Soru

Zorluk: ZorSecurity Governance Structures and Policy Frameworks

An organization is restructuring its information security governance framework following a major compliance assessment. The Chief Information Security Officer (CISO) needs to categorize four key documentation elements within the administrative governance hierarchy based on their operational enforcement level and organizational scope. Match each security governance document type on the left with its corresponding operational attribute on the right.

  • Acceptable Use Policy (AUP)High-level, mandatory executive directive defining employee behavioral expectations and authorization boundaries across the enterprise.
  • Data Encryption StandardMandatory technical requirement specifying approved cryptographic suites (e.g., AES-256) for data at rest across all applications.
  • Container Hardening BaselineMinimum required configuration state applied uniformly to all container images prior to deployment in production.
  • Remote Work Security GuidelineDiscretionary recommendations and best practices offering flexible advice for securing home Wi-Fi networks.

Cevap

Acceptable Use Policy matches the high-level mandatory executive directive; Data Encryption Standard matches the mandatory technical requirement specifying cryptographic suites; Container Hardening Baseline matches the minimum required configuration state for container images; Remote Work Security Guideline matches the discretionary recommendations and best practices.
In security governance, documents follow a clear administrative structure: Policies provide high-level mandatory management intent; Standards set compulsory technical requirements; Baselines define minimum mandatory operational configurations; and Guidelines provide non-mandatory, advisory recommendations.

Adım Adım Çözüm

1
Analyze the organizational governance hierarchy level for each document.
Identify high-level policy vs technical standards vs operational baselines vs discretionary guidelines.
Security governance relies on a formal structure where authority and enforcement flow from policies down to guidelines.
2
Differentiate mandatory technical requirements from high-level behavioral directives.
Assign the Acceptable Use Policy to behavioral expectations and the Data Encryption Standard to compulsory technical requirements.
Policies establish overarching behavioral scope, whereas standards specify exact technology controls.
3
Separate mandatory baseline configuration states from advisory guidelines.
Assign Container Hardening Baseline to mandatory minimum build settings and Remote Work Security Guideline to discretionary best practices.
Baselines are enforceable build minimums, while guidelines are optional recommendations.

Anahtar Kavram

Security Policy and Governance Hierarchy
Tahmini Süre:2m 0s
Bu soruyu puanla