A healthcare organization is issuing new tablet devices to clinical staff. Before provisioning the devices, the information security team must define a mandatory document specifying the minimum security configuration requirements, such as enabling full-disk encryption, enforcing PIN complexity, and disabling unused radio interfaces. Which of the following governance document types should the security team publish to enforce these minimum requirements?
- Security baselineCevap
- BSecurity guideline
- CSecurity policy
- DStandard operating procedure
Cevap
The security team should publish a security baseline because it establishes the mandatory minimum technical configuration standards for specific systems and hardware devices.
A security baseline establishes mandatory minimum security controls and configuration settings that systems, applications, or devices must satisfy. In this scenario, establishing required settings like full-disk encryption and PIN requirements across all tablet devices represents creating a technical baseline.
Adım Adım Çözüm
Anahtar Kavram
Security Baseline
Tahmini Süre:45s