Question

Difficulty: Very hardSecurity Governance Structures and Policy Frameworks

Following an enterprise-wide cloud transformation, an organization's Chief Information Security Officer (CISO) establishes a multi-tiered governance structure to enforce security controls across diverse engineering teams. The framework includes high-level security objectives, mandatory technical requirements for microservices, discretionary coding recommendations, and platform-specific step-by-step configuration steps. During an internal compliance review, a software development team is flagged for utilizing AES-128 encryption across microservices instead of the mandatory enterprise cipher specification. The team lead asserts that technical rules specified outside the overarching executive policy document are non-binding recommendations. Which governance document type did the CISO issue to enforce mandatory technical requirements across the enterprise, and what is its role within the governance hierarchy?

  1. Standard; it establishes mandatory technical specifications and rules that operationalize high-level security policies.Answer
  2. B
    Guideline; it provides mandatory operational commands designed to offer engineering teams flexibility during deployment.
  3. C
    Policy; it details granular system-level configurations and step-by-step execution workflows for cloud platform microservices.
  4. D
    Baseline; it serves as a discretionary reference model designed purely to inform voluntary implementation choices.

Answer

The standard is the governance document type issued to enforce compulsory technical specifications operationalizing high-level security policies.
In security governance hierarchies, a Standard establishes mandatory technical requirements, rules, or configurations (such as compulsory cryptographic algorithms) that operationalize executive Security Policies across an enterprise.

Step-by-Step Solution

1
Analyze the CISO's governance hierarchy and the nature of the requirement.
The requirement (specific AES cipher usage) is a mandatory technical specification designed to enforce consistent controls across engineering teams.
Governance documents are differentiated by their level of abstraction, authority level, and mandatory vs. discretionary nature.
2
Evaluate the distinct roles of governance document types in an enterprise framework.
High-level goals belong in policies, step-by-step workflows belong in procedures, suggestions belong in guidelines, and uniform mandatory technical rules belong in standards.
Standards bridge high-level policy intent with actionable, mandatory technical requirements across systems.
3
Identify the correct governance classification for the CISO's cipher requirement.
The document defining compulsory cipher usage across microservices is a Standard.
Engineers must comply with standards because they carry mandatory authority beneath the overarching policy.

Key Concept

Security Policy Hierarchy (Policies vs Standards vs Baselines vs Guidelines vs Procedures)
Estimated Time:2m 0s
Rate this question