Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

An enterprise risk committee is structuring its organizational governance framework. Match each policy framework document type on the left with its defining enforcement requirement and operational characteristics on the right.

  • Security PolicyHigh-level executive directive that establishes mandatory organizational security objectives, scope, and responsibilities.
  • Security StandardMandatory specification that defines exact technical rules, technologies, or quantitative parameters required across the organization.
  • Security BaselineMandatory minimum security configuration threshold established for a specific operating system, platform, or device class.
  • Security GuidelineDiscretionary operational recommendation that offers suggested best practices and flexible advice for implementation.

Cevap

Security Policy matches the high-level executive directive; Security Standard matches mandatory specific technical rules; Security Baseline matches mandatory minimum configuration thresholds; Security Guideline matches discretionary operational recommendations.
Each governance document plays a specific role within the governance hierarchy. Security Policies provide broad management authorization and intent. Security Standards enforce mandatory specific technical parameters. Security Baselines establish minimum operational hardening rules for deployed systems. Security Guidelines provide non-mandatory best practices.

Adım Adım Çözüm

1
Analyze the enforceability and scope of each governance document type.
Identified whether each document is mandatory or discretionary, and whether it operates at a strategic or technical level.
Governance documents strictly follow a hierarchy where intent flows from high-level management strategy down to operational implementation.
2
Pair each document type with its corresponding role in enterprise security governance.
Mapped policies to strategic directives, standards to mandatory technical rules, baselines to minimum platform configurations, and guidelines to advisory best practices.
Differentiating between mandatory controls (policy, standard, baseline) and discretionary guidance (guideline) prevents compliance misunderstandings.

Anahtar Kavram

Security Governance Policy Hierarchy
Tahmini Süre:1m 30s
Bu soruyu puanla