Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

A cybersecurity team at a pharmaceutical organization is revising its governance framework for cloud storage repositories housing sensitive clinical trial data. Which of the following governance document types represent mandatory rules that mandate compliance across the enterprise? (Select TWO.)

  1. High-level security policy signed by executive leadership that sets organizational security objectivesCevap
  2. Technical security standards specifying mandatory encryption algorithms and minimum key lengthsCevap
  3. C
    Security guidelines detailing recommended best practices for local data organization
  4. D
    Vendor whitepapers describing suggested administrative cloud deployment workflows
  5. E
    Authorization rules determining which specific roles may grant access permissions

Cevap

The high-level security policy signed by executive leadership and the technical security standards specifying mandatory encryption algorithms represent mandatory compliance requirements.
High-level security policies set mandatory corporate direction from executive leadership, while technical security standards specify compulsory baseline rules (such as mandatory key lengths and encryption algorithms). Both are binding governance documents within an enterprise framework.

Adım Adım Çözüm

1
Analyze the hierarchy of governance documentation to separate mandatory requirements from discretionary recommendations.
Identified policies and standards as mandatory elements, while guidelines and vendor whitepapers are discretionary.
Governance frameworks mandate compliance through top-level policies and specific technical standards.
2
Evaluate the remaining choices to verify they represent binding governance documents rather than functional permission controls or non-binding guidance.
Confirmed that authorization rules describe access control logic, whereas security policy and security standards fulfill the governance document criteria.
High-level policies dictate organizational goals, and technical standards provide compulsory implementation specifics.

Anahtar Kavram

Security Policy and Standard Hierarchy
Bu soruyu puanla