Question

Difficulty: EasySecurity Governance Structures and Policy Frameworks

Match each security governance document type on the left with its corresponding operational characteristic on the right.

  • Security PolicyHigh-level, mandatory directive reflecting executive management's intent and goals.
  • Security StandardMandatory course of action or rule defining exact technical specifications or metrics.
  • Security BaselineMinimum required security configuration state for a system or platform.
  • Security GuidelineDiscretionary recommendation or best practice that is not strictly mandatory.

Answer

Security Policy matches with the high-level mandatory directive; Security Standard matches with the mandatory course of action defining technical specifications; Security Baseline matches with the minimum required security configuration state; Security Guideline matches with the discretionary recommendation.
In security governance frameworks, policies set high-level executive direction. Standards provide compulsory technical rules. Baselines define the minimum required operational configurations across hardware or software assets. Guidelines provide flexible, non-binding recommendations.

Step-by-Step Solution

1
Identify top-level managerial intent documents
Map Security Policy to high-level mandatory executive management directives.
Policies represent high-level organizational intentions set by leadership.
2
Distinguish between mandatory technical requirements, configuration thresholds, and discretionary suggestions
Standards are mandatory technical rules; baselines establish minimum configuration states; guidelines are non-mandatory advice.
Governance documents strictly differentiate between required compliance rules (standards/baselines) and optional suggestions (guidelines).

Key Concept

Security Governance Document Hierarchy and Enforceability
Estimated Time:45s
Rate this question