Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

An autonomous vehicle fleet management enterprise is restructuring its security management oversight framework following an external compliance review. Match each security governance document type on the left with its corresponding organizational function and enforcement authority on the right.

  • Acceptable Use PolicyMandatory high-level administrative directive defining legal boundaries and rules for using organizational assets.
  • Technical Security StandardMandatory requirement specifying uniform technology selections, protocols, and encryption algorithms across systems.
  • System Security BaselineMandatory minimum hardened configuration build required for a specific platform before entering production.
  • Operational Security GuidelineDiscretionary recommendations and best-practice advice providing flexibility during implementation.

Cevap

Acceptable Use Policy matches mandatory high-level administrative directive defining legal boundaries for using assets; Technical Security Standard matches mandatory requirement specifying uniform technology selections and protocols; System Security Baseline matches mandatory minimum hardened configuration build required prior to production deployment; Operational Security Guideline matches discretionary recommendations providing flexibility.
Each item correctly aligns with its precise position in the governance documentation hierarchy: policies set compulsory behavioral rules, standards dictate uniform technical controls, baselines set mandatory minimum deployment configurations, and guidelines provide non-mandatory advice.

Adım Adım Çözüm

1
Evaluate the administrative weight and audience of high-level policy documentation.
Identify Acceptable Use Policies as mandatory organizational directives focused on user behavior and asset usage.
Policies sit at the top of the governance hierarchy and establish enforceable behavioral boundaries.
2
Differentiate between enterprise-wide technical rules and platform-specific initial configurations.
Categorize Technical Security Standards as compulsory technology specifications and System Security Baselines as minimum hardened deployment builds.
Standards specify mandated technologies or protocols, whereas baselines define the mandatory starting security state for individual operating platforms.
3
Distinguish mandatory compliance artifacts from advisory documentation.
Associate Operational Security Guidelines with discretionary advice.
Guidelines differ from policies, standards, and baselines because they are not compulsory and permit operational discretion.

Anahtar Kavram

Security Governance Documentation Hierarchy
Bu soruyu puanla