A biotechnology organization is establishing its security governance documentation. Executive leadership mandates the creation of an overarching, non-technical document that outlines management's strategic intent, defines security goals, and establishes mandatory rules for protecting intellectual property across the entire enterprise. Which security governance document type must executive leadership issue to satisfy this requirement?
- Organizational Security PolicyAnswer
- BSecurity Guideline
- CTechnical Security Baseline
- DStandard Operating Procedure
Answer
Organizational Security Policy
An Organizational Security Policy is a high-level, executive-approved document that defines management's intent, security objectives, and mandatory expectations for the entire enterprise. It serves as the foundation of the security governance framework and remains deliberately non-technical to maintain long-term relevance.
Step-by-Step Solution
Key Concept
Security Governance Hierarchy (Policy vs. Standard vs. Baseline vs. Guideline vs. Procedure)