A cybersecurity team at a pharmaceutical organization is revising its governance framework for cloud storage repositories housing sensitive clinical trial data. Which of the following governance document types represent mandatory rules that mandate compliance across the enterprise? (Select TWO.)
- High-level security policy signed by executive leadership that sets organizational security objectivesCevap
- Technical security standards specifying mandatory encryption algorithms and minimum key lengthsCevap
- CSecurity guidelines detailing recommended best practices for local data organization
- DVendor whitepapers describing suggested administrative cloud deployment workflows
- EAuthorization rules determining which specific roles may grant access permissions
Cevap
The high-level security policy signed by executive leadership and the technical security standards specifying mandatory encryption algorithms represent mandatory compliance requirements.
High-level security policies set mandatory corporate direction from executive leadership, while technical security standards specify compulsory baseline rules (such as mandatory key lengths and encryption algorithms). Both are binding governance documents within an enterprise framework.
Adım Adım Çözüm
Anahtar Kavram
Security Policy and Standard Hierarchy