A Chief Information Security Officer (CISO) is restructuring the enterprise security documentation hierarchy to streamline compliance and operational governance across cloud and on-premises environments. Match each security governance document type to its corresponding operational characteristic.
- Organizational Security PolicyHigh-level executive mandate establishing mandatory security goals, organizational scope, and management directives.
- Technical Security StandardMandatory technical specification defining compulsory hardware, software, or configuration controls across the enterprise.
- System Security BaselineMinimum required security configuration state that all systems must meet before being approved for production.
- Security GuidelineDiscretionary advice and recommended best practices that provide flexibility in operational execution.
Cevap
Organizational Security Policy matches high-level executive directives; Technical Security Standard matches mandatory technical rules; System Security Baseline matches minimum compulsory initial configurations; Security Guideline matches discretionary advice.
Security governance frameworks establish a clear hierarchy: policies reflect executive leadership directives and scope; standards define specific mandatory technologies and rules; baselines set the minimum compulsory security state for systems; guidelines offer discretionary best practice recommendations.
Adım Adım Çözüm
Anahtar Kavram
Security Policy and Governance Documentation Hierarchy