A financial technology firm's executive board issues a high-level directive requiring all employee remote access connections to utilize multi-factor authentication. To implement this directive across the organization, the security operations team must publish a mandatory document that defines the specific technical controls and required configuration rules for all remote access gateways. Which governance document type should the team publish to establish these mandatory requirements?
- Security StandardAnswer
- BSecurity Guideline
- CStandard Operating Procedure
- DAcceptable Use Policy
Answer
Security Standard
A security standard translates high-level policy objectives into specific, mandatory technical rules and configuration requirements that technical teams must adhere to.
Step-by-Step Solution
Key Concept
Security Standards vs. Guidelines, Policies, and Procedures