Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

Following an application security review, a Chief Information Security Officer (CISO) discovers that engineering teams are utilizing inconsistent cryptographic configurations across microservices. To resolve this, the CISO needs to issue a mandatory document that establishes explicit, uniform technical requirements—such as requiring AES-256 for data at rest and TLS 1.3 for data in transit—without specifying step-by-step execution workflows or platform-specific OS images. Which governance document type should the CISO publish to meet these requirements?

  1. Security standardCevap
  2. B
    Security guideline
  3. C
    Security baseline
  4. D
    Security procedure

Cevap

Security standard
A security standard is a mandatory governance document that specifies explicit, uniform technical requirements, controls, and configurations (such as designated cryptographic algorithms like AES-256 and protocol versions like TLS 1.3) that all teams must follow.

Adım Adım Çözüm

1
Analyze the requirements set forth by the CISO in the scenario.
The document must be mandatory and specify concrete technical rules (AES-256 and TLS 1.3) across systems without providing step-by-step procedures or OS-specific configurations.
Identifying the enforcement level and scope is critical to distinguishing between governance document types.
2
Evaluate each document type against the governance hierarchy characteristics.
Standards set mandatory technical controls and protocols. Guidelines are advisory. Baselines define minimum platform-specific hardening states. Procedures outline step-by-step implementation tasks.
Comparing document definitions isolates the exact document matching mandatory technical rules.
3
Select the governance document that enforces mandatory technical criteria across applications.
A security standard accurately fits mandatory cryptographic requirement specifications.
Security standards bridge high-level policy mandates and operational execution by stipulating mandatory technical parameters.

Anahtar Kavram

Security Standards within Governance Frameworks
Tahmini Süre:1m 15s
Bu soruyu puanla