Question

Difficulty: MediumSecurity Governance Structures and Policy Frameworks

A regional healthcare network is preparing to deploy standard desktop computer images across all administrative workstations. The security engineering team needs to document the mandatory minimum hardening requirements and line-by-line operating system security configurations that every system image must strictly conform to prior to being authorized for network placement. Which of the following governance documents should the security team create to specify these mandatory technical settings?

  1. A security baseline documentAnswer
  2. B
    A security guideline document
  3. C
    An organizational security policy
  4. D
    A corrective control specification

Answer

A security baseline document
A security baseline specifies the mandatory minimum security configurations and hardening benchmarks for a specific operating system, hardware platform, or software build. Establishing a baseline ensures all newly deployed systems maintain a consistent, secure configuration state before connecting to the enterprise network.

Step-by-Step Solution

1
Analyze the operational requirements stated in the scenario.
The scenario calls for mandatory minimum hardening settings and technical operating system parameters for system images.
Identifying whether requirements are mandatory, technical, or high-level dictates the appropriate governance document level.
2
Differentiate between governance document tiers in the security policy hierarchy.
Policies state broad management goals, standards set mandatory organizational rules, baselines establish mandatory technical platform build requirements, and guidelines offer discretionary advice.
Understanding document tiers ensures correct governance framework implementation.
3
Select the governance document type that matches mandatory platform configuration settings.
A security baseline directly fulfills the requirement for platform-specific minimum technical configurations.
Baselines serve as the official reference benchmark for technical hardening prior to deployment.

Key Concept

Security Baselines vs Policies and Guidelines
Estimated Time:1m 30s
Rate this question