Match each information security governance document type on the left with its correct operational description on the right.
- PolicyHigh-level management mandate establishing overall security direction, goals, and organizational rules.
- StandardCompulsory rules and specific technical parameters required to ensure uniform hardware or software implementation.
- BaselineMinimum mandatory operational configuration standard required for a system before deployment.
- GuidelineDiscretionary recommendations and best practice advice offering flexible implementation options.
Answer
Policy matches the high-level management mandate establishing security goals. Standard matches compulsory rules and technical parameters for uniform implementation. Baseline matches minimum mandatory security configuration standards required for system deployment. Guideline matches discretionary recommendations offering flexible advice.
Each security governance document serves a distinct purpose within an enterprise framework: Policies set executive-level direction and mandates; Standards provide mandatory, uniform technical requirements; Baselines establish the minimum security configuration standard required prior to system deployment; Guidelines supply non-binding, advisory recommendations.
Step-by-Step Solution
Key Concept
Information Security Governance Document Hierarchy