Soru

Zorluk: ZorSecurity Governance Structures and Policy Frameworks

Following an external compliance audit that uncovered inconsistent multi-cloud storage configurations across divisions, a Chief Information Security Officer (CISO) restructures the organization's security documentation hierarchy. The objective is to establish clear operational boundaries by distinguishing strictly enforceable mandates from discretionary guidance. Which of the following governance document types represent mandatory elements within an enterprise governance framework? (Select TWO.)

  1. High-level Information Security Policy establishing broad security requirements and management directivesCevap
  2. Technical Standards specifying compulsory encryption algorithms and exact configuration parametersCevap
  3. C
    Security Guidelines offering suggested best practices for cloud storage bucket administration
  4. D
    Discretionary Baselines permitting individual business units to determine minimum security controls independently
  5. E
    Compensating Controls policy that substitutes mandatory user authentication with optional data authorization checks

Cevap

The mandatory governance elements within an enterprise framework are the high-level Information Security Policy and Technical Standards.
An enterprise Information Security Policy and Technical Standards are mandatory compliance documents. Policies establish executive-level security goals and requirements, while Standards define specific mandatory controls, technical parameters, and configurations needed to uphold those policies across the organization.

Adım Adım Çözüm

1
Analyze the enforceability level of governance document types in an enterprise framework.
Governance documents are divided into mandatory directives (Policies, Standards, Baselines, Procedures) and discretionary guidance (Guidelines).
Establishing clear operational governance requires separating enforced compliance requirements from optional recommendations.
2
Evaluate the role of Information Security Policy and Technical Standards.
Information Security Policy provides executive-level mandatory intent, while Technical Standards specify compulsory rules and configurations to achieve that intent.
Both documents require mandatory compliance across all organizational units.
3
Evaluate non-mandatory options and misconceptions.
Guidelines provide non-binding recommendations, and baselines cannot be discretionary because they set required minimum security thresholds.
Categorizing guidelines or discretionary baselines as mandatory compliance items violates established governance hierarchy definitions.

Anahtar Kavram

Distinguishing mandatory enterprise security framework elements (Policies, Standards, Baselines, Procedures) from discretionary elements (Guidelines).
Bu soruyu puanla