Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

A multinational retail company is standardizing the operational security of its point-of-sale (POS) systems across hundreds of physical store locations. The security committee requires a document that establishes the mandatory minimum technical security settings, such as disabling legacy protocols and enforcing specific firewall port rules, that every POS device must continuously meet. Which of the following governance document types best satisfies this requirement?

  1. Security baselineCevap
  2. B
    Security guideline
  3. C
    Acceptable use policy
  4. D
    Standard operating procedure

Cevap

A security baseline is the governance document type that establishes mandatory minimum technical security settings and configurations for specific systems.
A security baseline defines the minimum required security configuration parameters that a specific class of system or device (such as POS terminals) must satisfy to maintain compliance. It ensures consistent hardening and baseline controls across all deployments.

Adım Adım Çözüm

1
Analyze the scenario requirements
The requirement specifies mandatory minimum technical security settings (e.g., protocol choices, port rules) for a specific system type (POS terminals).
Governance documents serve distinct roles based on whether they specify high-level intent, specific operational steps, discretionary advice, or minimum technical configurations.
2
Map the requirement to governance hierarchy concepts
Minimum required technical security settings represent a hardware/software baseline.
Baselines act as the standard minimum hardening standard that systems must satisfy before deployment and maintain throughout operation.
3
Evaluate alternative options against the requirement
Guidelines are optional, policies set high-level direction or behavioral expectations, and procedures detail step-by-step actions.
Only a security baseline focuses explicitly on enforcing fixed minimum technical parameters across target host environments.

Anahtar Kavram

Security Baseline Configurations within Security Governance Frameworks
Bu soruyu puanla