Soru

Zorluk: Çok zorSecurity Governance Structures and Policy Frameworks

An enterprise security governance team is reviewing its information security documentation hierarchy to resolve audit findings regarding governance ambiguity. Match each governance document type on the left with its corresponding organizational characteristic and legal/enforcement property on the right.

  • Security PolicyExecutive-approved mandatory directive defining high-level strategic goals, authority, roles, and risk tolerance across the organization.
  • Security StandardMandatory technical requirement establishing specific compulsory rules, metrics, or cryptographic parameters needed to meet policy goals.
  • Security BaselineMinimum compulsory operational configuration state required for specific hardware, operating systems, or cloud images prior to production.
  • Security GuidelineNon-mandatory operational advisory offering recommended best practices and flexible suggestions to assist staff in decision-making.

Cevap

Security Policy matches executive-approved strategic directives; Security Standard matches mandatory technical rules and metric parameters; Security Baseline matches minimum compulsory hardening settings for specific systems; Security Guideline matches non-mandatory recommended operational advice.
Each governance document type fulfills a distinct role in the governance framework hierarchy: Security Policy sets mandatory strategic intent; Security Standard defines compulsory technical specifications; Security Baseline sets mandatory minimum build states for platforms; and Security Guideline offers non-binding advice.

Adım Adım Çözüm

1
Analyze the overarching scope and authority of governance documents.
Identify high-level directives originating from senior leadership as Security Policies.
Policies establish top-down management intent and risk tolerance across the enterprise.
2
Differentiate mandatory technical specifications from high-level management intent.
Map compulsory technical rules, algorithms, or operational controls to Security Standards.
Standards operationalize policies by enforcing uniform technical requirements across systems.
3
Identify minimum platform-specific hardening requirements.
Assign minimum required security state parameters to Security Baselines.
Baselines serve as the mandatory foundation for platform configuration consistency and security auditing.
4
Evaluate discretionary documentation.
Match optional recommendations and practical advice to Security Guidelines.
Guidelines assist operational teams without imposing strict legal or regulatory compliance penalties.

Anahtar Kavram

Security Governance Documentation Hierarchy (Policy, Standard, Baseline, Guideline)
Tahmini Süre:2m 0s
Bu soruyu puanla