A regional health authority is updating its overarching security governance framework following an infrastructure modernization project. The governance steering committee must clearly distinguish between mandatory governance mandates and non-binding operational material. Which of the following document types constitute mandatory compliance requirements within the enterprise security governance framework? (Select TWO).
- Enterprise Security Policies that state management intent and define high-level mandatory requirements.Cevap
- Technical Security Standards that specify mandatory baseline rules and technology configurations.Cevap
- CSecurity Guidelines that offer recommended practices and discretionary operational advice.
- DCompensating Control Requests that document temporary exemptions from default security controls.
- EVendor Architecture Whitepapers that describe recommended third-party integration patterns.
Cevap
Enterprise Security Policies and Technical Security Standards are both mandatory elements of a security governance framework.
Enterprise Security Policies and Technical Security Standards are mandatory components of security governance. Policies reflect executive leadership direction and establish compulsory high-level rules, while standards define mandatory, measurable technical configurations and operational constraints.
Adım Adım Çözüm
Anahtar Kavram
Hierarchy of Security Governance Documents (Policies, Standards, Baselines, Guidelines, Procedures)
Tahmini Süre:1m 30s