Following an enterprise-wide risk assessment, a multi-national cargo shipping organization dictates that all database servers housing customer payment data must enforce mandatory AES-256 encryption at rest across all operating environments. Which governance document type should the security governance team publish to officially enforce this specific mandatory technical requirement?
- Security standardCevap
- BSecurity guideline
- CCompensating control
- DAuthorization policy
Cevap
Security standard
A security standard establishes compulsory technical requirements, hardware/software specifications, and uniform operational rules to ensure compliance with overarching organizational security policies.
Adım Adım Çözüm
Anahtar Kavram
Distinction between mandatory security standards, discretionary guidelines, and high-level governance policies.