A governance team at an online retail company is reviewing its security documentation hierarchy to ensure operational compliance across all engineering units. Which of the following governance document types establish mandatory requirements that all employees and system configurations must follow? (Select TWO).
- High-level organizational security policiesAnswer
- Specific technical baseline security standardsAnswer
- CRecommended operational security guidelines
- DDiscretionary implementation whitepapers
- EInformational vendor best practice documents
Answer
The mandatory governance document types are high-level organizational security policies and specific technical baseline security standards.
High-level organizational security policies and specific technical baseline security standards represent compulsory components of a security framework. Policies set top-down management directives that require compliance across the entity, while standards define mandatory operational parameters and baseline controls. In contrast, guidelines, implementation whitepapers, and vendor best practices offer discretionary suggestions rather than enforceable obligations.
Step-by-Step Solution
Key Concept
Mandatory vs. Discretionary Governance Documents