A financial institution is restructuring its cybersecurity governance framework to resolve ambiguities between executive mandates, operational requirements, and administrative duties. The Chief Information Security Officer (CISO) must clearly delineate the legal enforceability of document types and role responsibilities across the organization. Which of the following statements accurately characterize governance structures and policy hierarchy principles within an enterprise security framework? (Select TWO.)
- High-level security policies represent mandatory executive directives that establish organizational security objectives and define compliance expectations.Answer
- Security baselines specify mandatory minimum technical configuration standards that system administrators must enforce across specific operating environments.Answer
- CSecurity guidelines act as mandatory operational checklists that internal auditors enforce to measure technical compliance across enterprise systems.
- DTechnical data custodians retain ultimate business authority to establish data classification levels and accept risks associated with enterprise assets.
- ESecurity standards function as non-binding recommendations provided to software engineers to guide system configuration decisions.
Answer
Security policies are mandatory executive directives setting overarching organizational security goals, and security baselines establish mandatory minimum technical configuration requirements across systems.
High-level security policies serve as top-tier mandatory directives created by executive leadership to outline organizational goals and compliance bounds. Security baselines define mandatory minimum baseline settings and technical controls required to maintain consistent security postures across IT infrastructure.
Step-by-Step Solution
Key Concept
Enterprise Policy Hierarchy and Governance Roles
Estimated Time:1m 30s