Soru

Zorluk: ZorSecurity Governance Structures and Policy Frameworks

An enterprise cloud security engineering team is updating its operational documentation following a compliance review. Executive leadership has already established an overarching Information Security Policy mandating baseline security hygiene and risk minimization across all enterprise workloads. To operationalize this directive for system deployments, the team needs to publish a document detailing the mandatory minimum security configuration parameters—such as specific SSH cipher suites, disabled unneeded services, and firewall rule defaults—that every Linux virtual machine must satisfy before launch. Which of the following governance document types should the team publish to establish these minimum configuration requirements?

  1. Security baselineCevap
  2. B
    Security guideline
  3. C
    Security policy
  4. D
    Compensating security control

Cevap

Security baseline
A security baseline specifies the mandatory minimum technical hardening settings required for a particular operating system, application, or network device. Because the engineering team is publishing exact OS parameters (such as SSH ciphers and disabled services) that all Linux virtual machines must meet before deployment, the document represents a technical security baseline.

Adım Adım Çözüm

1
Analyze the scope and intent of the required security document described in the scenario.
The requirement specifies mandatory, technical, system-level minimum security parameters (e.g., SSH cipher suites, disabled services) for newly provisioned Linux virtual machines.
Governance documents are categorized by their level of abstraction, authority, and enforceability.
2
Evaluate the document types within the security governance hierarchy.
High-level policies govern organizational directives; standards establish mandatory rules; guidelines offer optional recommendations; baselines set minimum technical configuration standards for specific systems.
Identifying the specific level of technical detail distinguishes baselines from higher-level policy directives.
3
Select the governance document type that matches mandatory minimum OS configuration settings.
A security baseline is the correct designation for platform-specific minimum hardening requirements.
Baselines serve as the functional reference configuration for hardening operating systems before production use.

Anahtar Kavram

Security Governance Hierarchy (Policy vs. Standard vs. Baseline vs. Guideline)
Bu soruyu puanla