Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

An e-commerce corporation is auditing its security program to ensure proper alignment between executive directives, technical requirements, and operational advice across software development teams. The Chief Information Security Officer (CISO) publishes an updated organizational framework document. Which of the following governance elements represent mandatory requirements that organizational members and technical systems must strictly comply with? (Select TWO.)

  1. Information Security Policies detailing high-level management goals, objectives, and organizational directives for asset protectionCevap
  2. Security Standards specifying mandatory baseline technical configurations and specific operational rules, such as enforcing AES-256 encryption for sensitive customer databasesCevap
  3. C
    Security Guidelines suggesting best practices for microservice code refactoring and optional performance optimizations
  4. D
    Operational Guidelines offering recommended methods for developers choosing local integrated development environment (IDE) extensions
  5. E
    Access Control Guidelines suggesting advisory principles for defining role-based authorization rules during local testing

Cevap

Information Security Policies and Security Standards are mandatory governance elements.
Information Security Policies and Security Standards are both mandatory governance components. Policies define high-level executive requirements and organizational goals, while standards define compulsory, measurable technical requirements and configuration baselines.

Adım Adım Çözüm

1
Analyze the core characteristics of governance document types within an enterprise framework.
Identify that policies (high-level management directives) and standards (mandatory baseline configurations) are compulsory, whereas guidelines are advisory.
Governance frameworks separate mandatory directives from discretionary recommendations.
2
Evaluate the option choices against mandatory enforcement criteria.
Select the high-level policy directive and the technical security standard as the compulsory items.
Both policies and standards carry explicit mandatory compliance mandates.

Anahtar Kavram

Security Governance Hierarchy (Policies, Standards, Baselines, Guidelines, Procedures)
Bu soruyu puanla