An enterprise risk committee is structuring its organizational governance framework. Match each policy framework document type on the left with its defining enforcement requirement and operational characteristics on the right.
- Security PolicyHigh-level executive directive that establishes mandatory organizational security objectives, scope, and responsibilities.
- Security StandardMandatory specification that defines exact technical rules, technologies, or quantitative parameters required across the organization.
- Security BaselineMandatory minimum security configuration threshold established for a specific operating system, platform, or device class.
- Security GuidelineDiscretionary operational recommendation that offers suggested best practices and flexible advice for implementation.
Cevap
Security Policy matches the high-level executive directive; Security Standard matches mandatory specific technical rules; Security Baseline matches mandatory minimum configuration thresholds; Security Guideline matches discretionary operational recommendations.
Each governance document plays a specific role within the governance hierarchy. Security Policies provide broad management authorization and intent. Security Standards enforce mandatory specific technical parameters. Security Baselines establish minimum operational hardening rules for deployed systems. Security Guidelines provide non-mandatory best practices.
Adım Adım Çözüm
Anahtar Kavram
Security Governance Policy Hierarchy
Tahmini Süre:1m 30s