A security analyst is reviewing a high-level organizational document that explicitly states all company-owned endpoints must enforce encryption at rest to protect sensitive data. The document provides overall leadership direction and is mandatory for all employees, but it does not detail specific software configurations or step-by-step commands. Which of the following governance document types best describes this document?
- PolicyAnswer
- BGuideline
- CBaseline
- DProcedure
Answer
Policy
A security policy is a high-level directive issued by senior management that sets mandatory requirements and principles for protecting organizational assets without prescribing specific implementation steps.
Step-by-Step Solution
Key Concept
Security Policy Hierarchy and Document Types