A Chief Information Security Officer (CISO) is structuring an organization's governance framework. The CISO needs to clearly differentiate between binding organizational rules and discretionary advice. Which of the following governance document types establish MANDATORY requirements that personnel or technical systems must follow? (Select TWO).
- Security PoliciesAnswer
- Security StandardsAnswer
- CSecurity Guidelines
- DSecurity Control Categories
Answer
Security Policies and Security Standards establish mandatory compliance requirements within an enterprise governance hierarchy.
In security governance, Security Policies serve as mandatory high-level statements of management intent that direct user conduct and organizational security expectations. Security Standards set specific, mandatory requirements (such as technical requirements or operational constraints) that systems and users must adhere to without exception.
Step-by-Step Solution
Key Concept
Distinction between mandatory compliance documents (Policies, Standards) and discretionary governance materials (Guidelines).