During a multi-cloud infrastructure compliance review, a cloud engineering team is evaluating security controls against corporate documentation. Executive leadership previously published an overarching document mandating that all workloads in production environments must encrypt data in transit. To operationalize this directive, the security engineering department issued a compulsory document specifying that all inter-service cluster communications must strictly utilize TLS 1.3 with specific approved cipher suites and mandatory mutual authentication parameters. Which of the following governance framework document types is represented by this mandatory technical specification?
- ASecurity Policy
- Security StandardAnswer
- CSecurity Guideline
- DSecurity Baseline
Answer
The mandatory technical specification document is a Security Standard.
A Security Standard defines compulsory rules, technologies, parameters, and measurable metrics needed to achieve policy objectives. Specifying TLS 1.3, exact cipher suites, and mutual authentication parameters constitutes a mandatory technical standard.
Step-by-Step Solution
Key Concept
Hierarchy of Security Governance Documents (Policies vs. Standards vs. Baselines vs. Guidelines)