Question

Difficulty: MediumSecurity Governance Structures and Policy Frameworks

To align with newly enacted data privacy regulations, a financial institution's executive leadership issues an overarching directive declaring that all customer-facing applications must enforce data protection measures. The document establishes high-level business goals, defines organizational scope, and applies mandatorily to all employees, but deliberately omits technical algorithm choices, key lengths, and step-by-step administrative procedures. Which governance document tier does this directive represent?

  1. PolicyAnswer
  2. B
    Standard
  3. C
    Guideline
  4. D
    Baseline

Answer

The executive directive represents a Policy because it is a mandatory, high-level statement of management intent and scope without technical specificity.
A security policy is a top-level governance document issued by senior management that sets the organization's security posture, objectives, and responsibilities. It is mandatory, applies broadly across the organization, and avoids technical details to remain resilient against technology changes.

Step-by-Step Solution

1
Analyze the enforceability and scope of the document described in the scenario.
The directive is mandatory for all personnel and issued directly by executive leadership.
Governance documentation tiers are categorized by enforceability level and organizational authority.
2
Evaluate the technical specificity of the document contents.
The document specifies organizational goals and scope but intentionally avoids naming specific algorithms or step-by-step configurations.
Policies provide top-level direction, whereas lower governance tiers like standards and procedures contain granular technical specifications.
3
Map the document characteristics to the governance document hierarchy.
High-level + Mandatory + Executive Authority = Policy.
This combination of characteristics uniquely defines an information security policy within formal governance frameworks.

Key Concept

Security Policy Hierarchy and Documentation Tiers
Rate this question