Question

Difficulty: MediumSecurity Governance Structures and Policy Frameworks

A Chief Information Security Officer (CISO) at a global logistics firm is updating the corporate cybersecurity governance framework to clarify the enforceability of various security documents. Which of the following governance document types establish MANDATORY compliance requirements that enterprise personnel must follow? (Select TWO)

  1. Information Security Policy defining acceptable data handling and employee security responsibilitiesAnswer
  2. Enterprise Encryption Standard specifying approved algorithms, minimum key lengths, and cipher suitesAnswer
  3. C
    Remote Work Best Practices Guideline outlining recommended home network configurations for teleworkers
  4. D
    Incident Response Playbook detailing step-by-step technical execution steps for firewall isolation
  5. E
    Privileged Access Authorization Matrix mapping individual user permissions to administrative roles

Answer

The governance document types that establish mandatory compliance requirements are the Information Security Policy defining acceptable data handling and the Enterprise Encryption Standard specifying approved algorithms and key lengths.
In security governance frameworks, both policies and standards carry mandatory compliance obligations. An Information Security Policy serves as an executive mandate that sets high-level organizational security goals and expectations. An Enterprise Encryption Standard establishes compulsory technical specifications (such as mandatory key lengths and approved algorithms) required to achieve the policy objectives.

Step-by-Step Solution

1
Analyze the hierarchy of governance documentation and determine the intent of each document type.
Identify that policies provide high-level management directives, standards provide mandatory technical/operational specifications, guidelines provide discretionary recommendations, and procedures provide step-by-step execution instructions.
Understanding document authority distinguishes compulsory compliance items from optional or procedural references.
2
Evaluate the choices to isolate documents with mandatory status across the enterprise.
Information Security Policies and Enterprise Encryption Standards both carry compulsory compliance requirements.
Policies and standards are explicitly enforceable across organizational boundaries, whereas guidelines are discretionary and playbooks are task-level procedures.

Key Concept

Security Governance Hierarchy (Policies and Standards as Mandatory Directives vs Guidelines and Procedures)
Rate this question