An enterprise security manager is defining the organization's internal governance framework. Which of the following document types represent mandatory rules or directives within an enterprise security governance structure? (Select TWO).
- High-level security policies established by executive managementAnswer
- Technical security standards that specify compulsory requirementsAnswer
- CDiscretionary security guidelines that provide flexible recommendations
- DExternal vendor security whitepapers offering general technical advice
- EInformational security awareness posters distributed to office staff
Answer
High-level security policies established by executive management and technical security standards that specify compulsory requirements.
Within an enterprise security governance framework, high-level security policies set by leadership and technical security standards are compulsory and mandatory for all organizational members and systems to follow.
Step-by-Step Solution
Key Concept
Security Governance Hierarchy (Mandatory Policies and Standards vs. Discretionary Guidelines)
Estimated Time:45s