Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

A Chief Information Security Officer (CISO) is restructuring the enterprise security documentation hierarchy to streamline compliance and operational governance across cloud and on-premises environments. Match each security governance document type to its corresponding operational characteristic.

  • Organizational Security PolicyHigh-level executive mandate establishing mandatory security goals, organizational scope, and management directives.
  • Technical Security StandardMandatory technical specification defining compulsory hardware, software, or configuration controls across the enterprise.
  • System Security BaselineMinimum required security configuration state that all systems must meet before being approved for production.
  • Security GuidelineDiscretionary advice and recommended best practices that provide flexibility in operational execution.

Cevap

Organizational Security Policy matches high-level executive directives; Technical Security Standard matches mandatory technical rules; System Security Baseline matches minimum compulsory initial configurations; Security Guideline matches discretionary advice.
Security governance frameworks establish a clear hierarchy: policies reflect executive leadership directives and scope; standards define specific mandatory technologies and rules; baselines set the minimum compulsory security state for systems; guidelines offer discretionary best practice recommendations.

Adım Adım Çözüm

1
Analyze governance documentation hierarchy levels by enforceability and scope.
Identified policies and standards as mandatory high/medium level directives, baselines as minimum configuration requirements, and guidelines as non-mandatory advice.
Security governance relies on separating mandatory directives from discretionary guidance.
2
Map Organizational Security Policy to executive directives.
Policy aligns with high-level executive mandates that set organizational rules and security intent.
Policies are overarching governance frameworks set by leadership.
3
Differentiate between mandatory standards/baselines and non-mandatory guidelines.
Standards dictate mandatory technical specifications, baselines define minimum deployment configurations, and guidelines offer optional suggestions.
Standards and baselines are strictly compulsory, while guidelines provide operational flexibility.

Anahtar Kavram

Security Policy and Governance Documentation Hierarchy
Bu soruyu puanla