An organization is establishing a comprehensive security governance framework. The Chief Information Security Officer (CISO) needs to publish documents that define mandatory, high-level organizational security objectives as well as detailed step-by-step instructions for technical teams to execute. Which of the following governance document types fulfill these specific requirements? (Select TWO).
- PolicyCevap
- ProcedureCevap
- CGuideline
- DStandard
- EDeterrent control
Cevap
The correct document types are Policy (which defines high-level mandatory objectives) and Procedure (which provides step-by-step instructions).
Policies establish high-level mandatory goals and organizational security intentions mandated by management. Procedures complement policies by defining exact, step-by-step instructions for technical personnel to execute operational tasks.
Adım Adım Çözüm
Anahtar Kavram
Security Governance Hierarchy