An enterprise streaming media organization's executive security leadership issues an overarching mandate requiring all internal network microservices to enforce strict cryptographic protection. To enact this, the cloud engineering team publishes a document specifying mandatory technical requirements, including the exact protocol (mTLS) and minimum key lengths that all production container clusters must enforce without exception. Which of the following governance document types best categorizes this technical mandate?
- ASecurity guideline
- Security standardCevap
- CSecurity policy
- DCompensating control
Cevap
Security standard
The correct answer is the option designating a security standard. In security governance frameworks, a policy sets high-level executive intent, while a security standard establishes compulsory, non-discretionary rules and technical parameters (such as protocol and key length mandates) required to comply with that policy across the enterprise.
Adım Adım Çözüm
Anahtar Kavram
Distinction between Security Policies, Standards, Guidelines, and Baselines