflect executive management intent, whereas standards and baselines detail specific rules and minimum system settings.
Document hierarchy ranges from high-level management objectives down to technical implementation parameters.
3
Map each term to its specific operational definition.
Pair Policy with high-level directive, Standard with mandatory course of action, Guideline with discretionary advice, and Baseline with minimum security configuration.
Each document type fulfills a distinct level of governance within the organizational hierarchy.

Key Concept

Security Governance Document Hierarchy and Enforceability
Rate this question