Question

Difficulty: EasySecurity Governance Structures and Policy Frameworks

Match each information security governance document type on the left with its correct operational description on the right.

  • PolicyHigh-level management mandate establishing overall security direction, goals, and organizational rules.
  • StandardCompulsory rules and specific technical parameters required to ensure uniform hardware or software implementation.
  • BaselineMinimum mandatory operational configuration standard required for a system before deployment.
  • GuidelineDiscretionary recommendations and best practice advice offering flexible implementation options.

Answer

Policy matches the high-level management mandate establishing security goals. Standard matches compulsory rules and technical parameters for uniform implementation. Baseline matches minimum mandatory security configuration standards required for system deployment. Guideline matches discretionary recommendations offering flexible advice.
Each security governance document serves a distinct purpose within an enterprise framework: Policies set executive-level direction and mandates; Standards provide mandatory, uniform technical requirements; Baselines establish the minimum security configuration standard required prior to system deployment; Guidelines supply non-binding, advisory recommendations.

Step-by-Step Solution

1
Identify the high-level governance document
Policy corresponds to high-level executive direction and broad governance mandates.
Policies represent the top tier of governance and define organizational goals and obligations.
2
Distinguish mandatory technical requirements from deployment floors
Standards correspond to compulsory technical parameters for uniformity, while Baselines define minimum deployment configurations.
Standards enforce operational uniformity, whereas baselines establish the absolute minimum security posture required for operation.
3
Identify discretionary documents
Guideline corresponds to discretionary recommendations and advisory suggestions.
Guidelines are non-mandatory options provided to assist staff in achieving compliance.

Key Concept

Information Security Governance Document Hierarchy
Rate this question