Soru

Zorluk: ZorSecurity Governance Structures and Policy Frameworks

A financial enterprise is migrating its transaction processing infrastructure to a cloud-native container environment. The Chief Information Security Officer (CISO) mandates that every production container host and image must enforce an identical set of mandatory minimum security configurations, including root access restrictions, disabled unused daemons, and read-only root filesystems. Which of the following security governance documents should the security architecture team publish to define these compulsory minimum configuration settings across all host platforms?

  1. A security baselineCevap
  2. B
    A security guideline
  3. C
    An acceptable use policy
  4. D
    A technical procedure manual

Cevap

The correct document type is a security baseline, which specifies the mandatory minimum configuration settings and hardening requirements for systems across an organization.
A security baseline defines the minimum mandatory security state and configuration settings that systems, services, or platforms must maintain. Because the scenario calls for mandatory technical configuration settings (such as read-only filesystems and root restrictions) enforced across all container deployments, a security baseline is the exact governance document required.

Adım Adım Çözüm

1
Analyze the scenario requirements
The requirement specifies mandatory, uniform, low-level technical configuration settings (disabling unneeded daemons, restricting root privileges, enforcing read-only filesystems) across all production container platforms.
Identifying whether the requirement is high-level, technical, mandatory, or discretionary determines its position in the governance hierarchy.
2
Evaluate governance document characteristics
High-level rules are defined by policies; technical metrics/protocols are set by standards; step-by-step instructions are detailed in procedures; optional advice is conveyed in guidelines; and minimum mandatory technical configurations are established by baselines.
Security governance relies on strict documentation taxonomy to ensure operational enforcement.
3
Select the governance document matching compulsory technical hardening settings
A security baseline directly satisfies the need for compulsory minimum system configuration benchmarks.
Baselines serve as the reference standard against which system compliance and configuration drift are measured.

Anahtar Kavram

Security Baseline Definitions and Governance Hierarchy
Tahmini Süre:1m 30s
Bu soruyu puanla