An enterprise executive committee issues a high-level mandate requiring all internal data transmissions containing sensitive customer information to be strongly encrypted. To implement this directive across the organization, the IT security team publishes a mandatory technical document establishing the exact approved cipher suites, minimum key lengths, and required protocol versions that all systems must comply with. Which of the following governance document types is represented by this mandatory technical document?
- Security StandardCevap
- BSecurity Guideline
- CSecurity Policy
- DStandard Operating Procedure
Cevap
The technical specification document is a Security Standard because it contains compulsory technical requirements and configurations that operationalize high-level policy mandates.
A Security Standard specifies compulsory, measurable technical criteria—such as explicit encryption algorithms, minimum key sizes, and approved protocols—that must be implemented to fulfill a broader policy objective.
Adım Adım Çözüm
Anahtar Kavram
Information Security Governance Hierarchy (Policies, Standards, Baselines, Guidelines, Procedures)
Tahmini Süre:1m 15s