Following a third-party compliance audit that highlighted inconsistent multi-cloud storage configurations, an enterprise Chief Information Security Officer (CISO) publishes a high-level organizational mandate requiring all data at rest containing non-public personal information (NPI) to be protected with strong cryptographic controls. To translate this high-level directive into mandatory, non-negotiable operational requirements for deployment pipelines across all engineering units, the security governance committee drafts a document specifying exact encryption algorithms (AES-256), mandatory key rotation schedules (every 90 days), and rigid access control lists. Which document type in the security governance hierarchy is the committee publishing to establish these mandatory technical specifications?
- Security StandardCevap
- BSecurity Guideline
- CPreventive Control Matrix
- DAuthorization Framework